Keyfactor Tech Days 2027, The Trust Security Conference, is heading to San Diego!   Discover what’s coming up

  • Home
  • Blog
  • The Government Just Set a Quantum Computing Deadline. Here’s What It Actually Means for You.

The Government Just Set a Quantum Computing Deadline. Here’s What It Actually Means for You.

PQC

If you’ve seen headlines about a new “post-quantum cryptography” executive order and wondered whether it’s something you need to care about, the short answer is probably yes, even if you’ve never worked for a government agency in your life. 

In June 2026, the White House signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks.” A couple days later, the Office of Management and Budget (OMB) followed up with Memorandum M-26-15, which lays out exactly how federal agencies are supposed to carry the order out. Together, these two documents kick off what’s being called the largest cryptographic migration in history. 

That might sound like an IT problem that only federal agencies need to comply with. It isn’t. Here’s why it matters more broadly, and what it means depending on where you sit. 

The problem it’s trying to solve, in plain English

Almost everything digital, like banking apps, email, healthcare portals, online shopping, government services and more relies on encryption to keep data private, and to verify that messages and software actually came from who they claim. That encryption is built on math problems that are extremely hard for today’s computers to solve, but that a sufficiently powerful quantum computer could, in theory, crack. 

No such computer exists yet. But that’s almost beside the point, due to a strategy security experts call “harvest now, decrypt later.” An adversary can quietly collect encrypted data today (health records, financial data, trade secrets, communications) and simply hold onto it, waiting for the day quantum computers are powerful enough to unlock it. Information that needs to stay confidential for years or decades is already at risk, even though the computer that could break it hasn’t been built. 

That’s the risk the new executive order is trying to get ahead of. 

What the order does

EO 14412 moves up the federal government’s own deadline for switching to quantum-resistant encryption. The previous target, set back in 2022, gave agencies until 2035. The new order compresses that significantly: 

  • By the end of 2030, agencies must migrate the encryption used to establish secure connections (the handshake that happens before your data ever gets exchanged). 
  • By the end of 2031, agencies must migrate to quantum-resistant digital signatures (the mechanism that verifies data or software hasn’t been tampered with). 
  • By 2035, the migration is expected to be essentially complete across remaining systems. 

OMB’s M-26-15 memo translates that order into a five-phase roadmap running from 2026 to 2035, starting with agencies taking inventory of their existing cryptography and ending with full migration. It also sets a series of near-term procedural deadlines: agencies had 30 days to name someone responsible for the transition, and a few months to submit their initial migration plans. Additional rules on vulnerability disclosure and technical standards are due within the following months. 

Why this reaches far beyond federal agencies

This is the part that surprises people. The order is written for federal agencies, but its effects are designed to ripple outward through several channels: 

Federal contractors and subcontractors.
Rulemaking is already underway to require companies that do business with the federal government to meet the same cryptographic standards. If your company directly or indirectly sells software, hardware, or services to a federal agency this is very likely coming to a contract renewal near you.  DOW guidance is requiring all subcontractors and OEM’s to provide PQC migration plans for their products and corporate infrastructure.   
 

Critical infrastructure operators.
Sectors like energy, finance, healthcare, telecommunications, and water systems are being pulled into the same migration through sector-specific guidance from federal agencies that oversee them. You don’t have to be a government contractor to feel the pressure, you just have to run something the country depends on.
 

The defense industrial base.
Companies that build for the Department of Defense are facing their own accelerated PQC deadlines and updated certification requirements, layered on top of the broader federal timeline.
 

Basically everyone, eventually.
Regulators are also working on a new standard for something like a “cryptographic bill of materials” (CBoM). A CBoM is essentially a detailed inventory of which encryption a piece of software or hardware uses. If that concept sounds familiar, it’s because it closely mirrors the “software bill of materials” requirements that emerged a few years ago and are now common practice across the tech industry. History suggests that once a transparency requirement like this becomes standard for government suppliers, it tends to become the default expectation everywhere else too.
 

What this means for you, depending on who you are

  • If you work in IT, security, or compliance at any organization: even if no regulation currently applies to you, this is a good moment to ask a simple question: Do we actually know where and how we use encryption across our systems? Most organizations don’t have a clear answer, and that inventory is the unavoidable first step everyone eventually has to take. 
  • If your company sells to the government or to a regulated industry: expect cryptographic requirements to start showing up in contracts, audits, and vendor questionnaires over the next few years. Getting ahead of it is far cheaper than scrambling once it’s a contractual requirement with a hard deadline attached. 
  • If you’re a consumer or just a curious observer: you likely won’t notice anything change in the apps and services you use day to day – quantum-resistant encryption is designed to work behind the scenes. What’s actually happening is a long-overdue upgrade to the plumbing that keeps your data private, similar in spirit to past shifts like the move to HTTPS everywhere. 

The bottom line

Quantum computers capable of breaking today’s encryption don’t exist yet, and estimates for when they might vary widely. But the government isn’t waiting to find out. It’s basically betting that the safe move is to assume the timeline is shorter than we’d like, because the cost of being wrong (sensitive data exposed years or decades from now) is so much higher than the cost of migrating early. 

Whether you’re running a small business, working in IT at a hospital, or just paying attention to tech policy, the direction is the same: cryptography that’s been “good enough” for the last twenty years is on a clock, and that clock started ticking in June 2026.