Securing the Nation Against Advanced Cryptographic Attacks
Section by Section
What each section does, and how they differ.
Addresses the threat of large-scale quantum computers to widely used cryptographic systems; establishes policy to transition federal information systems to NIST-approved post-quantum cryptography standards and assist critical infrastructure with their transitions.
Defines key terms including agency, critical infrastructure, high impact systems, high value assets, post-quantum cryptography, PQC migration lead, and cryptographic terms required for implementing the order.
Directs OMB Director and National Cyber Director to lead strategic coordination and oversight of national PQC migration policy; directs NIST and CISA to provide agencies with ongoing technical guidance and best practices.
Directs each agency to identify its PQC migration lead within 30 days; directs OMB to issue guidance requiring agencies to transition high-value assets and high-impact systems to PQC by December 31, 2030 (key establishment) and 2031 (digital signatures).
Directs Sector Risk Management Agencies to assist critical infrastructure owners with PQC migration; directs State Department to engage foreign governments on PQC adoption; requires NSA reporting on National Security Systems PQC status.
Directs OMB, Defense, NASA, and GSA to coordinate cost-saving opportunities in PQC migration; directs NIST to accelerate cryptographic module validation processes; directs FAR Council to amend acquisition regulations to require PQC compliance.
Standard boilerplate: preserves existing agency authority, conditions the order on appropriations, and creates no enforceable private rights.