Federal Agencies Move Toward Post-Quantum Cryptography Adoption
The OMB mandates PQC migration plans by October 22, 2026, driving significant procurement needs. The DoD seeks software solutions via an RFI due September 27, signaling an increased focus on quantum-resistant technologies that adhere to NIST standards.
Key Signals
- OMB requires PQC migration plans by October 22, 2026
- DoD issues RFI for PQC solutions due September 27, 2026
- Projected billions in investments for PQC modernization over multiple years
"This $500 million investment signals our commitment to modernizing legacy systems over the next five years."
Federal agencies, recognizing the imminent threats posed by quantum computing, are rapidly advancing efforts to implement post-quantum cryptography (PQC) across sensitive systems. This transition is critical in safeguarding federal information from quantum-enabled attacks that could compromise existing cryptographic standards. The Office of Management and Budget (OMB) has set a firm deadline for agencies to submit detailed PQC migration plans by October 22, 2026, marking a significant shift away from theoretical discussions to actionable procurement activities.
The Department of Defense (DoD) has taken proactive steps in this initiative, recently issuing a Request for Information (RFI) due on September 27, 2026. The RFI specifically seeks software-only cryptographic solutions that do not require hardware modifications, aligning with the Pentagon’s ambitious objective of fully implementing PQC by 2031. By focusing on software-centric solutions, the DoD aims to ensure a smoother transition that mitigates the potential disruptions associated with hardware changes.
This movement towards PQC adoption reflects a broader commitment across federal agencies to enhance cybersecurity resilience. The anticipated changes require that all new systems adhere to the National Institute of Standards and Technology (NIST) PQC standards, with the formalization of the Federal Acquisition Regulation (FAR) rulemaking expected by December 2026. The projected multi-year modernization endeavor signifies a significant investment of billions of dollars, fundamentally altering cloud, software, and hardware procurement strategies within the federal landscape.
The implications of this modernization are vast, and procurement professionals are urged to prepare themselves to support agencies’ PQC initiatives actively. This includes demonstrating capabilities in quantum-resistant solutions and cryptographic agility. As agencies move to secure their systems, the demand for products and services that align with PQC standards is set to rise dramatically. Vendors that specialize in software-defined encryption and related technologies should capitalize on this opportunity to engage with the DoD and other federal entities before formal solicitation processes commence.
A notable quote from Patrick Manley, the Quantum-Security Lead at CISA, underscores the financial commitment underpinning these initiatives: “This $500 million investment signals our commitment to modernizing legacy systems over the next five years.” This statement exemplifies the substantial resources being allocated to fortify federal cybersecurity infrastructures against future quantum threats.
Agencies
- Department of Defense
- Office of Management and Budget
- Cybersecurity and Infrastructure Security Agency
- Federal Acquisition Regulatory Council
- General Services Administration
Sources
- Quantum security ‘drumbeat’ to grow louder in federal procurement | Federal News NetworkFederal News Network · Aug 28
- DOD probes industry about software-defined encryption as U.S. scurries to get quantum-safe | DefenseScoopDefenseScoop · Aug 28
- 🚨 Post-quantum crypto just moved from “future problem” to federal procurement reality. OMB’s Oct. 22 deadline means vendors need proof—not another glossy quantum-resistance promise. https://t.co/DqT59rd8z7 #NistStandards #FederalProcurement #PostQuantumCryptography https://t.co/twitter-fed-procurement · Aug 29