President Trump signed “Securing the Nation Against Advanced Cryptographic Attacks” on June 22, 2026, imposing a binding December 31, 2030 deadline on federal contractors to adopt NIST post-quantum cryptography FIPS standards for key establishment, and starting a 180-day clock for the FAR Council to publish a proposed rule codifying those requirements across the acquisition system.
Background
Quantum computing threatens the cryptographic algorithms protecting most federal data today. Current encryption methods rely on mathematical problems—integer factorization and discrete logarithm—that classical computers cannot solve in practical timeframes. A quantum computer of sufficient power would break those protections in hours. The more immediate danger, however, is a tactic called harvest-now-decrypt-later: adversaries collect encrypted federal communications now, store the data, and decrypt the archive once quantum computing matures. That threat operates today regardless of when operational quantum computers arrive, making it an active risk to data collected under current encryption rather than a future contingency. The executive order identifies this tactic as a primary driver of urgency behind the 2030 deadline.
NIST addressed the underlying technical problem by finalizing three post-quantum cryptography standards in 2024: FIPS 203 (ML-KEM for key establishment), FIPS 204 (ML-DSA for digital signatures), and FIPS 205 (SLH-DSA also for digital signatures). The June 22 executive order converts those technical standards into acquisition requirements by setting statutory-style compliance deadlines and directing FAR rulemaking to bring the contractor base into mandatory alignment with the new FIPS specifications.
Trump signed a companion order the same day—“Ushering in the Next Frontier of Quantum Innovation”—updating the National Quantum Strategy and reconstituting the National Quantum Initiative Advisory Committee. The two orders form a coordinated federal quantum strategy: accelerate domestic quantum capability development while simultaneously hardening federal and contractor systems against quantum-enabled attacks before adversary quantum computers reach operational maturity.
Key Details
The executive order establishes a two-phase compliance schedule. Federal agencies must transition high-value assets and high-impact systems to post-quantum cryptography for key establishment by December 31, 2030. Digital signature migration follows one year later, by December 31, 2031. The phased structure reflects the elevated risk profile of key establishment: that function—the process of securely exchanging cryptographic keys—is the primary channel exploited by harvest-now-decrypt-later collection operations and the first priority for migration.
The FAR Council must publish a proposed rule within 180 days of the June 22 signing date, placing the deadline at approximately December 19, 2026. Once effective, the rule will require contractors to comply with FIPS-aligned PQC standards through enforceable contract clauses—the first hard contractual obligation imposed on the contractor base for post-quantum cryptographic compliance, with flow-down requirements reaching subcontractors across the supply chain. A separate FAR proposed rule, due within 270 days, will require contractors to update their vulnerability disclosure programs to cover cryptographic vulnerabilities including the use of non-FIPS-approved algorithms.
The Secretary of Homeland Security, through the Director of CISA and in coordination with NIST, must release public guidance on cryptographic bill of materials (CBOM) within 270 days of signing. A CBOM is a structured inventory of the cryptographic assets embedded in a system—algorithms, key lengths, libraries, and dependencies—analogous to the software bill of materials requirements now standard in federal software acquisition. The Secretary of Commerce, through NIST, must initiate a PQC implementation pilot within 180 days and complete it by December 31, 2027, giving agencies tested migration playbooks roughly two years before the 2030 key-establishment deadline arrives.
Each federal agency must appoint a PQC migration lead within 30 days of signing and provide that designation to the Director of OMB and the National Cyber Director. OMB must separately issue guidance within 90 days directing agencies to inventory high-value assets and high-impact systems and develop prioritized migration plans aligned to the 2030 and 2031 deadlines.
What It Means for Contractors
Contractors supporting federal agencies across defense, civilian, intelligence, and law enforcement missions should treat the December 2026 proposed FAR rule as the near-term compliance trigger. That rulemaking will define which contract types, dollar thresholds, and system categories fall within scope, and will establish clause language that flows down to subcontractors. Prime contractors should begin inventorying which encryption libraries, hardware security modules, and key management systems their programs currently use, because replacing cryptographic infrastructure at scale requires procurement lead time that a 2030 deadline cannot absorb if planning does not begin until the FAR rule takes effect. Waiting for the final clause to appear before assessing current cryptographic posture creates avoidable schedule risk and likely limits the ability to comment meaningfully on the proposed rule.
The CBOM guidance due within 270 days signals that agencies will begin requiring contractors to document their cryptographic posture the same way SBOM requirements document software component lineage. Contractors who have built SBOM generation into DevSecOps pipelines are positioned to extend those workflows to cover cryptographic inventory; those who have not will face parallel compliance burdens on both fronts simultaneously.
Subcontractors and suppliers providing encryption-dependent products or services—network hardware, cloud platforms, identity and access management systems, and communications infrastructure—should expect prime contractors to push PQC compliance requirements down through the supply chain once the FAR clause takes effect. Companies whose products rely on RSA-2048 or elliptic curve cryptography will need migration roadmaps ready for contracting officers and program managers during source selection and performance reviews alike.
Mayer Brown characterizes the orders as signaling the federal government’s intent to simultaneously accelerate the quantum era and harden against it, and predicts the compressed 2030–2031 federal timeline will likely become a reference point for private-sector expectations as well. The FAR rulemaking represents a concrete shift from directional policy—previous PQC guidance from NSA and OMB set expectations without enforceable contract-level consequences—to mandatory contractual requirements. Non-compliance after the final rule takes effect will constitute a contract deficiency, not a policy deviation, with the full range of remedies available to contracting officers that classification implies.
Contractors should also monitor the Commerce Department’s implementation pilot, due December 31, 2027. Pilot results will likely shape agency-specific transition guidance and influence how the FAR clause defines acceptable PQC implementations. The FAR Council’s comment period on the proposed rule—expected to open before the end of 2026—will give industry a direct channel to shape compliance requirements around realistic migration timelines, particularly for programs with long acquisition cycles where mid-stream cryptographic overhauls carry substantial integration risk.
Sources
- Securing the Nation Against Advanced Cryptographic Attacks | The White House
- Securing the Nation Against Advanced Cryptographic Attacks | Federal Register
- White House Orders Federal Agencies to Migrate Systems to Post-Quantum Cryptography | Cybersecurity Dive
- President Trump Signs Two Executive Orders on Quantum Computing and Post-Quantum Cryptography Migration | Mayer Brown