Federal agencies must integrate post-quantum cryptography with identity and authentication systems to meet White House deadlines for migrating high-value assets by 2030 and completing full migration by 2035. DoD, CISA and NIST outlined a phased approach beginning with system inventories through 2027, followed by pilot deployments and full migration completion.
What's happening
- OMB and the National Cyber Director require agencies to submit post-quantum cryptography migration plans by end of October 2026.
- Phase one runs 2026-2027: agencies inventory cryptographic systems, define strategy and build awareness.
- Phase two spans 2027-2028: agencies execute pilot projects and early migrations of prioritized systems.
- White House deadlines require high-value assets PQC-ready by 2030, digital signature migration by end of 2031, and complete migration of all systems by 2035.
Why it matters
- Public key infrastructure and identity systems like PIV and CACs must support post-quantum cryptography or entire migration strategy will fail, according to DoD officials.
- Federal agencies currently lack consistent visibility into cryptographic assets across their enterprises, making risk-based prioritization and cost estimation impossible.
- Quantum computing threatens to break current encryption standards, creating urgent need to migrate high-value defense and intelligence systems before threat maturation.
- Mission-critical systems across DoD, civilian agencies and intelligence community face different urgency levels, requiring complex triage of limited migration resources.
Going deeper
- CISA identified that federal agencies are behind schedule in preparing system inventories and currently treat the process as box-checking compliance rather than true asset visibility.
- Budget constraints and personnel departures across agencies have slowed PQC migration preparations, with some organizations lacking dedicated PQC migration leads.
- DoD faces complexity in determining which systems within different mission areas should receive first-priority migration funding due to varying organizational purposes and dependencies.
- Agencies must identify interoperability and performance challenges through pilots before full migration to understand operational impacts of post-quantum cryptographic systems.
The intrigue
- Federal civilian agencies have not yet built consistent cost estimates for post-quantum cryptography migration and lack mechanisms to connect estimated costs to approved budgets.
- Identity and authentication systems present the biggest technical challenge to meeting the 2030 deadline, yet the article indicates incomplete specification of required changes to PIV and CACs.
The fine print
- Timelines reflect OMB June 2026 guidance and White House deadlines; all agencies must deliver migration plans by end of October 2026.
- Phase one focuses on inventory and planning; actual migration work does not accelerate until phase two beginning 2027.
- High-value assets have earlier deadline (2030) than digital signature systems (2031) and all other systems (2035), creating staged compliance requirements.