- Key Takeaways
- The Current Mandate: EO 14412 and OMB M-26-15
- Ownership and Inventory: What Every Plan Must Contain
- Procurement: What Vendors Now Need to Demonstrate
- Validated Implementations: The Shared Chokepoint
- Migration Waves and Key Dates
- Evidence: Turning Migration Into an Auditable Outcome
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Program With Dates, Not a Directive to Interpret
- Frequently Asked Questions
Quick answer: Federal PQC migration now runs on a specific, dated program model rather than general guidance. Executive Order 14412 (June 22, 2026) and OMB Memorandum M-26-15 (June 24, 2026) lay out a five-phase timeline from 2026 through 2035, require every covered agency to submit a PQC migration plan by roughly October 22, 2026, and specify exactly what that plan has to contain: automated inventory methodology, risk-based prioritization, a crypto-agility architecture, third-party coordination, resourcing, and governance roles. Defense systems run on a parallel track under CNSA 2.0, with a January 1, 2027 acquisition gate. This guide converts that program model into an execution checklist: ownership, inventory, procurement, validated implementations, migration waves, and evidence.
Federal and defense PQC guidance has moved fast in 2026, and the practical challenge for agencies and contractors is less “what does quantum-resistant mean” and more “what exactly does our migration plan need to contain, by what date, and who signs off on each piece.” This guide is built directly from the current executive order, OMB memo, and CNSA 2.0 requirements, not general best practice.
Key Takeaways
- EO 14412 and OMB M-26-15, both issued in June 2026, establish a five-phase civilian federal migration timeline running 2026 to 2035, with agency migration plans due roughly 120 days from the memo, around October 22, 2026.
- Required migration plan content is specific: automated inventory methodology, risk-based prioritization by system impact level, a crypto-agility architecture plan, third-party coordination, resourcing estimates, and governance roles.
- Defense systems run on CNSA 2.0’s separate track, with a January 1, 2027 acquisition gate, and NSA-led validation for High Assurance systems distinct from civilian CMVP validation.
- Validation is the shared chokepoint across both tracks: FIPS 140-3 (CMVP) validation currently runs around 18 months, and neither track has widened that pipeline despite direction to accelerate it.
- The FIPS 140-2 sunset on September 21, 2026 moves all remaining FIPS 140-2 certificates to CMVP’s Historical list, a hard compliance date that lands before most agency migration plans are even due.
The Current Mandate: EO 14412 and OMB M-26-15
President Trump signed Executive Order 14412 on June 22, 2026, mandating an accelerated federal transition to post-quantum cryptography. OMB followed two days later, on June 24, with Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” the operational playbook for civilian agencies. The speed of that follow-up, two days against an allowed ninety, signals the memo was drafted alongside the order rather than in response to it. M-26-15 sets out the first explicit five-phase federal PQC timeline: Phase 1 (2026-2027) covers strategy, planning, and inventory of High Value Assets and high-impact systems; Phase 2 (2027-2028) covers pilots and early migration; Phase 3 (2028-2030) covers prioritized key-establishment migration; Phase 4 (2031) covers signature migration; Phase 5 (2035) covers full migration of remaining systems.
Ownership and Inventory: What Every Plan Must Contain
M-26-15 is specific about migration plan content, which is what turns this from a general directive into an execution checklist. Required elements include: an automated cryptographic inventory methodology, not a manual spreadsheet exercise; risk-based prioritization keyed to FIPS 199 impact level and High Value Asset status; a crypto-agility architecture plan describing how the agency will accommodate future algorithm changes; third-party and vendor coordination; resourcing and funding estimates; and clearly assigned governance roles. Ownership has to be assigned before inventory work can proceed meaningfully, and the memo’s framing makes clear this is leadership-team accountability, not a delegated CISO project running in isolation.
Procurement: What Vendors Now Need to Demonstrate
For vendors selling into the federal market, the practical shift is that validated cryptography, not just algorithm support claimed in a data sheet, is becoming foundational to procurement eligibility. A product that supports ML-KEM and ML-DSA technically but has not entered FIPS 140-3 validation is not the same, from a procurement standpoint, as one with an active certificate or a credible, dated path to one. Agencies should expect to see, and vendors should expect to provide, current validation status with certificate numbers where available, or a specific, dated projection where validation is pending, the same evidentiary standard covered in our CNSA 2.0 compliance guide for defense contractors.
Validated Implementations: The Shared Chokepoint
Both the civilian and defense tracks depend on validation processes that have not scaled to meet 2026’s demand. On the civilian side, CMVP gates any product needing FIPS 140-3 validation, currently running around 18 months or longer per submission. On the defense High Assurance side, NSA certification gates every cryptographic unit destined for classified use. EO 14412 directs NIST to accelerate CMVP, and the Department of War’s own PQC strategy calls for streamlined NSA certification, but neither directive has yet widened the actual pipeline. Program plans that assume validation timelines will simply improve on schedule are building on an unproven assumption; plans that treat the current 18-month-plus CMVP timeline as the baseline, and start submissions accordingly, are the ones that will actually clear a 2027 or 2030 gate.
A separate, closer deadline compounds this: on September 21, 2026, CMVP moves all remaining FIPS 140-2 validated certificates to its Historical list. Any system still relying on an active FIPS 140-2 certificate needs a plan for that transition well before most agencies’ PQC migration plans are even due to OMB.
Migration Waves and Key Dates
| Date | Milestone |
|---|---|
| September 21, 2026 | FIPS 140-2 certificates move to CMVP’s Historical list |
| ~October 22, 2026 | Civilian agency PQC migration plans due to OMB and ONCD (120 days from M-26-15) |
| January 1, 2027 | CNSA 2.0 acquisition gate for National Security Systems |
| December 31, 2027 | NIST PQC pilot project completion deadline |
| January 2, 2030 | Federal TLS 1.3 support deadline |
| December 31, 2030 | Key-establishment migration for civilian HVAs and high-impact systems; DoW support-PQC-or-phase-out gate; CNSA 2.0 exclusive use for signing and networking |
| December 31, 2031 | Digital-signature migration for civilian HVAs and high-impact systems; DoW use-PQC gate |
| 2033 | CNSA 2.0 exclusive-use deadline for web/cloud, OS, large PKI, and constrained NSS devices |
| 2035 | Full migration of remaining federal civilian systems |
Evidence: Turning Migration Into an Auditable Outcome
NIST’s CSWP 48 maps PQC migration capabilities directly to NIST Cybersecurity Framework 2.0 and SP 800-53 Rev. 5 controls, giving governance teams a structured way to express migration progress as an auditable risk outcome rather than an isolated engineering effort. CISA and NIST also owe CBOM minimum-elements guidance roughly 270 days after EO 14412, expected around March 2027, which will standardize what a compliant cryptographic bill of materials needs to contain for federal evidence purposes. Building your inventory and evidence practices against that expected standard now, rather than waiting for the final guidance, avoids a rework cycle once it publishes.
What We’d Actually Recommend
Assign migration ownership at the leadership level immediately if it has not been done, since M-26-15 explicitly frames this as beyond a delegated CISO responsibility. Build the automated inventory the memo requires now, ahead of the October plan deadline, rather than treating inventory as a checkbox to satisfy after the plan is drafted. Submit FIPS 140-3 validation requests against the current 18-month-plus timeline, not an assumed accelerated one, and track the September 2026 FIPS 140-2 sunset as a distinct, nearer-term deadline from the broader PQC migration plan.
How Encryption Consulting Can Help
The automated inventory M-26-15 requires, and the evidence base CSWP 48 and the coming CBOM minimum-elements guidance expect, are exactly what CBOM Secure is built to produce, mapping every algorithm, key, and certificate across your agency or contractor environment into a structured, audit-ready inventory rather than a one-time spreadsheet exercise.
Our PQC Advisory Services build the full program model this guide describes, ownership structure, risk-based prioritization, crypto-agility architecture, and the phased migration wave plan aligned to M-26-15 and CNSA 2.0, into a submittable federal migration plan. Where certificate issuance is part of the execution, CertSecure Manager carries the plan into production across classical, hybrid, and CNSA 2.0-parameter certificates, and where hardware validation is the constraint, our HSM Services assess current HSM firmware against CMVP and NIAP requirements.
A Program With Dates, Not a Directive to Interpret
Federal PQC migration stopped being a general planning exercise in June 2026. EO 14412 and OMB M-26-15 specify exactly what a migration plan has to contain and when it is due; CNSA 2.0 specifies exactly which algorithms and parameter sets defense systems need and by when. The organizations that clear each gate cleanly are the ones treating validation lead time as the real constraint, building the required automated inventory now rather than after the plan is due, and tracking the September 2026 FIPS 140-2 sunset as its own near-term deadline distinct from the longer PQC migration arc.
Frequently Asked Questions
When are federal agency PQC migration plans due?
Roughly October 22, 2026, 120 days from OMB Memorandum M-26-15’s June 24, 2026 issuance. Plans go to both OMB and the Office of the National Cyber Director.
What has to be in a federal PQC migration plan?
An automated cryptographic inventory methodology, risk-based prioritization by system impact level, a crypto-agility architecture plan, third-party coordination, resourcing and funding estimates, and assigned governance roles, per OMB M-26-15’s specific requirements.
Is the federal PQC timeline the same for civilian agencies and defense systems?
No. Civilian agencies follow OMB M-26-15’s five-phase 2026-2035 timeline. Defense systems run on CNSA 2.0’s separate track, with a January 1, 2027 acquisition gate and its own 2030/2031/2033 milestones, administered by the NSA rather than OMB.
How long does FIPS 140-3 validation currently take?
Around 18 months or longer as of 2026. Executive Order 14412 directs NIST to accelerate CMVP, but that pipeline has not yet been demonstrably widened, making current timelines the safer planning assumption.
What happens to FIPS 140-2 certificates on September 21, 2026?
All remaining FIPS 140-2 validated certificates move to CMVP’s Historical list. Systems relying on active FIPS 140-2 validation need a transition plan for this date, which lands before most agencies’ broader PQC migration plans are even due.
- Key Takeaways
- The Current Mandate: EO 14412 and OMB M-26-15
- Ownership and Inventory: What Every Plan Must Contain
- Procurement: What Vendors Now Need to Demonstrate
- Validated Implementations: The Shared Chokepoint
- Migration Waves and Key Dates
- Evidence: Turning Migration Into an Auditable Outcome
- What We'd Actually Recommend
- How Encryption Consulting Can Help
- A Program With Dates, Not a Directive to Interpret
- Frequently Asked Questions
