OMB M-26-15: Execution of the Migration to Post-Quantum Cryptography
- Issuer
- Office of Management and Budget(OMB)
- Effective date
- Jun 24, 2026
- Published date
- Jun 24, 2026
- Full text
- View full text →
Summary
OMB implementing memorandum for Executive Order 14412. Directs agencies to submit PQC Migration Plans within 120 days and execute a 5-phase migration: Strategy and Discovery (2026-2027), Pilots and Early Migration (2027-2028), Prioritized Migration (2028-2030), Signature Migration (2031), and Full Migration (2035). Does not apply to National Security Systems. Includes detailed technical appendices on algorithm selection, hybrid architecture, TLS 1.3, cryptographic agility, and zero trust integration.
Milestones (8)
| Deadline | Label | Type | Hard | Notes |
|---|---|---|---|---|
| Aug 23, 2026 | GSA establishes FICAM PQC working group | Migration Plan | Inter-agency working group on modernizing Federal Identity, Credential, and Access Management to support PQC. | |
| Oct 22, 2026 | Agencies submit PQC Migration Plan to OMB and ONCD | Migration Plan | Must include system prioritization strategy, milestones, inventory methodology, agility architecture plan, third-party coordination plan, and resource estimates. | |
| Dec 31, 2027 | Phase 1: Strategy, Planning, and Discovery | Inventory | Inventory of HVAs and high impact systems, assessment, governance framework establishment. | |
| Dec 31, 2028 | Phase 2: Pilots and Early Migration | Begin Migration | Pilot programs and early migration of prioritized systems. | |
| Jan 2, 2030 | TLS 1.3 support deadline | Crypto Agility | Required per EO 14306 to enable hybrid key exchange at the network level. | |
| Dec 31, 2030 | Phase 3: Prioritized Migration — PQC key establishment | Full Compliance | All HVAs, high impact systems, and highly sensitive data systems must migrate to PQC for key establishment. | |
| Dec 31, 2031 | Phase 4: Signature Migration | Full Compliance | Same system scope must migrate to PQC for digital signatures. | |
| Dec 31, 2035 | Phase 5: Full Migration of remaining systems | Full Compliance | Contingent on risk assessment and availability of commercial PQC offerings. |
Algorithm references (3)
- ML-KEMFIPS 203Required
Replaces: RSA, ECDH
Required for key establishment per FIPS 203, explicitly listed in Appendix A.
- ML-DSAFIPS 204Required
Replaces: RSA, ECDSA
Required for digital signatures per FIPS 204, explicitly listed in Appendix A.
- SLH-DSAFIPS 205Recommended
Replaces: RSA, ECDSA
Listed as a hash-based fallback signature scheme in Appendix A.
PKI Impact
HIGH
PKI Impact
HIGHThe most detailed federal PQC implementation guidance to date, with explicit technical direction on TLS 1.3 hybrid key exchange, zero trust architecture integration, and a quantum-vulnerable algorithm list directly naming RSA, ECDSA, ECDH, and DH for deprecation.
Migration guidance
- Build a Cryptographic Bill of Materials (CBOM) now — M-26-15 treats this as foundational to compliance reporting
- Prioritize re-keying and re-issuance planning for PKI hierarchies supporting High Value Assets and High Impact Systems first
- Review FIPS 201/PIV physical access control systems against the GSA Approved Products List for PQC-capable replacements
- If you are a FedRAMP-authorized CSP or SaaS/PaaS/IaaS vendor used by federal agencies, expect CISA/DOW-led PQC migration coordination directly
Trust chain considerations
- Appendix A explicitly names ECDH, ECDSA, RSA, DH, and MQV as quantum-vulnerable — any Root or Intermediate CA issuing certificates with these algorithms is in scope for replacement planning
- Zero Trust Architecture device attestation rooted in TPM must migrate to PQC algorithms, directly affecting device identity PKI
Changelog (1)
| Date | Type | Description |
|---|---|---|
| Jun 24, 2026 | New | OMB issued M-26-15, the implementing guidance for EO 14412, establishing a 5-phase PQC migration timeline (2026-2035) and a 120-day deadline for agencies to submit PQC Migration Plans. |
Issuer
Office of Management and BudgetOMB
Type: GOVERNMENT
Region: US