Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration - SecurityWeek
SecurityWeekArchived Jul 15, 2026✓ Full text saved
Trump Signs Executive Order Accelerating Post-Quantum Cryptography Migration SecurityWeek
Full text archived locally
✦ AI Summary· Claude Sonnet
President Donald Trump on Monday signed an executive order to strengthen data protection in preparation for the arrival of practical quantum computing.
Executive Order 14409 highlights the threat posed by ‘harvest now, decrypt later’, in which threat actors exfiltrate encrypted data now, intending to crack the encryption later using quantum computers.
The private sector has been taking major steps toward post-quantum cryptography (PQC), including companies such as Google, Dell, and HP. And now the US government is also attempting to establish a clear roadmap and accelerate PQC migration.
The new EO tasks OMB, NIST, NSA, DHS, and CISA with working together to develop and oversee the implementation of comprehensive technical guidance to help federal agencies adopt PQC.
Agencies will have to inventory their high-value assets and high-impact systems and transition them to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031.
The order instructs agencies to designate a PQC migration lead, and the Department of Commerce will run a pilot project until the end of 2027.
“The pilot program will showcase a successful migration by 2027, setting a clear example for agencies to fortify their cyber defenses as quantum technology advances,” the White House said in a fact sheet accompanying Executive Order 14409.
The State Department has been tasked with encouraging and assisting critical infrastructure operators and foreign governments in their PQC transition, while the Pentagon, NASA, and the General Services Administration have been directed to find cost-saving opportunities.
Federal contractors will also be required to comply with NIST standards regarding the use of PQC-compliant algorithms by the end of 2030.
“This executive order sends an unambiguous signal to every organization doing business with the federal government: the clock is ticking and maybe running out for some,” commented Garfield Jones, EVP Strategy and Research at QuSecure.
“The 2030 deadline for key establishment is a tangible compliance deadline, and the gap between where most organizations are today and where they need to be is significant,” Jones added. “Agencies and contractors that haven’t started a cryptographic inventory are already behind. The organizations that move now will have options. The ones that wait will find themselves managing a crisis.”
This comes shortly after President Trump signed an executive order establishing a voluntary framework for federal vetting of frontier AI models before their public release.
Related: Google Slashes Quantum Resource Requirements for Breaking Cryptocurrency Encryption
Related: Quantum Bridge Raises $8 Million for Quantum-Safe Key Distribution Solution
Related: Quantum Decryption of RSA Is Much Closer Than Expected
WRITTEN BY
Eduard Kovacs
Eduard Kovacs (@EduardKovacs) is senior managing editor at SecurityWeek. He worked as a high school IT teacher before starting a career in journalism in 2011. Eduard holds a bachelor’s degree in industrial informatics and a master’s degree in computer techniques applied in electrical engineering.
More from Eduard Kovacs
Pentagon Suspends CMMC Phase 2 as It Rethinks Contractor Cybersecurity Rules
Cybersecurity M&A Roundup: 37 Deals Announced in June 2026
Centers Laboratory Data Breach Affects 540,000 Individuals
Third US Security Expert Sentenced to Prison for Helping Ransomware Gang
China, India-Linked Hackers Both Targeted Same Pakistani Police Force
‘HalluSquatting’ Turns AI Hallucinations Into Botnet Delivery Mechanism
Palo Alto Networks Patches 13 Vulnerabilities
Microsoft Patches Defender ‘RoguePlanet’ Vulnerability
Latest News
Critical Vulnerabilities Patched With Fresh Chrome 150, Firefox 152 Updates
SonicWall Issues Urgent SMA Patch Warning for Two Zero-Day Exploits
Microsoft Patches Record 622 Vulnerabilities, Including Two Exploited Zero-Days
Synopsys Finds No Evidence of Data Breach Amid Bosch Hack Claims
Adobe Patches Critical ColdFusion Vulnerabilities
7 Severe Vulnerabilities Patched in VMware Avi Load Balancer
Unpatched Claude for Chrome Flaw Lets Extensions Read Gmail, Calendar
SAP Patches Critical Vulnerabilities in NetWeaver, Approuter, Commerce Cloud
Trending
Webinar: Why Email Security Keeps Failing (And What Has To Change)
July 8, 2026
Join this live webinar as we break down why email-layer defenses alone can't keep pace with the modern phishing ecosystem, how agentic AI is changing the capacity equation for security teams, and more.
Register
Virtual Event: 2026 Cloud Security Summit
July 15, 2026
This year's summit will help organizations learn how to utilize tools, controls, and design models needed to properly secure cloud environments. Interact with leading solution providers and other end users facing similar challenges in securing a variety of cloud deployments.
Register
People on the Move
F5 has appointed Cathy Peterman as Chief People Officer.
Sean Murphy has joined F5 as a Field Chief Information Security Officer - North America.
CodeHunter has appointed Stephen McCarney as Chief Strategy Officer.
More People On The Move
Expert Insights
The Shift Toward Business-Aligned Risk Management
Moving from isolated, technical data to a continuous risk lifecycle can help organizations align security controls with actual business consequences. (Steve Durbin)
How To Conduct A Successful Audit Of AI-Driven Software Development
As AI-generated code becomes commonplace, CISOs need new audit strategies to measure developer practices, govern AI tool usage, and identify software risks before they reach production. (Matias Madou)
Frontier AI: Six Questions Every Enterprise Should Ask Security Vendors
From model selection and automation to validation and measurable results, the right questions can help enterprises separate genuine AI capabilities from marketing hype. (Joshua Goldfarb)
The AI Token Costs That Can Break Cybersecurity
As cybersecurity platforms embrace agentic AI, organizations must balance detection performance against the escalating costs of token consumption, deployment architecture, and AI credits. (Danelle Au)
When Information Becomes The Attack Surface – Understanding AI Agent Traps
From hidden content injections to cognitive state poisoning, attackers are turning trusted data sources into traps for autonomous AI. (Etay Maor)
Flipboard
Reddit
Whatsapp
Email