The clock is already running. Here’s what compliance with EO 14412 actually demands and where agencies can’t afford to miss a step.If you work in security or networking for a U.S. federal agency or a firm that holds federal contracts, Executive Order 14412 is no longer a future concern. It’s a present operational mandate. And with OMB Memorandum M-26-15 now in effect, the transition from awareness to accountability is complete.This blog covers what you need to know about the OMB’s guidance so you can include the required information in your PQC transition plan, which is due to the OMB by October 22, 2026. Why EO 14412 Exists: The Threat Is Already ActiveBefore getting into compliance mechanics, it’s worth understanding the driving threat model.EO 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” is built around one foundational problem: the cryptographic standards protecting federal data today will be broken by cryptographically relevant quantum computers (CRQCs). Some experts believe a viable CRQC could emerge by 2030.Adversaries are already executing “Harvest Now, Decrypt Later” (HNDL) campaigns. They’re exfiltrating encrypted federal data today, stockpiling it with the intent to decrypt it once quantum hardware is available. Data with a long operational shelf life, including intelligence sources, health records, and financial instruments, is already compromised in this model. The deadline to act is not 2030. It’s now.EO 14412 and the implementing guidance from OMB respond to this by shifting the federal government’s posture from “we should plan to migrate” to “migration is policy, with named owners, hard deadlines, and enforceable consequences.”Who Owns the Governance StructureEO 14412 establishes clear accountability at the top:OMB Director and the National Cyber Director jointly coordinate the government-wide migration.NIST, CISA, and NSA provide agencies technical implementation guidance.Each agency head was required to designate a PQC Migration Lead within 30 days of the order, a deadline that passed in July 2026.If your agency hasn’t named a PQC Migration Lead yet, that is already a compliance gap.The Migration Lead isn’t just a title. This individual owns accountability for the entire transition process and is responsible for coordinating across IT, cybersecurity, legal, procurement, and program offices. The cross-functional scope is intentional: PQC migration cannot be solved by the security team alone. OMB M-26-15: The Binding Implementation MemoIssued June 24, 2026, OMB Memorandum M-26-15 (“Execution of the Migration to Post-Quantum Cryptography”) is the document that turns EO 14412 into operational requirements. It establishes expectations, timelines, and the structure of what agencies must produce.The first hard deadline it creates: every civilian agency must submit a comprehensive PQC Migration Plan to OMB and the Office of the National Cyber Director (ONCD) by October 22, 2026. That is 30 days from this blog’s publication date. (Note that M-26-15 does not apply to National Security Systems, which follow a separate migration track.) What Must Be in the Migration Plan: Nine Required ElementsM-26-15 defines what a compliant migration plan must contain. Based on the memo’s requirements, here are the nine core components agencies must address:1. Governance and Named AccountabilityThe plan must document who is responsible for the transition. The designated PQC Migration Lead must be identified, with a clear governance structure that spans the CIO, CISO, program offices, and procurement. A plan that assigns cryptographic transition to a single team will not satisfy M-26-15’s cross-functional governance requirement. 2. A Complete Cryptographic InventoryYou cannot migrate what you haven’t mapped. The plan must describe the methodology used to inventory every cryptographic algorithm, key, certificate, and protocol in use across the agency’s systems and infrastructure. This inventory, often called a Cryptographic Bill of Materials (CBOM), must be:Comprehensive (covering applications, network infrastructure, SaaS, cloud services, and on-prem systems)Automated (not a one-time manual exercise)Continuously maintainedNote: CISA and NIST are expected to publish minimum-elements guidance for machine-readable CBOMs by March 2027. Agencies should build toward that standard now.3. Risk-Based System PrioritizationNot all systems carry equal urgency. The migration plan must include a risk-based prioritization framework that identifies which systems get migrated first. Mandatory first-priority categories include:High Value Assets (HVAs) as defined in OMB M-19-03High-Impact Systems (FIPS 199 “High” categorization)Any system storing or transmitting data with long-term sensitivity, the primary targets of HNDL attacks4. Phased Milestones Aligned to the Government-Wide ScheduleM-26-15 establishes a five-phase migration timeline. The October submission must map agency-specific milestones to the three migration phases within this five-phase schedule:PhasePeriodFocusPhase 12026–2027Strategy, planning, and discoveryPhase 22027–2028Pilots and early migrationPhase 32028–2030Prioritized migration (key establishment for HVAs and high-impact systems)Phase 42031Digital signature migrationPhase 52035Full migration of remaining systemsThe Phase 3 deadline is the one with the most regulatory weight: December 31, 2030 is the hard cutoff for PQC key establishment across HVAs and high-impact systems. M-26-15 also directs agencies to prioritize systems containing highly sensitive data and systems particularly vulnerable to CRQC-based attacks on that schedule. 5. TLS 1.3 Deployment MilestonesAgencies must specifically address migration to TLS 1.3, consistent with existing mandates under EO 14306. The overall federal deadline for TLS 1.3 support is January 2, 2030. Your plan must include milestones for testing and deploying PQC-enabled TLS 1.3 within that window.6. A Cryptographic Agility ArchitectureThis is arguably the most technically demanding requirement. Agencies must describe an architecture designed so that cryptographic algorithms can be swapped with minimal operational disruption as standards evolve. Depending on the agency’s risk assessment and technical requirements, this can include:Supporting cryptographic modes that run PQC algorithms alongside classical ones during the transition period (so you don’t break existing interoperability while hardening new sessions)Ensuring Hardware Security Modules (HSMs) and Key Management Systems are replaceableTreating crypto-agility as an architecture requirement, not a feature request7. Vendor and Supply Chain CoordinationFederal agencies don’t operate in isolation — much of the cryptographic footprint runs on commercial software, cloud platforms, and contractor-managed systems. The plan must detail:How the agency will engage Cloud Service Providers (CSPs) under the shared-responsibility model1Contract language and procurement requirements that mandate vendor PQC readiness and cryptographic agilityHow the agency will assess and manage cryptographic vulnerabilities in the supply chainThe first FAR Council rulemaking, due December 19, 2026, is required to propose that covered contractors comply by December 31, 2030, with applicable NIST FIPSs, including PQC-compliant algorithms. A second FAR Council rulemaking, due March 19, 2027, is required to propose changes to contractor vulnerability disclosure program (VDP) requirements covering cryptographic vulnerabilities. Contracting officers and procurement leads should be tracking both of these closely.8. Resource and Funding EstimatesOMB expects agencies to connect PQC migration to budget realities. The plan must include estimates of funding and personnel required, integrated into existing IT modernization budgets and multi-year appropriations requests. Plans without resource estimates will not satisfy M-26-15’s minimum requirements.9. Risk Management During the Transition PeriodBecause full migration takes years, agencies must address how they’ll manage security risk during the transition, specifically the period when some systems are migrated and others aren’t. This includes interoperability between PQC and legacy systems, monitoring for exposure in hybrid environments, and defining acceptable risk posture throughout each phase. What’s Happening on the GSA and DoW TracksThe civilian agency plan submission is the most immediate requirement, but two parallel tracks deserve attention:GSA has been directed to establish an inter-agency working group to modernize Federal Identity, Credential, and Access Management (FICAM) to support PQC. That group held its first meeting on August 12, 2026, with participation from 17 federal agencies and plans to meet on a bi-weekly basis. FICAM modernization has direct implications for how agencies manage identity verification, PKI, and digital signatures, all of which will require quantum-resistant cryptographic underpinning.The Department of War (DoW) is operating under its own PQC strategy, released June 23, 2026. All DoW systems must support PQC or be phased out by December 31, 2030. Solutions using CRQC-vulnerable algorithms, non-quantum-resistant symmetric key establishment, and non-NSA-KMI PSK solutions are all on the phaseout list by that date. Defense contractors face the most compressed timelines of any segment. What This Means for Contractors and SubcontractorsIf your firm holds federal contracts, EO 14412 reaches you through two mechanisms:The first FAR Council rulemaking (due December 19, 2026) must propose that covered contractors comply with applicable NIST FIPS, including PQC-compliant algorithms by December 31, 2030, matching the agency deadline for HVA key establishment.A second FAR Council rulemaking (due March 19, 2027) must propose amendments to FAR requirements and contract clauses for contractor Vulnerability Disclosure Programs, including coverage of cryptographic vulnerabilities,.lack of encryption, and non-FIPS-approved algorithms. This is a significant expansion: VDPs that don’t address crypto will no longer satisfy requirements.The practical implication: start your own cryptographic inventory now, not when the FAR rule is finalized. Agencies will increasingly require vendors to demonstrate a clear PQC roadmap as part of procurement. Firms that can’t show one will find themselves losing competitive ground on contract renewals and new awards, well before the 2030 deadline. The Practical Starting Point: Your First 90 DaysGiven that the migration plan submission deadline is October 22, any agency team, including its supporting contractors, that hasn’t started needs a rapid on-ramp. The work breaks down into three phases:Days 1–30 — Foundations: Appoint your PQC Migration Lead and form a cross-functional team. Initiate a cryptographic inventory (automated tools are essential — this cannot be done by hand at scale). Begin vendor and supply chain assessment. Prepare and submit the initial migration plan by October 22. M-26-15 treats the plan as a dynamic document that will mature as the inventory and implementation strategy develop.Days 31–60 — Assessment and Prioritization: Complete the initial CBOM. Conduct a risk assessment and prioritize systems by sensitivity, internet exposure, and operational importance. Pay special attention to anything protecting long-lived data: these are the HNDL targets. Refine your migration strategy and roadmap.Days 61–90 — Strategy and Early Implementation: Update and socialize the migration plan with leadership. Begin a pilot project on a non-critical system to test PQC algorithms before touching HVAs. Start migrating to post-quantum key exchange (ML-KEM / FIPS 203) where feasible. Update procurement policies and contract language to require PQC readiness from vendors going forward. Conclusion: The Bottom LineEO 14412 and OMB M-26-15 represent the federal government’s most concrete response yet to the quantum threat. For agencies, these are binding mandates with named owners, firm deadlines, and budget implications. For contractors, two FAR rulemakings will translate the policy into formal acquisition requirements. For security and networking practitioners, the critical action items are clear:If you haven’t mapped your cryptographic assets, that is the first thing to fix.If your agency doesn’t have a Migration Lead, identify one ASAP.If your firm holds federal contracts, assume FAR requirements are coming and get ahead of them.The threat actors running Harvest Now, Decrypt Later campaigns are not waiting for 2030. Your migration plan shouldn’t wait for October 22 either.Sources: EO 14412 (“Securing the Nation Against Advanced Cryptographic Attacks”)OMB Memorandum M-26-15: “Execution of the Migration to Post-Quantum Cryptography” June 24, 2026Zscaler Webinar — “EO 14412 Decoded: Your First 90 Days” (watch it now)Notes:1 M-26-15 assigns CISA and DoW, in coordination with GSA, to lead PQC migration efforts for FedRAMP-authorized CSPs and SaaS, PaaS, and IaaS solutions used by more than one agency.
[#item_full_content] The clock is already running. Here’s what compliance with EO 14412 actually demands and where agencies can’t afford to miss a step.If you work in security or networking for a U.S. federal agency or a firm that holds federal contracts, Executive Order 14412 is no longer a future concern. It’s a present operational mandate. And with OMB Memorandum M-26-15 now in effect, the transition from awareness to accountability is complete.This blog covers what you need to know about the OMB’s guidance so you can include the required information in your PQC transition plan, which is due to the OMB by October 22, 2026. Why EO 14412 Exists: The Threat Is Already ActiveBefore getting into compliance mechanics, it’s worth understanding the driving threat model.EO 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” is built around one foundational problem: the cryptographic standards protecting federal data today will be broken by cryptographically relevant quantum computers (CRQCs). Some experts believe a viable CRQC could emerge by 2030.Adversaries are already executing “Harvest Now, Decrypt Later” (HNDL) campaigns. They’re exfiltrating encrypted federal data today, stockpiling it with the intent to decrypt it once quantum hardware is available. Data with a long operational shelf life, including intelligence sources, health records, and financial instruments, is already compromised in this model. The deadline to act is not 2030. It’s now.EO 14412 and the implementing guidance from OMB respond to this by shifting the federal government’s posture from “we should plan to migrate” to “migration is policy, with named owners, hard deadlines, and enforceable consequences.”Who Owns the Governance StructureEO 14412 establishes clear accountability at the top:OMB Director and the National Cyber Director jointly coordinate the government-wide migration.NIST, CISA, and NSA provide agencies technical implementation guidance.Each agency head was required to designate a PQC Migration Lead within 30 days of the order, a deadline that passed in July 2026.If your agency hasn’t named a PQC Migration Lead yet, that is already a compliance gap.The Migration Lead isn’t just a title. This individual owns accountability for the entire transition process and is responsible for coordinating across IT, cybersecurity, legal, procurement, and program offices. The cross-functional scope is intentional: PQC migration cannot be solved by the security team alone. OMB M-26-15: The Binding Implementation MemoIssued June 24, 2026, OMB Memorandum M-26-15 (“Execution of the Migration to Post-Quantum Cryptography”) is the document that turns EO 14412 into operational requirements. It establishes expectations, timelines, and the structure of what agencies must produce.The first hard deadline it creates: every civilian agency must submit a comprehensive PQC Migration Plan to OMB and the Office of the National Cyber Director (ONCD) by October 22, 2026. That is 30 days from this blog’s publication date. (Note that M-26-15 does not apply to National Security Systems, which follow a separate migration track.) What Must Be in the Migration Plan: Nine Required ElementsM-26-15 defines what a compliant migration plan must contain. Based on the memo’s requirements, here are the nine core components agencies must address:1. Governance and Named AccountabilityThe plan must document who is responsible for the transition. The designated PQC Migration Lead must be identified, with a clear governance structure that spans the CIO, CISO, program offices, and procurement. A plan that assigns cryptographic transition to a single team will not satisfy M-26-15’s cross-functional governance requirement. 2. A Complete Cryptographic InventoryYou cannot migrate what you haven’t mapped. The plan must describe the methodology used to inventory every cryptographic algorithm, key, certificate, and protocol in use across the agency’s systems and infrastructure. This inventory, often called a Cryptographic Bill of Materials (CBOM), must be:Comprehensive (covering applications, network infrastructure, SaaS, cloud services, and on-prem systems)Automated (not a one-time manual exercise)Continuously maintainedNote: CISA and NIST are expected to publish minimum-elements guidance for machine-readable CBOMs by March 2027. Agencies should build toward that standard now.3. Risk-Based System PrioritizationNot all systems carry equal urgency. The migration plan must include a risk-based prioritization framework that identifies which systems get migrated first. Mandatory first-priority categories include:High Value Assets (HVAs) as defined in OMB M-19-03High-Impact Systems (FIPS 199 “High” categorization)Any system storing or transmitting data with long-term sensitivity, the primary targets of HNDL attacks4. Phased Milestones Aligned to the Government-Wide ScheduleM-26-15 establishes a five-phase migration timeline. The October submission must map agency-specific milestones to the three migration phases within this five-phase schedule:PhasePeriodFocusPhase 12026–2027Strategy, planning, and discoveryPhase 22027–2028Pilots and early migrationPhase 32028–2030Prioritized migration (key establishment for HVAs and high-impact systems)Phase 42031Digital signature migrationPhase 52035Full migration of remaining systemsThe Phase 3 deadline is the one with the most regulatory weight: December 31, 2030 is the hard cutoff for PQC key establishment across HVAs and high-impact systems. M-26-15 also directs agencies to prioritize systems containing highly sensitive data and systems particularly vulnerable to CRQC-based attacks on that schedule. 5. TLS 1.3 Deployment MilestonesAgencies must specifically address migration to TLS 1.3, consistent with existing mandates under EO 14306. The overall federal deadline for TLS 1.3 support is January 2, 2030. Your plan must include milestones for testing and deploying PQC-enabled TLS 1.3 within that window.6. A Cryptographic Agility ArchitectureThis is arguably the most technically demanding requirement. Agencies must describe an architecture designed so that cryptographic algorithms can be swapped with minimal operational disruption as standards evolve. Depending on the agency’s risk assessment and technical requirements, this can include:Supporting cryptographic modes that run PQC algorithms alongside classical ones during the transition period (so you don’t break existing interoperability while hardening new sessions)Ensuring Hardware Security Modules (HSMs) and Key Management Systems are replaceableTreating crypto-agility as an architecture requirement, not a feature request7. Vendor and Supply Chain CoordinationFederal agencies don’t operate in isolation — much of the cryptographic footprint runs on commercial software, cloud platforms, and contractor-managed systems. The plan must detail:How the agency will engage Cloud Service Providers (CSPs) under the shared-responsibility model1Contract language and procurement requirements that mandate vendor PQC readiness and cryptographic agilityHow the agency will assess and manage cryptographic vulnerabilities in the supply chainThe first FAR Council rulemaking, due December 19, 2026, is required to propose that covered contractors comply by December 31, 2030, with applicable NIST FIPSs, including PQC-compliant algorithms. A second FAR Council rulemaking, due March 19, 2027, is required to propose changes to contractor vulnerability disclosure program (VDP) requirements covering cryptographic vulnerabilities. Contracting officers and procurement leads should be tracking both of these closely.8. Resource and Funding EstimatesOMB expects agencies to connect PQC migration to budget realities. The plan must include estimates of funding and personnel required, integrated into existing IT modernization budgets and multi-year appropriations requests. Plans without resource estimates will not satisfy M-26-15’s minimum requirements.9. Risk Management During the Transition PeriodBecause full migration takes years, agencies must address how they’ll manage security risk during the transition, specifically the period when some systems are migrated and others aren’t. This includes interoperability between PQC and legacy systems, monitoring for exposure in hybrid environments, and defining acceptable risk posture throughout each phase. What’s Happening on the GSA and DoW TracksThe civilian agency plan submission is the most immediate requirement, but two parallel tracks deserve attention:GSA has been directed to establish an inter-agency working group to modernize Federal Identity, Credential, and Access Management (FICAM) to support PQC. That group held its first meeting on August 12, 2026, with participation from 17 federal agencies and plans to meet on a bi-weekly basis. FICAM modernization has direct implications for how agencies manage identity verification, PKI, and digital signatures, all of which will require quantum-resistant cryptographic underpinning.The Department of War (DoW) is operating under its own PQC strategy, released June 23, 2026. All DoW systems must support PQC or be phased out by December 31, 2030. Solutions using CRQC-vulnerable algorithms, non-quantum-resistant symmetric key establishment, and non-NSA-KMI PSK solutions are all on the phaseout list by that date. Defense contractors face the most compressed timelines of any segment. What This Means for Contractors and SubcontractorsIf your firm holds federal contracts, EO 14412 reaches you through two mechanisms:The first FAR Council rulemaking (due December 19, 2026) must propose that covered contractors comply with applicable NIST FIPS, including PQC-compliant algorithms by December 31, 2030, matching the agency deadline for HVA key establishment.A second FAR Council rulemaking (due March 19, 2027) must propose amendments to FAR requirements and contract clauses for contractor Vulnerability Disclosure Programs, including coverage of cryptographic vulnerabilities,.lack of encryption, and non-FIPS-approved algorithms. This is a significant expansion: VDPs that don’t address crypto will no longer satisfy requirements.The practical implication: start your own cryptographic inventory now, not when the FAR rule is finalized. Agencies will increasingly require vendors to demonstrate a clear PQC roadmap as part of procurement. Firms that can’t show one will find themselves losing competitive ground on contract renewals and new awards, well before the 2030 deadline. The Practical Starting Point: Your First 90 DaysGiven that the migration plan submission deadline is October 22, any agency team, including its supporting contractors, that hasn’t started needs a rapid on-ramp. The work breaks down into three phases:Days 1–30 — Foundations: Appoint your PQC Migration Lead and form a cross-functional team. Initiate a cryptographic inventory (automated tools are essential — this cannot be done by hand at scale). Begin vendor and supply chain assessment. Prepare and submit the initial migration plan by October 22. M-26-15 treats the plan as a dynamic document that will mature as the inventory and implementation strategy develop.Days 31–60 — Assessment and Prioritization: Complete the initial CBOM. Conduct a risk assessment and prioritize systems by sensitivity, internet exposure, and operational importance. Pay special attention to anything protecting long-lived data: these are the HNDL targets. Refine your migration strategy and roadmap.Days 61–90 — Strategy and Early Implementation: Update and socialize the migration plan with leadership. Begin a pilot project on a non-critical system to test PQC algorithms before touching HVAs. Start migrating to post-quantum key exchange (ML-KEM / FIPS 203) where feasible. Update procurement policies and contract language to require PQC readiness from vendors going forward. Conclusion: The Bottom LineEO 14412 and OMB M-26-15 represent the federal government’s most concrete response yet to the quantum threat. For agencies, these are binding mandates with named owners, firm deadlines, and budget implications. For contractors, two FAR rulemakings will translate the policy into formal acquisition requirements. For security and networking practitioners, the critical action items are clear:If you haven’t mapped your cryptographic assets, that is the first thing to fix.If your agency doesn’t have a Migration Lead, identify one ASAP.If your firm holds federal contracts, assume FAR requirements are coming and get ahead of them.The threat actors running Harvest Now, Decrypt Later campaigns are not waiting for 2030. Your migration plan shouldn’t wait for October 22 either.Sources: EO 14412 (“Securing the Nation Against Advanced Cryptographic Attacks”)OMB Memorandum M-26-15: “Execution of the Migration to Post-Quantum Cryptography” June 24, 2026Zscaler Webinar — “EO 14412 Decoded: Your First 90 Days” (watch it now)Notes:1 M-26-15 assigns CISA and DoW, in coordination with GSA, to lead PQC migration efforts for FedRAMP-authorized CSPs and SaaS, PaaS, and IaaS solutions used by more than one agency.