Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks

ActiveUS FederalExecutive Order
Effective date
Jun 22, 2026
Published date
Jun 22, 2026

Summary

Executive Order directing the migration of federal information systems (excluding National Security Systems) to NIST-approved PQC FIPS standards. Establishes the first government-wide hard deadlines for civilian federal PQC migration: key establishment by December 31, 2030 and digital signatures by December 31, 2031 for High Value Assets and High Impact Systems. Requires each agency to designate a PQC migration lead and mandates TLS 1.3 support by January 2, 2030.

Milestones (7)

DeadlineLabelTypeHardNotes
Jul 22, 2026Agencies designate PQC migration leadMigration PlanEach agency head must identify a PQC migration lead reporting to the agency CIO and provide contact details to OMB and ONCD.
Sep 20, 2026OMB issues implementing guidanceMigration PlanFulfilled early — OMB published M-26-15 on June 24, 2026, just two days after the EO was signed.
Dec 19, 2026FAR Council proposed rule for contractor PQC complianceMigration PlanProposed rule requiring covered federal contractors to comply with PQC-incorporating FIPS by December 31, 2030.
Dec 31, 2027NIST PQC migration pilot project completedCrypto AgilityNIST must complete a pilot PQC migration on a subset of its own information systems.
Jan 2, 2030TLS 1.3 support deadline (federal systems)Crypto AgilityRequired to enable hybrid PQC key exchange at the network level, per EO 14306.
Dec 31, 2030HVAs and High Impact Systems: PQC key establishmentFull ComplianceApplies to High Value Assets and High Impact Systems, excluding National Security Systems.
Dec 31, 2031HVAs and High Impact Systems: PQC digital signaturesFull ComplianceDigital signature migration deadline for the same scope of systems.

Algorithm references (3)

  • ML-KEMFIPS 203Required

    Replaces: RSA, ECDH

    Required for key establishment per FIPS 203.

  • ML-DSAFIPS 204Required

    Replaces: RSA, ECDSA

    Required for digital signatures per FIPS 204.

  • SLH-DSAFIPS 205Recommended

    Replaces: RSA, ECDSA

    Named as an available hash-based signature alternative.

PKI Impact

HIGH
TLS/SSLPIV/CACRoot CAIntermediate CADevice/IoTCode Signing

Establishes the first government-wide hard deadlines (2030/2031) for civilian federal PQC migration outside CNSA 2.0/NSS scope, with explicit focus on PKI-based logical access control systems and FICAM credentials.

Migration guidance

  • Identify your organization's PQC migration lead if operating as or contracting with a federal agency
  • Inventory High Value Assets and High Impact Systems using asymmetric encryption first — these are the priority systems under the implementing OMB guidance
  • Plan TLS 1.3 hybrid key exchange support (e.g. x25519 + ML-KEM-768) ahead of the January 2, 2030 deadline
  • Engage FedRAMP cloud service providers now to clarify PQC migration responsibilities under the shared responsibility model

Trust chain considerations

  • GSA's FICAM working group will directly affect PIV/CAC and physical access control PKI hierarchies
  • Federal PKI Root CA and subordinate CA operators should anticipate updated cross-certification requirements as agencies build PQC-capable trust chains

Changelog (2)

DateTypeDescription
Jun 24, 2026ClarificationOMB issued M-26-15 implementing guidance just two days after the EO, fulfilling the 90-day guidance requirement well ahead of schedule and establishing a 5-phase migration timeline through 2035.
Jun 22, 2026NewExecutive Order 14412 signed, establishing hard PQC migration deadlines (Dec 31 2030 for key establishment, Dec 31 2031 for digital signatures) for federal HVAs and high impact systems outside CNSA 2.0/NSS scope.

Issuer

Executive Office of the PresidentEOP

Type: GOVERNMENT

Region: United States

Visit website →