up:: For Policymakers MOC

What can a city actually do?

A city is the level of government most residents actually deal with, and it is the level no post-quantum mandate reaches.

OMB M-26-15 binds federal civilian executive branch agencies. CNSA 2.0 governs national security systems. A city files no migration plan under either, answers to no phase date in either, and appears nowhere in the scope of either.

This is checkable rather than an interpretation

M-26-15 is addressed “TO THE HEADS OF EXECUTIVE DEPARTMENTS AND AGENCIES” and carries exactly one explicit exclusion, stated verbatim: “This memorandum does not apply to national security systems.” The words local, tribal, municipal and territorial appear zero times in the document. Local government is not excluded from the memo; it was never inside the universe the memo addresses. Verified against the source PDF on 2026-08-10 and reproducible by anyone with the same file. Source: OMB, M-26-15, June 24, 2026, M-26-15 PDF.

Meanwhile the city operates the schools, the public hospitals, the benefits office, the courts, the transit system, the emergency dispatch, the property records and the vital records.

Not legal advice

This is general education about available authority rather than legal advice. What a particular city may do is a determination for its own counsel and its own charter.

The short version:

  • No federal post-quantum requirement applies to a city. The mandates that get quoted in coverage bind federal agencies.
  • One federal requirement does reach local government, and it arrives by data type. Criminal Justice Information carries a cryptographic obligation that follows the data into a local police department.
  • The result is a split inside one government. Police systems can carry a federal cryptographic duty while schools, hospitals and finance carry none.
  • A city’s fastest lever is procurement, and in most cities it needs no legislation at all. Many large cities already run a centralized review of technology purchases. The measure is a line added to a review that already happens.
  • Most of a city’s cryptographic posture is not a city decision. It is set by whichever provider operates the service, which is measurable from the outside in an afternoon.
  • The email lane is the one nobody looks at, and it is where the published measurements are worst.

Why is the city level different from the state level?

A state has a legislature, regulatory agencies, and supervisory authority over insurers, banks and hospitals. What can a state actually do describes levers built on those. A city usually has none of them, and pursuing the state playbook at city level wastes a year.

What a city has instead is narrower and faster.

A city is an operator before it is a regulator. Its primary exposure is its own systems, holding its own residents’ records, and it can act on those without asking anyone.

A city buys continuously and centrally. Large municipal technology purchasing is substantial, recurring, and in most charters governed by administrative rules rather than by ordinance. A purchasing condition is typically an administrative act.

A city’s decision cycle is short. A commissioner or a chief technology officer can issue a directive covering every agency in weeks. That is faster than any legislature in the country.

And a city has almost no cryptographic staff. Whatever a city adopts has to be executable by people who already have full jobs, which rules out anything requiring specialist headcount.

What can a city do with no legislation and no budget?

Three actions, in the order they should happen.

1. Add one line to the procurement review that already exists

Most large cities centralize technology purchasing review somewhere, often in a technology office with a cybersecurity function inside it. New York City is the clearest published example: its Cyber Command was created by New York City Charter § 20-j and sits within the Office of Technology and Innovation, which carries a cyber policy function that writes citywide standards and an audit function that checks compliance against them.

New York City’s own contracting documents define that office’s powers, and the relevant clause is explicit:

“Cyber Command” means the Office of Cyber Command, created by New York City Charter § 20-j, established within the New York City Office of Technology and Innovation (“OTI”), that is empowered to ensure compliance with Policies and Standards, lead citywide cyber defense, investigation and incident response… coordinate deployment of citywide technical and administrative controls related to information technology, information security and information privacy and review citywide cyber related procurements, in collaboration with procuring agencies.

Sources: New York City Charter § 20-j and NYC contract security requirements, October 2023, nyc.gov. The office is headed by a director appointed by the mayor who serves as the chief information security officer of the city.

Confirm the equivalent in your own charter

The point generalizes even where the details differ: almost every large city already reviews technology purchases somewhere, and that review is the insertion point. A city adapting this should confirm where its own purchasing review sits and what it is empowered to ask.

What the line does is require a written answer, not a capability. A vendor that cannot yet support post-quantum cryptography answers the question honestly and the city has a dated record. A vendor that will not answer has told the city something more useful than a yes.

2. Direct an inventory of what the city operates itself

The federal executive branch has required its own agencies to maintain an algorithm-level cryptographic inventory since 2023. A city chief technology officer can direct the equivalent for city systems under ordinary administrative authority in most charters.

Source: Office of Management and Budget, Memorandum M-23-02, November 18, 2022, OMB M-23-02.

Scope it to what the city runs rather than to everything. The systems a city operates directly are the only ones a city decision can fix directly, and they are usually a small enough set to inventory in a quarter. Everything else is a vendor question, which is action 1.

3. Measure the outside surface, which takes an afternoon

A city’s public-facing cryptographic posture is measurable from outside, by anyone, without touching a city system. This matters more than it sounds, because it means the answer already exists and someone else may publish it first.

The measurement also usually shows that the answer was never a city decision. See the next section.

Why is most of a city’s posture not a city decision?

Because the city does not operate the service.

Two independent measurement studies published in 2026 found the same thing at different scales: which infrastructure provider operates an endpoint predicts its post-quantum support far better than any property of the organization that owns it.

A UK study of 4,665 organizations across 10 sectors put a number on it. A model using only the provider identity achieved an AUC of 0.957 at predicting web support, against 0.573 for a model using only the organization’s sector. On the email lane, with the analysis grouped by mail host, provider-only reached 0.994 while sector-only reached 0.156, which is below chance.

Source: Loizou and Ghadafi, Measuring Post-Quantum TLS Deployment Across UK Internet Sectors, arXiv 2608.02147, 2026. Corroborated at global scale by Wickramasinghe et al., arXiv 2607.29005, 2026.

For a city that has three consequences.

A good post-quantum score on the city website may be entirely the content delivery network’s doing, and reflects no decision anyone at the city made. A bad score on another service is usually the same situation in reverse. And the only systems where a city decision changes the answer are the ones it operates itself, which is why action 2 above is scoped that way.

Why is the email lane the one to look at?

Because it is where the measured numbers are worst, and because almost nobody checks it.

The same UK study measured both lanes on the same organizations. 44.0% of reachable web endpoints supported a post-quantum key exchange, against 6.4% of email endpoints. Among the 3,510 organizations reachable over both, 144 supported it on both, 1,419 supported it on the web only, and 1,863 supported it on neither.

The gap is not evenly spread across providers. In that study one provider accounted for 98.4% of all post-quantum-supporting email endpoints, while several large mail providers showed no observable support at all across thousands of endpoints.

What this means for a city. A readiness assessment that looks only at the website will report the city as substantially further along than it is. The web lane is largely handled by content delivery networks that turned the feature on. The email lane runs through mail providers, many of which have not, and email is where a city’s correspondence with residents, clinicians, attorneys and caseworkers actually travels.

Checking it is cheap. The mail provider for any public domain is visible in public DNS records, which is not a scan of anyone’s systems and touches nothing the city operates.

What does the actual language look like?

Two artifacts, neither of which is legislation.

A. The procurement condition

Adaptable to a solicitation, a contract rider, or a purchasing standard. The obligation is disclosure, not capability, which is what makes it adoptable immediately rather than after a market exists.

Cryptographic transition disclosure. The vendor shall state in writing, at contract execution and at each renewal: (a) whether the products or services provided support post-quantum key establishment as standardized by the National Institute of Standards and Technology, and for which components; (b) if support is not present, the vendor’s dated plan for providing it; (c) whether the products or services can receive cryptographic updates during the contemplated service life, and by what mechanism; and (d) the name of the underlying infrastructure or hosting provider on which the service depends, where the vendor does not itself operate that infrastructure.

A response of “not currently supported” is a complete and acceptable answer. A refusal to respond is not.

Clause (d) is the one most drafts omit and the one this Guide would keep. It is the clause that surfaces the finding above, that the answer usually belongs to a provider the city never contracted with directly.

B. The review addendum

For the office that already reviews technology purchases.

Technology procurements are reviewed for a completed cryptographic transition disclosure. Where a procurement covers a system that stores or transmits records with a retention or sensitivity period exceeding 10 years, the absence of a disclosure is noted for the record and reported in the review’s periodic summary.

A city can adopt both in a quarter. Neither requires a council vote in most charters, an appropriation, or a single new position.

Which municipal systems are most exposed?

Worth naming, because a city asking about its own house asks better questions of its vendors.

SystemWhy it’s the worst case
Public hospitals and clinicsClinical records with lifetime sensitivity, often on self-operated infrastructure
SchoolsStudent records, health and disciplinary files, held from childhood forward
Benefits and social servicesHousehold financial and immigration-adjacent data on vulnerable residents
Courts and correctionsSealed records, juvenile files, protected identities, witness information
Vital recordsBirth, death, marriage. Permanent by definition and not reissuable
Police and emergency dispatchCriminal justice information, which carries its own federal obligation
Transit and utilitiesOperational equipment with service lives past 20 years
Property and tax recordsPermanent, public in part, and financially load-bearing

The pattern is the same one the state analysis finds, with the budgets an order of magnitude smaller.

What should a city avoid attempting?

A city-wide technology mandate on private businesses. A city requiring that products sold or services operated in its jurisdiction meet a cryptographic standard invites a preemption fight it will lose, and it consumes the year that the procurement route would have used productively.

A migration program the city cannot execute. Announcing a transition of systems the city does not operate produces a plan whose milestones belong to vendors, which is how these efforts become documented non-compliance rather than progress.

Waiting for the state or the federal government. No current instrument reaches this layer, and nothing indicates one is coming. See What is not legislated yet.

What are the 5 questions for a city agency head?

Answerable without technical background, and a deflection is audible in each.

  1. Which of the systems you operate hold records that stay sensitive for more than 10 years?
  2. For your most important service, who actually operates the infrastructure it runs on, and is that in your contract?
  3. What does your email travel through, and have you ever asked that provider about post-quantum support?
  4. Which of your systems or equipment cannot receive a cryptographic update at all?
  5. Does your next procurement ask the vendor to state its cryptographic transition position in writing?

A longer version with what a substantive answer and a deflection each sound like is at What should I ask in a hearing.

What are the questions for a vendor?

Written so a roadmap is not an answer.

  1. Which of the post-quantum key-exchange groups do your production endpoints support today, by name?
  2. If the answer is none, on what date will that change, and is that date contractual or aspirational?
  3. Whose infrastructure does this service run on, and does your answer to question 1 depend on their decision rather than yours?

See The Vendor-Claims Checklist for the fuller version and the common evasions.

Questions people ask

Does any post-quantum mandate apply to my city? No federal one does. The instruments that get quoted bind federal civilian agencies or national security systems. Check whether your state has acted, since a state can reach its municipalities through procurement terms or funding conditions in ways no federal instrument currently does.

What about our police department? Criminal Justice Information carries a federal cryptographic requirement that follows the data to any entity handling it, including local law enforcement. Controls SC-13 and SC-28 require a cryptographic module certified to FIPS 140-3, or a FIPS-validated symmetric algorithm with a 256-bit key, for that information in transit and at rest outside a physically secure location. That requirement is classical, verified against the policy text on 2026-08-10: the word quantum appears zero times across all 473 pages of CJIS Security Policy v6.1, and the policy sets no key-establishment requirement anywhere. Your police systems are covered by a federal cryptographic rule and uncovered by any post-quantum one, which is a useful thing to know before a vendor tells you otherwise.

We have no cybersecurity staff. Is any of this realistic? The three actions on this page were chosen to be executable without specialist staff. Asking a vendor a written question, listing the systems you operate, and reading public DNS records are administrative tasks. The work that needs a cryptographer starts after those three produce a picture.

Isn’t this a problem for 2035? The exposure that matters at a city is records with long confidentiality horizons, and those are being transmitted today. See Harvest Now Decrypt Later.

Our website already shows post-quantum support. Are we finished? Probably that is your content delivery network rather than a decision anyone at the city made, and it says nothing about your email, your internal systems, or your vendors. The measured gap between the two lanes is large.

Can a city really change what a vendor does? One city, rarely. A requirement appearing in the solicitations of many cities changes a supplier’s roadmap, and every other customer of that supplier benefits without asking. This is the same mechanism the state analysis relies on. Whether municipal purchasing in aggregate outweighs any given state is not a figure this Guide has sourced, so it is not claimed here; what matters is that a requirement appearing repeatedly changes a roadmap, and cities buy from the same suppliers states do.

Is any city doing this already? This resource does not track municipal activity comprehensively. If a city has adopted a post-quantum procurement condition or an inventory directive that is not reflected here, that is a correction worth sending. See Corrections and verification.

Where to go next

Go deeper into the technical detail

The Vendor-Claims Checklist is the tool for evaluating the answers action 1 produces.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.