Post-Quantum Migration: A Realistic Timeline for Mid-Market Teams
On June 22, 2026, the White House ordered federal agencies to migrate their highest-value systems to quantum-resistant cryptography by December 31, 2030 and 2031. That deadline does not stay inside federal agency walls — it flows into contractor requirements through a forthcoming FAR rule, runs alongside an NSA timeline already governing national security systems, and lands on top of research that keeps cutting the estimated cost of breaking today's encryption. If your organization is mid-market and not first in line for these mandates, the honest question is not whether you are exempt. It is how much runway you have, and the answer is shorter than “start in 2029” suggests.
The order is Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” the first presidential order to put hard calendar dates on federal post-quantum cryptography (PQC) migration. It builds on standards NIST finalized nearly two years earlier, and arrives as research keeps shrinking the hardware gap between today's quantum computers and ones capable of breaking RSA and elliptic-curve encryption. None of that is a five-alarm fire for a mid-market organization today. It is a real, dated planning problem that a “we'll deal with it when quantum computers exist” posture does not survive.
What post-quantum cryptography actually is
Post-quantum cryptography is a set of encryption and digital-signature algorithms designed to resist attack from both classical and quantum computers, replacing the RSA and elliptic-curve cryptography (ECC) securing most TLS connections, VPNs, code signing, and digital certificates today. NIST finalized the first three PQC standards on August 13, 2024: FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber, for key establishment), FIPS 204 (ML-DSA, derived from CRYSTALS-Dilithium, for digital signatures), and FIPS 205 (SLH-DSA, a hash-based signature scheme derived from SPHINCS+). A fourth, FIPS 206 for FALCON, remains in development. These are final, published federal standards, not drafts — vendors are already building them into TLS libraries, browsers, and enterprise PKI products.
The mandate stack: what EO 14412 and CNSA 2.0 actually require, and by when
EO 14412 sets specific, dated obligations for civilian federal agencies, distinct from the National Security Agency's separate timeline for national security systems. The two run in parallel and use different vocabulary, which is where most confusion starts:
| Deadline | Who | Requirement |
|---|---|---|
| 30 days after June 22, 2026 | Each agency | Name a PQC migration lead reporting to the agency CIO |
| 90 days after June 22, 2026 | OMB, via CISA | Issue guidance requiring agencies to inventory high-value assets and high-impact systems |
| December 31, 2030 | Each agency | Transition high-value assets and high-impact systems to PQC for key establishment |
| December 31, 2031 | Each agency | Transition the same systems to PQC for digital signatures |
| Within 180 days (proposed rule) | FAR Council | Propose a rule requiring covered contractors to comply with PQC-inclusive FIPS by December 31, 2030 |
| Within 270 days (proposed rule) | FAR Council | Propose contractor vulnerability disclosure rules covering cryptographic weaknesses, including use of non-FIPS-approved algorithms |
That fifth row is the one defense contractors and subcontractors should read twice. The order does not just bind agencies — it directs the FAR Council to write PQC compliance into federal contracts on the same December 31, 2030 clock. Combined with flow-down obligations already in DFARS 252.204-7012, a prime contractor's 2030 PQC deadline is likely to become every subcontractor's deadline, the pattern CUI safeguarding already followed.
Separately, the NSA's Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) governs national security systems (NSS) and their vendors on its own schedule: software/firmware signing and networking equipment (VPNs, routers) go exclusive by 2030; web browsers, servers, cloud services, and operating systems by 2033; niche or legacy equipment updated or replaced by 2033. NSA expects the full NSS transition complete by 2035, per National Security Memorandum 10. Vendors selling networking gear, firmware, or cloud services into defense or intelligence markets face CNSA 2.0's 2030 dates — arguably tighter than EO 14412's.
Why "we're not a federal agency" is not the same as "we can wait"
Three groups should stop treating this as someone else's deadline. First, any defense contractor or subcontractor tracking CMMC and DFARS obligations should assume PQC requirements arrive as a flow-down clause with a real audit consequence, the same path CUI safeguarding took. Second, any vendor selling software, hardware, or managed services to a federal agency, defense prime, or NSS operator will be asked for a PQC roadmap well before 2030, because the customer's own compliance depends on it. Third — regardless of federal exposure — any organization protecting data with a shelf life longer than a few years is exposed to “harvest now, decrypt later”: an adversary intercepts encrypted traffic today, betting a cryptographically relevant quantum computer will exist before that data stops mattering. Healthcare records, long-term financial data, litigation holds, and trade secrets all clear that bar with no federal contract involved.
How close is a quantum computer that can actually do this?
Nobody has built a quantum computer capable of breaking RSA-2048 today, and estimates of how large one would need to be keep dropping fast enough to matter for planning. In 2019, Google researcher Craig Gidney and KTH's Martin Ekerå estimated factoring a 2048-bit RSA key would require roughly 20 million noisy qubits. In a May 2025 paper, Gidney cut that estimate 20-fold: fewer than one million noisy qubits, running under a week, using algorithmic improvements rather than better hardware — a result Google's own security blog confirmed. Research reported through early 2026 described further reductions, with some architectures projected under 100,000 qubits, per The Quantum Insider's review. Today's largest quantum computers still run thousands of qubits, not hundreds of thousands — the hardware gap is real. But a threat model shrinking by an order of magnitude every year or two is not one to plan around using yesterday's timeline.
A realistic timeline for a mid-market security team
Mid-market organizations are neither the tip of the spear on this migration nor at the back of the line. A defensible, phased approach looks like this:
- Now through early 2027 — build the cryptographic inventory. You cannot migrate what you have not found. Catalog where RSA, ECC, and Diffie-Hellman are used: TLS endpoints, VPN concentrators, code-signing infrastructure, PKI, database encryption, and homegrown cryptographic code. CISA, NSA, and NIST's joint quantum-readiness factsheet frames this as the first step every later deadline depends on.
- 2027 — open vendor conversations. Ask every vendor with cryptography in their product (firewalls, VPNs, identity providers, backup and encryption software) for a PQC roadmap and target dates. No answer is a data point for your next renewal, not a reason to panic.
- 2027–2028 — prioritize by data lifetime, not federal deadline. Systems protecting long-lived, high-sensitivity data (health records, financial history, CUI, trade secrets) move to the front of the queue regardless of which federal mandate applies, because harvest-now-decrypt-later makes today's traffic tomorrow's exposure.
- 2028–2029 — pilot hybrid deployments. Most enterprise PQC rollouts pair a classical algorithm with a post-quantum one during transition, giving a fallback if an implementation issue surfaces. Test on non-critical systems first.
- 2029–2031 — migrate priority systems ahead of the federal clock. Organizations with DIB, federal, or NSS-adjacent exposure should aim to be compliant well before the 2030 and 2031 EO 14412 dates, since audit and procurement rarely move at the speed of the underlying deadline.
What to do this quarter
You do not need a finished migration plan by the end of this quarter. You need the inputs that make one possible:
- Assign an owner. EO 14412's model of a single accountable PQC migration lead reporting to a CIO-level function is worth copying — migration that belongs to everyone belongs to no one.
- Start the inventory, even incomplete. A partial cryptographic asset inventory this quarter beats a complete one in 2029. Prioritize internet-facing TLS endpoints, VPN gateways, and code-signing infrastructure first.
- Fold PQC readiness into vendor risk reviews. Add "what is your PQC roadmap and target date" to renewal and RFP questionnaires now, so it isn't a surprise question in 2029.
- Extend zero trust planning to cryptographic agility. An architecture that already assumes credentials will be revoked and reissued is a better starting point for an algorithm swap than one built around static, long-lived keys.
- If you hold CMMC or DFARS obligations, watch the FAR rulemaking directly. The proposed contractor PQC rule under EO 14412 is expected within 180 days of June 22, 2026 — track it the way your CMMC program already tracks rule changes, rather than waiting for a prime to relay it.
The organizations that handle this well will not be the ones that migrated everything by 2027. They will be the ones that had an honest inventory, a vendor conversation already underway, and a prioritized list sorted by actual data exposure well before any deadline forced the question. If you want help building that inventory or mapping your CMMC-scoped systems against the federal PQC timeline, reach out to start that conversation, or see how our FedRAMP certification coverage intersects with the same federal compliance calendar.
Frequently asked questions about post-quantum cryptography migration
What is post-quantum cryptography?
PQC refers to cryptographic algorithms designed to resist attack from both classical and quantum computers. NIST finalized the first three PQC standards on August 13, 2024: FIPS 203 (ML-KEM, key establishment), FIPS 204 (ML-DSA, digital signatures), and FIPS 205 (SLH-DSA, hash-based signatures).
What is Executive Order 14412 and who does it apply to?
EO 14412, "Securing the Nation Against Advanced Cryptographic Attacks," was signed June 22, 2026. It binds federal civilian agencies to transition high-value and high-impact systems to PQC key establishment by December 31, 2030 and digital signatures by December 31, 2031, and directs the FAR Council to propose rules requiring contractors to comply by the same 2030 date.
Does a mid-market company with no federal contracts need to worry about EO 14412?
Not directly, but indirectly: as a subcontractor or vendor to an in-scope organization, as a vendor whose customers will ask for a PQC roadmap anyway, and as any organization protecting data with a multi-year shelf life against harvest-now-decrypt-later collection.
How is CNSA 2.0 different from EO 14412?
CNSA 2.0 is an NSA-issued suite and timeline governing national security systems (NSS) and their vendors, with deadlines from 2030 (software, firmware, networking equipment) to 2033 (operating systems, web services, legacy equipment). EO 14412 is a broader presidential directive covering federal civilian agencies and, eventually, contractors, with its own 2030 and 2031 dates. The two overlap where organizations touch both federal civilian and national security systems.
What is "harvest now, decrypt later" and why does it matter before quantum computers exist?
Harvest now, decrypt later describes an adversary strategy of intercepting and storing encrypted data today, betting on decrypting it once a powerful enough quantum computer exists. It matters now because data with a shelf life longer than that maturation timeline is already exposed the moment it is intercepted.
How close are we to a quantum computer that can break RSA-2048?
No quantum computer today has the scale to do this. Estimates of the hardware required have fallen sharply, from roughly 20 million noisy qubits in a 2019 estimate to fewer than one million in a May 2025 paper by Google researcher Craig Gidney, with later research describing further reductions. Today's largest quantum computers remain several orders of magnitude below even the reduced estimates.
What is the first practical step a mid-market security team should take?
Build a cryptographic asset inventory of where RSA, ECC, and Diffie-Hellman are used across TLS endpoints, VPNs, code-signing infrastructure, PKI, and custom code. CISA, NSA, and NIST's joint quantum-readiness guidance identifies this as the necessary first step before any migration plan can be prioritized.
Should organizations wait for pure post-quantum algorithms or start with hybrid deployments?
Most enterprise PQC rollouts in 2026 use hybrid key exchange, pairing a classical algorithm with a post-quantum one, so a flaw in either implementation does not fully break the connection. Piloting hybrid deployments on non-critical systems in 2028-2029 is a reasonable middle path.