Quick answer: CISA’s Post-Quantum Cryptography Initiative does not hand organizations a ready-made project plan. It gives them a cryptographic inventory framework, a vendor engagement model, and a two-tier product categories list (published January 23, 2026 under Executive Order 14306), and leaves the sequencing up to the organization. This guide turns that guidance into a 90-day action plan: assign ownership in the first 30 days, build the inventory in the next 30, and use it to drive vendor engagement and procurement language in the final 30.
CISA has published a genuinely useful body of post-quantum guidance since 2022. What it has not published is a step-by-step operational plan that tells a mid-sized enterprise or a critical infrastructure operator exactly what to do on day one, day thirty, and day ninety. That translation gap is where most organizations stall, not because the guidance is unclear, but because it is organized around federal policy structure rather than an internal execution timeline.
This guide converts CISA’s inventory, vendor engagement, and risk prioritization guidance into a concrete 90-day plan covering ownership, discovery, procurement, and governance.
Key Takeaways
- CISA’s PQC Initiative, established July 6, 2022, organizes work into four areas: risk assessment, interagency engagement, tool development, and published guidance.
- The core operational document is the joint CISA, NSA, and NIST factsheet “Quantum-Readiness: Migration to Post-Quantum Cryptography,” which frames a roadmap around cryptographic inventory, vendor engagement, and supply chain assessment.
- CISA published its PQC Product Categories List on January 23, 2026, under Executive Order 14306, splitting products into “Widely Available” and “Transitioning” tiers to guide procurement.
- None of this guidance sequences itself into a timeline. The 90-day plan below does that translation: ownership first, inventory second, vendor engagement and procurement language third.
- CISA’s guidance is advisory for most organizations, but it increasingly intersects with binding requirements like Executive Order 14409’s 2030 and 2031 federal deadlines, which extend to covered contractors.
What CISA’s PQC Initiative Actually Covers
CISA established its Post-Quantum Cryptography Initiative on July 6, 2022, organizing the work into four areas: risk assessment of the 55 National Critical Functions, interagency engagement, tool development, and published guidance. In practice, three artifacts from that initiative matter most to enterprise planning teams:
- The Quantum-Readiness factsheet: a joint CISA, NSA, and NIST document that recommends organizations build a quantum-readiness roadmap around cryptographic inventory, vendor engagement, and supply chain risk assessment.
- The PQC Product Categories List: published January 23, 2026 in response to Executive Order 14306, classifying hardware and software into “Widely Available” categories (cloud services, web browsers, endpoint security, where PQC-capable products already exist commercially) and “Transitioning” categories (networking hardware and software, storage area networks, identity and access management, containers, where PQC capability is still maturing).
- Automated Cryptographic Discovery and Inventory (ACDI) tool guidance: developed with NIST’s National Cybersecurity Center of Excellence to help organizations evaluate discovery and inventory tooling, documented in NIST SP 1800-38.
The Product Categories List is advisory, not a procurement mandate, for most organizations. But it is already functioning as a de facto benchmark: CISA has publicly signaled that vendors without a credible PQC roadmap risk exclusion from federal opportunities as the list matures.
The 90-Day Enterprise Action Plan
CISA’s guidance describes what a mature quantum-readiness program looks like. It does not sequence how to get there from zero. Here is a sequencing that works for most enterprise and critical infrastructure organizations.
Days 1 to 30: Ownership and Scope
- Name a single accountable owner for the PQC transition program, reporting to the CISO or equivalent, mirroring the migration-lead structure federal agencies are now required to stand up under Executive Order 14409.
- Define scope against CISA’s National Critical Functions framing if applicable, or against your own high-value assets and high-impact systems if not.
- Identify which of CISA’s Product Categories List tiers apply to your current vendor footprint, so procurement conversations in Days 61 to 90 start from an accurate baseline rather than a cold start.
Days 31 to 60: Cryptographic Inventory
- Build the cryptographic inventory CISA’s factsheet calls the foundation of the roadmap: every certificate, key, algorithm, and library in use, mapped to system owner and criticality.
- Evaluate discovery and inventory tooling against the ACDI framework NIST and CISA developed, rather than building inventory processes from scratch.
- Flag systems that fall into CISA’s “Transitioning” product category tier specifically, since those are the systems most likely to lack a mature PQC-capable replacement today.
Days 61 to 90: Vendor Engagement and Procurement
- Engage technology vendors using CISA’s supply chain assessment guidance: ask directly whether each vendor’s product falls in the Widely Available or Transitioning tier, and request a dated PQC roadmap for anything in the latter.
- Update procurement language and RFP templates to require PQC-capable products in categories where CISA’s list shows they are already widely available, consistent with the acquisition guidance the list is designed to support.
- Establish the governance cadence, quarterly review of the inventory, the vendor roadmap tracker, and the CISA product categories list, since CISA updates that list on an ongoing basis rather than as a one-time publication.
Risk Prioritization: What to Migrate First
CISA’s National Critical Functions framing is useful even for organizations outside critical infrastructure, because it prioritizes by consequence rather than by convenience. Applied to enterprise planning, the same logic ranks systems by two factors: how long the data or signature needs to remain trustworthy, and how exposed the system is to harvest-now-decrypt-later collection today. Systems handling long-lived sensitive data, internet-facing key exchange, and long-lived signing keys such as code-signing or CA roots should move to the front of the queue regardless of how CISA’s product category tiers classify the specific technology involved.
How Encryption Consulting Can Help
The 90-day plan above lives or dies on the accuracy of the inventory built in Days 31 to 60. CBOM Secure builds and continuously maintains that inventory, aligned to the same discovery principles behind CISA and NIST’s ACDI tooling guidance, scanning certificates, keys, libraries, and protocols across on-prem, cloud, and hybrid environments and mapping each finding to an owner and a CISA product category tier where relevant.
From that inventory, our PQC Advisory Services build the governance layer CISA’s guidance assumes but does not provide: a risk-prioritized migration roadmap, a vendor engagement tracker aligned to the Widely Available and Transitioning tiers, and the quarterly review cadence that keeps the program current as CISA updates its product categories list.
From Guidance to a Working Plan
CISA’s PQC guidance is credible and well constructed, and it is also organized around policy structure rather than an execution calendar. The organizations that make progress are the ones that convert it into a plan with owners and dates: ownership in the first 30 days, an accurate cryptographic inventory in the next 30, and vendor engagement and procurement language built on that inventory in the final 30. Everything after that is governance, keeping the inventory current and the vendor roadmap tracker updated as CISA’s own guidance continues to evolve.
Frequently Asked Questions
Is CISA’s PQC Product Categories List mandatory?
It is advisory for most organizations. It guides federal procurement decisions under Executive Order 14306, and organizations should treat it as a strong signal for planning, but it does not itself impose a compliance deadline the way Executive Order 14409’s federal migration dates do.
What is the difference between the “Widely Available” and “Transitioning” product tiers?
Widely Available covers categories, like cloud services, web browsers, and endpoint security, where PQC-capable products already exist commercially and organizations should only acquire PQC-capable options. Transitioning covers categories, like networking hardware, storage area networks, and identity and access management, where PQC capability is still maturing across the vendor market.
How often does CISA update the Product Categories List?
CISA has committed to regularly updating the list rather than treating it as a one-time publication, which is why the governance step in the 90-day plan includes a recurring review cadence rather than a single check.
Does CISA’s guidance apply outside critical infrastructure sectors?
The inventory, vendor engagement, and risk prioritization framework is written for critical infrastructure and government network owners specifically, but the underlying methodology, and the product categories list itself, is useful planning input for any enterprise building a PQC roadmap.
How does CISA’s guidance relate to Executive Order 14409?
They are complementary but distinct. CISA’s product categories list and readiness guidance are advisory tools that support planning. Executive Order 14409 sets binding federal deadlines, key establishment by December 31, 2030 and digital signatures by December 31, 2031, and extends compliance obligations to covered contractors through a forthcoming FAR rule.
