OMB Memo Directs Federal Agencies to Submit Post-Quantum Cryptography Migration Plans Within 120 Days as NSA and CISA Lead Transition
OMB issued Memorandum M-26-15 on June 24, directing federal civilian agencies to submit post-quantum cryptography migration plans within 120 days to OMB and the Office of the National Cyber Director
M-26-15 converts the June 22 executive order into operational requirement, pushing accountability to agency front offices rather than confining it to CIO and CISO chains. The five-phase architecture supplies what the EO lacked: agency migration leads, December 2030 and December 2031 milestones for key establishment and digital signature migration on high-priority systems, and a GSA-led FICAM working group. Whether agencies can produce credible October plans turns on NSM-10 cryptographic inventory work since 2022. No public indicator supports that baseline, and sourcing is a single federal IT trade-press cluster drawing from the same memo with no IG, GAO, or congressional corroboration. Moderate confidence reflects direct memo access, absent any readiness signal or appropriations commitment. The 2030 and 2031 deadlines may function as procurement forcing functions, with OMB accepting phased partial compliance as a baseline for appropriations requests rather than enforcing them as hard thresholds.
4 sources
- M-26-15: Execution of the Migration to Post-Quantum Cryptography -
Office of Management and Budget - OMB memo on post-quantum cryptography directs agencies to develop transition plans, achieve certain milestones -
Inside Cybersecurity - Agencies have four months to finalize quantum-ready migration plans -
FedScoop - OMB issues instructions for agency migration to quantum-proof encryption -
Nextgov/FCW