DoD RFI seeks software-only quantum-safe encryption
The Pentagon wants PQC migration without touching hardware, compressing the timeline for primes whose legacy systems weren't built for cryptographic agility.
TL;DR
The Defense Department released a request for information Thursday seeking software-only post-quantum cryptography solutions that require zero hardware changes. Vendors must describe products aligned with a PQC migration strategy scheduled on or before Dec. 31, 2029, with the broader DoD mandate that every system employ PQC by Dec. 31, 2031 unless excepted. The RFI is one of the first concrete procurement signals following the June PQC strategy and the White House quantum executive orders, it asks industry to show what's possible before the department locks in acquisition paths.
The Pentagon is asking industry whether it can deliver post-quantum cryptography without touching a single chip.
A request for information released Thursday seeks software-only encryption solutions that require no replacement, modification, or augmentation of existing hardware, no new cryptographic cards, radios, hardware security modules, or other physical components. The desired solution, officials wrote, "should provide utility-based, data packet-level cryptographic protection that aligns with the government's PQC migration strategy and implementation plan, scheduled for on or before December 31, 2029."
That 2029 date isn't the RFI's invention. It lands within the timeline DoD's CIO already set in the June 2026 PQC strategy: all systems must support PQC by Dec. 31, 2030, and every system must employ PQC by Dec. 31, 2031 unless otherwise specified. What's new is the operational framing. The RFI asks vendors to show how they'd meet these milestones without the hardware refresh cycles that normally accompany cryptographic modernization.
The hardware problem
Deputy CIO for Cybersecurity David McKeown flagged the scale challenge in late 2024: "The hardware and software that we use for securing our nation's secrets takes a long time to develop and test and field. It is scattered throughout many, many platforms and weapon systems." The June strategy itself acknowledged that "nearly every deployed military asset will be affected in some way."
The RFI's software-only constraint is a direct response to that reality. Hardware replacement cycles across the department's sprawling inventory of platforms, weapon systems, and communications gear would take longer than the migration deadlines allow. The RFI also stipulates that the technology must ensure "the Department retains full control and sovereignty over its data and cryptographic keys."
The policy cascade behind the RFI
The RFI doesn't exist in isolation. The White House issued two quantum executive orders on June 24, 2026, one aimed at accelerating federal PQC adoption and one reprioritizing domestic quantum computing investment. DoD's PQC strategy dropped the next day. CISA had already published, in January 2026, a list of product categories where PQC-capable products are widely available, advising that "organizations should plan acquisitions to procure only PQC-capable products" in those categories.
The RFI asks vendors to map their solutions against NIST's post-quantum cryptographic standards and describe how they'd support DoD's review of programs of record for PQC feasibility. It's market research, but the kind that shapes acquisition strategy before the RFP drops.
Industry responses are due Sept. 27.
Published ·Deep Fathom