Federal agencies will increasingly seek out technology products that use quantum-resistant encryption, as cybersecurity leaders also eye ways to validate the cryptography used in critical systems.
A code-breaking quantum computer holds the potential to break classical encryption methods, putting sensitive systems and communications at risk. And even though such a computer is not yet known to exist, organizations are also concerned that hackers could steal sensitive encrypted data today and decrypt it in the future.
The National Institute of Standards and Technology has released three primary PQC standards in recent years, with additional algorithms under consideration. Agencies and industry are now on the clock to begin the time consuming and costly process of migrating current systems to the new algorithms.
“Now is the time to budget, to test, and to implement,” Will Loucks, senior director for intelligence in the White House Office of the National Cyber Director, said during an Aug. 26 panel discussion at the Intelligence and National Security Summit in North Bethesda, Md.
“And that’s especially true for national security systems, including the commercial technologies and algorithms that support them,” Loucks continued. “But it’s also more generally true for federal networks and commercial systems more broadly.”
Agencies received new PQC marching orders earlier this summer, when President Donald Trump signed an executive order directing agencies to transition “high value assets” and “high impact systems” to post-quantum cryptographic keys by Dec. 31, 2030, and PQC digital signatures by the end of 2031.
Under subsequent guidance from the Office of Management and Budget, agencies have until Oct. 22 to submit their PQC migration plans.
Agencies will have to factor PQC upgrades into cloud migrations, software development lifecycles, and hardware refresh schedules, meaning the government will be reliant on industry partners to help with the transition.
“What do we want from industry? I think from a government perspective, we want to see a clear path and a roadmap on how you’re getting to PQC capable products,” Patrick Manley, lead for quantum security at the Cybersecurity and Infrastructure Security Agency, said during the Aug. 26 panel.
Manley added that “there’s a lot of noise” and marketing regarding PQC compliant products, meaning agencies will have to “trust but verify.”
He said agencies are considering procurement mechanisms, such as cryptography — and software — bills of materials.
“I think you’ll start to see a louder drumbeat over time from a procurement perspective,” Manley said. “How do we modify some contract language? How do we ensure that our vendors are providing us with products that are quantum resistant? I don’t want to buy a product in 2027 that is hard-coded classical algorithms, that I have to buy again in two years. I want to be able to see that pathway. How are you getting the PQC compliance, and then trust that you’ve done the homework and you’ve been able to show that, yeah we can sell to you, and we’ll bring that product in and go, ‘Yep, it checks the boxes.’ We’re able to test, configure, and show you it is quantum resilient in our network.’’
PQC costs
But the costs of upgrading to PQC-compliant algorithms could be substantial. A 2024 OMB report estimated it would cost $7.1 billion between 2025 and 2035 to transition priority civilian IT systems to quantum-resistant algorithms.
That estimate is likely outdated, given that many agencies were early in their cryptographic planning efforts two years ago.
Manley said organizations writ large should prioritize their most critical systems and start moving toward migration, including by involving the chief financial officer in PQC discussions.
“If you aren’t connecting a cost estimate to move to PQC for your most critical systems into your resource allocation planning, you’re behind,” Manley said. “You need to have budget behind what you’re doing in this planning process because you could just identify, you could do discovery all day, you could inventory all day. But if you’re not putting resourcing behind moving that system to security, you’re behind the eight ball.”
Manley also cautioned against expecting a central pot of funding at an agency like CISA to spur on PQC migration.
“I really don’t want this to be a crisis of the moment where Congress provides an emergency appropriation and says, ‘Hey, we think Q Day is here,’ and then all of a sudden helicopters are dropping pallets of money on top of CISA. Like, ‘go figure it out,’” Manley said.
“We want to have a clear understanding of cost,” he added. “We want to build that into our planning horizons. We should be able to think about that in a multi-year way, both from the government and from industry, and we need to be communicating that. So if I’m industry and I’m building a product, I want to be open and honest about, this is what it’s going to take to get to PQC, and this is what it’s going to cost. Having that transparency and having that understanding, I think, is important.”
Treasury task force
Agencies are starting to establish discrete efforts to advance PQC adoption.
The General Services Administration announced this week that it will update the Federal Identity, Credential and Access Management architecture to support quantum-resistant encryption, while also developing a new PQC testing process for technology that helps secure federal buildings.
Meanwhile, the Treasury Department established a “Quantum-Readiness Task Force” to accelerate the financial sector’s adoption of quantum-safe technology.
Manley urged organizations to watch what comes from the Treasury task force in particular.
“Where we can find goodness across the board to help other sectors, to help state and locals, to help different government agencies, we’re looking for ways, especially at CISA, to grab that and get it out to the masses, so that we all move in the same direction,” Manley said.
Copyright
© 2026 Federal News Network. All rights reserved. This website is not intended for users located within the European Economic Area.
