ONCD, CISA push agencies on post-quantum cryptography deadlines
The "trust now, forge later" threat makes PQC migration a present-day problem, not a future one, and CISA's quantum lead says if you haven't costed it yet, you're behind.
TL;DR
ONCD and CISA officials urged federal agencies to treat post-quantum cryptography migration as an immediate priority, not a long-range planning exercise. Trump's June 2025 executive order sets hard deadlines, PQC key establishment for high-value assets and high-impact systems by December 31, 2030, and digital signatures by December 31, 2031. CISA quantum security lead Patrick Manley told agencies that the "trust now, forge later" threat makes PQC readiness real today, and warned that organizations without a cost estimate for their most critical systems are already behind.

Will Loucks, senior director for intelligence at ONCD, framed the stakes plainly at the Intelligence and National Security Summit on August 26: "A code-breaking quantum computer, if fully operational, would have immediate and far-reaching consequences. It could be used to undermine the confidentiality and integrity of sensitive communications, including internet-based communications."
Loucks pointed to Trump's June 6, 2025 executive order (EO 14306) as the operative timeline. Under it, civilian agencies must transition their high-value assets and high-impact systems to post-quantum cryptography for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. The Office of Management and Budget published implementation guidance on June 24, and the Pentagon released its own PQC strategy on June 23.
CISA quantum security lead Patrick Manley zeroed in on what he called the "trust now, forge later" threat, the risk that adversaries collect encrypted data today to decrypt it once quantum capability matures. "I don't think enough people are talking about it," Manley said. That threat, he argued, makes PQC migration a present-day problem.
Manley's operational message to agency attendees was direct: the budget conversation should have already happened. "If you are connecting a cost estimate to move to PQC for your most critical systems into your resource allocation money, you're behind," he said. "You can identify, you can do discovery all day, you can do inventory all day", but without resources behind the planning, the migration stalls.
The procurement picture
The EO's deadlines are beginning to shape federal procurement. CISA published its initial list of product categories supporting PQC standards on January 23, 2026, developed in consultation with the NSA. The guidance tells agencies that when PQC-capable products are widely available in a given category, organizations should plan acquisitions to procure only those products. Acting CISA Director Madhu Gottumukkala said the list "will support organizations making that critical transition."
ONCD is separately exploring what "cryptographic agility" means for the Federal Acquisition Regulation, according to ONCD federal cyber lead Phil Stupak. The goal is procurement language that encourages agencies to seek out encryption solutions with built-in flexibility to use a range of cryptographic algorithms, not just swap one standard for another.
Loucks tied PQC migration to a broader defensive strategy, citing the Trump administration's national cyber strategy, a June 12 national security memorandum on securing national security systems, and CISA's binding operational directives on vulnerability management. The policies, he said, "are designed to interact to holistically reduce risk to American networks."
What remains unclear is how many civilian agencies have actually identified their high-value assets and high-impact systems, and what the current PQC readiness baseline looks like across the federal landscape. Neither official addressed that gap publicly.
Published ·Deep Fathom