GSA, Treasury kick off post-quantum initiatives to protect against cyber threats | #hacking | #cybersecurity | #infosec | #comptia | #pentest | #ransomware


The Trump administration still has four months to update the National Quantum Strategy, but that doesn’t mean agencies are waiting for that document, expected by late December, to get started.

The General Services Administration and the Treasury Department today both announced initiatives and changes to processes to prepare for the future of quantum cryptography to protect data and systems.

GSA says it’s updating the Federal Identity, Credential and Access Management (FICAM) architecture and developing a new testing process for the technology that helps secure federal buildings.

“[I]f current encryption is a complex lock that would take thousands of years to pick, quantum computers could potentially pick that same lock in hours or days. This creates an urgent need to develop new types of quantum-resistant encryption ‘locks’ before quantum computers become widely available,” wrote Dan Pomeroy, the deputy associate administrator for the Office of Technology Policy with the Office of Governmentwide Policy at GSA, in a blog post. “Transitioning to quantum-resistant security is a complex, multiyear process that requires careful coordination across government and a steady investment/funding strategy. GSA’s early action helps mitigate risks and supports a secure, orderly migration that protects both digital systems and physical facilities. By leading this transition, GSA ensures that federal employees can continue to work securely while protecting sensitive government information and facilities against emerging threats.”

At the Treasury Department, Secretary Scott Bessent launched the Quantum-Readiness Task Force, which will be a public-private initiative to help accelerate the financial sector’s transition to quantum-safe technology.

“The Financial Sector Quantum Readiness Task Force will help ensure that the transition to quantum-safe technology is coordinated, risk-based and operationally resilient,” said Treasury Assistant Secretary for Financial Institutions Luke Pettit in the release. “By bringing together government and industry to lead the transition to quantum-safe finance, the U.S. will strengthen trust in its financial system and reinforce its economic and national security.”

Deadlines coming from two EOs

Both initiatives come from President Donald Trump’s June 22 executive orders around quantum. One was focused on cybersecurity, calling for, among other things, agencies to transition “high value assets” and “high impact systems” to post-quantum cryptographic keys by Dec. 31, 2030, and PQC digital signatures by the end of 2031.

The Office of Management and Budget quickly followed up on the executive order with guidance, instructing agencies to, among other things, submit within 120 days a “PQC Migration Plan” to OMB and the Office of the National Cyber Director. That plan, which is due in about 30 days, should include details about how agencies will inventory cryptographic systems, define a strategy, spread “awareness and training” and other steps to “lay the foundation for a phased PQC migration approach,” the memo stated.

Between 2027 and 2028, under phase two in OMB’s memo, agencies should plan to focus on “pilots, executing early migrations of prioritized systems, and refining the migration plan based on lessons learned.”

The second order focused on quantum innovation and how agencies can support research, manufacturing, commercialization and application of these technologies.

GSA’s initial steps to prepare two key systems for post-quantum cryptography are part of how they are meeting the goals of the executive orders.

For the FICAM effort, GSA says it’s updating the “framework to support quantum-resistant algorithms while maintaining compatibility with existing systems. This modernization ensures that agencies can transition smoothly to new security standards without disrupting daily operations. Our approach emphasizes ‘crypto agility’ — the ability to quickly switch between different encryption methods as threats evolve or new standards emerge. This flexibility will be crucial as quantum-resistant technology continues to develop.”

Additionally, GSA held the first meeting of the interagency working group on FICAM modernization on Aug. 12.  Pomeroy said this initial session brought together 40 people from 17 agencies.

“The interagency working group is aiming to meet bi-weekly to continue to tackle non-human identities, automation, and other modern identity features in the Post-Quantum Cryptography (PQC) environment,” he said.

Keeping physical security products safe

To protect federal buildings, GSA is expanding its Federal Information Processing Standards (FIPS) 201 Evaluation Program under the Physical Access Control System (PACS) lab.

GSA says the lab is expanding its testing capabilities to evaluate quantum-resistant technologies.

“This ensures that employee badges, visitor passes, and building access controls will remain secure against future quantum threats,” Pomeroy wrote. “The enhanced lab infrastructure represents an entirely new capability, requiring extensive research and development to test quantum-resistant technology for both physical access control systems and employee identification cards.”

The testing lab’s efforts also will ensure agencies are buying PQC-resistant products and services under the approved products list for physical access control systems that GSA manages.

“The lab is starting to incorporate quantum-resistant algorithms into its testing process, so future approved products can protect against future quantum computing threats,” Pomeroy said.

All of these and other topics will be part of GSA’s 2026 Post-Quantum Cryptography Summit on Sept. 16. The hybrid event will bring together federal leaders, industry partners and subject matter experts to chart the path toward quantum-resistant cryptography.

Treasury also is bringing together experts in its new task force to better prepare to mitigate quantum-related cyber risks.

“It will focus on practical, risk-based approaches to quantum readiness, including identifying critical dependencies, improving cryptographic agility, promoting interoperability, strengthening operational resilience and addressing implementation challenges related to third-party dependencies and digital assets,” the agency stated.

The task force will operate through three workstreams:

  • Sector alignment and PQC transition
  • Third-party and vendor readiness
  • Digital assets and emerging technology risk

“The transition requires organizations to prioritize critical systems and processes, manage dependencies across the financial ecosystem, and address implementation challenges. This task force sets the conditions for industry and government to align priorities and accelerate the transition to post-quantum cryptography,” said Deborah Guild, chairwoman of the Financial Services Sector Coordinating Council and head of Technology at PNC Financial Services Group, Inc., in a statement.

Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.



——————————————————-


Click Here For The Original Source.