Executive Order

Home > Executive Order


Securing the Nation Against Advanced Cryptographic Attacks

AI Summary: This regulation establishes a national policy to transition Federal information systems to Post-Quantum Cryptography (PQC) standards approved by the National Institute of Standards and Technology (NIST) to protect against advanced cryptographic attacks, particularly from large-scale quantum computers. The policy aims to safeguard national security, critical infrastructure, and the digital economy by strengthening cryptographic protections for sensitive data. It defines key terms such as "agency," "critical infrastructure," "high impact system," "high value asset" (HVA), "information systems," "National Security Systems," "post-quantum cryptography" (PQC), and roles like "PQC migration lead." The regulation mandates agencies to identify PQC migration leads within 30 days, and within 90 days, the Office of Management and Budget (OMB) will issue guidance requiring agencies to review their HVAs and high impact systems, transitioning them to use PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031, with a requirement to submit migration plans. NIST will initiate a pilot PQC migration project within 180 days, and Sector Risk Management Agencies will assist critical infrastructure owners and operators with their PQC transition plans. The regulation also outlines efforts to encourage foreign governments and industry groups to adopt NIST-standardized PQC algorithms, requires reporting on PQC migration for National Security Systems, and directs the release of public guidance on the minimum elements for a cryptographic bill of materials. Furthermore, it addresses procurement by coordinating cost-saving opportunities, revising validation processes for cryptographic modules, and proposing amendments to the Federal Acquisition Regulation (FAR) to require covered contractors to comply with NIST FIPS incorporating PQC algorithms by December 31, 2030, and to implement vulnerability disclosure policies that include cryptographic vulnerabilities.