Trump EO orders PQC migration for high-value assets by 2030, 31
Agencies face an Oct. 22 deadline for migration plans, and CISA is signaling that procurement language and cryptography bills-of-materials will become the enforcement mechanism for vendor compliance.
TL;DR
President Trump signed an executive order directing federal agencies to transition high-value assets and high-impact systems to post-quantum cryptographic key establishment by Dec. 31, 2030, and PQC digital signatures by Dec. 31, 2031. OMB followed with guidance requiring agencies to submit PQC migration plans by Oct. 22. The order builds on NIST's 2024 PQC standards and comes as CISA pushes agencies to write PQC requirements into acquisition documentation, a procurement lever that the prior administration's framework left largely untapped.

The Trump administration's PQC executive order, signed June 22, sets a hard federal deadline for the first time: agencies must transition high-value assets and high-impact systems to post-quantum cryptographic key establishment by Dec. 31, 2030, and PQC digital signatures by Dec. 31, 2031. Under the Biden administration, agencies had been working toward a 2035 goal for mitigating quantum risk, but that target was framed as a planning horizon rather than a binding deadline. The new EO "really lights a fire under everyone," former CISA associate chief of strategic technology Garfield Jones told Federal News Network.
OMB Director Russell Vought delivered the follow-through within days. A June 24 memo gives agencies 120 days, until Oct. 22, to submit PQC migration plans. The memo prescribes a phased approach: inventorying cryptographic systems and laying groundwork through 2027, then piloting and executing early migrations through 2028.
The procurement dimension is where CISA's posture has sharpened. Patrick Manley, CISA's lead for quantum security, said during an Aug. 26 panel that agencies are "considering procurement mechanisms, such as cryptography (and software) bills of materials." His message to vendors: "I don't want to buy a product in 2027 that is hard-coded classical algorithms, that I have to buy again in two years. I want to be able to see that pathway." CISA has been pushing federal IT officials to write PQC requirements into acquisition documentation since at least May 2025, when Jones said the agency hosted a call with more than 600 federal IT officials on the topic.
CISA published a list of product categories in which PQC-capable products are widely available on Jan. 23, 2026, covering both hardware and software. The agency's guidance: when PQC-capable products are widely available in a category, organizations should acquire only those products. That's a procurement gate in everything but name.
The cost picture
A 2024 OMB report estimated $7.1 billion to transition priority civilian IT systems to quantum-resistant algorithms between 2025 and 2035. That estimate was produced when many agencies were still early in cryptographic planning; the figure is now two years old and likely understates the actual cost. Manley stressed that agencies need to attach cost estimates to their migration plans now: "If you aren't connecting a cost estimate to move to PQC for your most critical systems into your resource allocation planning, you're behind."
He also cautioned against expecting a centralized funding vehicle. "I really don't want this to be a crisis of the moment where Congress provides an emergency appropriation and says, 'Hey, we think Q Day is here,' and then all of a sudden helicopters are dropping pallets of money on top of CISA."
What's missing
Cost estimates and timelines for national security systems run on a separate track from civilian IT and aren't specified in the EO or OMB guidance. Nor is there yet clarity on whether legacy products will be permitted during transitional periods or how procurement mechanisms will formally penalize non-PQC-capable vendors. The EO accelerates the timeline; the enforcement architecture is still being assembled.
Published ·Deep Fathom