HackMyIP
← Back to News
2026-06-23 The Hacker News

Trump Executive Order Mandates Post-Quantum Crypto Migration by 2030

EncryptionRegulationVulnerability

President Trump signed Executive Order 14409 on June 22, establishing firm deadlines for federal agencies to migrate high-value assets and high-impact systems to post-quantum cryptography (PQC). Key establishment mechanisms must transition by December 31, 2030, while digital signatures have until December 31, 2031. National security systems remain on a separate, classified track. The order accelerates the federal PQC timeline by four to five years compared to the 2035 target set by National Security Memorandum 10 in 2022, driven by the well-documented "harvest now, decrypt later" threat in which adversaries collect encrypted data today for future decryption once cryptographically relevant quantum computers emerge.

The deadlines align with standards NIST finalized in August 2024. Key establishment will use FIPS 203 (ML-KEM, formerly CRYSTALS-Kyber), while digital signatures will rely on FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). The implementation clock starts immediately: within 30 days, each agency must appoint a PQC migration lead reporting to the CIO; within 90 days, OMB must issue inventory and planning guidance. NIST will also run a pilot migration on a subset of its own systems, due by December 31, 2027. Organizations can begin auditing their own deployments with an SSL/TLS checker to identify non-compliant cryptographic implementations before federal deadlines arrive.

The order's reach extends beyond federal networks. The Federal Acquisition Regulatory Council has 180 days to propose rules requiring covered contractors to meet NIST's FIPS standards, including PQC algorithms, by December 31, 2030. A second proposed rule, due in 270 days, would integrate cryptographic flaws into contractor vulnerability disclosure programs, requiring tests for missing encryption and non-FIPS algorithms. Within 270 days, CISA and NIST must also publish minimum elements for a cryptographic bill of materials (CBOM), the foundation for crypto-agility. Given the persistent threat of harvested encrypted data, individuals can monitor exposure with an email breach checker and confirm authentication credentials meet current standards via a password checker.

For federal teams and government contractors, the binding task is now inventory. Identify every key exchange and signature operation, flag non-PQC implementations, and sequence the migration against the 2030 and 2031 deadlines. The standards are ready, the deadlines are codified, and the only remaining question is execution speed. Organizations that begin cryptographic asset discovery and PQC planning now will be best positioned to meet compliance milestones without disrupting operations.

Source: The Hacker News →

Related Tools

Check whether this kind of story affects you — free, no signup:

My IP →IP Lookup →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is my IP and why it matters →IP address security →How to stop being tracked online →