- Key Takeaways
- What Does the Federal Quantum Action Plan Actually Mandate?
- What Are the Current PQC Standards and Deadlines?
- What Cryptographic Inventory Work Has to Happen First?
- What Algorithm and Interoperability Caveats Should You Watch For?
- What Does a Realistic Phased Migration Look Like?
- What Testing Evidence and Compliance Documentation Will You Need?
- Federal Quantum Action Plan Implementation Checklist
- Federal Quantum Policy Requirements at a Glance
- What Are the Limitations of the Current Plan?
- What Would Encryption Consulting Recommend?
- Conclusion
- Frequently Asked Questions
Quick answer: “The federal quantum action plan” is shorthand for a stack of policies, not one document: National Security Memorandum 10 (2022), OMB Memorandum M-23-02 (2022), Executive Order 14412 (June 2026), and OMB Memorandum M-26-15 (June 2026). Together they require federal agencies to inventory quantum-vulnerable cryptography, submit a migration plan by around October 22, 2026, and move high-value systems to NIST-approved post-quantum algorithms by December 31, 2030 for key establishment and December 31, 2031 for digital signatures. A parallel FAR Council rule is expected to extend a matching deadline to federal contractors.
Key Takeaways
- The “federal quantum action plan” is not a single document. It is the cumulative effect of NSM-10 (2022), OMB M-23-02 (2022), Executive Order 14412 (June 22, 2026), and OMB M-26-15 (June 24, 2026), each layering new requirements on the last.
- Civilian agencies must submit a PQC migration plan to OMB and the Office of the National Cyber Director by roughly October 22, 2026, then migrate high value assets and high-impact systems to post-quantum key establishment by December 31, 2030 and digital signatures by December 31, 2031.
- National Security Systems run on a separate, earlier track under CNSA 2.0 and NSM-10, administered by the NSA rather than OMB, with a January 1, 2027 acquisition gate.
- A Federal Acquisition Regulatory (FAR) Council rule, due roughly 180 days after EO 14412 (around December 2026), will require covered federal contractors, not just defense contractors, to meet NIST’s post-quantum FIPS by December 31, 2030.
- There are effectively three different compliance bars in play at once, civilian OMB baseline, CNSA 2.0 for national security systems, and the coming FAR contractor rule, and most vendors we talk to are tracking only one of them.
Published: August 2024. Updated: August 2026. Reviewed by Encryption Consulting’s PQC Advisory team.
Search “federal quantum action plan” and you will land on a stack of White House memos, an executive order, and a handful of acronyms, NSM-10, OMB M-23-02, CNSA 2.0, that were each written for a slightly different audience and issued years apart. Most explainers treat that stack as one continuous policy. It is not. It is four separate actions from two different administrations, each with its own scope, deadline, and enforcing agency, and the gap between them is exactly where agencies and contractors lose time. This guide maps the whole stack in plain terms, then hands off to our execution guide for government and defense for the dated, phase-by-phase program model civilian agencies and defense contractors need to build against.
What Does the Federal Quantum Action Plan Actually Mandate?
The federal quantum action plan mandates that federal agencies inventory their cryptography, prioritize systems by risk, and migrate to NIST-approved post-quantum algorithms on a fixed schedule, with a parallel, faster track for national security systems and an emerging track for federal contractors. It is built from four documents:
- National Security Memorandum 10 (NSM-10), May 2022: set the policy goal of migrating vulnerable National Security Systems to quantum-resistant cryptography and created the interagency migration structure that later guidance builds on.
- OMB Memorandum M-23-02, November 2022: directed civilian agencies to inventory quantum-vulnerable cryptographic systems and develop cost estimates for migration, without setting a hard migration deadline of its own.
- Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” June 22, 2026: the order that actually put dates on the migration, requiring high value assets and high-impact systems to complete post-quantum key establishment by December 31, 2030 and digital signatures by December 31, 2031, and directing the FAR Council to extend compliance to federal contractors.
- OMB Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” June 24, 2026: the operational playbook that turns the executive order into a five-phase program, spelling out what an agency’s migration plan has to contain and by when it is due.
A companion order, Executive Order 14413, “Ushering in the Next Frontier of Quantum Innovation,” was signed the same day and drives quantum technology investment rather than cryptographic migration. It shares a signing date with EO 14412 but is a different program with a different purpose, and conflating the two in a compliance conversation is a common, avoidable mistake.
What Are the Current PQC Standards and Deadlines?
The current standards are three NIST Federal Information Processing Standards finalized in August 2024: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) as a stateless hash-based signature fallback. M-26-15’s Appendix A names all three as the baseline algorithm set for civilian agency migration.
The deadlines split by system category. For civilian high value assets and high-impact systems (rated “high” under FIPS 199), key establishment must move to PQC by December 31, 2030 and digital signatures by December 31, 2031. For National Security Systems, CNSA 2.0 sets its own category-by-category schedule, software and firmware signing by 2030, web and cloud services and operating systems by 2033, with a January 1, 2027 acquisition gate that governs new NSS procurement regardless of the later exclusive-use dates. Everything else, lower-impact civilian systems not designated a high value asset, has a softer target of full migration by 2035 under M-26-15’s Phase 5, with no interim enforcement checkpoint before then.
A separate, nearer-term date matters here too: on September 21, 2026, NIST’s Cryptographic Module Validation Program (CMVP) moves all remaining FIPS 140-2 certificates to its Historical list. That date has nothing to do with post-quantum algorithms directly, but any agency or vendor still relying on an active FIPS 140-2 certificate needs a transition plan for it, and it lands before most civilian migration plans are even due.
What Cryptographic Inventory Work Has to Happen First?
An agency cannot prioritize or migrate a system it cannot see, which is why M-26-15’s Phase 1 (2026 to 2027) is entirely inventory and planning before any migration work begins. The memo requires an automated cryptographic inventory methodology, not the manual spreadsheet exercise most agencies produced under the original M-23-02 directive in 2022 and 2023. That distinction matters: a spreadsheet built from asking system owners what algorithms they use routinely misses embedded firmware, vendor-supplied components, and cryptography buried inside commercial off-the-shelf software, which is exactly the cryptography most likely to be hard to replace.
CISA is separately expected to publish minimum-elements guidance for a cryptographic bill of materials (CBOM) within roughly 270 days of EO 14412, around March 2027. Agencies and contractors building an inventory now, rather than waiting for that guidance to land, avoid a rework cycle once the format is standardized. This is the single highest-leverage prerequisite in the entire plan, and it is where CBOM Secure is built to help, producing an automated, continuously updated inventory rather than a point-in-time survey.
What Algorithm and Interoperability Caveats Should You Watch For?
The biggest practical caveat is that there are three different compliance bars in the federal ecosystem right now, and confusing them is the single most common mistake we see in agency and vendor planning conversations.
- The civilian OMB baseline (EO 14412, M-26-15) accepts standard NIST parameter sets for FIPS 203, 204, and 205, and treats hybrid classical-plus-PQC deployments as an acceptable transitional step.
- CNSA 2.0, for National Security Systems, requires specific, larger parameter sets, ML-KEM-1024 and ML-DSA-87, not the general FIPS defaults, plus NIAP Protection Profile validation on top of FIPS 140-3, and it explicitly excludes SLH-DSA (FIPS 205) from its approved suite even though NIST finalized it.
- The coming FAR contractor rule is expected to require covered contractors to meet NIST’s PQC-incorporating FIPS, but as of publication the rule is only proposed, not final, so contractors have a compliance date without regulatory text to build against.
A product that is compliant against the civilian baseline is not automatically compliant for an NSS-scoped contract, and a vendor’s marketing claim of “FIPS 203/204/205 support” says nothing about whether that support is validated. FIPS 140-3 validation through CMVP is running well over a year from submission to an active certificate as of 2026, so algorithm support in a data sheet and algorithm support in an active, numbered certificate are two different claims, and procurement language increasingly asks for the second one specifically.
M-26-15 also treats hybrid architectures, classical and post-quantum algorithms running side by side, as intentionally transitional rather than a permanent posture, describing them as intricate and resource-intensive to operate. Agencies designing around indefinite hybrid deployment should expect that framing to work against them in later phase reviews.
What Does a Realistic Phased Migration Look Like?
M-26-15 lays out five phases running from 2026 through 2035. Mapped onto what an agency or contractor actually needs to do, in order:
- Designate a PQC migration lead at the leadership level, a requirement due within 30 days of EO 14412, around July 2026, and one M-26-15 frames as beyond a delegated CISO task.
- Build an automated cryptographic inventory of high value assets and high-impact systems, Phase 1, 2026 to 2027, prioritized by FIPS 199 impact level and HVA status.
- Submit the migration plan to OMB and the Office of the National Cyber Director by roughly October 22, 2026, including risk-based prioritization, a crypto-agility architecture, third-party and FedRAMP vendor coordination, and resource estimates.
- Run pilots on prioritized systems using validated FIPS 203, 204, and 205 implementations, Phase 2, 2027 to 2028.
- Migrate key establishment for high value assets and high-impact systems, Phase 3, targeting December 31, 2030.
- Migrate digital signatures for the same systems, Phase 4, targeting December 31, 2031.
- Extend migration to remaining systems by risk tier, Phase 5, through 2035.
The dates above look sequential and comfortable on paper. They are less comfortable against the federal budget cycle. EO 14412 landed in June 2026, after most agencies’ FY2027 budget requests were already substantially built and submitted. That means the first budget cycle where an agency can realistically request dedicated PQC migration funding as a named line item is FY2028, which does not begin until October 2027, roughly a year and a half after the executive order, and only two years before the 2030 key-establishment deadline for HVAs. Agencies that treat 2030 as a distant date and wait for a dedicated appropriation before starting inventory work are compressing their own runway before the clock even starts on procurement.
For the dated, phase-by-phase execution model with the full validation-backlog analysis, read our PQC for Government and Defense guide. If your organization is a defense contractor or part of the defense industrial base, the CNSA 2.0 track has its own, earlier acquisition gate, covered in our CNSA 2.0 compliance guide for defense contractors.
What Testing Evidence and Compliance Documentation Will You Need?
Agencies and contractors will need to produce evidence at each phase, not just a plan submitted once and filed. At minimum, expect to maintain:
- An automated cryptographic inventory, kept current rather than refreshed annually, mapped to NIST’s CSWP 48 guidance connecting PQC migration activity to Cybersecurity Framework 2.0 and SP 800-53 Rev. 5 controls.
- Active FIPS 140-3 validation certificates, with certificate numbers, for cryptographic modules in use, or a dated projection where validation is still pending.
- For any system touching National Security Systems, NIAP Protection Profile validation evidence in addition to FIPS 140-3, since the two processes are independent and neither substitutes for the other.
- Interoperability test results for hybrid classical-plus-PQC deployments run during the transition window, documented against production, not lab-only, conditions.
- A phased status update to OMB and ONCD as the migration plan’s timeline milestones are reached, not only at initial submission.
Federal Quantum Action Plan Implementation Checklist
- Assign a PQC migration lead at the leadership level and document the assignment.
- Start an automated cryptographic inventory now, ahead of the plan submission deadline, rather than after.
- Classify systems against FIPS 199 impact level and High Value Asset status.
- Draft the migration plan’s required elements: prioritization, crypto-agility architecture, third-party coordination, resourcing.
- Confirm which of the three compliance bars, civilian OMB, CNSA 2.0, or the coming FAR rule, applies to each system or product line.
- Check current FIPS 140-3 validation status for cryptographic modules in use or planned, and submit early against the current validation timeline, not an assumed accelerated one.
- Plan for the September 21, 2026 FIPS 140-2 sunset as a separate, nearer-term item from the broader PQC migration timeline.
- Track the FAR Council’s proposed contractor rule as it develops, expected around December 2026.
- Budget for PQC migration as a named FY2028 line item now rather than waiting for a dedicated appropriation to appear.
Federal Quantum Policy Requirements at a Glance
| Requirement | Governing document | Deadline | Who it applies to |
|---|---|---|---|
| Cryptographic inventory (automated) | OMB M-26-15, Phase 1 | 2026 to 2027 | Civilian federal agencies |
| PQC migration plan submitted to OMB/ONCD | OMB M-26-15 | Around October 22, 2026 | Civilian federal agencies |
| FIPS 140-2 certificates move to CMVP Historical list | NIST CMVP | September 21, 2026 | Agencies and vendors on FIPS 140-2 |
| Key establishment migrated to PQC | Executive Order 14412 | December 31, 2030 | High value assets, FIPS 199 high-impact systems |
| Digital signatures migrated to PQC | Executive Order 14412 | December 31, 2031 | Same systems as above |
| CNSA 2.0 acquisition gate | NSM-10 / CNSA 2.0 | January 1, 2027 | National Security Systems procurement |
| FAR contractor rule proposed | FAR Council, per EO 14412 | Around December 2026 | Covered federal contractors |
| Contractor compliance with PQC-incorporating FIPS | FAR Council rule, per EO 14412 | December 31, 2030 | Covered contractors and subcontractors |
| Remaining civilian systems fully migrated | OMB M-26-15, Phase 5 | 2035 | Lower-impact civilian systems |
What Are the Limitations of the Current Plan?
The plan is more specific than anything the federal government has published on this topic before, but it still has real gaps worth naming honestly.
- Lower-tier systems have a soft deadline. Anything not classified a high value asset or high-impact system has only the 2035 Phase 5 target, with no interim checkpoint, which makes it easy to deprioritize behind higher-visibility systems for years.
- The civilian and NSS tracks are not fully reconciled. M-26-15 explicitly excludes National Security Systems, but many civilian systems interconnect with NSS environments, and the plan does not spell out how a civilian system handles a boundary case.
- The contractor rule is not final. As of publication, the FAR Council rule required by EO 14412 is only proposed, so contractors have a compliance date, December 31, 2030, without the actual regulatory text to plan against.
- Funding is directed, not appropriated. EO 14412 and M-26-15 require resource estimates in each agency’s migration plan, but neither document appropriates new money, so migration work competes with existing IT modernization budgets until Congress acts separately.
- Vendor readiness is uneven. Some HSM, PKI, and networking vendors have shipped validated FIPS 203/204/205 support; others have only a roadmap. An agency’s realistic timeline is capped by its slowest critical vendor, not by the policy’s own dates.
What Would Encryption Consulting Recommend?
Agencies with an existing CNSA 2.0 obligation, defense components and the intelligence community, are furthest along simply because NSM-10 gave them a head start of several years and a single administering agency, the NSA, setting unambiguous parameter requirements. Most civilian agencies are still at the inventory and plan-drafting stage as of this update, which is not a criticism, October 2026 is the first real deadline they have faced. The organizations that will struggle are the ones treating the migration plan submission as the finish line rather than the starting gate for phases two through five.
For an agency or contractor that has not started, we would scope the work in two tracks that run in parallel rather than sequentially. First, a CBOM Secure-driven automated cryptographic inventory of high value assets and high-impact systems, built to finish well ahead of your next OMB reporting checkpoint rather than the week before it is due. Second, a PQC Advisory engagement structured around our nine-phase quantum readiness roadmap, mapped explicitly onto M-26-15’s five phases, so the deliverable your leadership signs off on is the same document OMB expects to see, not a parallel internal plan that needs translating later. Where the open question is regulatory rather than technical, tracking the FAR Council rule, interpreting FIPS 199 categorization disputes, reconciling civilian and CNSA 2.0 obligations for interconnected systems, our Compliance Advisory team scopes that work separately so it does not stall the technical migration.
Encryption Consulting holds ISO/IEC 27001:2022 and SOC 2 certifications and is a certified Texas minority-owned business, credentials that matter directly in federal and state procurement evaluation criteria, not just as general trust signals.
Conclusion
The federal quantum action plan is no longer an aspirational strategy document. Between June 2026’s Executive Order 14412 and OMB Memorandum M-26-15, it is now a dated program with a plan submission deadline, migration phases, and an enforcement structure, layered on top of NSM-10 and M-23-02’s earlier groundwork. The agencies and contractors that will clear the 2030 and 2031 deadlines cleanly are the ones treating this as three parallel compliance obligations, civilian OMB, CNSA 2.0, and the coming FAR rule, and building the automated inventory that every one of those obligations depends on now, rather than after the next deadline lands.
Frequently Asked Questions
Is my agency required to comply with Executive Order 14412 if we are not a defense or intelligence agency?
Yes. EO 14412 and OMB M-26-15 apply to all federal executive departments and agencies. National Security Systems follow a separate, faster track under CNSA 2.0 administered by the NSA, but civilian agencies are bound by the same order, just on the OMB M-26-15 timeline rather than the CNSA 2.0 one.
What is the difference between OMB M-23-02 and OMB M-26-15?
M-23-02 (November 2022) directed agencies to inventory quantum-vulnerable cryptography and estimate migration costs, without a hard migration deadline. M-26-15 (June 2026) functionally supersedes that inventory-only mandate with a five-phase migration program, a required plan submission date around October 22, 2026, and firm 2030 and 2031 migration deadlines for high value assets and high-impact systems.
Do federal contractors have to comply with the same deadlines as federal agencies?
Contractors face a related but separate requirement. EO 14412 directs the FAR Council to propose a rule, expected around December 2026, requiring covered contractors to comply with NIST’s PQC-incorporating FIPS by December 31, 2030, the same date as the agency key-establishment deadline. Defense contractors delivering into National Security Systems face the earlier CNSA 2.0 acquisition gate on January 1, 2027 instead.
What happens if an agency system cannot be migrated to post-quantum cryptography by 2030?
M-26-15 does not describe a blanket waiver process in public guidance, and the practical answer depends on why the system cannot migrate: a legacy or embedded system with no crypto-agile upgrade path typically needs a documented replacement plan and risk acceptance through the agency’s own governance process, since the memo’s Phase 5 timeline already extends non-priority systems through 2035.
Are critical infrastructure owners covered by the federal quantum action plan?
Critical infrastructure owners and operators are addressed differently than federal agencies. EO 14412 directs federal agencies to provide assistance to critical infrastructure owners and operators on post-quantum migration rather than imposing a direct regulatory deadline on them the way it does on agencies and, through the FAR rule, on contractors. In practice, critical infrastructure entities that also hold federal contracts will likely feel the contractor rule’s deadline regardless.
References
- Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” June 22, 2026. The American Presidency Project
- OMB Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” June 24, 2026. whitehouse.gov
- National Security Memorandum 10 on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, May 4, 2022. whitehouse.gov archives
- OMB Memorandum M-23-02, “Migrating to Post-Quantum Cryptography,” November 18, 2022. whitehouse.gov
- NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), finalized August 2024. csrc.nist.gov
- Key Takeaways
- What Does the Federal Quantum Action Plan Actually Mandate?
- What Are the Current PQC Standards and Deadlines?
- What Cryptographic Inventory Work Has to Happen First?
- What Algorithm and Interoperability Caveats Should You Watch For?
- What Does a Realistic Phased Migration Look Like?
- What Testing Evidence and Compliance Documentation Will You Need?
- Federal Quantum Action Plan Implementation Checklist
- Federal Quantum Policy Requirements at a Glance
- What Are the Limitations of the Current Plan?
- What Would Encryption Consulting Recommend?
- Conclusion
- Frequently Asked Questions
