PQC Readiness for Manufacturing:
The timeline is now written down
| Region | United States (federal policy with global supply chain reach) |
| Applicability | Federal contractors and subcontractors: any manufacturer selling hardware, software, or connected products into federal or defense-adjacent supply chains Critical infrastructure suppliers: manufacturers whose customers operate under federal cybersecurity expectations All manufacturers of long-lived industrial systems: any organization whose products or plant-floor assets will still be in service in 2035 |
| Relevant sections | Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (June 22, 2026) OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography NIST IR 8547, Transition to Post-Quantum Cryptography Standards |
Overview
Every framework in this guide points in the same direction: know what cryptography you have, prove you control it, and be ready to change it. Post-quantum cryptography is where that direction gets a deadline.
In 2024, NIST finalized the first three post-quantum cryptographic standards and published a transition timeline that deprecates the RSA and elliptic curve algorithms underpinning most industrial infrastructure by 2030, with full disallowance targeted for 2035. In June 2026, Executive Order 14412 converted that technical guidance into federal policy. The order directs OMB and the National Cyber Director to lead an accelerated national migration, requires agencies to transition high value assets to PQC by 2030 or 2031 depending on use case, and sets a Department of Commerce migration pilot for completion by the end of 2027.
For manufacturers, two provisions matter most. First, the order directs the FAR Council to require covered federal contractors to meet PQC-aligned cybersecurity standards and vulnerability disclosure policies by the end of 2030, extending the migration obligation into the supply chain. Second, it directs CISA, in coordination with NIST, to publish minimum elements for a cryptographic bill of materials (CBOM): a machine-readable inventory of the cryptographic assets in any hardware or software element. If the CBOM follows the trajectory of the software bill of materials, it will move from federal procurement requirement to standard commercial expectation.
Why it matters
An executive order is not a conformance standard, and manufacturers will not be audited against EO 14412 directly. Its significance is what it signals: the questions this guide has raised in every section now have dates attached.
The economics of manufacturing make those dates closer than they look. A PLC commissioned this year will still be running when RSA and ECC are formally disallowed. Proprietary process data and control-plane traffic encrypted today can be harvested now and decrypted once quantum capability arrives, which means the sensitivity horizon of the data, not the delivery date of a quantum computer, sets the deadline. And procurement moves faster than regulation: federal buyers, critical infrastructure operators, and prime contractors will begin asking suppliers for PQC migration plans and cryptographic inventories well before any rule requires them to.
The CRA’s cryptographic component visibility expectations, IEC 62443’s algorithm inventory requirements, NIS2’s cryptography policy mandate, and SP 800-82’s key lifecycle documentation all converge on the same foundation the CBOM formalizes. Organizations that build that foundation once will satisfy all of them.
How this maps to cryptography
| Section | Function | What it says | Supporting products |
|---|---|---|---|
| EO 14412 §4; forthcoming CISA CBOM guidance | Cryptographic inventory and CBOM readiness | Discover and inventory certificates, keys, algorithms, and embedded cryptographic libraries across IT, OT, and product firmware, producing the asset-level visibility a CBOM requires | Command AgileSec |
| NIST IR 8547 deprecation schedule | Quantum vulnerability assessment | Analyze discovered cryptography against approved and deprecated algorithm lists to identify quantum-vulnerable assets and prioritize by data sensitivity and asset lifespan | AgileSec |
| EO 14412 §3; OMB M-26-15 | PQC-capable certificate issuance | Issue and manage certificates using NIST-standardized PQC algorithms, including hybrid certificates that support staged migration across long-lived device fleets | EJBCA |
| EO 14412 §5 (CMVP revision); IEC 62443-4-2 patch and agility expectations | Cryptographic agility | Rotate, reissue, and re-key certificates at fleet scale when algorithms change, without manual per-device intervention | Command EJBCA |
| EO 14412 procurement provisions; CRA Annex I update requirements | PQC-ready code and firmware signing | Sign firmware and software with quantum-resistant algorithms so update pipelines remain trustworthy across the product’s full support period | SignServer Signum |
Readiness questions
PQC migration reviews, whether initiated by a federal customer, a prime contractor, or an internal risk function, focus on whether the organization knows its exposure and has a governed plan. Key areas assessors will probe:
- Cryptographic inventory completeness: Can the organization enumerate every certificate, key, algorithm, and cryptographic library in use across IT, OT, and shipped products, including inherited dependencies?
- Quantum vulnerability classification: Has the inventory been assessed against the NIST deprecation schedule, with quantum-vulnerable assets identified and ranked by data sensitivity and asset lifespan?
- Migration plan and ownership: Is there a named owner, a documented migration plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates?
- Long-lived asset strategy: For devices that will outlive current algorithms and cannot be re-keyed in the field, are compensating controls or replacement plans documented?
- CBOM production capability: Could the organization produce a cryptographic bill of materials for its products today if a federal customer requested one?
- Supplier PQC posture: Are component and software suppliers being assessed for their own migration plans, given that inherited cryptography becomes the manufacturer’s exposure?
TAKE THIS TO MANAGEMENT
The post-quantum transition now has federal dates attached: NIST deprecates today’s core algorithms by 2030, and Executive Order 14412 requires federal contractors to meet PQC-aligned standards by the end of that year. Our industrial systems and the products we ship will still be in service well past both dates, so the cryptographic decisions we make now determine whether we meet them.
The practical first step is the same one every framework in this guide asks for: a complete cryptographic inventory. The order’s cryptographic bill of materials concept will formalize that expectation for anyone selling into federal supply chains, and commercial customers will follow. If we build the inventory, assessment, and lifecycle automation now, PQC becomes a managed migration on our schedule rather than a scramble on someone else’s.


