Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” pulled the federal post-quantum migration forward from a 2035 posture to hard deadlines: PQC for key establishment by December 31, 2030 and for digital signatures by December 31, 2031, across high value assets and FIPS-199 high-impact systems.
But the nearest deadline is not in 2030. OMB M-26-15 (June 24, 2026) makes agency PQC Migration Plans due around October 22, 2026 — and the plan is only as good as the cryptographic inventory underneath it.
Four regimes interlock here: EO 14412, OMB M-26-15 (which functionally supersedes M-23-02 without formally rescinding it), the CMVP FIPS 140 transition, and NSA's CNSA 2.0 for National Security Systems. Each row is labeled with who it binds.
EO 14412 directs OMB to issue implementing guidance to agencies roughly 90 days after signing. Expect it to operationalize the 2030/2031 deadlines and tie into the M-26-15 plan regime.
FIPS 140-2 certificates are usable for new systems only through September 21, 2026. On September 22, every remaining 140-2 certificate moves to the CMVP Historical List. As of July 26, 2026: 506 Active 140-2 certs, 3,911 already Historical, 638 Active 140-3. Full breakdown on our FIPS 140-2 sunset page.
OMB M-26-15 (June 24, 2026) gives agencies 120 days to submit PQC Migration Plans — a five-phase migration arc through 2035 with crypto-agility explicitly required. This is the nearest hard federal deliverable on the calendar.
EO Sec. 6(c) directs the FAR Council to publish a proposed rule that would require covered contractors to comply with NIST FIPS, including PQC algorithms, by December 31, 2030. It is a proposed rule — notice-and-comment still lies ahead, and the EO does not directly bind contractors today.
Under CNSSP-15, new acquisitions must support CNSA 2.0 (AES-256, ML-KEM-1024, ML-DSA-87, SHA-384/512). This gate applies to National Security Systems only — it is not a government-wide requirement.
Two items land the same day: CISA-led (NIST-coordinated) guidance defining minimum elements for cryptographic bills of materials (EO Sec. 5(d)), and a separate proposed FAR rule on contractor vulnerability-disclosure programs covering cryptographic vulnerabilities (EO Sec. 6(d)).
M-26-15 sets a hard TLS 1.3 deadline for federal systems — the transport-layer prerequisite for hybrid and PQC key establishment at scale.
EO 14412 Sec. 4(b): high value assets and FIPS-199 high-impact federal systems must use post-quantum cryptography for key establishment. The same date is the contractor NIST-FIPS/PQC compliance target under the proposed FAR rule, and the NSS deadline to phase out equipment that cannot support CNSA 2.0.
EO 14412 Sec. 4(b): PQC for digital signatures across the same HVA / high-impact scope. CNSA 2.0 also becomes mandated for National Security Systems on this date.
The end of the M-26-15 five-phase arc — and the end date of the M-23-02 annual CRQC-vulnerable inventory obligation. 2035 is no longer the deadline; it is the cleanup horizon after the 2030/2031 gates.
EO 14412's 2030/2031 deadlines scope to high value assets and FIPS-199 high-impact systems — National Security Systems are excluded and run on the separate CNSA 2.0 track instead. M-26-15 adds the near-term deliverable: a PQC Migration Plan due ~October 22, 2026, with crypto-agility explicitly required.
Nothing binds you yet — but EO Sec. 6(c) orders a proposed FAR rule by December 19, 2026 that would require covered contractors to meet NIST FIPS, including PQC algorithms, by December 31, 2030. Notice-and-comment still lies ahead. The smart move is to get ahead of the proposed FAR rule with an inventory now, not to wait for the final text.
The annual CRQC-vulnerable inventory (OMB M-23-02, Nov 2022) continues until 2035 — CyberScope submission to ONCD and CISA, nine data elements per system. M-26-15 functionally supersedes M-23-02 without formally rescinding it — the annual inventory obligation carries forward, with the migration-plan regime layered on top.
System-owner names are explicitly excluded. In-scope algorithms: ECDH, MQV, ECDSA, Diffie-Hellman, RSA — with M-26-15 adding RSA key establishment, DSA, and other non-PQC asymmetric algorithms.
EO 14412 directs CISA-led, NIST-coordinated guidance on the minimum elements of a cryptographic bill of materials, due March 19, 2027. A CBOM stops being a nice-to-have and becomes a defined federal artifact.
CipherM already emits CycloneDX 1.6 CBOMs with a loose, namespaced extension model — designed so that when the minimum-elements guidance drops, conforming is a mapping exercise we ship the same week, not a re-architecture.
The memo explicitly endorses a central CBOM and requires crypto-agility in Phases 3–4 (Appendix A, sec. 5). CipherM's agility score gives you a defensible measure of that posture, per system, from your real code and configs.
Our export tooling turns scan results into the artifacts the obligations actually ask for: the M-23-02 nine-element inventory rows, migration-plan inputs for M-26-15, and the CBOM itself — evidence you can hand to OMB, ONCD, or a prime.
A fixed-scope, two-week Rapid Assessment: we scan your code, configs, and live TLS, review by hand, and hand you a CycloneDX 1.6 CBOM, an agility score, and inventory exports mapped to the M-23-02 elements — the raw material for an M-26-15 plan or a get-ahead posture on the proposed FAR rule.
CipherM produces evidence: cryptographic inventories, CBOMs, agility scores, and submission-ready artifacts. We do not perform CMVP validation, we do not remediate or switch your algorithms, and a scan is not a certification or legal advice. Every deadline on this page cites the primary sources below — verify against them before you plan, and expect the OMB implementing guidance (~September 20, 2026) to add detail.