The Office of Management and Budget has moved federal agencies and their contractors from inventorying cryptography to actively replacing it. On June 24, 2026, OMB issued Memorandum M-26-15, "Execution of the Migration to Post-Quantum Cryptography," the implementation companion to Executive Order 14412. The memo translates the order's high-level deadlines into execution milestones and adds a new artifact contractors will have to produce: a Cryptographic Bill of Materials, or CBOM, that catalogs the encryption algorithms and protocols running inside the systems and software they deliver to the government.
Background
The federal government has spent years preparing for a cryptographic problem it cannot yet see. A sufficiently capable quantum computer would break the public-key algorithms that secure most government and commercial communications today, and adversaries are widely understood to be harvesting encrypted data now to decrypt it later, once that capability arrives. Data with a long secrecy lifespan, such as weapons designs, intelligence reporting, and personnel records, is exposed to that "harvest now, decrypt later" threat regardless of how far off practical quantum computing remains. Earlier federal efforts focused on discovery, directing agencies to inventory their cryptographic systems and report which ones relied on vulnerable algorithms. That baseline was about knowing what cryptography agencies actually ran.
Key Details
M-26-15 marks the shift from discovery to execution. It follows Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks," signed June 22, 2026. The order sets firm dates: agencies must move their High Value Assets and high-impact systems to post-quantum key establishment by December 31, 2030, and to post-quantum digital signatures by December 31, 2031. A NIST pilot project must be complete by December 31, 2027. The new OMB memo is the document that tells agencies and the vendors serving them how to hit those dates rather than simply restating them. It builds on a standards foundation NIST has already laid, having finalized its first post-quantum algorithms, and it pushes the work of swapping those algorithms into live systems onto a defined schedule.
The memo and its parent order create several obligations that reach directly into the contractor base. First, the timeline. Covered contractors must comply with NIST Federal Information Processing Standards, including the post-quantum algorithms NIST has finalized, by December 31, 2030. That is the same end-of-2030 deadline agencies face for their most sensitive systems, which means vendors cannot treat compliance as a problem for the next decade. Agencies, for their part, must designate post-quantum migration leads within 30 days of the order, creating the points of contact who will eventually press suppliers for evidence of progress.
Second, the Cryptographic Bill of Materials. EO 14412 directs CISA and NIST to publish, within 270 days, the minimum elements for a CBOM. The concept is deliberately modeled on the Software Bill of Materials, or SBOM, that contractors increasingly attach to software deliverables. Where an SBOM lists the components and dependencies in a piece of software, a CBOM inventories the cryptographic algorithms and protocols embedded in hardware and software components, and it is meant to enable automated assessment of which cryptographic assets are quantum-vulnerable. Once CISA and NIST publish the minimum elements, the CBOM becomes the mechanism by which agencies will check whether a delivered product meets the post-quantum standard, rather than relying on a vendor's assurances.
Third, supporting deadlines that shape how fast the standards mature. NIST must accelerate its Cryptographic Module Validation Program processes within 180 days, easing one of the bottlenecks that has slowed vendors trying to get post-quantum modules certified. NIST is also tasked with leading international engagement with foreign governments and industry groups, and with completing the pilot project by the end of 2027. Contractors are separately directed to maintain vulnerability disclosure policies that account for cryptographic vulnerabilities, consistent with NIST guidance, folding cryptographic weaknesses into the same reporting discipline that already covers software flaws.
What It Means for Contractors
For companies that sell software, hardware, or cloud services to the federal government, M-26-15 converts post-quantum cryptography from a research topic into a delivery requirement with a date attached. The end-of-2030 FIPS-compliance deadline applies to the products vendors ship, so engineering teams need to know now which of their components rely on the public-key algorithms slated for replacement. That assessment is exactly what the forthcoming CBOM is designed to support, and contractors who already produce SBOMs have a head start on the tooling and processes a CBOM will demand. The harder cases are embedded systems and long-lived hardware, where cryptography is baked into firmware that cannot be patched as easily as an application, and where the runway to 2030 is shorter than it looks.
The CBOM mandate also signals where contracting requirements are heading. SBOMs moved from voluntary best practice to contractual expectation over several years; the deliberate framing of the CBOM as its cryptographic analog suggests a similar trajectory. Vendors who build cryptographic inventories into their development pipelines before the minimum elements are finalized will be positioned to meet whatever solicitation language follows, rather than scrambling to retrofit it. The 270-day clock for those minimum elements means the specification should arrive in roughly the first quarter of 2027, leaving a narrow runway to the 2030 deadline and little margin for vendors who wait for the requirement to appear in a contract before acting.
There is also a competitive dimension. The 180-day instruction to speed up the Cryptographic Module Validation Program addresses a real constraint, because vendors cannot sell a validated post-quantum module faster than NIST can validate it. Companies that enter that pipeline early, while the queue is shorter, will have validated products to offer agencies that must show progress against their own 2030 and 2031 milestones. As agencies designate migration leads and begin pressing their supply chains, the contractors who can already document quantum-resistant cryptography, and prove it through a CBOM, will hold an advantage in the procurements that follow. The memo does not create a new market so much as it sets a date by which the existing one must change, and it rewards the vendors who treat that date as 2026 work rather than 2030 work.