Trump Sets Deadlines for Quantum-Resistant Encryption

U.S. federal agencies must adopt post-quantum cryptography by 2030–2031.

Trump Sets Deadlines for Quantum-Resistant Encryption

The Trump administration has launched preparations for a transition to cryptography designed to withstand attacks from quantum computers. A new executive order requires federal agencies to implement quantum-resistant security measures. The deadline for deploying new cryptographic key exchange mechanisms is set for December 31, 2030, while digital signature systems must be upgraded by December 31, 2031.

The order, signed on June 22, applies to sensitive federal systems, government procurement processes, and efforts aimed at protecting critical infrastructure.

The move is driven by concerns over the rapid advancement of quantum computing. U.S. officials warn that some organizations may already be intercepting and storing encrypted data today in the hope of decrypting it in the future once quantum computers become powerful enough. Post-quantum cryptography is intended to protect information against attacks carried out by both classical and quantum computers.

The executive order emphasizes that the United States must strengthen the protection of sensitive data, critical infrastructure, and the digital economy.

Within 30 days, every federal agency must appoint an official responsible for overseeing the transition to the new cryptographic standards. This person will be tasked with inventorying existing security mechanisms, developing implementation plans, and coordinating migration efforts across departments.

Within 90 days, the Office of Management and Budget, working alongside the Cybersecurity and Infrastructure Security Agency (CISA) and the National Cyber Director, must publish detailed implementation guidance. Federal agencies will then assess their most critical systems and submit transition timelines for adopting the new standards. National security systems are excluded from this process.

A key role has also been assigned to the National Institute of Standards and Technology (NIST). Within 180 days, NIST must launch a pilot migration program for selected systems, with completion targeted for December 31, 2027. The results are expected to support broader adoption of post-quantum technologies ahead of the 2030 and 2031 deadlines.

The changes will also affect companies working with the federal government. The Federal Acquisition Regulatory Council has 180 days to draft new regulations requiring covered contractors to comply with NIST standards, including the use of post-quantum algorithms, by the end of 2030.

Critical infrastructure operators are also included in the initiative. Relevant federal agencies will work with CISA to develop migration strategies, while CISA and NIST must publish guidance within 270 days outlining minimum requirements for documenting cryptographic systems and technologies.

The administration also intends to promote the new standards internationally. The Secretary of State has been tasked with coordinating efforts to encourage foreign partners to adopt NIST’s post-quantum cryptographic standards.

National security systems will follow a separate implementation process. The Director of the National Security Agency (NSA) must submit a progress report to the President within 180 days of the order taking effect and continue providing annual updates thereafter.

Share