Agencies have until the end of October to deliver their post-quantum computing migration plans to the Office of Management and Budget and the Office of the National Cyber Director.
Unlike other migrations plans for things like IPv6 or cloud computing that OMB has laid out over the years, the PQC migration plans are even more of a living document.
“I think we want to have a good understanding of the scope of the problem and what we have to migrate. And I think that’s why we’re still in this discovery, inventory and visibility phase,” said Patrick Manley, lead for quantum security at the Cybersecurity and Infrastructure Security Agency, at a recent AFCEA DC lunch. “I think that’s important because if you don’t have a good full picture of what you got, you can’t make risk decisions and plan and feed into a phased approach, where you’re going to migrate and understand where you may be willing to accept some risk and migrate something later versus, ‘Hey, we got to get this now.’ The timelines are moving us left and left and left.”
Manley and other federal PQC executives say starting with an inventory of systems is a critical step to supporting mission systems and an organization’s most valuable data.
OMB’s June guidance prescribed a phased approach for agency plans. During phase one, between 2026 and 2027, agencies should focus on continuing to inventory cryptographic systems, defining a strategy, spreading “awareness and training” and other steps to “lay the foundation for a phased PQC migration approach.” Between 2027 and 2028, under phase two in OMB’s memo, agencies should plan to focus on “pilots, executing early migrations of prioritized systems and refining the migration plan based on lessons learned.”
Manley said federal civilian agencies already are behind in preparing their inventories.
“I think the process that we’ve been going through every year has been clunky and not consistent across the board. We’re filling out spreadsheets and treating it like compliance and submitting them into a system and walking away. We have to move past that. I think when you look at that process as it exists today, it’s a box check, and it’s not about true visibility and truly understanding what your cryptographic assets look like across your enterprise,” he said. “We’re trying to shift the mindset. I think we’re doing some good work internally at CISA, looking at our own stuff, but I think writ large across the government, we’ve seen a lot of people leave. We don’t have consistency in PQC migration leads. For one, budgets are being cut. People aren’t funding these transitions. They don’t have a good understanding of what their inventory looks like, nor how to estimate their cost. And even worse, we’re not connecting any poorly formed cost estimate to a budget.”
Manley said as Congress finalizes the fiscal 2027 budget and agencies submit their 2028 requests through OMB, PQC funding must be a priority.
2030 deadline coming fast
Britta Hale, the director of PQC at the Defense Department, said one challenge the Pentagon faces, similar to other agencies, is that different missions have different urgencies, and because every organization within the department has its own purpose, that makes the decisions of where to start even more complex.
“It’s not simply a matter of saying ‘Okay, we’ll fund the intelligence community first.’ There are different systems that each organization is responsible for to do its purpose, and if those mission systems fail, that’s a big problem,” Hale said. “That’s very extendable to other, even vendor, organizations. If you have financial sectors, you have a purpose for that business. What does it need to accomplish to be relevant? If it was attacked and its systems failed, which systems are actually critical that need to be hardened versus which ones could be let go?”
The inventory and plan are the first steps to meeting the White House’s deadlines of getting all high-value assets and systems PQC ready by 2030, migrating to PQC for digital signatures for all high-value assets and systems before the end of 2031 and finishing the complete migration to PQC for all other systems by 2035.
Manley added each organization’s inventory is going to drive their migration plan.
“Your most critical systems, your high value assets, you’re going to want to prioritize those first. You need to understand how you’re going to phase this, so having a good inventory helps inform that planning process,” he said. “We’re looking at it internally, so we get a good inventory and make some risk decisions. We will really start marching through that and identify potential pilots where we can see how we might be migrating to PQC and what some of the impacts may be, some of the interoperability and performance challenges that may come with it. I’d like to see that by the end of this next fiscal year for CISA.”
Hale said one of the biggest challenges to meeting those deadlines, no matter what the White House laid out, is around identity and authentication. She said if an agency’s public key infrastructure (PKI) can’t handle post-quantum cryptography, then the rest of the goals are moot.
“Personal Identity Verification (PIV) and Common Access Cards (CACs) have to incorporate the algorithms, which means all your core infrastructure, all your PKI infrastructure has to be ready by 2030. That really means actually using PQC by 2030, and that starts a countdown where you go backwards in time,” she said. “You roll that out across the entire department means you need to have systems already able to accept post-quantum algorithms. Otherwise, when you plug in those cards, nothing works, and people lose access. So that actually means, in practicality, by the end of 2029, all systems and products in the department have to be post-quantum ready and able to use those new post-quantum algorithms.”
FICAM efforts underway
The National Institute of Standards and Technology and the General Services Administration are working to solve the PIV/CAC challenges.
Bill Newhouse, a cybersecurity engineer and PQC project lead for NIST’s National Cybersecurity Center of Excellence, said his agency is working on new smart card standards around PQC
NIST says it’s updating NIST Special Publication (SP) 800-73, Parts 1 and 2, and NIST SP 800-78 to support PQC standards.
At the same time, GSA is leading an identity management effort through the Federal Identity, Cybersecurity and Access Management (FICAM) program.
“Through coordinated experimentation and strategic planning, the FICAM program is identifying quantum-resistant solutions to protect the PIV cards, digital certificates, and trust infrastructure that secure federal operations,” GSA wrote on the identitymanagement.gov. “To date, our initial experiments have identified viable pathways for integrating quantum-resistant algorithms into federal identity systems, while revealing the hardware, software, and policy updates required for successful implementation. The FICAM program will continue to experiment with post-quantum cryptography algorithms and technologies until all aspects of federal ICAM are quantum-resistant and fully protected against future cryptographic threats.”
GSA says the FICAM effort currently is in phase 2 that is focused on developing a “deployable, standards-aligned, PQC PKI certification authority service blueprint and an operational pilot that can scale across agencies while maintaining compatibility with federal PKI trust expectations and existing PIV workflows.”
Newhouse said the PIV/CAC challenge is one federal agency chief information security officers just can’t ignore.
“It becomes the parallel part that starts to happen because that person is going to have to rationalize how to ask his team, in this case, how are we going to deal with that?” he said. “You’re talking about a re-architecture that isn’t taking away from the use of asymmetric encryption and public key infrastructures. It is picking where these algorithms, which don’t fit as a replacement to what you’re using on all your devices. So there is recoding and re-standardization that was necessary. The security strength is a question that some people need to answer, and we need to make sure we market it, or it becomes part of the approved list for security strengths that you need in the Department of [Defense] and the IC needs versus potentially the standard communications from agencies out to the public.”
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
