nisttrade-pressNewsThe Broadside1 min read

DoD solicits software encryption for weapons systems

The software-only requirement sidesteps hardware swaps on platforms that can't be retrofitted, but it also means DoD is accepting the gap between what's deployable now and what post-quantum readiness actually requires.


TL;DR

The Defense Department issued an Aug. 27 RFI for data packet-protection software that works without replacing, modifying, or augmenting existing hardware, chips, radios, the works. It's an interim layer on the way to post-quantum cryptography, with responses due Sept. 27. The solicitation requires DoD-approved multifactor authentication, exclusion of unauthorized parties, and full government control of decryption keys. The department's June 2026 PQC strategy told the military to stop using legacy platforms that can't support advanced encryption, but this software bridge suggests the sunset won't be clean.

The RFI is explicit about the constraint: products must not require "replacement, modification or augmentation of existing hardware components." That rules out the cleanest path to cryptographic modernization (hardware security modules or silicon with PQC-native acceleration) across a swath of platforms where physical retrofitting is impractical or procurement cycles stretch past the deadline.

The department's June 2026 PQC strategy, signed by CIO Kirsten Davies, directed the military to stop using "all legacy devices and platforms" that can't support the new protections. That language is absolute. This solicitation is the asterisk: a bridge for systems that won't be sunset on schedule, protected by software the department knows is an interim measure.

The trade-off is real. Software-based encryption deploys faster and reaches systems that hardware can't touch, but it's also more exposed to side-channel attacks and key extraction than hardware-backed alternatives. DoD is accepting that risk for the near term. The strategy's own framing ("nearly every deployed military asset will be affected in some way, adversaries will continue to probe for weaknesses and costs will be incurred") reads now as a warning that the department is already living inside.

Responses are due Sept. 27. The solicitation is one of the first acquisition-side moves following the Trump administration's June 2026 PQC executive order, which accelerated the transition timeline for high-value assets and high-impact systems to 2030, 2031. The order also directed CISA to publish a PQC product categories list, which CISA released in January 2026. This RFI, in contrast, is a request for what's available now, not what's on the categories list.


Published ·Deep Fathom