Skip to content
    Back to Regulatory Radar
    ImportantNew RegulationJune 22, 2026

    Executive Order 14412 Sets Binding Federal PQC Migration Deadlines for 2030 and 2031

    President signed Executive Order 14412, 'Securing the Nation Against Advanced Cryptographic Attacks,' on June 22, 2026, establishing the first binding government-wide deadlines for post-quantum cryptography migration. Federal agencies must transition all high value assets and high impact systems (excluding National Security Systems) to PQC for key establishment by December 31, 2030, and to PQC for digital signatures by December 31, 2031. The order also directs the FAR Council to publish a proposed rule within 180 days requiring covered federal contractors to comply with NIST's FIPS incorporating PQC algorithms, including FIPS 203, by the end of 2030.

    NIST 800-53FedRAMPNIST 800-171DefenseSaaS

    Key Analytics

    June 22, 2026
    Event Date
    Time Remaining
    August 24, 2026
    Last Verified
    3
    Frameworks Affected

    Impact Analysis

    Federal contractors, FedRAMP-authorized cloud providers, and any SaaS company handling federal data now face a concrete cryptographic modernization timeline rather than an open-ended advisory posture. The contractor requirement is still a proposed rule as of August 2026, but organizations that wait for the final FAR text will be compressing a multi-year migration (cryptographic inventory, vendor dependencies, PKI and code signing overhaul) into a shrinking window. The order also directs a second proposed FAR rule, due within 270 days, amending contractor vulnerability disclosure requirements to cover cryptographic weaknesses such as missing encryption and non-FIPS algorithms, which will surface crypto hygiene in future assessments and audits.

    Recommended Actions

    • Build a cryptographic inventory (cryptographic bill of materials) covering key establishment, digital signatures, TLS, and PKI across all systems that touch federal data
    • Map every dependency on quantum-vulnerable algorithms such as RSA and ECDH against the December 2030 and December 2031 deadlines
    • Request PQC migration roadmaps from HSM, certificate authority, and TLS termination vendors, prioritizing FIPS 203 support for key establishment
    • Track the FAR Council's proposed contractor compliance rule and budget for PQC readiness in 2027-2028 planning cycles
    • Extend vulnerability management and disclosure programs to test for missing encryption and non-FIPS approved algorithms ahead of the anticipated FAR amendment

    Always verify requirements with official regulatory sources.

    Estimated Remediation Effort

    Indicative effort to address this development, broken down by your organization's current compliance posture. Select the posture that best matches where you are today.

    A partial program exists: some policies and controls are in place, but coverage, evidence, and ownership have gaps.

    Analyst estimate
    Significant140-300 hours
    Key Workstreams
    • Extend the cryptographic inventory across every system touching federal data
    • Map RSA and ECDH dependencies against the December 2030 and December 2031 deadlines
    • Confirm vendor FIPS 203 support and sequence the migration
    • Extend vulnerability management to missing encryption and non-FIPS algorithms

    The Cost of Waiting

    Readiness work is dramatically cheaper before a deadline than after one. The ranges below come from the same estimate: the difference is only how prepared you are when the work starts.

    Start preparing nowSignificant · 140-300 hours
    Start cold under pressureMajor · 340-700 hours

    Roughly 200 to 400 hours avoided by preparing early

    Effort ranges are indicative planning estimates, not quotes. Actual effort depends on organizational scope, environment complexity, and evidence maturity. Talk to us for a scoped assessment.

    Related Events