United States

Executing
White House / OMB · NSA · NIST

NSM-10 (4 May 2022) set 2035 as the target for migrating National Security Systems; OMB M-23-02 (18 November 2022) required civilian agency cryptographic inventories and funding estimates under the Quantum Computing Cybersecurity Preparedness Act (Pub. L. 117-260). NIST finalised FIPS 203/204/205 on 13 August 2024. Executive Order 14412, 'Securing the Nation Against Advanced Cryptographic Attacks' (22 June 2026, 91 FR, published 25 June 2026) and implementing memorandum OMB M-26-15 (24 June 2026) convert the roadmap into a mandate: agency PQC migration plans within 120 days and a five-phase execution programme.

Two separate obligation tracks: OMB memoranda bind civilian agencies, CNSA 2.0 binds National Security Systems and their suppliers. NIST IR 8547, the source of the widely quoted 2030 deprecation / 2035 disallowance dates, is still an initial public draft — those dates are proposals, not law.

Scope

Federal executive-branch civilian agencies (OMB), National Security Systems and their vendors (CNSA 2.0), plus the FIPS algorithm baseline used worldwide

Band rationale

The only jurisdiction with a binding, dated federal execution mandate on top of the algorithm standards themselves.

Readiness dimensions
Policy
Deadline maturity
Technical standards
Execution evidence
Supply-chain enablement
Evidence confidence
Milestones
  1. 2022-05-04

    NSM-10 issued

    National Security Memorandum 10 sets 2035 as the NSS migration target and directs inventory work.

    Bindingness · mandate
  2. 2022-09-07

    CNSA 2.0 advisory

    NSA Cybersecurity Advisory U/OO/194427-22 sets the algorithm suite and adoption phases for National Security Systems.

    Bindingness · mandate
  3. 2022-11-18

    OMB M-23-02

    Civilian agencies must maintain prioritised cryptographic inventories and submit funding estimates.

    Bindingness · mandate
  4. 2024-08-13

    FIPS 203, 204 and 205 final

    ML-KEM, ML-DSA and SLH-DSA published as final federal standards.

    Bindingness · standard
  5. 2024-11-12

    NIST IR 8547 initial public draft

    Draft transition schedule proposing deprecation from 2030 and disallowance by 2035; these dates remain proposals.

    Bindingness · policy roadmap
  6. 2026-06-22

    Executive Order 14412 signed

    Directs a mandated federal migration to post-quantum cryptography; published in the Federal Register on 25 June 2026.

    Bindingness · mandate
  7. 2026-10-22

    Agency migration plans due

    OMB M-26-15 requires plans no later than 120 days after its 24 June 2026 issuance.

    Bindingness · mandate
  8. 2027

    Strategy, planning and discovery

    OMB M-26-15 Phase 1 runs through 2026–2027; Phase 2 pilots and early migration run through 2027–2028.

    Bindingness · mandate
  9. 2030

    Proposed deprecation

    NIST IR 8547 (draft) would deprecate 112-bit-security classical algorithms from 2030.

    Bindingness · policy roadmap
  10. 2030-12-31

    Prioritised key-establishment migration

    OMB M-26-15 Phase 3 targets PQC key establishment for high-value, high-impact and other prioritised systems by the end of 2030.

    Bindingness · mandate
  11. 2031

    Prioritised signature migration

    OMB M-26-15 Phase 4 targets PQC digital signatures for high-value, high-impact and other prioritised systems.

    Bindingness · mandate
  12. 2035

    Full federal migration phase

    OMB M-26-15 Phase 5 targets remaining systems by 2035; NSM-10 separately sets 2035 as the NSS migration target.

    Bindingness · mandate
Why it matters

US algorithm standards anchor almost every other jurisdiction's technical requirements, and the 2026 executive order is the first instrument anywhere that attaches enforcement to a national migration schedule.

Migration implications
  • ·Federal suppliers should expect PQC clauses flowing from M-26-15 migration plans
  • ·Separate CNSA 2.0 obligations (NSS) from OMB obligations (civilian agencies)
  • ·Do not cite NIST IR 8547's 2030/2035 dates as final requirements — it is still a draft
  • ·Track FIPS 203/204/205 validation status for products you buy, not vendor 'PQC-ready' claims
Evidence
Compare with United KingdomCompare with European UnionCompare with FranceCompare with NetherlandsCompare with Canada