Post-quantum cryptography for federal systems
Current understanding
Federal policy is moving to secure government information systems against ‘harvest now, decrypt later’ and other advanced cryptographic attacks, including those anticipated from quantum computers. Executive Order 14412 established requirements for federal agencies to inventory vulnerable cryptography and migrate to post-quantum standards; HR9516 (119th Congress) would codify those requirements into permanent statute. For developers and platforms serving federal customers, this shapes cryptographic migration timelines; for users, it affects the long-term confidentiality of data held by federal systems.
Evidence log
- 2026-06-15 — National Security Commission Quantum Computing Act of 2026: cross-connection with national-security-commission-quantum-computing: A national security commission on quantum computing would likely evaluate cryptographic risks that PQC federal systems policies aim to mitigate. (novelty: 2)
- 2026-06-25 — Securing the Nation Against Advanced Cryptographic Attacks: Executive action ‘Securing the Nation Against Advanced Cryptographic Attacks’ (EO 14412) directs federal agencies to secure national systems against advanced cryptographic attacks, likely mandating migration to post-quantum cryptographic standards — the underlying executive directive that HR9516 seeks to codify. (novelty: 3)
- 2026-06-29 — To codify Executive Order 14412, entitled “Securing the Nation Against Advanced Cryptographic Attacks”.: cross-connection with national-quantum-initiative-reauthorization: The NQI reauthorization funds federal quantum R&D (including PQC standards work at NIST), while HR9516 would codify the operational mandate that federal agencies migrate systems to those standards — two sides of the same quantum-security policy stack. (novelty: 2)