On June 22, 2026, the White House released Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” accelerating post-quantum cryptography adoption across federal systems, government contractors, critical infrastructure, and software and cloud providers. OMB Memorandum M-26-15 followed two days later with the first phased federal migration roadmap: agencies must inventory their cryptography and submit migration plans within 120 days, and high-value assets and high-impact systems must move to post-quantum key establishment by December 2030.
This order covers not only federal agencies, but also government contractors, operators of critical government infrastructure, and software and cloud providers. Organizations throughout the supply chain must find ways to comply with the executive order. Full migration is expected by December 2030—but your organization may be affected by compliance obligations much sooner than you think.
Harvesting Now to Decrypt Later
Data harvesters don’t need to be able to decrypt your data now to steal it. “Q-Day,” the point in technology evolution when quantum computers can easily break standard encryption, is approaching faster than many believed it would. In fact, researchers at the Harvard Quantum Initiative say that early quantum systems could be viable by the end of the decade. This is about five to ten years earlier than expected—and this is why the White House is treating future technology as a current risk. If your systems are vulnerable, bad actors may already be storing your data to decrypt as soon as large-scale quantum systems become available.

3 Steps That You Can Take Right Now
- Inventory your current cryptography—The Cryptographic Bill of Materials (CBOM) is the concept the federal roadmap is built on, with NIST and CISA guidance due by March 2027. Transparency of your cryptography standards will be necessary to comply with the order—and will help ensure you can continue to partner with current clients and vendors.
- Identify your most at-risk systems—Reducing vulnerabilities now will make sure your migration goes more smoothly.
- Plan your migration—Full migration is due in December 2030, so take this time to create a comprehensive plan. This transition will be more complex than the migration from SHA-1 to SHA-2, which took 12 years. Time is of the essence.
Next Steps
According to the executive order, federal agencies’ plans are due by late October, and the standards work will continue through the decade. The good news is that you don’t have to manage this complexity alone. Connection’s security experts are available to help you understand your obligations in light of the executive order—and to help you take stock of your current environment so you can plan your migration. Contact your Account Manager today—or check out our Security Services online to learn more.