ARTICLE
·
August 15, 2026

What Is PQC? A Federal Contractor’s Guide to Post-Quantum Cryptography Compliance

Post-quantum cryptography (PQC) protects data against future quantum computers capable of breaking today's encryption. The recent Executive Order 14412 set 2030/2031 deadlines for federal systems, and the Pentagon wants to add PQC compliance to CMMC. Government contractors need to act now or risk losing opportunities.

The looming quantum computing threat has prompted federal mandates for the migration to post-quantum cryptography (PQC). While earlier PQC compliance frameworks and implementation timelines were ambiguous, the directives are now moving faster. Executive Order 14412 sets concrete deadlines for high-value federal systems, and federal contractors should expect that pressure to reach the supply chain soon.

The recent Executive Order 14412 sets clear deadlines for high-value federal systems and signals what’s to come in federal procurement. Even as the rules affecting the downstream supply chain ecosystem are pending, federal contractors should expect increasing PQC compliance pressure.

The potential timelines for the arrival of cryptographically relevant quantum computers have also accelerated in recent months. Long-value data such as government records is already vulnerable to “harvest now, decrypt later” attacks.

The convergence of all these forces makes it clear that federal contractors must act now. This guide explains what federal contractors need to know today about PQC.

What is PQC and why has it emerged as a requirement?

Security experts have long known that quantum computers would be capable of breaking today’s cryptographic systems. The encryption that digital communications and transactions have relied on for decades is based on complex mathematical problems. Classical computers would need potentially billions of years to solve these. A sufficiently capable quantum computer could reduce that to hours or less.

Nobody knows when “Q-Day” will arrive. Some industry projections place it as early as 2030. Recent research from Google and other scientists has lowered the estimated quantum resources needed to break widely used public-key cryptography, and progress is being made on other fronts, including hardware.

These developments further increase concerns that cryptographically relevant quantum computers could arrive sooner than expected. Google has accelerated its own PQC migration target. So have other major infrastructure providers, including Microsoft and Cloudflare.

Whenever the day arrives, the implications would be widespread. A range of systems relying on public-key cryptography could become vulnerable, including:

  • Encrypted connections: data transmitted through VPNs, TLS, email, and cloud traffic could be decrypted.
  • Authentication and verification: digital signatures and certificates that authenticate software, identities, and communications could be forged.
  • IT infrastructure: applications, web browsers, APIs, and cloud platforms could be compromised.
  • Embedded systems: IoT devices, sensors, and operational technology may be difficult, or impossible, to upgrade without significant disruption.

Despite the uncertainty around timing, adversaries are not waiting. National security authorities have warned that nation-state actors could collect encrypted data now to decrypt once quantum computing catches up. HNDL attacks put data that needs to stay confidential for years at immediate risk: 56% of respondents in an ISACA poll cited HNDL attacks as a concern.

PQC compliance, readiness, and “quantum-safe”: what’s the difference?

These terms are related but shouldn’t be used interchangeably. They represent different states:

  • PQC readiness describes your organization’s preparedness to migrate to PQC, a pre-migration phase that starts with understanding your cryptographic posture, prioritizing risks, and creating a migration plan.
  • Quantum-safe means your migration is complete, with quantum-resistant cryptography fully deployed and enforced, including the cryptographic agility to adapt as standards mature.
  • PQC compliance is its own category: checking the boxes a specific framework sets. As with security in general, you can be fully compliant but not fully protected.

The quantum-resistant algorithms and their implications

NIST’s release of three quantum-safe standards in August 2024 marked a shift from PQC research to implementation, based on three algorithm types:

  • FIPS 203 uses ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) as the primary standard for general encryption, letting two parties securely establish a shared key.
  • FIPS 204 uses ML-DSA (Module-Lattice-Based Digital Signature Algorithm) as the main standard for protecting digital signatures.
  • FIPS 205 uses SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) as a hash-based backup if ML-DSA becomes vulnerable.

In practice, FIPS 203 protects data confidentiality (including against HNDL attacks), while FIPS 204 and 205 support authenticity and integrity. A migration plan needs to address both functions long term. Note that a given mandate may not call for every standardized algorithm: CNSA 2.0, for instance, specifies ML-KEM and ML-DSA but doesn’t currently approve SLH-DSA.

What PQC compliance means for federal contractors today

As of August 2026, no framework broadly applicable to federal contractors mandates PQC outright yet. That doesn’t mean compliance and security teams can relax: provisions for quantum-safe solutions are already influencing procurement decisions.

Cybersecurity Maturity Model Certification (CMMC)

CMMC Level 2 is built on NIST SP 800-171, Revision 2, which includes FIPS-validated cryptography but doesn’t prescribe a PQC migration deadline or specific algorithms. However, a new U.S. Department of War PQC strategy published in June calls for adding PQC to CMMC requirements, with a December 31, 2031 deadline for DoW systems. CMMC’s third-party certification requirement is currently paused pending a Reform Task Force review, but the underlying NIST 800-171 obligation remains in force.

CNSA 2.0

CNSA 2.0 has more granular, concrete timetables for National Security Systems:

  • January 1, 2027: new NSS acquisitions must be CNSA 2.0 compliant
  • December 31, 2030: phase out equipment and services that can’t support PQC/CNSA
  • December 31, 2031: full use of CNSA 2.0 algorithms
  • 2030: software and firmware signing, traditional networking equipment
  • 2033: web browsers and servers, cloud services, operating systems, niche devices, large PKI, custom applications, legacy equipment

FedRAMP

FedRAMP generally requires cryptographic modules validated to FIPS 140 standards. A cloud service provider would need to implement FIPS 203 to 205 using FIPS 140-validated modules before deployment, a process that can take years. FedRAMP-authorized PQC won’t be widely available until validation catches up, though some providers, like Cloudflare with its recent FedRAMP High authorization, are already moving ahead.

What contractors need to do now

Waiting for mandates to finalize is not a viable strategy. Migration is a complex, multi-year effort involving multiple functions and systems, and many CISOs are already behind. The risks of delay range from competitive disadvantage to increased cost.

Regardless of framework, understanding your cryptographic posture is one of the critical first steps. You have to know your exposure before you can build a plan to mitigate it.

Get started with a simple tool

PQC posture assessment can feel like a heavy lift because cryptographic inventory platforms are typically built for enterprise environments, with pricing and complexity to match. Ciphersound offers a simple tool that compliance and security teams can use immediately, at no cost, without waiting for budget approval or a procurement cycle.

Written by the team behind Anvil Secure.
Wondering if this applies to you? Check a domain, free, no signup.
Check a domain