clAIrtybeta
    DashboardDocumentsSearch
    Dashboard/Documents/Executive Orders/Executive Order 14412 of June 22, 2026 Securing the Nation Against Advanced Cryptographic Attacks
    Executive Order

    Executive Order 14412 of June 22, 2026 Securing the Nation Against Advanced Cryptographic Attacks

    ActiveExecutive Orders
    Published
    June 22, 2026
    Lineage
    —
    Ingested
    June 29, 2026

    Summary

    Executive Order 14412, issued by the President on June 22, 2026, directs a national transition to Post-Quantum Cryptography (PQC) to secure the nation against advanced cryptographic attacks, especially from quantum computers. It requires Federal agencies to migrate high-value assets and high-impact systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. The order also mandates the Federal Acquisition Regulatory Council to amend the FAR to require covered contractors to comply with NIST's PQC-compliant FIPS by December 31, 2030.

    Key provisions

    Executive Order 14412, issued on June 22, 2026, establishes a comprehensive strategy for the United States to transition its Federal information systems and assist critical infrastructure in adopting Post-Quantum Cryptography (PQC). This is in response to the emerging threat posed by large-scale quantum computers to existing cryptographic security systems.

    Policy and Background

    • The Executive Order establishes a national policy to safeguard national security and maintain technological leadership by transitioning Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography (PQC).
    • It acknowledges the significant threat posed by large-scale quantum computers, especially in adversarial hands, to current cryptographic systems, and the risk of adversaries collecting data now for future decryption.
    • The policy also directs assistance to critical infrastructure owners and operators with their PQC transitions.

    Key Definitions

    • The Order defines critical terms to ensure consistent implementation, including "agency," "critical infrastructure," "information systems," and "National Security Systems."
    • "High impact system" refers to an information system in which at least one security objective (confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of "high."
    • "High value asset" (HVA) means Federal information or a Federal information system designated as such under OMB Memorandum M–19–03 or any successor document.
    • A "PQC migration lead" is an agency employee reporting to the agency's chief information officer, responsible for overseeing agency-wide cryptographic inventory management, developing a prioritized PQC migration plan, and coordinating cross-agency PQC efforts.

    PQC Transition Coordination and Acceleration

    • Coordination: The Director of OMB and the National Cyber Director are tasked with leading the strategic coordination and oversight of the national PQC migration policy. NIST, in consultation with the NSA and CISA, will provide ongoing comprehensive technical guidance on PQC implementation, including best practices and risk management strategies.
    • Compliance Requirement (Agency PQC Lead): Within 30 days of June 22, 2026, each agency head must identify and provide the name and contact details of their PQC migration lead to the Director of OMB and the National Cyber Director.
    • Compliance Requirement (Agency Transition Plan): Within 90 days of June 22, 2026, the Director of OMB must issue guidance requiring each agency to:
      • Review their inventory of HVAs and high impact systems (excluding National Security Systems).
      • Transition all HVAs and high impact systems to PQC for key establishment by December 31, 2030.
      • Transition all HVAs and high impact systems to PQC for digital signatures by December 31, 2031.
      • Develop and submit a plan to the Director of OMB and the National Cyber Director to accomplish these directives.
    • NIST Pilot Project: Within 180 days of June 22, 2026, NIST must initiate a pilot project for PQC migration on an appropriate subset of its information systems, to be completed no later than December 31, 2027.

    Leadership and Reporting Requirements

    • Critical Infrastructure Assistance: All agencies serving as Sector Risk Management Agencies (SRMAs) must work with CISA to assist critical infrastructure owners and operators in developing their PQC migration plans.
    • International Engagement: The Secretary of State, in coordination with other specified agencies, will engage foreign governments and industry groups in key countries to encourage their transition to NIST-standardized PQC algorithms.
    • Compliance Requirement (National Security Systems Report): Within 180 days of June 22, 2026, and annually thereafter until PQC migration is complete, the Director of the NSA must submit a report to the President on the status of PQC migration for agencies that own or operate National Security Systems.
    • Cryptographic Bill of Materials (CBOM): Within 270 days of June 22, 2026, the Secretary of Homeland Security, through the Director of CISA, and in coordination with the Director of NIST, must release public guidance describing the minimum elements for a cryptographic bill of materials to enable automated assessment of cryptographic assets.

    Procurement and Contractor Compliance

    Ask this document

    Enter

    Knowledge graph

    This document
    Executive Orders

    Belongs to

    Executive Orders
    View original PDF →

    Full document