Agencies are expected to undertake two actions in service of enhanced security: execute a phased migration of cryptographic systems to prepare for quantum computing risk; and submit a PQC migration plan to OMB.

da-kuk/Getty Images
By
Alexandra Kelley,
Staff Correspondent, Nextgov/FCW
| June 25, 2026
The Office of Management and Budget issued a memorandum to federal agencies on Wednesday outlining the steps they need to take to migrate select government systems to post-quantum cryptography, or PQC, an encryption standard intended to withstand the anticipated code-breaking capacity of a fault-tolerant quantum computer.
The memo expands on requirements outlined in President Donald Trump’s June 22 executive order on government PQC migration. The guidance has been in the works for approximately a year, with a draft version first reported in July 2025 by Nextgov/FCW.
Multiple aspects from the draft memo made it into the final version, such as requirements for federal agencies to conduct inventories of their digital networks. The final version placed priority on migrating legacy systems and high-value assets.
Wednesday's final guidance also requires agencies to report their inventorying efforts as a part of required PQC migration plans. These plans must be delivered to OMB and the Office of the National Cyber Director within 120 days of the memo being published. In keeping with the draft, these timelines are intended to be phased, spanning efforts to plan, discover, pilot and eventually fully migrate digital networks to PQC.
The memo also instructs agencies to ensure that their vendor-supplied software meets PQC requirements by referencing the Cybersecurity and Infrastructure Security Agency’s “Product Categories for Technologies That Use Post-Quantum Cryptography Standards” lists.
While vendors are not explicitly required to submit PQC migration timelines like agencies are, agency program offices will need to ensure that their requirements for software vendors include PQC-readiness and cryptographic agility. Agency migration plans must also include an individual protocol for “third-party coordination.”
Automation remains central to inventory and migration management.
“Given the scale and complexity of Federal IT environments, manual approaches to discovery and management of cryptography are often insufficient,” the memo reads. “Agencies should use automation when feasible and appropriate to achieve a comprehensive and continuously updated understanding of their cryptographic posture.”
Agencies have until 2035 to reach the full migration phase of their PQC transition.
| # | Наименование новости | Тональность | Информативность | Дата публикации |
|---|---|---|---|---|
| 1 | GSA begins quantum security efforts for digital and physical systems | 0 | 11.52 | 24-08-2026 |
| 2 | Treasury launches task force to prepare financial sector for quantum cyber threats | 0 | 12.29 | 24-08-2026 |
| 3 | Минэнерго планирует создать группы реагирования на киберинциденты | 0 | 0 | 23-09-2019 |
| 4 | Кабмин утвердил план реализации основ госполитики в области промышленной безопасности | 0 | 0 | 22-09-2018 |
| 5 | Кабмин утвердил план по переходу к выдаче ряда разрешений в электронном виде | 0 | 0 | 10-02-2020 |
| 6 | Правительство решило создать Центр мониторинга и прогноза ЧС на Курилах | 0 | 0 | 21-09-2018 |
| 7 | ЦБ обяжет финорганизации сообщать о кибератаках | 0 | 0 | 22-11-2018 |
| 8 | Трамп подписал закон о создании Агентства по кибербезопасности и защите инфраструктуры | 0 | 0 | 17-11-2018 |
| 9 | ПА ОДКБ разрабатывает рекомендации по регулированию оборота виртуальных валют | 0 | 0 | 02-07-2019 |
| 10 | Мутко поручил Минстрою и Минфину до 15 сентября отчитаться о переходе на эскроу | 0 | 0 | 04-07-2019 |