Key Takeaways
- The Trump administration’s June 2024 executive orders set 2030‑2031 deadlines for moving high‑value federal systems to post‑quantum cryptography (PQC).
- The General Services Administration (GSA) is modernizing the Federal Identity, Credential and Access Management (FICAM) framework, emphasizing crypto‑agility and expanding its FIPS 201 Evaluation Lab to test quantum‑resistant access‑control products.
- An interagency working group on FICAM meets bi‑weekly to align identity‑management practices across 17 agencies.
- GSA will host a hybrid 2026 Post‑Quantum Cryptography Summit on September 16 to share progress and chart the migration path.
- The Treasury Department launched a public‑private Quantum‑Readiness Task Force focused on sector alignment, third‑party/vendor readiness, and digital‑asset risks.
- OMB guidance requires agencies to submit a PQC Migration Plan within 120 days (≈30 days from the memo) and to begin pilots and early migrations between 2027‑2028.
- Successful transition hinges on crypto‑agility, coordinated planning, steady funding, and collaboration across government, industry, and standards bodies.
Introduction: Federal Momentum on Quantum‑Ready Security
Although the Trump administration still has four months to finalize the updated National Quantum Strategy, agencies are already acting on the June 22 executive orders that directed a shift to post‑quantum cryptography (PQC). The General Services Administration (GSA) and the Treasury Department have announced concrete steps to prepare federal buildings, financial systems, and identity‑management infrastructures for the era when quantum computers could break today’s encryption. These early moves aim to mitigate risk, ensure a smooth migration, and protect both digital and physical assets against emerging quantum threats.
GSA Updates FICAM for Crypto‑Agility
GSA is revising the Federal Identity, Credential and Access Management (FICAM) architecture to support quantum‑resistant algorithms while preserving compatibility with legacy systems. According to Dan Pomeroy, deputy associate administrator for the Office of Technology Policy, the redesign emphasizes “crypto agility”—the ability to swap encryption methods swiftly as standards evolve or new threats appear. This flexibility is essential because quantum‑resistant technology will continue to mature over the next decade, and agencies must be able to adopt newer algorithms without overhauling entire identity ecosystems.
Interagency Working Group Drives FICAM Modernization
To coordinate the FICAM overhaul, GSA convened the first meeting of an interagency working group on August 12, bringing together roughly 40 representatives from 17 federal agencies. Pomeroy noted that the group plans to meet bi‑weekly to address non‑human identities, automation, and other modern identity features within a PQC environment. By sharing best practices and aligning requirements early, the working group seeks to avoid duplicated effort and ensure that identity‑management solutions across government remain both secure and operable as quantum‑safe standards are adopted.
Expanding the FIPS 201 Evaluation Lab for Quantum‑Resistant Testing
Beyond identity management, GSA is upgrading its Federal Information Processing Standards (FIPS) 201 Evaluation Program under the Physical Access Control System (PACS) lab. The enhanced lab will evaluate quantum‑resistant technologies for employee badges, visitor passes, and building access controls. Pomeroy explained that the upgraded infrastructure represents an entirely new capability, requiring extensive research and development to test PQC algorithms on physical tokens and readers. The lab’s work will also ensure that only PQC‑resistant products appear on GSA’s approved products list for physical access systems, helping agencies procure secure hardware today.
GSA’s 2026 Post‑Quantum Cryptography Summit
All of these efforts will be showcased at GSA’s 2026 Post‑Quantum Cryptography Summit, scheduled as a hybrid event on September 16. The summit will convene federal leaders, industry partners, and subject‑matter experts to discuss progress, share lessons learned, and chart the roadmap toward widespread quantum‑resistant cryptography. By providing a forum for collaboration, GSA aims to accelerate the adoption of PQC across civilian agencies and to align federal priorities with industry innovation cycles.
Treasury Launches the Quantum‑Readiness Task Force
Simultaneously, Treasury Secretary Scott Bessent announced the creation of the Quantum‑Readiness Task Force, a public‑private initiative designed to hasten the financial sector’s transition to quantum‑safe technology. Treasury Assistant Secretary for Financial Institutions Luke Pettit said the task force will ensure the shift is coordinated, risk‑based, and operationally resilient. By uniting government and industry, the initiative aims to strengthen trust in the U.S. financial system while bolstering economic and national security against future quantum‑enabled attacks.
Three Workstreams Structure the Treasury Task Force
The task force operates through three focused workstreams. The first, Sector Alignment and PQC Transition, concentrates on identifying critical financial systems, establishing migration timelines, and promoting interoperability among market participants. The second, Third‑Party and Vendor Readiness, addresses the supply chain by evaluating whether vendors and service providers can deliver quantum‑resistant products and services. The third, Digital Assets and Emerging Technology Risk, examines threats to cryptocurrencies, tokenized assets, and other novel financial instruments that may be especially vulnerable to quantum attacks. Together, these streams aim to create a comprehensive, risk‑based approach to quantum readiness across the financial ecosystem.
OMB Guidance Sets Concrete Deadlines and Planning Steps
Both agency initiatives flow from the June 22 executive orders and the subsequent Office of Management and Budget (OMB) guidance. The orders require agencies to migrate “high value assets” and “high impact systems” to PQC keys by December 31, 2030, and to adopt PQC digital signatures by the end of 2031. OMB’s memo directs agencies to submit a PQC Migration Plan within 120 days (roughly 30 days from the memo’s issuance). The plan must detail cryptographic system inventories, migration strategies, awareness‑training programs, and other foundational steps for a phased approach.
Phase Two: Pilots and Early Migrations (2027‑2028)
OMB’s guidance further outlines a two‑phase timeline. Between 2027 and 2028, agencies should focus on pilot projects, execute early migrations of prioritized systems, and refine their migration plans based on lessons learned. This phase is intended to uncover practical challenges—such as performance impacts, integration complexities, and workforce skill gaps—before the broader rollout begins. By iterating on pilots, the federal government hopes to de‑risk the transition and ensure that the eventual migration to PQC is both secure and minimally disruptive to mission operations.
Conclusion: A Coordinated, Multiyear Effort Toward Quantum Safety
The actions taken by GSA and Treasury illustrate that federal agencies are not waiting for a finalized National Quantum Strategy to begin preparing for quantum‑era threats. Through crypto‑agile identity upgrades, expanded testing labs, interagency collaboration, and a dedicated financial‑sector task force, the government is laying the groundwork for a systematic migration to post‑quantum cryptography. Success will depend on sustained funding, clear timelines, rigorous testing, and ongoing partnership with industry and standards bodies. If these elements remain aligned, the United States can safeguard its critical data, financial systems, and physical facilities against the disruptive potential of quantum computing well before the technology becomes widely available.

