U.S. Government and Microsoft Speed Up Quantum‑Safe Cryptography Transition
An executive order signed by the U.S. administration on June 22, 2026 (EO 14409) mandates that all federal agencies migrate high‑value and high‑impact systems to NIST‑approved post‑quantum cryptography (PQC) by Dec 31 2030, and digital signatures by Dec 31 2031. Agencies must name a PQC migration lead within 30 days and conduct a comprehensive cryptographic review within 90 days. The order also requires contractors in the federal supply chain to meet the same standards, with the FAR Council given 180 days to draft the necessary regulations.
Microsoft’s security blog reports that the company is advancing its Quantum Safe Program, moving the target for transitioning its products and services to PQC forward to 2029. The acceleration aligns with recent U.S. and French guidance calling for early adoption in high‑risk systems and focuses on three priorities: upgrading network cryptography (e.g., TLS 1.3), building crypto‑agility for data at rest, and modernizing cryptographic trust chains such as code signing and certificates. Both the government mandate and Microsoft’s roadmap reflect a broader shift toward earlier preparedness for quantum‑computing threats.
The combined efforts signal that organizations—especially those supplying the federal government—must now prioritize PQC readiness, potentially influencing broader sectors like energy, finance, and health as industry standards evolve.