up:: For Policymakers MOC
What laws and rules already exist?
More than most people expect, and less than the situation needs.
Congress has passed 1 statute on this. The executive branch has issued 3 directives and an agency memorandum. NIST has published the technical schedule and the NSA has published its own. Every one of those reaches federal systems, and none of them requires a private company to do anything.
That’s the shape of the gap: the government has regulated itself thoroughly and has left the private sector to inherit the requirement through procurement, certification, and contracts.
Not legal advice
This is general education about published instruments. Whether any of them reaches a particular organization is a legal determination.
The short version:
- One act of Congress exists, signed December 21, 2022, and it directs agencies to inventory and prioritize rather than setting a deadline.
- The most-quoted date, 2035, is the softest instrument, a policy goal with “as is feasible” written into the operative sentence.
- The dates with teeth land earlier: 2027 for national security acquisitions, 2030 and 2031 for federal civilian systems.
- The retirement schedule is a draft, so its years are stated intent rather than settled rule.
- Nothing here binds a private company directly. The requirement reaches the private sector through purchasing and certification.
- The oldest relevant instrument is from 2009, and it’s the classification order that sets 25, 50, and 75-year secrecy horizons.
What has Congress actually passed?
One statute. The Quantum Computing Cybersecurity Preparedness Act became Public Law 117-260 when it was signed on December 21, 2022, having passed as H.R. 7535.
What it does is procedural rather than technical. It directs the Office of Management and Budget to prioritize federal agency migration to post-quantum cryptography, requires agencies to inventory their cryptographic systems, and requires reporting to Congress on the funding and strategy needed. It names no algorithm and sets no deadline for completing a migration.
Source: govinfo.gov, “Public Law 117-260, Quantum Computing Cybersecurity Preparedness Act,” govinfo.gov; congress.gov, “H.R.7535, 117th Congress,” congress.gov.
The significance is that Congress established inventory and prioritization as a statutory duty rather than an administrative preference, which means it survives a change of administration in a way an executive order may not. What it doesn’t do is reach anybody outside the federal government.
Which executive directives are in force?
Three, issued across 4 years, each doing a different job.
| Instrument | Date | What it does |
|---|---|---|
| National Security Memorandum 10 | May 4, 2022 | Sets the whole-of-government goal of mitigating quantum risk “as is feasible” by 2035, and assigns the implementing work to NIST, the NSA, and OMB |
| Executive Order 14306 | June 6, 2025 | Requires federal agencies to support TLS 1.3 or a successor by January 2, 2030, and directs CISA to publish a list of product categories that support post-quantum cryptography |
| Executive Order 14412 | June 22, 2026 | Sets the operative federal civilian deadlines for High Value Assets and high impact systems: key establishment migrated by December 31, 2030, and digital signatures by December 31, 2031 |
| NSPM-12 | June 12, 2026 | Rewrites cybersecurity governance for national security systems, rescinding a 1990 directive and a 2022 memorandum, and naming the standard those systems are held to. Sets no post-quantum date. |
Source: NSM-10, May 4, 2022, bidenwhitehouse.archives.gov; The White House, presidential action of June 6, 2025, whitehouse.gov; Executive Order 14412, June 22, 2026, whitehouse.gov; NSPM-12, June 12, 2026, whitehouse.gov.
A caution on NSPM-12, because it’s recent and gets described loosely. It rewrites governance for national security systems and it addresses cryptographic authority, and it contains no explicit mention of post-quantum cryptography and sets no migration date. Citing it as a post-quantum instrument is an error a reader with the document open will catch. The full treatment is NSPM-12.
Two features of that table matter for legislative purposes. The 2035 in NSM-10 carries its own hedge, which is why treating it as a deadline overstates it, and the 2030 and 2031 dates in the 2026 order are the ones a federal program is actually measured against. And the TLS date in the 2025 order is a transport-readiness milestone rather than a completed migration, since it leaves certificates, code signing, and stored data untouched.
What do the agencies require?
Three instruments, and they differ in force.
The OMB memorandum is binding on agencies. Memorandum M-23-02, issued November 18, 2022, requires federal civilian agencies to submit a prioritized, algorithm-level inventory of their cryptographic systems, annually, first due May 2023. It reaches contractor-operated systems explicitly, and the accountability stays with the agency rather than transferring to the vendor.
Source: Office of Management and Budget, Memorandum M-23-02, whitehouse.gov.
The NSA suite is binding on national security systems. CNSA 2.0 requires post-quantum algorithms in all new national security system acquisitions from January 1, 2027, exclusive use for software and firmware signing and traditional networking equipment by 2030, and web browsers, servers, cloud, and operating systems by 2033. It reaches commercial vendors through procurement rather than by naming them.
Source: NSA, “CNSA 2.0 FAQ,” media.defense.gov.
The NIST schedule is a draft. NIST IR 8547 sets out the retirement plan: 112-bit RSA and elliptic-curve cryptography deprecated after 2030, all classical public-key disallowed after 2035. It sits in an initial public draft, so those years are NIST’s stated intent and could change. They’re already propagating through procurement language and vendor roadmaps regardless.
Source: NIST IR 8547, initial public draft, csrc.nist.gov.
Which of these is binding, and on whom?
| Instrument | Binding on | Type |
|---|---|---|
| Public Law 117-260 | Federal agencies, via OMB | Statute |
| NSM-10 | Federal agencies | Presidential directive with a hedged goal |
| Executive Order 14306 | Federal agencies | Binding executive order |
| Executive Order 14412 | Federal civilian executive-branch systems | Binding executive order |
| OMB M-23-02 | Federal civilian agencies, including contractor-operated systems | Binding agency memorandum |
| CNSA 2.0 | National security systems and their vendors | Binding national security system policy |
| NIST IR 8547 | Federal systems directly, and anyone bound to validated cryptography indirectly | Draft technical guidance |
| CISA, NSA, and NIST joint guidance | Nobody, formally | Advisory, and treated as the reasonable-organization baseline |
| Executive Order 13526 | Classified national security information | Binding, and the source of the 25, 50, and 75-year horizons |
The last 2 rows do more work than their status suggests. Advisory guidance sets what a careful organization was expected to be doing, which is the reference an auditor, a regulator, an insurer, or an opposing lawyer reaches for afterward. And the classification order is what makes the confidentiality lifetime of government material a matter of published policy rather than of judgment.
Source: CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov; Executive Order 13526, archives.gov.
What do these instruments leave out?
Four things, and each is a live legislative question rather than an oversight.
- No private-sector obligation. No U.S. instrument requires a bank, hospital, utility, or software vendor to inventory its cryptography or migrate it. The requirement arrives through federal procurement, sector regulators, and customer contracts.
- No notification duty. Nothing requires anyone to tell a person that their encrypted data was collected, because no law contemplates a harm with no detectable event. See What is not legislated yet.
- No funding attached. The inventory and migration duties came without appropriations sized to them, and the projected federal civilian cost is roughly $7.1 billion. See Who pays for this.
- No obligation on long-lived products. Nothing requires a manufacturer to ship a device whose cryptography can be updated during its service life, which is the gap that makes medical and industrial equipment the hardest category.
Questions people ask
Is post-quantum cryptography required by U.S. law? For federal systems and national security systems, yes, through the instruments above. For a private company, no U.S. instrument requires it directly.
Which single date binds a federal civilian agency? December 31, 2030 for key establishment and December 31, 2031 for digital signatures, from Executive Order 14412, and both apply to High Value Assets and high impact systems rather than to every system an agency runs.
Does the act of Congress set a deadline? No. It directs inventory, prioritization, and reporting. The dates live in the executive directives and the NIST and NSA schedules.
Why is 2035 quoted so often when it’s the weakest instrument? It was the first number published, it’s memorable, and it appears in the founding directive. The hedge sits in the same sentence, which is what gets dropped in retelling.
Can an executive order be reversed? Yes, which is why the statutory inventory duty and the NIST technical schedule matter independently. Public Law 117-260 doesn’t depend on any administration.
What happens if a federal agency misses a date? These are compliance obligations enforced through oversight, budget, and reporting rather than through penalties. The consequence is administrative rather than financial.
Do these reach state and local government? Not directly. State systems inherit requirements through federal grant conditions, through federal data-sharing agreements, and through the same procurement channel that reaches private vendors.
Where to go next
- What are other countries doing compares this against 6 other national approaches.
- Is anyone coordinating this internationally covers whether these regimes fit together.
- What is not legislated yet covers the gaps in detail.
- Who pays for this covers the funding question.
- For Policymakers MOC is the full legislative route.
Go deeper into the technical detail
The technical index of every instrument, with primary sources, is The Mandates MOC.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.