IC Technology & Cyber — 2026-06-29

OMB Memo Directs Federal Agencies to Submit Post-Quantum Cryptography Migration Plans Within 120 Days as NSA and CISA Lead Transition

BLUFAgency capacity to produce credible migration plans by October hinges on four years of cryptographic inventory work under NSM-10 whose completeness remains unaudited.

OMB issued Memorandum M-26-15 on June 24, directing federal civilian agencies to submit post-quantum cryptography migration plans within 120 days to OMB and the Office of the National Cyber Director 12. The memo sets December 31, 2030 as the target for mitigating "as much quantum risk as feasible" and requires plans to prioritize high-value assets and high-impact systems, appoint an agency-level migration lead, and flag PQC-incapable systems for replacement or decommissioning 23. Five implementation phases run from 2026-2027 planning through full migration by 2035, with 2030 and 2031 deadlines for key establishment and digital signature migration on high-priority systems 23. GSA will stand up an interagency FICAM modernization working group within 60 days, while CISA and the Department of War will coordinate PQC migration for FedRAMP-authorized cloud providers 2.

Analysis
M-26-15 converts the June 22 executive order into operational requirement, pushing accountability to agency front offices rather than confining it to CIO and CISO chains. The five-phase architecture supplies what the EO lacked: agency migration leads, December 2030 and December 2031 milestones for key establishment and digital signature migration on high-priority systems, and a GSA-led FICAM working group. Whether agencies can produce credible October plans turns on NSM-10 cryptographic inventory work since 2022. No public indicator supports that baseline, and sourcing is a single federal IT trade-press cluster drawing from the same memo with no IG, GAO, or congressional corroboration. Moderate confidence reflects direct memo access, absent any readiness signal or appropriations commitment. The 2030 and 2031 deadlines may function as procurement forcing functions, with OMB accepting phased partial compliance as a baseline for appropriations requests rather than enforcing them as hard thresholds.
4 sources
  1. M-26-15: Execution of the Migration to Post-Quantum Cryptography - Office of Management and Budget
  2. OMB memo on post-quantum cryptography directs agencies to develop transition plans, achieve certain milestones - Inside Cybersecurity
  3. Agencies have four months to finalize quantum-ready migration plans - FedScoop
  4. OMB issues instructions for agency migration to quantum-proof encryption - Nextgov/FCW

View in full brief →

UNCLASSIFIED // OPEN SOURCE