Skip to Main Content Subscribe

GSA Reveals PQC Priorities to Secure Identity Management

Share

Following a White House executive order, GSA’s PQC priorities tackle digital identity and building access systems from quantum threats.

2m read
Written by:
Following the June executive order, GSA is guiding federal agencies through PQC migration for digital identity and building access systems.
Photo Credit: Mark Gomez/Shutterstock

The General Services Administration (GSA) is modernizing identity and building access systems to support quantum-resistant algorithms and secure identity systems against emerging cyber threats.

GSA said in a blog post that the agency is prioritizing crypto agility, the ability to switch between different encryption methods, to keep pace with future standards and evolving threats.

Led by the Technology Policy Office within the Office of Government-wide Policy, GSA will help support and guide federal CIOs throughout their PQC journey. Dan Pomery, deputy associate administrator of the office, said the transition to PQC requires careful government coordination and steady investments and funding that GSA is ready to support.

“GSA’s early action helps mitigate risks and supports a secure, orderly migration that protects both digital systems and physical facilities,” said Pomeroy. “By leading this transition, GSA ensures federal employees can continue to work securely while protecting government information and facilities against emerging threats.”

PQC’s Role in Securing Federal Identity

A White House executive order accelerated the timeline for agencies to prepare for post-quantum cryptography (PQC) and harden cybersecurity responses. It directed agencies to transition high-value assets and high-impact systems to PQC by Dec. 31, 2030. Agencies are also required to submit prioritized migration plans under implementation guidance from the Office of Management and Budget (OMB).

“Maybe some of your data doesn’t need to be prioritized, but that’s for every organization and every CIO to undertake that assessment and make a plan,” Celia Merzbacher, director of the Quantum Economic Development Consortium (QED-C), told GovCIO Media & Research earlier this year. “We’re never going to be able to say we’re 100% cyber secure. It’s an ongoing expense that needs to be allocated for, and there’s a risk assessment that goes along with that.”

GSA also established an interagency working group on federal identity, credential, and access management (FICAM) that first met Aug. 12. GSA said the first session had participants across 17 federal agencies and will meet bi-weekly to discuss methods to secure systems against non-human identities, automation and other identity security threats.

Securing Federal Building Access

In addition to modernizing identity management, GSA is also testing PQC’s role in securing building access for federal employees. The Federal Information Processing Standards (FIPS) 201 Evaluation Program is expanding testing capabilities to evaluate how PQC can help secure employee badges, visitor passes and building access controls against future quantum threats. The Federal Acquisition Regulation (FAR) requires agencies to only order physical access control systems (PACS) equipment from GSA’s approved product list (APL)

“GSA’s PACS lab testing determines which products qualify for the APL, making GSA’s role in upholding strict security and interoperability standards essential for governmentwide security,” said Pomeroy. “The lab is starting to incorporate quantum-resistant algorithms into its testing process, so future approved products can protect against future quantum computing threats.”

Related Content