What Is PQC? A Federal Contractor’s Guide to Post-Quantum Cryptography Compliance

Post-quantum cryptography (PQC) protects data against future quantum computers capable of breaking today’s encryption. The threat of quantum computing has broad implications, and the federal government is trying to get ahead of the problem. The recent Executive Order 14412 set 2030/2031 deadlines for federal systems, and the Pentagon wants to add PQC compliance to CMMC. With federal agencies expecting to cascade requirements down to their supply chain, government contractors need to act now or risk losing opportunities.


The looming quantum computing threat has prompted federal mandates for the migration to post- quantum cryptography (PQC). While earlier PQC compliance frameworks and implementation timelines were ambiguous, the directives are now moving faster.

The recent Executive Order 14412 sets clear deadlines for high-value federal systems and signals what’s to come in federal procurement. Even as the rules affecting the downstream supply chain ecosystem are pending, federal contractors should expect increasing PQC compliance pressure.

The potential timelines for the arrival of cryptographically relevant quantum computers have also accelerated in recent months. And long-value data such as government records is already vulnerable to “harvest now, decrypt later” attacks.

The convergence of all these forces makes it clear that federal contractors must act now. This guide explains what federal contractors need to know today about PQC.

What is PQC and why has it emerged as a requirement?

Security experts have long known that quantum computers would be capable of breaking today’s cryptographic systems. The encryption that digital communications and transactions have relied on for decades is based on complex mathematical problems. Classical computers would need potentially billions of years to solve these. A sufficiently capable quantum computer could reduce that to hours or less.

Nobody knows when “Q-Day” will arrive. Some industry projections place it as early as 2030. But recently, research from Google and other scientists has lowered the estimated quantum resources needed to break widely used public-key cryptography. Progress is also being made on other fronts, including hardware.

These developments further increase the concerns that cryptographically relevant quantum computers would be available sooner than previously expected. Google has since accelerated its own target date for PQC migration. So have other major infrastructure providers, including Microsoft and Cloudflare.

Whenever the day arrives, the implications would be widespread. A range of systems relying on public- key cryptography could become vulnerable, including:
Despite the uncertainty around timing, adversaries are not waiting. National security authorities have warned that nation-state actors could collect encrypted data now to decrypt once quantum computing catches up. Some security researchers have observed attacker behavior that “aligns with the HNDL riskmodel.”

HNDL attacks put data that needs to stay confidential for years at immediate risk. For security practitioners, this is a clear pain point: 56% of respondents in an ISACA poll cited HNDL attacks as aconcern.

PQC compliance, readiness, and ‘quantum-safe’: what’s the difference?

The terms compliance, readiness, and quantum-safe are related but should not be used interchangeably. They represent different states.

The quantum-resistant algorithms and their implications

NIST’s release of three quantum-safe standards in August 2024 marked a shift from PQC research to implementation. The standards are based on three different types of algorithms:

In practice, FIPS 203 protects data confidentiality (including against HNDL attacks) and FIPS 204 and 205 support authenticity and integrity. A migration plan will need to address both functions in the long term.

It’s worth noting that a given PQC mandate may not call for every NIST-standardized algorithm. For instance, the National Security Agency’s Commercial National Security Algorithm Suite (CNSA) 2.0 specifies ML-KEM (FIPS 203) for key establishment and ML-DSA (FIPS 204) for general digital signatures. At the same time, SLH-DSA (FIPS 205) is not approved for the current framework.

What PQC compliance means for federal contractors today

As of August 2026, no framework that’s broadly applicable to federal contractors pushes PQC outright yet. But that doesn’t mean compliance and security teams can relax. Provisions for quantum-safe solutions are already influencing procurement decisions, and federal authorities continue to update their expectations.

Cybersecurity Maturity Model Certification (CMMC)

CMMC Level 2 is built on NIST SP 800-171, Revision 2, which includes the use of FIPS-validated cryptography to protect controlled unclassified information. It doesn’t prescribe a contractor migration deadline or PQC algorithms.

However, a new U.S. Department of War PQC strategy, published in June, calls for adding PQC to CMMC requirements and sets a December 31, 2031, deadline for DoW systems to use PQC. While CMMC’s third-party certification stipulation itself is paused as of July, pending a Reform Task Force review, the underlying NIST 800-171 compliance obligation remains in force.

The DoW strategy came on the heels of Executive Oorder 14412, which has similar deadlines for high-impact systems and high-value assets. The EO accelerated the target date for transitioning to PQC from 2035 to the end of 2030 for key establishment schemes and to the end of 2031 for digital signatures.

The Federal Acquisition Regulatory Council has until December to translate EO 14412 into specific rules for covered contractors.

CNSA 2.0

CNSA 2.0 has more granular and concrete timetables. The target deadlines for National Security Systems vary by requirement and technology category:
As with CMMC, the CNSA 2.0 framework is generally not directed at contractors but has ramifications for government contracts.

FedRAMP

The Federal Risk and Authorization Management Program (FedRAMP) generally calls for cryptographic modules to be validated to the FIPS 140 standards. A cloud service provider would need to implement the FIPS 203–205 PQC standards using FIPS 140-validated cryptographic modules before deployment. This process takes substantial time — potentially years.

FedRAMP-authorized PQC won’t be widely available until validation catches up, no matter what the rules eventually entail.

However, some providers are already moving ahead. For example, Cloudflare recently earned FedRAMP High authorization for a platform that supports post-quantum encryption. It’s a sign that PQC readiness is emerging as a competitive differentiator before formal mandates are in place.

The impact of the key deadlines on federal contractors

The bottom line: To migrate to PQC, federal agencies need to use PQC-validated products.

Effectively, all these frameworks will likely force the federal supply chain ecosystem to ship compliant solutions before the deadlines. Prime contractors that need PQC-capable solutions may pass this obligation to their suppliers, who will cascade it down their own supply chains.

What contractors need to do now

Waiting for mandates to be finalized is not a viable strategy for federal contractors. By the time PQC becomes an established requirement across frameworks, organizations that are still at square one will be scrambling. Migration is a complex, multi-year effort that involves multiple functions and systems. In effect, many CISOs are already behind.

The risks of delaying the process range from competitive disadvantage to increased costs. Mapping cryptographic systems across your environment, working through numerous custom applications, coordinating schedules with various vendors, and swapping out cryptographic libraries doesn’t happen overnight. And you can’t get very far without first getting organizational alignment and leadership buy- in.

Regardless of the compliance framework, understanding your cryptographic posture is one of the critical first steps. You have to know your exposure before you can create a plan for mitigating it. A cryptographic inventory and posture assessment will help you better understand the scope of what’s involved and get your leadership on board.

Get started with a simple tool

PQC posture assessment can feel like a heavy lift because cryptographic inventory platforms are typically designed for enterprise environments. Their price and complexity reflect those needs. On the flip side, they can create a barrier that keeps organizations stuck.

Ciphersound offers a simple tool that compliance and security teams can use immediately and at no cost. You don’t need to wait for budget approval or a procurement cycle to get real answers.