Here’s what changed and why it matters even if you’re not a federal CISO:
The mandate. OMB Memorandum M-26-15, issued June 24 under Executive Order 14412, gave civilian agencies 120 days to submit PQC migration plans — risk-based system prioritization, a cryptographic inventory methodology, crypto-agility architecture, and funding estimates. That clock runs out October 22.
The algorithms. Plans get mapped against ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) for signatures, and SLH-DSA (FIPS 205) as a hash-based alternative. Worth flagging: SLH-DSA is allowed here but excluded from CNSA 2.0 for National Security Systems — a civilian/defense split CISOs will need to track separately.
The long game. Plans due now; key establishment for High Value Assets complete by 2030; signatures by 2031; full federal estate migrated by 2035. Nine years sounds generous until you remember harvest-now-decrypt-later attacks are already banking today’s traffic.
The gap. None of this is credible without an accurate answer to “where does RSA, ECDSA, or Diffie-Hellman actually run in our stack?” — across code, build pipelines, cloud KMS, HSMs, and vendor dependencies. Most organizations, federal or not, don’t have that inventory yet.
Bottom line: If you’re racing this deadline — or watching it as a preview of what’s coming to banking, healthcare, and critical infrastructure — the migration plan is only as good as the crypto inventory underneath it. Discovery has to come first.
At Qubit Guard, this is exactly the gap our QuantVision engine closes: multi-layer CBOM discovery across network traffic, repos, build artifacts, and PKI, mapped straight to FIPS 203/204/205 and CNSA 2.0.
If you had to file a PQC migration plan today, could you list every place classical crypto is hiding in your environment? What’s missing?
#PostQuantumCryptography #PQC #CNSA2 #NIST #FIPS140 #CISO #CryptoAgility #QuantumSafe #Cybersecurity #RiskManagement
