Key takeaways
- EO 14412 and other global PQC readiness initiatives are turning up the heat on post-quantum readiness with deadlines looming.
- EO 14412 is a 2026 U.S. executive order requiring U.S. federal agencies and their suppliers everywhere to switch to NIST’s post-quantum algorithms, with key establishment due by the end of 2030 and digital signatures by the end of 2031.
- The same requirement applies well outside the United States: UK, EU, Australia, and Canada run post-quantum programs on the same NIST algorithms and comparable timelines.
- The obligation extends to any organization in the government’s supply chain, inside and outside the U.S., and for many it arrives first as a clause in a contract or bid.
- The scope of the cryptographic inventory determines whether the 2030 deadline is reachable
EO 14412 sets fixed dates for replacing public-key cryptography that a future quantum computer could break. Signed in June 2026, it gives the federal migration a 2030 and 2031 timeline and reaches the organizations that do business with the U.S. government, in the United States and abroad. It also sits inside a wider shift: the United Kingdom, European Union, Australia, and Canada have all set post-quantum deadlines of their own.
What is EO 14412?
EO 14412 is a presidential executive order that directs information systems to move to post-quantum cryptography (PQC), the encryption designed to withstand attack by quantum computers. Its full title is Securing the Nation Against Advanced Cryptographic Attacks. It was signed on June 22, 2026, and entered the Federal Register on June 25, 2026, at 91 FR 38483. Its effect is not limited to those agencies: any organization that sells to or supplies the U.S. government, wherever it is based, falls within its reach. The order also tasks agencies with helping critical-infrastructure operators plan their own migrations.
A companion order, EO 14413, Ushering in the Next Frontier of Quantum Innovation, carries the same date and funds quantum research across the federal government. Congress has since introduced H.R. 9516, a bill that would write EO 14412 into statute and hold its deadlines in place beyond a single administration.
Why it exists
A cryptographically relevant quantum computer would defeat the public-key algorithms that secure federal data. RSA, elliptic-curve cryptography, and Diffie-Hellman protect web sessions, digital signatures, and key exchange across government systems, and all three rely on math that such a machine could solve.
The nearer-term concern is harvest now, decrypt later (HNDL): an adversary copies encrypted data now and stores it until a quantum computer can read it. Data with a long secrecy lifetime, such as health records, financial data, and classified material, faces exposure now, because a copy taken today can be decrypted once the hardware matures.
The global picture on post-quantum deadlines
EO 14412 is one national program among many. The same quantum threat has produced post-quantum deadlines across the world, and they converge on a shared destination: the NIST algorithms, and a migration window that runs from about 2030 to 2035.
Section 5(b) directs the State Department, working with NIST and other agencies, to engage foreign governments and industry groups and encourage them to adopt the NIST post-quantum standards.
How the timelines line up worldwide
National roadmaps land in the same window, one runs ahead of the rest.
The United States, through EO14412, requires post-quantum cryptography for key establishment by 2030 and digital signatures by 2031, with NIST’s schedule disallowing the vulnerable algorithms after 2035.
The United Kingdom’s National Cyber Security Centre sets three milestones: identify cryptographic assets and build a migration plan by 2028, migrate the highest-priority systems by 2031, and finish the transition by 2035.
The European Union’s Coordinated Implementation Roadmap, published in 2025, asks member states to define national strategies by the end of 2026, secure critical infrastructure by 2030, and complete migration by 2035 where feasible.
Canada’s Cyber Centre roadmap, effective in 2025, has federal departments submit migration plans by April 2026, move high-priority systems by the end of 2031, and finish the rest by the end of 2035, and it covers systems run through third-party and cloud services as well as those managed in-house.
Australia runs the most aggressive schedule. Its Signals Directorate expects a transition plan by the end of 2026, critical systems underway by the end of 2028, and traditional algorithms such as RSA, Diffie-Hellman, and elliptic-curve cryptography retired by the end of 2030, five years ahead of the disallowment date most other programs use.
Why NIST standards travel abroad
NIST finalized ML-KEM, ML-DSA, and the hash-based backup scheme before other standards bodies, and hardware and software supply chains cross borders, so roadmaps around the world reference the same algorithm set.
Any company that sells to the U.S. federal government inherits its 2030 date, whether or not it stores federal data. A vendor that builds to the NIST standards for that date also moves toward United Kingdom and European Union expectations, which lowers the cost of a single, standards-based migration.
The programs side by side
Six programs appear together, from discovery through full migration:
| Jurisdiction or Program | Start or Discovery | Critical Systems | Full Migration |
| United States, EO 14412 | Migration leads and plans in 2026 | Key establishment by 2030, digital signatures by 2031 | 2035, per NIST IR 8547 |
| United Kingdom, NCSC roadmap | Discovery and planning by 2028 | Highest-priority systems by 2031 | 2035 |
| European Union, Coordinated Roadmap | National strategies by end of 2026 | Critical infrastructure by 2030 | 2035 where feasible |
| Australia, ASD guidance | Transition plan by end of 2026 | Critical infrastructure by 2030 | 2030 |
| Canada, Cyber Centre roadmap | Migration plans by April 2026 | High-priority systems by 2031 | 2035 |
| NIST IR 8547, algorithm status | Guidance issued 2024 | Deprecated after 2030 | Disallowed after 2035 |
How the U.S. reached a PQC deadline
EO 14412 completes a policy chain that began years earlier.

From planning memos to firm dates
The groundwork dates to 2022. A national security memorandum that May directed organizations to inventory their vulnerable cryptography and set a migration goal. An Office of Management and Budget memo that November, M-23-02, required organizations to submit a prioritized inventory of its cryptographic systems.
Congress made the effort law the following month through the Quantum Computing Cybersecurity Preparedness Act, which requires annual migration-progress reports. EO 14412 built on that work by setting firm deadlines for the migration.
The standards behind the mandate
On August 13, 2024, the National Institute of Standards and Technology (NIST) finalized three specific sets of post-quantum cryptography standards:
- FIPS 203: The Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), for key establishment
- FIPS 204: The Module-Lattice-Based Digital Signature Algorithm (ML-DSA), for digital signatures
- FIPS 205: A hash-based backup signature scheme built on a different mathematical foundation
These replace the RSA and elliptic-curve algorithms in use today, a change that reaches across certificates and key estates.
What EO 14412 requires
EO 14412 is built around dated obligations. Deadlines begin within a month of signing, procurement carries the requirement to the companies worldwide that supply the government, and a cryptographic inventory records what has to change.

Deadlines for agencies and systems
The first requirement lands within 30 days of signing, when each agency head must name a post-quantum cryptography migration lead. Within 90 days, the Office of Management and Budget issues guidance for agencies to review their high-value assets and high-impact systems and submit migration plans. NIST begins a pilot migration within 180 days and completes it by December 31, 2027.
The two headline deadlines follow: high-value assets and covered systems must use post-quantum cryptography for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. National Security Systems migrate on a separate track under National Security Agency guidance.
Who beyond federal agencies must comply
EO 14412 directs the Federal Acquisition Regulation Council to propose two rules: one requiring covered contractors to meet NIST Federal Information Processing Standards, including the post-quantum algorithms, by December 31, 2030, and a second extending vulnerability-disclosure programs to cover cryptographic weaknesses.
Covered contractors is a broad term, reaching any organization, in the United States or abroad, whose products or services touch a federal contract:
- Vendors and their subcontractors
- Suppliers and manufacturers
Cloud and software providers
Post-quantum requirements are already surfacing in government contracts, requests for proposals, and vendor security questionnaires, so for many organizations the operative deadline arrives with the next contract renewal, well before 2030.
The cryptographic bill of materials
A cryptographic bill of materials (CBOM) is a structured, machine-readable record of the cryptography inside a system: the algorithms, keys, certificates, protocols, and libraries it uses, along with how they connect. The order directs the Cybersecurity and Infrastructure Security Agency (CISA) and NIST to publish the minimum elements of a CBOM within 270 days of signing, or around March 2027. A CBOM makes cryptographic posture readable across a supply chain and repeatable from one audit to the next.
The full compliance schedule
Each row pairs an obligation with its deadline and the party responsible for it:
| Deadline | Requirement | Responsible Party |
| Within 30 days (July 2026) | Name an agency post-quantum cryptography migration lead and report it to OMB and the National Cyber Director | Each agency head |
| Within 90 days (September 2026) | Issue guidance to review HVAs and high-impact systems and submit migration plans | OMB, with CISA and the Office of the National Cyber Director |
| Within 180 days (December 2026) | Begin the NIST pilot migration, speed up cryptographic module validation, and propose the contractor acquisition rule | NIST and the FAR Council |
| Within 270 days (March 2027) | Publish the baseline requirements of a CBOM and propose the vulnerability-disclosure rule | CISA with NIST, and the FAR Council |
| December 31, 2027 | Complete the NIST pilot migration | NIST |
| December 31, 2030 | Run post-quantum cryptography for key establishment on high-value assets and high-impact systems, and meet NIST standards for covered contractors | Agencies and contractors |
| December 31, 2031 | Run post-quantum cryptography for digital signatures on high-value assets and high-impact systems | Agencies |
Why the order matters beyond government
EO 14412 binds federal agencies, and its requirements reach the private sector through three routes:
- Procurement pushes the requirement down the supply chain to subcontractors and to the cloud services and software dependencies that federal systems run on.
- Sector oversight reaches critical-infrastructure operators, because the order tasks Sector Risk Management Agencies and CISA with helping energy, finance, telecommunications, and healthcare organizations plan migrations.
- A cryptographic bill of materials lets buyers ask sellers what cryptography their products contain, once CISA and NIST publish their minimum elements, the way a software bill of materials works today.
How to prepare for the 2030 deadline
Preparation follows the sequence the major roadmaps name:
- Start with Discovery: Build a complete cryptographic inventory across code, certificates, keys, protocols, and libraries. The CBOM requirement, the OMB migration plans, and allied roadmaps all name inventory as the first step, and an organization can only migrate what it can see.
- Prioritize by Risk: Map which systems hold long-lived or high-value data, because harvest now, decrypt later targets exactly that data, and those systems fall under the earliest deadlines.
- Build Crypto-Agility: Move to certificate and key management that can swap algorithms and rotate certificates through automation.
- Treat Readiness as Ongoing: NIST will keep updating its standards, and the cryptographic footprint keeps growing, so post-quantum readiness is a must.
How AppViewX supports the PQC transition
The vulnerable cryptography behind every one of these deadlines lives in certificates, keys, and PKI. Replacing it across the systems that rely on it is a certificate lifecycle problem, and that is what AppViewX manages.
AppViewX brings these capabilities together on one platform:
- Discovery: Finds the certificates, keys, and algorithms in use across your environment, keeping the inventory that decides whether 2030 is reachable complete and current.
- Certificate lifecycle automation: Issues, renews, rotates, and re-keys certificates by policy, turning an estate-wide algorithm swap into a controlled, repeatable change without manual, cert-by-cert work.
- Quantum-ready PKI: Issues certificates from a private certificate authority or as a service, letting teams stand up quantum-safe issuance now.
- Cryptographic bill of materials: Generates a standard, machine-readable record of your cryptography, meeting the EO’s reporting requirement and answering what buyers and auditors already ask.








