The 2030 quantum-safe deadline
what EO 14412 requires, and by when

Key facts
- 22 Jun 2026EO 14412, 91 FR 38483
- Signed
- 31 Dec 2030HVAs and high impact systems
- Key establishment
- 31 Dec 2031same systems
- Signatures
- 2035OMB phase 5, the rest
- Full migration
- 22 Oct 2026under OMB M-26-15
- Agency plans due
Washington has put dates on the migration. EO 14412 requires federal high value assets and high impact systems to run post-quantum key establishment by the end of 2030 and post-quantum signatures by the end of 2031, with contractors pulled in through procurement. The older 2035 goal survives for everything else.
The United States now has a legal deadline for quantum-safe encryption. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, signed on 22 June 2026 and published in the Federal Register three days later, requires federal agencies to move their most sensitive systems to post-quantum cryptography for key establishment “by December 31, 2030” and for digital signatures by 31 December 2031. The algorithms themselves are on our post-quantum cryptography page.
What the order requires, and of which systems
The deadlines attach to a defined subset of the federal estate: high value assets, a category set by OMB guidance, and “high impact systems”, meaning systems rated high under the FIPS 199 security framework. National security systems are excluded and run on the NSA’s own track. For the covered systems, the order’s Section 4, headed “Accelerating the PQC Transition”, instructs OMB to issue guidance requiring each agency to “transition all HVAs and high impact systems to use PQC for key establishment by December 31, 2030” and the same for digital signatures a year later.
Key establishment first, signatures second is the threat model in miniature. Encrypted traffic can be recorded today and decrypted by a future quantum computer, the harvest-now-decrypt-later problem, so the key exchange protecting data in transit carries the urgent date. A forged signature only works once a quantum computer actually exists, so signatures get the extra year.
2030 for the priority systems, 2035 for the rest
The 2030 date sits inside an older commitment rather than replacing it. National Security Memorandum 10, from May 2022, set the national goal of “mitigating as much of the quantum risk as is feasible by 2035”. OMB’s implementing memorandum for the new order, M-26-15, issued two days after the EO, keeps both horizons in one five-phase plan:
| Phase | Years | What it covers |
|---|---|---|
| 1. Strategy, planning, discovery | 2026-2027 | Inventories and agency migration plans |
| 2. Pilots and early migration | 2027-2028 | First production systems move |
| 3. Prioritised migration | 2028-2030 | Key establishment on HVAs and high impact systems |
| 4. Signature migration | 2031 | Signatures on the same systems |
| 5. Full migration | 2035 | Everything else, risk-assessed |
So the accurate reading is a carve-out, sharpened: the priority subset now has hard dates in 2030 and 2031, and the 2035 horizon survives for the remainder. Agencies owe OMB a PQC migration plan by 22 October 2026, and M-26-15 adds a separate requirement to support TLS 1.3 “not later than January 2, 2030”.
The clock the order set running
| Deadline | What is due |
|---|---|
| 24 June 2026 | OMB guidance carrying the 2030/2031 requirements, issued as M-26-15 two days after the order and inside its 90-day window |
| ~22 July 2026 | Every agency names a PQC migration lead |
| 22 October 2026 | Agency PQC migration plans reach OMB |
| ~19 December 2026 | FAR Council proposes the contractor rule; NIST pilot begins |
| 31 December 2027 | NIST completes its own migration pilot |
| ~19 March 2027 | CISA guidance on cryptographic bills of materials |
The contractor rule is the row with the widest reach: the proposed Federal Acquisition Regulation change will require government suppliers to comply with the post-quantum FIPS standards “by December 31, 2030”, the same date the agencies carry, which is how the deadline propagates into the private sector. CISA had already published, in January 2026, its first list of product categories in which post-quantum products are widely available, procurement-facing tables that tell agencies where “the market is not ready” no longer works as an answer.
The standards underneath the dates
The deadline is buildable because the standards are finished. NIST finalised FIPS 203, 204 and 205 in August 2024, standardising ML-KEM for key establishment and ML-DSA and SLH-DSA for signatures, and selected HQC as a backup encryption algorithm in March 2025. The order’s definitions point straight at them: “key establishment” is defined by reference to FIPS 203.
Two supporting documents carry the transition detail. NIST’s IR 8547, still a draft as of today, tables the retirement of the classical algorithms: RSA and elliptic-curve key establishment at the 112-bit level are deprecated after 2030 and disallowed after 2035. For national security systems, the NSA’s CNSA 2.0 advisory runs its own timeline, from software signing now to “exclusively use CNSA 2.0 by 2033” for browsers and cloud services, with the NSS transition expected complete by 2035.
What has happened since June
The order is twelve weeks old and the machinery is assembling on schedule. M-26-15 arrived within two days. The 30-day deadline for naming agency migration leads passed in July, with no public roster; the first hard, checkable deliverable is the migration plans due on 22 October 2026. On the vendor side, Cloudflare published its response the day after signing, reporting that over two-thirds of browser traffic to its network already runs post-quantum encryption and committing itself to full post-quantum security by 2029, a year inside the federal date.
For the wider context around this order, our US quantum policy page covers EO 14413, signed the same day, and the money that travels with the policy. The short version of this one: the algorithms have been ready since 2024, and as of June 2026 the deadline for using them is law for the systems Washington cares most about losing.