Two days ago, on June 22, U.S. Executive Order EO 14409 ("Securing the Nation Against Advanced Cryptographic Attacks") was signed, requiring federal agencies to migrate high-value/high-impact systems to QR key establishment by end of 2030 and QR digital signatures by end of 2031, plus requirements for contractors by 2030 and a CISA cryptographic-bill-of-materials standard. Its effect is to put a date on enforceable PQC migration obligations back on agencies and, for the first time, extended QR obligations to contractors.
This is certainly good, but some misleading interpretation is circulating about this EO. In particular, I don't like the narrative that this "tightens the Biden-era 2035 target".
Technically, this is true: Biden's EO 14144 referenced the 2035 target set in 2022 for QR migration. What the narrative leaves out is that, in June last year, Trump's cybersecurity EO 14306 amended the Obama/Biden-era EOs 13694 and 14144, and among other things rolled back several PQC requirements. After the amendment, the only PQC requirements left were two: a PQC product-category list plus a TLS 1.3 mandate for federal agencies.
So, the last EO actually was a 180-degree correction compared to the previous position of the current administration. Given the cost for such a maneuver in terms of political ego, I think we can interpret this as a strong urgency signal, that aligns with the current trends in the industry after the recent breakthroughs in quantum cryptanalysis and the constant improvements in quantum computing tech.
Time is ticking, folks!
#quantum #cryptography #pqc #quantumcomputing #cybersecurity #infosec #quantumresistant #quantumsafe #postquantum #trump #biden #obama








🐦🔥nemo™🐦⬛ 🇺🇦🍉
