Post-Quantum Cryptography for Federal Contractors: What the June 2026 Executive Order Actually Requires — and When
Executive Order 14412 set a December 31, 2030 post-quantum deadline and started a FAR rulemaking that reaches federal contractors directly. What's actually required today, what's coming, what's hype — and the five-step head start a small contractor can do now.
The quantum deadline now has a date — and a contract clause on the way
On June 22, 2026, the White House signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks". Most of the coverage focused on what it means for federal agencies. Buried in the acquisition section is the part that matters to you: the order starts a 180-day clock for a proposed Federal Acquisition Regulation (FAR) rule requiring covered contractors to comply with NIST's Federal Information Processing Standards — including the post-quantum cryptography standards — by December 31, 2030.
That's the first time the government's quantum migration has reached the contractor base directly, with a date attached. Until now, post-quantum cryptography (PQC) was an agency problem. It is becoming a supply-chain requirement — the same path CMMC and the DFARS clauses took.
If you sell to the government, or to a prime who does, here's what's actually true, what isn't, and what a small contractor should do with the head start.
What the executive order actually says
For agencies: the government's most sensitive systems — high-value assets and high-impact systems — must transition to post-quantum key establishment by December 31, 2030, and to post-quantum authentication by December 31, 2031. OMB memorandum M-26-15 directs the execution, aligned to NIST's transition guidance, with full migration of remaining systems by 2035.
For contractors: two rulemakings are now in motion.
- Within 180 days, the FAR Council must publish a proposed rule requiring covered contractors to comply with NIST FIPS — including the PQC standards — by December 31, 2030.
- Within 270 days, a second proposed rule will require covered contractors to run vulnerability disclosure programs that cover cryptographic weaknesses — including testing for missing encryption and use of non-FIPS-approved algorithms.
The foundation is already in place. NIST finalized the post-quantum standards in August 2024 — FIPS 203 (ML-KEM for key establishment), FIPS 204 (ML-DSA for signatures), and FIPS 205 (SLH-DSA). NIST's transition roadmap, IR 8547, deprecates the classical algorithms almost everyone uses today — RSA-2048, ECDSA and ECDH on P-256, Diffie-Hellman — in 2030, and disallows them entirely in 2035. And CISA has already published its list of product categories where agencies should be buying PQC-capable products, which means your customers' procurement teams have a shopping checklist today.
What is NOT required of you today
This is the part most vendors won't tell you, so we will:
- There is no PQC requirement in NIST SP 800-171 Rev 2 or CMMC Level 1/2 today. The contractual bar for protecting CUI remains what it has been: FIPS-validated cryptography (800-171 requirement 3.13.11). If someone tells you you're out of compliance right now for not running quantum-resistant algorithms, they're selling fear.
- A proposed rule is not a contract clause. The FAR rulemaking has to run its course — proposal, comment period, final rule — and "covered contractor" will be defined in that process. Nothing lands in your contracts tomorrow.
- You don't need to buy "quantum security" products this quarter. The 2030 obligation is about your cryptography being FIPS-compliant as the FIPS themselves go post-quantum — mostly a software, configuration, and vendor question, not a hardware shopping spree.
Sound familiar? It's the same honest framing we gave when CMMC Phase 2 was suspended: know exactly what's binding, exactly what's coming, and don't pay panic prices for either.
Why smart contractors start anyway
Harvest now, decrypt later is already happening. Adversaries are collecting encrypted traffic and stolen data today to decrypt when quantum capability arrives. If you handle CUI — technical data, drawings, specifications — ask one question: does any of this still need to be confidential in 2033? For most defense work the answer is decades, not years. Encryption you deploy today is the only protection that data will ever have.
The compliance bar moves with FIPS. Your current obligation is FIPS-validated crypto. When the FIPS are post-quantum and the classical algorithms are formally deprecated in 2030, "FIPS-validated" and "quantum-resistant" become the same requirement. The contractors who treat 3.13.11 as a living requirement will roll through the transition; the ones who treat it as a checkbox will face a cliff.
Primes will ask before the FAR does. This is the CMMC pattern repeating: prime contractors are accountable for their supply chains, and their supplier questionnaires update faster than federal rulemaking. "What is your PQC migration plan?" is already appearing in supplier security reviews at large primes. Having a one-page answer is a competitive advantage; having nothing is a red flag.
2030 is one refresh cycle away. Most small businesses replace laptops, servers, firewalls, and VPNs on a 3-5 year cycle. The equipment you buy in 2027 will still be in service on the deadline. Getting PQC into your procurement questions now means you migrate by attrition — nearly free — instead of by forklift in 2029.
Your PQC head start in five steps
None of this requires a cryptographer. It requires a spreadsheet, your vendor list, and a policy.
- Inventory your cryptography. Where do RSA, ECC, and Diffie-Hellman live in your environment? Typical answers: TLS on your websites and apps, VPN tunnels, email encryption, SSH keys, code signing, disk encryption, and your certificate authority. You can't migrate what you haven't mapped — and a crypto inventory is exactly what the government required of its own agencies as step one.
- Assess your data horizons. For each type of sensitive data you hold (especially CUI), estimate how long it must remain confidential. Anything with a horizon past ~2033 is exposed to harvest-now-decrypt-later and should be first in line for quantum-resistant protection.
- Put the question to your vendors. Your cryptography mostly lives inside products you buy — operating systems, firewalls, VPNs, cloud services, SaaS. Ask each: what is your roadmap to FIPS 203/204/205 support? CISA's product-category list tells you where PQC-capable options already exist.
- Adopt a cryptographic agility policy. Commit, in writing, to maintaining a crypto inventory, preferring products with algorithm agility (crypto you can swap without replacing the system), allowing NIST-approved hybrid modes during transition, and aligning to the 2030/2035 dates. This is the artifact that answers the prime's questionnaire.
- Set milestones and track them. Fold the migration into the same plan-of-action discipline you use for 800-171 gaps: owners, dates, and a review cadence. Target: new purchases PQC-capable starting now, high-horizon data protected first, classical crypto retired ahead of the 2030 deprecation.
How CyberPolicify does the heavy lifting
CyberPolicify now includes a Cryptographic Agility & PQC Readiness Policy template — the written commitment from step 4, generated and tailored to your business in minutes, alongside the full policy library contractors use for 800-171, CMMC, SOC 2, and ISO 27001. Pair it with your gap assessment and you have a defensible, dated answer to "what's your quantum plan?" — before your competitors have opened the executive order.
And because the FAR rule, the FIPS updates, and the eventual 800-171 revisions will keep moving, the subscription is how you stay current as they land: when the rules change, your policy file updates with them — that's the point of continuous compliance over a one-time binder.
Generate documentation mapped to frameworks
Generate policies, procedures, and gaps you can act on—without consultant-heavy overhead.