
The White House has dramatically accelerated the timeline for government agencies and critical infrastructure to adopt quantum-resistant encryption, issuing an executive order that moves the deadline forward by four to five years for the most sensitive systems.
The order, titled “Securing the Nation against Advanced Cryptographic Attacks,” requires computing systems classified as “high-value assets” and “high-impact systems” to transition to post-quantum cryptographic (PQC) key establishment schemes by December 31, 2030, and to quantum-safe digital signature schemes by December 31, 2031. The previous timeline, set by the National Security Agency in 2022, gave most organizations until 2035 to complete the transition.
The acceleration follows recent research indicating that the resources required to build a cryptographically relevant quantum computer are falling faster than previously estimated. Google and Cloudflare have already tightened their internal timelines to 2029.
“Ongoing cyber activity against our Nation also presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational,” the order states, referencing the “harvest now, decrypt later” threat model that has driven much of the urgency around PQC migration.
The order also establishes a government-wide transition coordination process led by the Office of Management and Budget and the National Cyber Director. Each federal agency must designate a point person responsible for reporting quantum transition progress. It directs NIST and CISA to issue guidance on cryptographic bills of materials (CBOMs), comprehensive lists of all cryptographic components in a system, and creates new procurement rules that may require covered contractors to meet the same deadlines.
The challenge is substantial. PQC algorithms are not drop-in replacements for RSA and elliptic-curve cryptography. Public key sizes for ML-KEM, one of the leading replacement standards, are roughly three times larger. The transition involves auditing every cryptographic component across thousands of systems, a process that experts warn will take years for large organizations.
Recent research underscores the urgency. In March, researchers demonstrated that breaking ECC-256, used to secure Bitcoin and Ethereum, could be done with approximately 30,000 physical qubits in 10 days. Separately, Google developed quantum circuits that could solve the elliptic-curve discrete logarithm problem using roughly 500,000 physical qubits, half the estimate published by the same team in June 2025.
Sources: White House drastically shortens deadline for dropping quantum-vulnerable crypto (Ars Technica, June 24, 2026)

