Post -quantum cryptography (PQC) has become a central focus of US national security, as President Donald Trump signed Executive Order 14409, “Securing the Nation Against Advanced Cryptographic Attacks,” on June 22 , 2026. The order mandates the entire federal government to transition to post-quantum cryptography algorithms by 2030–2031 , addressing the growing threat of quantum computers. It is one of the most ambitious cybersecurity initiatives in recent years, with immediate implications for both the public and private sectors worldwide.

The central issue that post- quantum cryptography is called upon to address is the strategy known as “harvest now, decrypt later” : malicious actors — mainly state actors such as the Chinese Volt Typhoon group — are already extracting encrypted data from critical infrastructure, storing it, and planning to decrypt it once quantum computers become operational. According to CISA estimates, terabytes of encrypted data were stolen from energy, water, and healthcare sectors in 2025 alone . The NSA issued a special warning in March 2026 , calling on agencies to immediately begin the transition to PQC .
See also: MITRE publishes Post-Quantum Cryptography roadmap
The scientific community estimates that the US — and rivals like China — will be able to develop large-scale quantum computers between 2028 and 2030, capable of breaking current public-key algorithms such as RSA-2048 and ECC (Elliptic Curve Cryptography). Dr. Lidar, a leading quantum computing researcher, emphasizes that “quantum computers perform multiple calculations simultaneously, making them uniquely capable of breaking existing encryption.”
Post-Quantum Cryptography: What Executive Order 14409 Provides
The order directs OMB, NIST, NSA, DHS , and CISA to jointly develop and oversee comprehensive technical guidance for federal agencies’ transition to PQC. Agencies are required to list their “high-value assets” and “high-impact systems” and migrate them to post-quantum cryptography for key establishment by December 31, 2030 , and for digital signatures by December 31, 2031.Each agency will also be required to designate a PQCmigration lead.
See also: Trump Mobile T1 is supposedly made in America

The Department of Commerce will manage a pilot program through the end of 2027 , which will serve as a model for successful transition for the remaining services. The State Department is committed to encouraging and supporting critical infrastructure operators and foreign governments in their own transition to PQC . In parallel, the Pentagon , NASA , and the General Services Administration have been mandated to identify cost-saving opportunities during the transition process. Federal contractors will also be required to comply with NIST standards for PQC algorithms by the end of 2030 .
Companies like Google, Dell , and HP have already taken significant steps: Google announced PQC in TLS 1.3 by 2025.However, the majority of organizations — public and private — are still in the early stages of evaluating their cryptographic infrastructure.
Garfield Jones, EVP Strategy and Research at QuSecure, warns: “This executive order sends a clear message to every organization that works with the federal government: the clock is ticking. The 2030 for key establishment is a tangible compliance deadline, and the gap between where most organizations are today and where they need to be is enormous. Organizations that have not initiated a cryptographic inventory are already falling behind.” Michael Kratsios of the White House OSTP adds: “This order ensures that American cybersecurity keeps pace with emerging technology and recognizes the urgent need to address quantum threats.”
See also: BYD threatens to sue Trump administration over Pentagon military company list

The order is also linked to a parallel executive order (EO 14411) to develop a U.S. quantum computer for scientific research by 2028.According to SecurityWeek, the order is a preventive national defense measure — not a response to an active quantum breach — but delay equals weakness.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
