Skip to Main Content Subscribe

How Federal Agencies Should Prepare for PQC Migration

Share

NIST’s Dustin Moody explains how agencies can prepare for PQC by prioritizing inventories, staffing and risk-based migration.

4m read
Written by:
quantum computer
Engineer operating advanced quantum computing equipment through glass in research lab with cryogenic cooling and braided tubing. Photo Credit: Germanru/Shutterstock

Federal agencies now have an accelerated timeline to secure against quantum threats, but meeting the new deadlines will require more than replacing encryption, according to National Institute of Standards and Technology mathematician Dustin Moody.

Following President Donald Trump’s June executive order on post-quantum cryptography, Moody said CIOs should first inventory where cryptography exists across their organizations, identify their highest-priority systems and assign dedicated teams to lead the transition.

Trump’s executive order requires agencies to transition all high-value assets and high-impact systems to post-quantum cryptography for key establishment by Dec. 31, 2030, and for digital signatures by Dec. 31, 2031. The order excludes national security systems, which follow a separate reporting process through the National Security Agency. The timeline accelerates the federal government’s migration by four to five years from the previous 2035 target established in the prior administration.

Know What You Have Before You Fix It

Moody said agencies vary widely in their preparedness, making it impossible to prescribe a one-size-fits-all migration plan.

“There’s a lot of good guidance out there,” Moody said. “It’s hard to say a single step by step guidance just because everybody’s organization and situations are a little bit different.”

For any CIO starting the process, Moody said the work begins with an honest accounting of the problem. Agencies need to understand that much of the cryptography protecting their systems is vulnerable to a future quantum computer, then inventory where that cryptography lives and what type protects which data. That inventory becomes the basis for prioritization, since not every system carries equal risk and not every dataset holds equal sensitivity.

“You’re going to need to prioritize. Some systems are going to need that more urgently than others. Some data is more sensitive than other data,” Moody said.

Bolstering Staffing

Moody said agencies also need dedicated leadership and resources because migrating to PQC extends far beyond replacing cryptographic algorithms. Encryption underpins countless products, applications and services, requiring sustained coordination across IT, security and mission owners.

“You’re also going to need to just have a dedicated point person who has a team that’s got resources, who is going to be able to build the roadmap for your organization,” Moody said.

Moody was candid about the workforce gap underlying the migration. Most IT professionals can contribute to the effort if they understand where cryptography sits within their systems, though few currently do. The accelerated timeline, he said, will require growing that base of expertise quickly.

When asked whether the 2030 deadline is realistic, Moody said agencies that commit sufficient resources should meet it, but he does not expect universal compliance.

He noted that the consequences of missing the deadline depend on the sensitivity of the affected systems and on when a cryptographically relevant quantum computer becomes available. But history suggests cryptographic transitions often take longer than expected.

“We’ve seen cryptographic transitions in the past have taken longer than this. There’s still, for an example, ATMs out there that are using an algorithm called DES, which was originally published in the 1970s. It’s not hard to break it, but it’s still out there because once crypto is out there, it’s hard to ever update everything,” Moody said.

Moody’s advice to agency leaders was simple: “It’s gonna be really hard. This is going to be challenging, complex, and if you wait for others to lead the way, you’re gonna be behind and may not be able to get it done.”