Post-quantum cryptography (PQC) protects data against future quantum computers capable of breaking today’s encryption. The threat of quantum computing has broad implications, and the federal government is trying to get ahead of the problem. The recent Executive Order 14412 set 2030/2031 deadlines for federal systems, and the Pentagon wants to add PQC compliance to CMMC. With federal agencies expecting to cascade requirements down to their supply chain, government contractors need to act now or risk losing opportunities.
The looming quantum computing threat has prompted federal mandates for the migration to post- quantum cryptography (PQC). While earlier PQC compliance frameworks and implementation timelines were ambiguous, the directives are now moving faster.
The recent Executive Order 14412 sets clear deadlines for high-value federal systems and signals what’s to come in federal procurement. Even as the rules affecting the downstream supply chain ecosystem are pending, federal contractors should expect increasing PQC compliance pressure.
The potential timelines for the arrival of cryptographically relevant quantum computers have also accelerated in recent months. And long-value data such as government records is already vulnerable to “harvest now, decrypt later” attacks.
The convergence of all these forces makes it clear that federal contractors must act now. This guide explains what federal contractors need to know today about PQC.
What is PQC and why has it emerged as a requirement?
Nobody knows when “Q-Day” will arrive. Some industry projections place it as early as 2030. But recently, research from Google and other scientists has lowered the estimated quantum resources needed to break widely used public-key cryptography. Progress is also being made on other fronts, including hardware.
These developments further increase the concerns that cryptographically relevant quantum computers would be available sooner than previously expected. Google has since accelerated its own target date for PQC migration. So have other major infrastructure providers, including Microsoft and Cloudflare.
Whenever the day arrives, the implications would be widespread. A range of systems relying on public- key cryptography could become vulnerable, including:
- Encrypted connections: Data transmitted through VPNs, TLS, email, and cloud traffic could be decrypted.
- Authentication and verification: Digital signatures and certificates that authenticate software, identities, and communications could be forged.
- IT infrastructure: Applications, web browsers, APIs, and cloud platforms could be compromised.
- Embedded systems: IoT devices, sensors, and operational technology may be difficult to upgrade without significant disruption, or even impossible.
HNDL attacks put data that needs to stay confidential for years at immediate risk. For security practitioners, this is a clear pain point: 56% of respondents in an ISACA poll cited HNDL attacks as aconcern.
PQC compliance, readiness, and ‘quantum-safe’: what’s the difference?
- PQC readiness describes your organization’s preparedness to migrate to PQC and is a pre- migration phase. Achieving readiness starts with understanding your cryptographic posture (current state), prioritizing risks, creating a migration plan, and allocating budget.
- Quantum-safe means your migration is complete, with quantum-resistant cryptography fully deployed and enforced. Migration is typically rolled out in phases and includes building cryptographic agility, which allows you to protect against quantum threats as standards mature and new vulnerabilities emerge.
- PQC compliance is a category of its own. It means you’re checking the boxes a specific framework sets. As with security in general, you can be fully compliant but not fully protected, particularly when a specific framework doesn’t stipulate PQC.
The quantum-resistant algorithms and their implications
- Federal Information Processing Standard (FIPS) 203: Intended as the primary standard for general encryption, it uses ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism), which allows two parties to establish a shared key for encryption securely.
- FIPS 204: Intended as the main standard for protecting digital signatures, it uses ML-DSA (Module-Lattice-Based Digital Signature Algorithm), which allows a signer to generate a verifiable signature over a message using a private key that only the signer holds.
- FIPS 205: Designed as a backup method if ML-DSA becomes vulnerable, it uses SLH-DSA (Stateless Hash-Based Digital Signature Algorithm), which is based on hash functions rather than the lattice-based math behind ML-DSA.
In practice, FIPS 203 protects data confidentiality (including against HNDL attacks) and FIPS 204 and 205 support authenticity and integrity. A migration plan will need to address both functions in the long term.
It’s worth noting that a given PQC mandate may not call for every NIST-standardized algorithm. For instance, the National Security Agency’s Commercial National Security Algorithm Suite (CNSA) 2.0 specifies ML-KEM (FIPS 203) for key establishment and ML-DSA (FIPS 204) for general digital signatures. At the same time, SLH-DSA (FIPS 205) is not approved for the current framework.
What PQC compliance means for federal contractors today
As of August 2026, no framework that’s broadly applicable to federal contractors pushes PQC outright yet. But that doesn’t mean compliance and security teams can relax. Provisions for quantum-safe solutions are already influencing procurement decisions, and federal authorities continue to update their expectations.
Cybersecurity Maturity Model Certification (CMMC)
CMMC Level 2 is built on NIST SP 800-171, Revision 2, which includes the use of FIPS-validated cryptography to protect controlled unclassified information. It doesn’t prescribe a contractor migration deadline or PQC algorithms.
However, a new U.S. Department of War PQC strategy, published in June, calls for adding PQC to CMMC requirements and sets a December 31, 2031, deadline for DoW systems to use PQC. While CMMC’s third-party certification stipulation itself is paused as of July, pending a Reform Task Force review, the underlying NIST 800-171 compliance obligation remains in force.
The DoW strategy came on the heels of Executive Oorder 14412, which has similar deadlines for high-impact systems and high-value assets. The EO accelerated the target date for transitioning to PQC from 2035 to the end of 2030 for key establishment schemes and to the end of 2031 for digital signatures.
The Federal Acquisition Regulatory Council has until December to translate EO 14412 into specific rules for covered contractors.
CNSA 2.0
- January 1, 2027, for new NSS acquisitions to be CNSA 2.0 compliant
- December 31, 2030, for phasing out equipment and services that can’t support PQC/CNSA
- December 31, 2031, for full use of CNSA 2.0 algorithms
- 2030 for software and firmware signing and traditional networking equipment
- 2033 for web browsers and servers, cloud services, operating systems, niche or constrained devices, large PKI, custom applications, and legacy equipment
FedRAMP
FedRAMP-authorized PQC won’t be widely available until validation catches up, no matter what the rules eventually entail.
However, some providers are already moving ahead. For example, Cloudflare recently earned FedRAMP High authorization for a platform that supports post-quantum encryption. It’s a sign that PQC readiness is emerging as a competitive differentiator before formal mandates are in place.
The impact of the key deadlines on federal contractors
Effectively, all these frameworks will likely force the federal supply chain ecosystem to ship compliant solutions before the deadlines. Prime contractors that need PQC-capable solutions may pass this obligation to their suppliers, who will cascade it down their own supply chains.
What contractors need to do now
The risks of delaying the process range from competitive disadvantage to increased costs. Mapping cryptographic systems across your environment, working through numerous custom applications, coordinating schedules with various vendors, and swapping out cryptographic libraries doesn’t happen overnight. And you can’t get very far without first getting organizational alignment and leadership buy- in.
Regardless of the compliance framework, understanding your cryptographic posture is one of the critical first steps. You have to know your exposure before you can create a plan for mitigating it. A cryptographic inventory and posture assessment will help you better understand the scope of what’s involved and get your leadership on board.
Get started with a simple tool
Ciphersound offers a simple tool that compliance and security teams can use immediately and at no cost. You don’t need to wait for budget approval or a procurement cycle to get real answers.