Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks
- Issuer
- Executive Office of the President(EOP)
- Effective date
- Jun 22, 2026
- Published date
- Jun 22, 2026
- Full text
- View full text →
Summary
Executive Order directing the migration of federal information systems (excluding National Security Systems) to NIST-approved PQC FIPS standards. Establishes the first government-wide hard deadlines for civilian federal PQC migration: key establishment by December 31, 2030 and digital signatures by December 31, 2031 for High Value Assets and High Impact Systems. Requires each agency to designate a PQC migration lead and mandates TLS 1.3 support by January 2, 2030.
Milestones (7)
| Deadline | Label | Type | Hard | Notes |
|---|---|---|---|---|
| Jul 22, 2026 | Agencies designate PQC migration lead | Migration Plan | Each agency head must identify a PQC migration lead reporting to the agency CIO and provide contact details to OMB and ONCD. | |
| Sep 20, 2026 | OMB issues implementing guidance | Migration Plan | Fulfilled early — OMB published M-26-15 on June 24, 2026, just two days after the EO was signed. | |
| Dec 19, 2026 | FAR Council proposed rule for contractor PQC compliance | Migration Plan | Proposed rule requiring covered federal contractors to comply with PQC-incorporating FIPS by December 31, 2030. | |
| Dec 31, 2027 | NIST PQC migration pilot project completed | Crypto Agility | NIST must complete a pilot PQC migration on a subset of its own information systems. | |
| Jan 2, 2030 | TLS 1.3 support deadline (federal systems) | Crypto Agility | Required to enable hybrid PQC key exchange at the network level, per EO 14306. | |
| Dec 31, 2030 | HVAs and High Impact Systems: PQC key establishment | Full Compliance | Applies to High Value Assets and High Impact Systems, excluding National Security Systems. | |
| Dec 31, 2031 | HVAs and High Impact Systems: PQC digital signatures | Full Compliance | Digital signature migration deadline for the same scope of systems. |
Algorithm references (3)
- ML-KEMFIPS 203Required
Replaces: RSA, ECDH
Required for key establishment per FIPS 203.
- ML-DSAFIPS 204Required
Replaces: RSA, ECDSA
Required for digital signatures per FIPS 204.
- SLH-DSAFIPS 205Recommended
Replaces: RSA, ECDSA
Named as an available hash-based signature alternative.
PKI Impact
HIGH
PKI Impact
HIGHEstablishes the first government-wide hard deadlines (2030/2031) for civilian federal PQC migration outside CNSA 2.0/NSS scope, with explicit focus on PKI-based logical access control systems and FICAM credentials.
Migration guidance
- Identify your organization's PQC migration lead if operating as or contracting with a federal agency
- Inventory High Value Assets and High Impact Systems using asymmetric encryption first — these are the priority systems under the implementing OMB guidance
- Plan TLS 1.3 hybrid key exchange support (e.g. x25519 + ML-KEM-768) ahead of the January 2, 2030 deadline
- Engage FedRAMP cloud service providers now to clarify PQC migration responsibilities under the shared responsibility model
Trust chain considerations
- GSA's FICAM working group will directly affect PIV/CAC and physical access control PKI hierarchies
- Federal PKI Root CA and subordinate CA operators should anticipate updated cross-certification requirements as agencies build PQC-capable trust chains
Changelog (2)
| Date | Type | Description |
|---|---|---|
| Jun 24, 2026 | Clarification | OMB issued M-26-15 implementing guidance just two days after the EO, fulfilling the 90-day guidance requirement well ahead of schedule and establishing a 5-phase migration timeline through 2035. |
| Jun 22, 2026 | New | Executive Order 14412 signed, establishing hard PQC migration deadlines (Dec 31 2030 for key establishment, Dec 31 2031 for digital signatures) for federal HVAs and high impact systems outside CNSA 2.0/NSS scope. |
Issuer
Executive Office of the PresidentEOP
Type: GOVERNMENT
Region: United States