Your PQC Migration Plan Is Due October 22: What OMB M-26-15 Requires

By Antonio Sanchez

Share this post

quantum-xchange-omb-m-26-15-pqc-migration-plan-blog

OMB Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” dated June 24, 2026, directs agencies on carrying out Executive Order 14412. It requires each agency to submit a post-quantum cryptography (PQC) Migration Plan to OMB and the Office of the National Cyber Director within 120 days. That deadline is October 22, 2026.

Our Executive Order 14412 post covers the order itself.

Who Is Bound by M-26-15

M-26-15 covers federal civilian agencies and the systems they own or operate. It does not apply to National Security Systems, which follow CNSA 2.0. Under CNSA 2.0, new National Security System acquisitions must be compliant starting January 1, 2027.

Executive Order 14412 has separate provisions for covered contractors. M-26-15 affects vendors too. It directs agencies to include PQC integration in product requirements for categories on CISA’s product categories list, and tells program offices to require PQC readiness and cryptographic agility from vendors.

Our U.S. government quantum preparedness infographic and government page cover the full set of mandates.

What the Plan Must Contain

Appendix B lists the minimum contents:

  • A risk-based system prioritization strategy
  • Timelines and milestones for each migration phase
  • Testing and deployment timelines to meet the January 2, 2030 TLS 1.3 deadline
  • Inventory methodologies and automated tools
  • A crypto-agile architecture implementation plan
  • A third-party coordination plan
  • Funding and personnel estimates
  • A risk management strategy for the migration period
  • Governance roles and responsibilities

Plans must follow NIST IR 8547 or its successor. OMB describes the plan as a dynamic document that will mature over time.

Migration Phases and Deadlines

The memo’s objective is to mitigate as much quantum risk as feasible by December 31, 2030. Agencies must prioritize high impact systems, High Value Assets, and systems holding data expected to remain mission-sensitive in 2030.

  1. Phase 1, Strategy, Planning, and Discovery (2026 to 2027): inventory, assessment, governance, and risk
  2. Phase 2, Pilots and Early Migration (2027 to 2028): PQC pilots and migration of priority systems
  3. Phase 3, Prioritized Migration (2028 to 2030): PQC key establishment on priority systems; all systems crypto-agile
  4. Phase 4, Signature Migration (2031): PQC digital signatures on priority systems
  5. Phase 5, Full Migration (2035): remaining systems, based on risk and commercial availability

Our PQC migration page covers implementation.

Legacy Systems, Crypto-Agility, and Hybrid Cryptography

Agencies must identify legacy systems where migration would be too difficult or too costly. The memo directs them to fold PQC upgrades into planned cloud migrations, software development lifecycles, and hardware refresh schedules. Systems that can’t support PQC or hybrid cryptography go first in line for replacement or decommissioning.

OMB defines cryptographic agility as an architectural principle that lets an organization switch algorithms with minimal disruption. The memo states that agility requires more than avoiding hardcoded algorithm names. Its examples are configuration-driven cryptography, protocol negotiation, and key management infrastructure that handles both classical and post-quantum keys. All systems must be crypto-agile by the end of 2030.

The memo calls hybrid cryptography a useful tool for managing risk during migration, and a complex, resource-intensive stopgap agencies should evaluate carefully.

Further reading: NIST’s guidance on cryptographic agility, our eBook Crypto-Agility: What It Is. What It Isn’t. Why the Difference Matters, Confronting a New Reality, and our post on migrating to PQC without disruption to critical infrastructure.

Where Phio TX Fits

Harvest Now, Decrypt Later (HNDL) is the practice of collecting encrypted data in transit today to decrypt once quantum computers are available. Protecting the network layer covers that traffic while inventory and system-by-system migration continue.

Phio TX® is the Cryptographic Management Platform (Network and Data Security) from Quantum XChange®.

  • Dual-path architecture. Key generation and delivery run out-of-band, separate from the data plane. Operators hot-swap PQC algorithms centrally, without application rewrites or downtime.
  • Overlay deployment. Phio TX runs on existing network infrastructure with no hardware refresh. Existing equipment stays on its planned refresh schedule, which matches the memo’s direction on refresh cycles.
  • Validations. FIPS 140-3 CMVP Certificate #4850, FIPS 203 CAVP Certificate #6060, and NIST Entropy Source Certificate #E79. Validation details
  • Open standards. Phio TX distributes keys over ETSI GS QKD 014 and Cisco SKIP. Phio TX-EM runs in Cisco environments.

Phio TX does not perform cryptographic discovery. It runs alongside the inventory tools the memo calls for.

Phio TX by Plan Section

Plan sectionPhio TX relevance
Crypto-agile architectureAlgorithms change centrally because key delivery is separate from the data plane
Third-party coordinationETSI GS QKD 014 and Cisco SKIP support multi-vendor equipment
Funding and personnelNo hardware refresh required
Governance and monitoringThe Centralized Management Console provides visibility, configuration, and monitoring of the cryptographic assets Phio TX manages
Risk managementData in motion is protected during later migration phases

Questions for Vendors

The memo assigns program offices and requirement owners to make sure vendor requirements include PQC readiness and cryptographic agility. Ask each vendor:

  1. Which validations does the product hold today, and what are the certificate numbers?
  2. Can the algorithm change without downtime?
  3. What existing infrastructure must be replaced?

The CISO and CIO Guide to Post-Quantum Cryptography covers vendor evaluation in more detail. Antonio Sanchez and Eric Hay present a 6-question checklist at our Carahsoft webinar on October 22. Register for the webinar.

Next Steps by Phase

  1. Before October 22: add network-layer protection to the prioritization strategy, starting with links that carry High Value Asset data.
  2. Phase 2 (2027 to 2028): pilot PQC key delivery on a priority link.
  3. Phase 3 (2028 to 2030): meet the crypto-agility requirement before the end of 2030.

Frequently Asked Questions

When is the OMB M-26-15 PQC migration plan due?

Agencies must submit their PQC Migration Plan to OMB and the Office of the National Cyber Director no later than 120 days from the memo’s June 24, 2026 date. That puts the deadline at October 22, 2026. OMB treats the plan as a dynamic document, so the first submission sets a baseline agencies will revise.

Does M-26-15 apply to National Security Systems?

No. M-26-15 states that it does not apply to National Security Systems. Those systems follow a separate track, including the CNSA 2.0 requirement that new National Security System acquisitions be compliant starting January 1, 2027. M-26-15 covers federal civilian agencies and the systems they own or operate.

What must an OMB M-26-15 PQC migration plan include?

At a minimum, the plan needs a risk-based system prioritization strategy, phase timelines, TLS 1.3 testing and deployment timelines, inventory methods and automated tools, a crypto-agile architecture plan, a third-party coordination plan, funding and personnel estimates, a risk management strategy, and a section defining governance roles and responsibilities. Plans must also follow NIST IR 8547.

What are the M-26-15 migration phases and deadlines?

M-26-15 sets 5 phases: strategy, planning, and discovery (2026 to 2027); pilots and early migration (2027 to 2028); prioritized migration for key establishment (2028 to 2030); signature migration (2031); and full migration (2035). The objective is to mitigate as much quantum risk as feasible by December 31, 2030.

What does crypto-agility mean under M-26-15?

The memo describes cryptographic agility as an architectural principle that lets an organization switch algorithms with minimal disruption. It goes beyond avoiding hardcoded algorithm names. Its examples include configuration-driven cryptography, protocol negotiation, and key management infrastructure able to manage both classical and post-quantum keys.

How does Phio TX fit into an agency’s migration plan?

Phio TX is a Cryptographic Management Platform that overlays existing network infrastructure and delivers keys out-of-band, separate from the data plane. It supports the plan’s crypto-agility and third-party coordination sections and protects data-in-motion without downtime. It holds FIPS 140-3, FIPS 203, and NIST Entropy validations and works alongside cryptographic discovery tools.

Ready to Secure Your Network?

Tell us what you run, and we’ll confirm compatibility and the right Phio TX form factor.

Talk to an Expert | Register for the October 22 webinar

Change Nothing. Change Everything.™

About Quantum XChange

Quantum XChange® builds Phio TX®, a Cryptographic Management Platform that protects data in motion for government agencies and enterprises in financial services, healthcare, and critical infrastructure. Phio TX holds FIPS 140-3, FIPS 203, and NIST Entropy validations and deploys as an overlay on existing network infrastructure.

Quantum XChange is a member of the Quantum Industry Coalition, alongside AWS, Google, IBM, Microsoft, and Accenture.

Share this post

See Phio TX in action

Have one of our experts show you how Phio TX protects your organization from threats today and the quantum future.

Request Request 

a a 

demo demo

grainy-bg-blue