Executive Order 14412 Put Quantum Security on a Federal Clock. The Planning Phase Is Over.
Back to Blogs & Podcasts
07 Oct 2026
OMB Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” dated June 24, 2026, directs agencies on carrying out Executive Order 14412. It requires each agency to submit a post-quantum cryptography (PQC) Migration Plan to OMB and the Office of the National Cyber Director within 120 days. That deadline is October 22, 2026.
Our Executive Order 14412 post covers the order itself.
M-26-15 covers federal civilian agencies and the systems they own or operate. It does not apply to National Security Systems, which follow CNSA 2.0. Under CNSA 2.0, new National Security System acquisitions must be compliant starting January 1, 2027.
Executive Order 14412 has separate provisions for covered contractors. M-26-15 affects vendors too. It directs agencies to include PQC integration in product requirements for categories on CISA’s product categories list, and tells program offices to require PQC readiness and cryptographic agility from vendors.
Our U.S. government quantum preparedness infographic and government page cover the full set of mandates.
Appendix B lists the minimum contents:
Plans must follow NIST IR 8547 or its successor. OMB describes the plan as a dynamic document that will mature over time.
The memo’s objective is to mitigate as much quantum risk as feasible by December 31, 2030. Agencies must prioritize high impact systems, High Value Assets, and systems holding data expected to remain mission-sensitive in 2030.
Our PQC migration page covers implementation.
Agencies must identify legacy systems where migration would be too difficult or too costly. The memo directs them to fold PQC upgrades into planned cloud migrations, software development lifecycles, and hardware refresh schedules. Systems that can’t support PQC or hybrid cryptography go first in line for replacement or decommissioning.
OMB defines cryptographic agility as an architectural principle that lets an organization switch algorithms with minimal disruption. The memo states that agility requires more than avoiding hardcoded algorithm names. Its examples are configuration-driven cryptography, protocol negotiation, and key management infrastructure that handles both classical and post-quantum keys. All systems must be crypto-agile by the end of 2030.
The memo calls hybrid cryptography a useful tool for managing risk during migration, and a complex, resource-intensive stopgap agencies should evaluate carefully.
Further reading: NIST’s guidance on cryptographic agility, our eBook Crypto-Agility: What It Is. What It Isn’t. Why the Difference Matters, Confronting a New Reality, and our post on migrating to PQC without disruption to critical infrastructure.
Harvest Now, Decrypt Later (HNDL) is the practice of collecting encrypted data in transit today to decrypt once quantum computers are available. Protecting the network layer covers that traffic while inventory and system-by-system migration continue.
Phio TX® is the Cryptographic Management Platform (Network and Data Security) from Quantum XChange®.
Phio TX does not perform cryptographic discovery. It runs alongside the inventory tools the memo calls for.
| Plan section | Phio TX relevance |
|---|---|
| Crypto-agile architecture | Algorithms change centrally because key delivery is separate from the data plane |
| Third-party coordination | ETSI GS QKD 014 and Cisco SKIP support multi-vendor equipment |
| Funding and personnel | No hardware refresh required |
| Governance and monitoring | The Centralized Management Console provides visibility, configuration, and monitoring of the cryptographic assets Phio TX manages |
| Risk management | Data in motion is protected during later migration phases |
The memo assigns program offices and requirement owners to make sure vendor requirements include PQC readiness and cryptographic agility. Ask each vendor:
The CISO and CIO Guide to Post-Quantum Cryptography covers vendor evaluation in more detail. Antonio Sanchez and Eric Hay present a 6-question checklist at our Carahsoft webinar on October 22. Register for the webinar.
Agencies must submit their PQC Migration Plan to OMB and the Office of the National Cyber Director no later than 120 days from the memo’s June 24, 2026 date. That puts the deadline at October 22, 2026. OMB treats the plan as a dynamic document, so the first submission sets a baseline agencies will revise.
No. M-26-15 states that it does not apply to National Security Systems. Those systems follow a separate track, including the CNSA 2.0 requirement that new National Security System acquisitions be compliant starting January 1, 2027. M-26-15 covers federal civilian agencies and the systems they own or operate.
At a minimum, the plan needs a risk-based system prioritization strategy, phase timelines, TLS 1.3 testing and deployment timelines, inventory methods and automated tools, a crypto-agile architecture plan, a third-party coordination plan, funding and personnel estimates, a risk management strategy, and a section defining governance roles and responsibilities. Plans must also follow NIST IR 8547.
M-26-15 sets 5 phases: strategy, planning, and discovery (2026 to 2027); pilots and early migration (2027 to 2028); prioritized migration for key establishment (2028 to 2030); signature migration (2031); and full migration (2035). The objective is to mitigate as much quantum risk as feasible by December 31, 2030.
The memo describes cryptographic agility as an architectural principle that lets an organization switch algorithms with minimal disruption. It goes beyond avoiding hardcoded algorithm names. Its examples include configuration-driven cryptography, protocol negotiation, and key management infrastructure able to manage both classical and post-quantum keys.
Phio TX is a Cryptographic Management Platform that overlays existing network infrastructure and delivers keys out-of-band, separate from the data plane. It supports the plan’s crypto-agility and third-party coordination sections and protects data-in-motion without downtime. It holds FIPS 140-3, FIPS 203, and NIST Entropy validations and works alongside cryptographic discovery tools.
Tell us what you run, and we’ll confirm compatibility and the right Phio TX form factor.
Talk to an Expert | Register for the October 22 webinar
Change Nothing. Change Everything.™
Quantum XChange® builds Phio TX®, a Cryptographic Management Platform that protects data in motion for government agencies and enterprises in financial services, healthcare, and critical infrastructure. Phio TX holds FIPS 140-3, FIPS 203, and NIST Entropy validations and deploys as an overlay on existing network infrastructure.
Quantum XChange is a member of the Quantum Industry Coalition, alongside AWS, Google, IBM, Microsoft, and Accenture.
Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.
Request Request
a a
demo demo