in effect
Executive Order 14412, signed June 22, 2026, directs federal agencies to replace their current encryption systems with quantum-resistant cryptography — algorithms designed to withstand attacks from both conventional and future quantum computers. It sets binding deadlines, assigns coordination responsibilities across several federal offices, and extends requirements to government contractors and critical infrastructure sectors.
Each federal agency must name an internal PQC migration lead within 30 days. By December 31, 2030, all agency High Value Assets and high-impact systems must use quantum-resistant encryption for key establishment (how secure connections are set up), and by December 31, 2031, those same systems must use it for digital signatures (how documents and data are authenticated). The Federal Acquisition Regulation will be amended so that government contractors must also comply with the new encryption standards by December 31, 2030, and must include cryptographic vulnerabilities in their existing vulnerability disclosure programs. NIST must run a pilot migration on its own systems by end of 2027 and accelerate its validation process for compliant cryptographic products.
Every federal civilian agency is required to audit its systems and execute a documented migration plan. Companies that hold federal contracts will face new procurement rules requiring them to adopt the same NIST-approved quantum-resistant standards by the 2030 deadline. Operators of critical infrastructure — such as energy, water, and financial systems — will receive guidance and assistance from their designated Sector Risk Management Agencies and CISA to support their own transitions.