US Post-Quantum Cryptography Regulation: NIST, OMB M-26-15 and CNSA 2.0
The United States is the jurisdiction where post-quantum cryptography moved from standards work into an execution mandate with named dates for federal High Value Assets. NIST finalised FIPS 203, 204 and 205. The Quantum Computing Cybersecurity Preparedness Act already required agencies to plan. National Security Memorandum 10 set a 2035 mitigation goal. In June 2026, Executive Order 14412 and OMB Memorandum M-26-15 turned that stack into a phased migration with a submission deadline measured in days, not years. National Security Systems sit on a separate track under NSA's CNSA 2.0.
This guide covers what those instruments actually say, who is in scope (agencies, contractors, critical infrastructure and NSS operators), the timeline you should plan against, and the first practical steps: cryptographic inventory, HSM/KMS readiness, and hybrid PQC deployment. For control mapping into CSF 2.0 and SP 800-53, see also our NIST PQC compliance page.
Table of Contents
- What the Regulator Said
- Who Is in Scope
- The Timeline
- Practical First Steps
- The Technical Checklist
- How This Maps to DuoKey Cockpit
- FAQ
What the Regulator Said
NIST: the algorithms
NIST's FIPS publications define the cryptographic destination for civilian federal systems:
| Standard | Algorithm | Role |
|---|
| FIPS 203 | ML-KEM | Key establishment / encapsulation |
| FIPS 204 | ML-DSA | General-purpose digital signatures |
| FIPS 205 | SLH-DSA | Stateless hash-based signatures |
NIST Internal Report 8547 (and successors) describe the broader transition to those standards. OMB M-26-15 requires agency plans to align with IR 8547.
Statute and early OMB direction
The Quantum Computing Cybersecurity Preparedness Act (Public Law 117-260, December 2022) directed OMB to require agencies to prioritise migration and develop plans, with annual congressional reporting. OMB M-23-02 (November 2022) made the first operational move: a prioritized inventory of cryptographic systems on federal information systems, excluding National Security Systems, focused on High Value Assets and high-impact systems. That inventory work is the foundation M-26-15 now expects agencies to turn into an actionable migration plan.
Executive Order 14412 (22 June 2026)
EO 14412, Securing the Nation Against Advanced Cryptographic Attacks, states US policy to migrate federal information systems to NIST-approved FIPS for PQC and to assist critical infrastructure owners and operators with their transitions. Among its directives:
- Each agency head names a PQC migration lead within 30 days
- OMB issues implementing guidance within 90 days requiring agencies to review HVA and high-impact inventories (excluding NSS), transition those systems to PQC for key establishment by 31 December 2030, transition them to PQC for digital signatures by 31 December 2031, and submit a plan
- NIST runs a PQC migration pilot on a subset of its own systems, to complete no later than 31 December 2027
- Sector Risk Management Agencies work with CISA to help critical infrastructure owners develop migration plans
- The FAR Council publishes a proposed rule requiring covered contractors to comply with applicable NIST FIPS, including PQC, by 31 December 2030
OMB M-26-15 (24 June 2026)
M-26-15, Execution of the Migration to Post-Quantum Cryptography, is the implementing memorandum for civilian (non-NSS) agencies. It does not apply to national security systems. Core requirements:
- Prioritized migration of cryptographic systems on agency-owned or operated information systems, with the objective of mitigating as much quantum risk as feasible by 31 December 2030
- Submission of a PQC Migration Plan to OMB and ONCD within 120 days of the memorandum (approximately 22 October 2026)
- Risk-based prioritisation of high-impact systems, HVAs, and other systems with highly sensitive data or particular CRQC vulnerability
- Use of automation for inventory where feasible
- Engagement with FedRAMP-authorized providers on shared-responsibility migration
- A five-phase execution model from strategy and discovery through full migration in 2035
CNSA 2.0: national security systems
NSA's Commercial National Security Algorithm Suite 2.0 is the separate algorithm and timeline track for National Security Systems. It sets support-and-prefer then exclusive-use milestones by product category (software/firmware signing, networking equipment, operating systems, web/cloud services and constrained devices), with exclusive-use dates typically in the 2030-2033 window depending on category, ahead of the broader NSM-10 2035 goal. Software and firmware signing is deliberately early because roots of trust are hard to update after deployment. If you build for NSS or dual-use products that enter NSS environments, CNSA 2.0 is the bar, not M-26-15 alone.
Who Is in Scope
| Track | Who it binds | Primary instruments |
|---|
| Civilian federal agencies | Executive departments and agencies operating non-NSS information systems | EO 14412, OMB M-26-15, M-23-02 inventories, NIST FIPS / IR 8547 |
| National Security Systems | NSS owners/operators and vendors supplying them | CNSA 2.0, CNSSP policy, NSM-10 |
| Federal contractors / covered FAR parties | Contractors once the FAR PQC rule is final; planning should assume the EO's 31 December 2030 FIPS compliance direction | EO 14412 § FAR directive; forthcoming FAR rule |
| FedRAMP CSPs and multi-agency SaaS/PaaS/IaaS | Cloud and shared services used across agencies | M-26-15 coordination via CISA / Department of War / GSA |
| Critical infrastructure | Owners and operators assisted by Sector Risk Management Agencies and CISA | EO 14412 assistance mandate; not the same as a direct OMB plan filing, but migration planning is now an explicit federal engagement topic |
| Commercial sector (de facto) | Any vendor selling into the above | Product cryptography that cannot meet FIPS PQC or CNSA 2.0 timelines becomes a procurement blocker |
Private companies with no federal contract and no critical-infrastructure designation are not directly filed under M-26-15. They still inherit pressure through supply chain, FedRAMP, sector guidance and customer questionnaires that increasingly ask for PQC roadmaps.
The Timeline
| By | Milestone | Applies to |
|---|
| ~22 October 2026 | Agency PQC Migration Plan due to OMB and ONCD (120 days from M-26-15) | Civilian agencies |
| 2026-2027 | Phase 1: strategy, planning, discovery, governance, HVA/high-impact inventory refresh | Civilian agencies |
| 2027-2028 | Phase 2: pilots and early migration | Civilian agencies |
| By 31 December 2027 | NIST PQC migration pilot complete | NIST systems (EO 14412) |
| 2028-2030 | Phase 3: PQC key establishment on HVAs, high-impact and high-sensitivity systems; crypto-agility across those systems | Civilian agencies |
| 31 December 2030 | HVA / high-impact key establishment on PQC; EO target for covered contractor FIPS compliance | Agencies; contractors (per FAR rule once final) |
| 2031 | Phase 4: PQC digital signatures on the same priority systems | Civilian agencies |
| 31 December 2031 | HVA / high-impact signature migration complete | Civilian agencies |
| 2030-2033 (by category) | CNSA 2.0 exclusive-use milestones | NSS |
| 2035 | Phase 5: remaining systems; NSM-10 mitigation goal | Broad federal objective |
Key establishment is intentionally ahead of signatures for the civilian HVA track, matching the store-now-decrypt-later problem. CNSA 2.0 front-loads firmware signing for a different reason: update difficulty after fielding.
Practical First Steps
1. Cryptographic inventory
M-23-02 already required a prioritized inventory. M-26-15 assumes that work exists and pushes agencies to automate and maintain it. Whether you are an agency, a CSP or a contractor supporting HVAs, the inventory still has to answer:
- Where is classical public-key cryptography used for key establishment, signatures and authentication?
- Which systems are HVAs, FIPS 199 high-impact, or hold data that remains sensitive through 2030?
- Which products fall into CISA's product categories for technologies that use PQC standards?
- Which dependencies sit with FedRAMP providers versus agency-operated components?
A CBOM is the practical machine-readable form. Our CBOM guide and NIST PQC compliance mapping align that inventory work to CSF 2.0 / SP 800-53 style controls rather than a one-time spreadsheet.
2. HSM and KMS readiness
Federal migration fails when the algorithm is approved but the key store cannot hold or use it.
- Validate FIPS-validated modules and vendor roadmaps for ML-KEM, ML-DSA and hybrid key derivation
- Separate identity/PKI roots from application keys so signature migration in 2031 does not collide with 2030 key-establishment cutovers
- For NSS paths, confirm CNSA 2.0 algorithm support (including stateful hash-based signatures for software/firmware where required) on the earlier exclusive-use dates
- Treat cloud KMS under shared responsibility as a contractual migration workstream, which is what M-26-15 already tells agencies to do with FedRAMP providers
Systems that cannot support PQC or hybrid cryptography should be flagged for replacement or decommissioning inside the migration plan, not left as "exceptions" without owners.
3. Hybrid PQC deployment
M-26-15's technical direction supports phased migration with cryptographic agility; commercial TLS and IPsec stacks already ship hybrid key establishment combining classical ECDH with ML-KEM. For priority external and inter-system links:
- Deploy hybrid key establishment on HVA-adjacent TLS and VPN paths first (F5, FortiGate)
- Keep configurations crypto-agile so dropping the classical half later is a controlled change
- Sequence signature and certificate migration behind key establishment for civilian HVAs, except where firmware/code-signing lifetimes force earlier CNSA-style action
- Record pilot results in 2027-2028 so Phase 3 is an expansion, not a first contact with production traffic
The Technical Checklist
How This Maps to DuoKey Cockpit
M-26-15's emphasis on automated, maintained inventory is the same problem a CBOM and Quantum Risk Score are built to solve: continuous discovery of classical public-key use, prioritised by system criticality, rather than an annual static list. See the CBOM guide and the NIST PQC compliance page for control-oriented mapping.
Hybrid key establishment on common enterprise edge platforms is covered in the F5 and FortiGate guides, including MCP tools that apply ML-KEM hybrid profiles from a prioritised asset list. Customer-controlled key management addresses the shared-responsibility gap M-26-15 flags for cloud services: agencies and contractors can migrate algorithms without surrendering key custody to the provider by default.
FAQ
Q: Does M-26-15 apply to National Security Systems?
No. The memorandum states that it does not apply to NSS. Those systems follow CNSA 2.0 and related CNSS policy.
Q: Are private companies directly regulated by EO 14412?
Not in the same way as federal agencies. The order drives agency migration, critical-infrastructure assistance via Sector Risk Management Agencies and CISA, and a FAR rulemaking path for covered contractors. Commercial exposure is primarily contractual and sector-driven, but it is already real for anyone in the federal supply chain.
Q: Is hybrid cryptography required?
NIST and OMB emphasise migration to FIPS PQC with cryptographic agility. Hybrid classical-plus-PQC key establishment is the widely deployed interim pattern in commercial protocols and is consistent with a phased plan; treat it as a bridge you can exit, not as a permanent substitute for meeting the 2030 key-establishment objective on priority systems.
Q: How does this compare to UK, German or Swiss timelines?
The US civilian HVA track is more directive on near-term plan submission (days after M-26-15) and on 2030 key establishment for priority systems. The UK centres NCSC programme milestones through 2035. Germany names classical-only key-agreement retirement by 2031 in BSI TR-02102. Switzerland pushes FINMA-supervised firms to a mid-2027 roadmap without a single national technical sunset. Multinationals should map products once against the strictest applicable row.
Conclusion
US federal PQC policy is past the "please inventory" stage. NIST defined the algorithms, statute required planning, EO 14412 and OMB M-26-15 set HVA key establishment by 2030 and signatures by 2031, with agency plans due in late 2026, while CNSA 2.0 runs a tighter category calendar for NSS. Build the inventory you can automate, prove HSM/KMS readiness for FIPS PQC key types, and put hybrid key establishment on priority paths early enough that 2030 is an expansion year, not a discovery year.
References