Post-quantum migration — dated, federal, and earlier than it looks
Executive Order 14412 gave federal encryption a 2030 date and authentication 2031, ordered a FAR rule binding contractors to PQC-capable FIPS by the end of 2030, and commissioned a CBOM standard. CNSA 2.0 binds new national-security acquisitions from 1 January 2027. The algorithms are final and hybrid TLS is already a configuration change; what stops organisations is not knowing which cryptography they use, and harvest-now-decrypt-later means long-lived secrets are already exposed.
Key dates
8 dated obligations. Rows marked verify are not final in their source. See the whole calendar.
What practitioners need to know
Lifted verbatim from the kits below, each attributed to the product that says it.
-
EO 14412 (22 June 2026) set federal PQC encryption at 31 December 2030 and authentication at 2031, ordered a FAR rule binding contractors to PQC-capable FIPS by end-2030, extended VDPs to cryptographic weaknesses and commissioned a CBOM standard.
— Post-Quantum Migration Kit -
Count uses, not systems. One application is six inventory rows — TLS in, TLS out, SSH, JWT signing, database encryption with an RSA-wrapped key, a code-signing cert — each with its own algorithm, longevity and migration path.
— Post-Quantum Migration Kit -
"AES-256 at rest" is quantum-vulnerable if the data key is wrapped with RSA — the trap most inventories miss.
— Post-Quantum Migration Kit -
Mosca decides the order. For ten-year secrets against a three-year migration and a 2032 threshold, you are already late — so Wave 1 is exposed long-lived data and the trust anchors, and the web server is Wave 2.
— Post-Quantum Migration Kit -
The algorithms are final and hybrid TLS is a config change today — X25519MLKEM768 is default in browsers and CDNs, OpenSSH 10 defaults to hybrid, OpenSSL 3.5 ships PQC. What stops organisations is not knowing what they use.
— Post-Quantum Migration Kit
Kits that cover it
1 product, cheapest first.
Bundles
2 bundles cover this alongside adjacent work — always below the sum of the parts.
First 100 Days + Quantum
The kit for the job you just took, and the answer to the question the board will ask in your first quarter. 14% off buying them separately.
Product Security Complete
Everything a product vendor owes the EU and the crypto clock in one purchase — the CRA scope test, the Article 14 reporting runbook, the technical file with SBOM and CE declaration, and the post-quantum inventory and migration plan. 19% off buying the four separately.
Other regimes: EU AI Act · HIPAA · DORA & NIS2 · PCI DSS · Third-party risk · Critical infrastructure
Working to a date? The compliance calendar. Not legal advice.