Signed June 22, 2026 · 91 FR 38483

EO 14412: 2035 just became 2030.

Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” pulled the federal post-quantum migration forward from a 2035 posture to hard deadlines: PQC for key establishment by December 31, 2030 and for digital signatures by December 31, 2031, across high value assets and FIPS-199 high-impact systems.

But the nearest deadline is not in 2030. OMB M-26-15 (June 24, 2026) makes agency PQC Migration Plans due around October 22, 2026 — and the plan is only as good as the cryptographic inventory underneath it.

The full deadline timeline

Every date, in order. Nearest first.

Four regimes interlock here: EO 14412, OMB M-26-15 (which functionally supersedes M-23-02 without formally rescinding it), the CMVP FIPS 140 transition, and NSA's CNSA 2.0 for National Security Systems. Each row is labeled with who it binds.

~Sept 20, 2026
Agencies

OMB implementing guidance due

EO 14412 directs OMB to issue implementing guidance to agencies roughly 90 days after signing. Expect it to operationalize the 2030/2031 deadlines and tie into the M-26-15 plan regime.

Sept 21–22, 2026
CMVP / everyone

FIPS 140-2 sunset — all remaining certs go Historical

FIPS 140-2 certificates are usable for new systems only through September 21, 2026. On September 22, every remaining 140-2 certificate moves to the CMVP Historical List. As of July 26, 2026: 506 Active 140-2 certs, 3,911 already Historical, 638 Active 140-3. Full breakdown on our FIPS 140-2 sunset page.

~Oct 22, 2026
Agencies

Agency PQC Migration Plans due to OMB / ONCD

OMB M-26-15 (June 24, 2026) gives agencies 120 days to submit PQC Migration Plans — a five-phase migration arc through 2035 with crypto-agility explicitly required. This is the nearest hard federal deliverable on the calendar.

Dec 19, 2026
Contractors

FAR Council PROPOSED contractor rule due

EO Sec. 6(c) directs the FAR Council to publish a proposed rule that would require covered contractors to comply with NIST FIPS, including PQC algorithms, by December 31, 2030. It is a proposed rule — notice-and-comment still lies ahead, and the EO does not directly bind contractors today.

Jan 1, 2027
NSS only

CNSA 2.0 new-acquisitions gate

Under CNSSP-15, new acquisitions must support CNSA 2.0 (AES-256, ML-KEM-1024, ML-DSA-87, SHA-384/512). This gate applies to National Security Systems only — it is not a government-wide requirement.

Mar 19, 2027
Agencies + contractors

CBOM minimum elements + FAR vulnerability-disclosure rule

Two items land the same day: CISA-led (NIST-coordinated) guidance defining minimum elements for cryptographic bills of materials (EO Sec. 5(d)), and a separate proposed FAR rule on contractor vulnerability-disclosure programs covering cryptographic vulnerabilities (EO Sec. 6(d)).

Jan 2, 2030
Agencies

TLS 1.3 across federal systems

M-26-15 sets a hard TLS 1.3 deadline for federal systems — the transport-layer prerequisite for hybrid and PQC key establishment at scale.

Dec 31, 2030
Agencies + contractors (proposed) + NSS

PQC for key establishment — the big one

EO 14412 Sec. 4(b): high value assets and FIPS-199 high-impact federal systems must use post-quantum cryptography for key establishment. The same date is the contractor NIST-FIPS/PQC compliance target under the proposed FAR rule, and the NSS deadline to phase out equipment that cannot support CNSA 2.0.

Dec 31, 2031
Agencies + NSS

PQC for digital signatures

EO 14412 Sec. 4(b): PQC for digital signatures across the same HVA / high-impact scope. CNSA 2.0 also becomes mandated for National Security Systems on this date.

2035
Agencies

Full migration horizon

The end of the M-26-15 five-phase arc — and the end date of the M-23-02 annual CRQC-vulnerable inventory obligation. 2035 is no longer the deadline; it is the cleanup horizon after the 2030/2031 gates.

Who is affected

Three audiences, three different obligations.

01

Federal agencies

EO 14412's 2030/2031 deadlines scope to high value assets and FIPS-199 high-impact systems — National Security Systems are excluded and run on the separate CNSA 2.0 track instead. M-26-15 adds the near-term deliverable: a PQC Migration Plan due ~October 22, 2026, with crypto-agility explicitly required.

02

Contractors & federal-facing ISVs

Nothing binds you yet — but EO Sec. 6(c) orders a proposed FAR rule by December 19, 2026 that would require covered contractors to meet NIST FIPS, including PQC algorithms, by December 31, 2030. Notice-and-comment still lies ahead. The smart move is to get ahead of the proposed FAR rule with an inventory now, not to wait for the final text.

03

Everyone already filing under M-23-02

The annual CRQC-vulnerable inventory (OMB M-23-02, Nov 2022) continues until 2035 — CyberScope submission to ONCD and CISA, nine data elements per system. M-26-15 functionally supersedes M-23-02 without formally rescinding it — the annual inventory obligation carries forward, with the migration-plan regime layered on top.

The nine M-23-02 data elements, per system

  1. FISMA system identifier
  2. FIPS 199 categorization
  3. HVA identifier, if applicable
  4. Each actively-used vulnerable crypto system: algorithm, the service it provides (key creation/exchange, encrypted connections, or digital signature creation/validation), and key or module length
  5. COTS / GOTS / Other, with vendor or developer name
  6. Operating system with major.minor version
  7. Hosting: agency on-premise, commercial CSP (named), government CSP (named), or hybrid
  8. Data lifecycle: records-management category and time-to-live
  9. Additional notes

System-owner names are explicitly excluded. In-scope algorithms: ECDH, MQV, ECDSA, Diffie-Hellman, RSA — with M-26-15 adding RSA key establishment, DSA, and other non-PQC asymmetric algorithms.

The CBOM angle

By March 19, 2027, the government defines what a CBOM must contain.

Sec. 5(d) makes the CBOM official

EO 14412 directs CISA-led, NIST-coordinated guidance on the minimum elements of a cryptographic bill of materials, due March 19, 2027. A CBOM stops being a nice-to-have and becomes a defined federal artifact.

CipherM CBOMs are built to absorb the guidance

CipherM already emits CycloneDX 1.6 CBOMs with a loose, namespaced extension model — designed so that when the minimum-elements guidance drops, conforming is a mapping exercise we ship the same week, not a re-architecture.

M-26-15 endorses a central CBOM and demands crypto-agility

The memo explicitly endorses a central CBOM and requires crypto-agility in Phases 3–4 (Appendix A, sec. 5). CipherM's agility score gives you a defensible measure of that posture, per system, from your real code and configs.

cipherm-inventory maps scans to submissions

Our export tooling turns scan results into the artifacts the obligations actually ask for: the M-23-02 nine-element inventory rows, migration-plan inputs for M-26-15, and the CBOM itself — evidence you can hand to OMB, ONCD, or a prime.

The migration plan is due in months. Start with the inventory.

A fixed-scope, two-week Rapid Assessment: we scan your code, configs, and live TLS, review by hand, and hand you a CycloneDX 1.6 CBOM, an agility score, and inventory exports mapped to the M-23-02 elements — the raw material for an M-26-15 plan or a get-ahead posture on the proposed FAR rule.

Honest scope

CipherM produces evidence: cryptographic inventories, CBOMs, agility scores, and submission-ready artifacts. We do not perform CMVP validation, we do not remediate or switch your algorithms, and a scan is not a certification or legal advice. Every deadline on this page cites the primary sources below — verify against them before you plan, and expect the OMB implementing guidance (~September 20, 2026) to add detail.

Sources
  • Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks” (June 22, 2026), Federal Register 91 FR 38483.
  • OMB Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography” (June 24, 2026).
  • OMB Memorandum M-23-02, “Migrating to Post-Quantum Cryptography” (November 18, 2022).
  • NIST Cryptographic Module Validation Program (CMVP) FIPS 140-2 to 140-3 transition pages; certificate counts as of July 26, 2026.
  • NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) FAQ — applies to National Security Systems under CNSSP-15.