PQC · 2026-09-01

Why the PQC deadline matters for federal programs

Harvest-now-decrypt-later risk, CNSA 2.0 exclusive-use dates, and NSM-10's 2035 goal make crypto-agility a near-term authorization issue—not a distant R&D topic.

The deadline is not abstract

Post-quantum cryptography (PQC) is often framed as a research problem. For primes building technical volumes and for agencies holding long-lived sensitive data, it is an inventory and migration problem with calendar dates attached.

Adversaries can harvest encrypted traffic today and decrypt it later when a cryptographically relevant quantum computer arrives. That "harvest now, decrypt later" risk is why migration planning cannot wait until 2035.

What the timelines actually say

Several overlapping clocks matter:

  • NIST has published PQC standards (ML-KEM, ML-DSA, SLH-DSA) and is driving deprecation of quantum-vulnerable algorithms toward 2035, consistent with NSM-10.
  • CNSA 2.0 sets exclusive-use milestones for national security systems—software/firmware signing and many networking products by 2030, with broader exclusive-use targets through 2033.
  • The June 2026 executive order on advanced cryptographic attacks directs high-value and high-impact systems to PQC key establishment by 31 December 2030 and digital signatures by 31 December 2031.

Those are not marketing slogans. They are acquisition and authorization drivers.

What primes should put in the technical volume

A credible PQC paragraph is not a product logo. It is evidence that the team can:

  • Inventory public-key use (TLS, VPN, code signing, PKI, HSMs, application crypto)
  • Prefer crypto-agile designs that can swap algorithms without rewriting the system
  • Map migration work to authorization boundaries and FedRAMP/ATO evidence
  • Sequence high-impact systems first rather than promising a wholesale overnight cutover

How this shows up in our scopes

Legate does not sell a standalone "PQC product." We bring PQC readiness into the same work packages primes already buy from us: secure AI architecture for CUI, ATO/FedRAMP readiness, and network/zero-trust design. Crypto-agility belongs next to authorization and segmentation—not as a slide in the appendix.

If your solicitation asks for quantum-resistant roadmap language, we can help you write a scoped, honest approach and map it to labor categories within a few days of RFP release.

Related work package

Need this mapped into a scoped subcontract?

We usually price by work package after a short no-cost scoping call.

Experience described reflects work performed by Legate Solutions principals while employed by other organizations. It is provided to show individual qualifications and is not represented as corporate past performance of Legate Solutions LLC or as an endorsement by any agency named. Corporate past performance and references are available where applicable; where no relevant corporate record exists, Legate requests evaluation consistent with FAR 15.305(a)(2)(iv).