Executive Order 14409 Locks In Federal PQC Deadlines: 2030 for Key Establishment, 2031 for Signatures
The June 22 order sets binding migration dates for high-value assets and high-impact systems, while leaving national security systems on a parallel track.

President Trump signed Executive Order 14409 on June 22, putting hard dates on the federal government's transition to post-quantum cryptography.
The order requires agencies to migrate key establishment for high-value assets and high-impact systems to NIST-approved post-quantum algorithms by December 31, 2030. Digital signatures get one extra year: December 31, 2031.
National security systems are carved out. They follow a separate track set by CNSS policy, not the civilian timeline in EO 14409.
The deadlines are not arbitrary. They reflect the "harvest now, decrypt later" threat model — adversaries intercepting encrypted traffic today and warehousing it for the day a cryptographically relevant quantum computer exists. RSA-2048 and the elliptic-curve key exchanges that underpin most federal TLS and VPN sessions would not survive that day. Data with a confidentiality lifetime extending past 2030 is already exposed in any practical sense.
The order builds on work already in motion. NIST finalized its first post-quantum standards in August 2024: FIPS 203 (ML-KEM, for key establishment), FIPS 204 (ML-DSA, for signatures), and FIPS 205 (SLH-DSA). Those are the algorithms agencies will be deploying to meet the 2030 and 2031 dates.
It also sits on top of statutory scaffolding. The Quantum Computing Cybersecurity Preparedness Act of 2022 (Public Law 117-260) directed OMB to prioritize federal migration and to maintain an inventory of vulnerable systems. National Security Memorandum 10, issued in May 2022, set the original 2035 government-wide target. EO 14409 pulls the most sensitive civilian systems forward by roughly four years.
Agencies will not be starting from zero. CISA, NSA and NIST published joint migration guidance in 2023, and OMB has been collecting cryptographic inventories under M-23-02. The harder work is contract language, hardware refresh cycles, and the long tail of embedded systems that quietly terminate TLS somewhere on a federal network.
What to watch next:
- OMB implementation guidance fleshing out the EO's reporting cadence and the definition of "high-impact system" for PQC purposes. Expect it within 180 days.
- Updated FAR and DFARS clauses requiring vendors to ship PQC-capable products. Without procurement leverage, the deadlines slip.
- CNSS movement on the national security systems track, which historically runs ahead of the civilian side but does so quietly.
For vendors selling into federal civilian agencies, the practical message is simpler. If your product terminates TLS, signs firmware, or issues certificates, you need a hybrid or pure-PQC roadmap that lands well before December 2030. Procurement officers will start asking in the next budget cycle.
The order is effective on signing. There is no comment period; this is an executive directive, not a rulemaking.



