OMB’s New PQC Memo: What Federal Agencies Need to Do Now

OMB’s New PQC Memo: What Federal Agencies Need to Do Now

With every new advancement in technology comes both opportunity … and risk. A prime example dominating the headlines of late is the impending rise of cryptographically relevant quantum computers (CRQCs), which have the potential to revolutionize the fields of defense, science, medicine, financial services, and so many others while, at the same time, ushering in an “existential threat” to the systems, missions, and processes that run the modern world. 

Employing the complex principles of quantum physics, CRQCs are immensely powerful and extremely agile, capable of rapidly tearing through the encryption standards and digital signature algorithms of any present-day device. Which means that traditional security models—often based on asymmetric cryptographic methodologies such as prime number factorization—can’t keep pace and, in many cases, will be rendered obsolete, leaving public-key infrastructure (PKI) exposed and vulnerable. 

While CRQCs have yet to enter a phase of widespread adoption, the threat is still very much real and immediate. Cyber criminals, including nation-state adversaries, are actively leveraging a tactic called “Harvest Now, Decrypt Later,” in which they steal encrypted data today with the intention of holding on to it until quantum capabilities have evolved sufficiently enough to decode it, thereby making modern security measures, in essence, a “time-delayed vulnerability.” 

In other words, the moment to prepare is now.

Executive Direction

Earlier this summer, in an effort to help mitigate the looming threat posed by CRQCs, President Donald Trump signed two Executive Orders aimed at both accelerating quantum development and preparing the government’s technical environments for its imminent arrival. Key to those efforts is a mandated migration to post-quantum cryptography (PQC) by December 31, 2031, with assorted benchmarks and adoption phases carefully regimented for the months and years leading up to it, in what some are now calling a “high-stakes five-year sprint.” 

The Pathway Forward

The first major milestone is set for this coming October, when federal agencies must submit a PQC migration plan to the Office of Management and Budget (OMB), per OMB Memorandum M-26-15. Central to any such roadmap will be a comprehensive inventory of an agency’s current cryptographic implementations that might be susceptible to quantum-enabled attacks. This includes an accounting of “which algorithms are in use, which systems depend on vulnerable cryptography, what data requires long-term confidentiality, and which business processes would be disrupted by migration.” As you can see, the inventory process is an extensive one, and yet it is a critical piece of the whole: Intelligent, real-time visibility will be the foundation on which any successful PQC migration is built. 

Other transition deadlines are also rapidly approaching. The discovery phase—which calls for thorough inventorying, risk assessment, and governance optimization—runs from 2026 to 2027. Pilots and early migration are scheduled for 2027-2028. The following two years, 2028 through 2030, are allocated to the prioritized migration of key establishment for high-value assets and high-impact systems. By 2031, signature migration for those same priority systems is required, with full migration of any remaining systems expected to be completed within four years, by 2035. All in, it’s a tight schedule that leaves little time to waste. 

Don’t Go It Alone: How Sterling Can Help

For those agencies looking to get ahead of the mandatory PQC migration, Federal Year End provides the perfect opportunity to direct available funding toward cybersecurity, observability, asset management, and other infrastructure modernization initiatives. Agencies don’t have to take this journey alone, either. Sterling is here to assist, with a partner ecosystem made up of leading innovators in PQC—from Eracent, Gigamon, and Splunk to Fortinet, Eclypses, and IonQ (among others). Together with these partners, we act as a trusted resource that pairs best-in-class technology solutions with deep, hands-on expertise at every stage of the process. Our elite team will help you assess your systems, detect vulnerabilities, and build out a comprehensive plan to support your PQC modernization efforts—all the way from discovery to full deployment. 

More specifically, our approach features three distinct stages that map directly to the prescribed federal timeline: 

Discover, Inventory, Analyze 

Our team identifies every cryptographic asset in your environment while pinpointing exactly where encryption falls short of the NIST FIPS 203, 204, and 205 standards, thus providing you a clear, prioritized picture of your risk before you spend a single dollar on remediation. 

Solve, Roadmap, Execute 

Our team identifies every cryptographic asset in your environment while pinpointing exactly where encryption falls short of the NIST FIPS 203, 204, and 205 standards, thus providing you a clear, prioritized picture of your risk before you spend a single dollar on remediation. 

Monitor, Comply, Modernize 

Post-quantum migration doesn’t end at deployment. After implementation, we’ll help you track your ongoing progress with automated compliance reporting, manage the lifecycle of PQC hardware and software as it evolves, and fold your new quantum-resilience efforts into your agency’s broader Zero Trust strategy. 

In the end, like any innovation, quantum computing presents both challenges and opportunity. Stay ahead of your compliance obligations and fortify your agency for the future with the help of Sterling: your trusted technology partner for PQC, here to support you at every step of your modernization journey. Begin today by booking a complimentary readiness session with one of our PQC experts here

Share the Post: