nistregulatorNewsThe Broadside2 min read

CISA and G7 Issue Joint Call for PQC Transition

The quantum threat graduates from a NIST research track to a synchronized international priority, and the framework's procurement language gives agencies cover to write PQC into RFPs before formal rulemaking.


TL;DR

CISA and the G7 Cyber Security Working Group jointly released a post-quantum cryptography transition framework urging organizations and governments to begin migrating cryptographic systems now. The call to action sets out five priorities: awareness, national strategies, R&D, public-private partnerships, and integrating PQC into procurement requirements. It's the first time the quantum threat has been framed as a coordinated international demand rather than a single-nation research program. The framework doesn't impose mandates, but its procurement language arrives alongside CISA's January 2026 product-category list, which says agencies should acquire only PQC-capable products in categories where they're widely available.

CISA and G7 Issue Joint Call for PQC Transition
Editorial illustration · drawn by The Broadside

The joint CISA-G7 call to action marks a shift in how the quantum threat is being handled at the policy level. Since NIST began its PQC standardization work, the migration conversation has been largely a research-and-standards track, algorithm selection, draft guidance, comment periods. The G7 framework repositions it as a procurement and policy problem requiring synchronized action across the world's largest economies.

The document's five priorities hew to the same playbook CISA, NSA, and NIST have been building since at least the 2022 CISA Insight on PQC and the 2023 Quantum-Readiness factsheet: inventory your cryptographic assets, assess your supply chain, talk to your vendors, plan your migration. What's new is the framing, this isn't a single agency recommending preparation. It's the G7 cyber working group telling member governments to bake PQC into national strategies and procurement processes.

That procurement angle is where the operational pressure lands. The framework doesn't name specific FAR clauses, DFARS amendments, or contractor tiers. It doesn't have to. CISA's January 2026 product-category list, issued under EO 14306, already directs agencies to acquire only PQC-capable products in categories where they're widely available. The G7 call adds allied-government consensus behind the same logic. An agency contracting officer who wants to require PQC in a solicitation now has two documents to cite.

The missing piece remains a timeline with teeth. NIST's IR 8547 describes the transition approach but doesn't set hard deadlines. The White House's 2022 NSM-10 targets 2035 for migrating the most sensitive systems, and that's still the long pole. CISA guidance has kept PQC in the "should" register. The G7 framework doesn't change that, it's a call to action, not a directive. But it does give OMB and the FAR Council a ready-made international consensus to point to if and when they decide to move PQC from optional to mandatory.

For contractors, the practical takeaway is that the procurement language is arriving ahead of the rulemaking. The G7 framework and the CISA product-category list together create an environment where PQC requirements can appear in RFPs before anyone formally mandates them. The cryptographic inventory that CISA and NIST have been urging since 2022 isn't just good hygiene anymore, it's becoming table stakes for selling to governments that take the G7 framework seriously.


Published ·Deep Fathom