GSA Announces Roadmap to Quantum-Resistant Technology

0
2

Key Takeaways

  • The General Services Administration (GSA) is leading the federal government’s shift to post‑quantum cryptography (PQC) by modernizing identity, credential, and access‑management (FICAM) systems and testing quantum‑resistant solutions for physical building access.
  • GSA’s efforts emphasize “crypto agility,” enabling agencies to swap encryption methods as standards evolve without disrupting daily operations.
  • The Physical Access Control System (PACS) lab is expanding its testing regime to evaluate quantum‑resistant algorithms for employee badges, visitor passes, and building access controls, ensuring only approved products appear on the GSA Approved Products List (APL).
  • An interagency working group, launched on August 12 2026 with 40 participants from 17 agencies, will meet bi‑weekly to address identity‑and‑access‑management challenges in a post‑quantum environment, including non‑human identities and automation.
  • GSA will host the 2026 Post‑Quantum Cryptography Summit, a hybrid event that brings federal leaders, industry partners, and experts together to chart the roadmap for quantum‑resistant security across the government.
  • These coordinated actions support OMB Memorandum M‑26‑15’s directive for a faster, government‑wide migration to quantum‑resistant cryptography, protecting both digital systems and physical facilities against future quantum threats.

Overview of GSA’s Expanding Role in Post‑Quantum Security
The General Services Administration (GSA) has been entrusted with pivotal responsibilities for safeguarding federal identity and building‑access systems as the United States advances its updated Cyber Strategy and the new Executive Order on ushering in the next frontier of quantum innovation. Under OMB Memorandum M‑26‑15, GSA must help the government migrate to post‑quantum cryptography (PQC) while also taking on new interagency coordination duties. This positions GSA at the forefront of a critical cybersecurity initiative aimed at thwarting the future capability of quantum computers to break today’s encryption. By updating the Federal Identity, Credential, and Access Management (FICAM) architecture, testing quantum‑resistant physical‑access solutions, and fostering cross‑agency collaboration, GSA seeks to ensure a smooth, secure transition that protects both digital information and physical facilities.


Understanding the Quantum Challenge
Current digital security relies on mathematical problems—such as factoring large integers or computing discrete logarithms—that are infeasible for classical computers to solve within a reasonable time frame. Quantum computers, however, exploit quantum superposition and entanglement to perform certain calculations exponentially faster, potentially rendering widely used algorithms like RSA and ECC obsolete. In practical terms, if today’s encryption were a lock that would take thousands of years to pick with conventional tools, a sufficiently powerful quantum computer could open that same lock in hours or days. This looming vulnerability creates an urgent need to develop and deploy quantum‑resistant “locks” before quantum computers become broadly available, especially for systems that protect federal employee identities, building access, and sensitive government data.


Modernizing the FICAM Architecture
The Federal Identity, Credential, and Access Management (FICAM) architecture forms the backbone of all federal identity systems, governing how credentials are issued, authenticated, and managed across agencies. GSA is updating this framework to support quantum‑resistant algorithms while preserving compatibility with legacy systems. A central tenet of this modernization is “crypto agility”—the ability to switch between different encryption methods swiftly as threats evolve or new standards emerge. By building flexibility into the FICAM foundation, agencies can adopt post‑quantum solutions incrementally, avoiding costly rip‑and‑replace cycles and maintaining uninterrupted service for employees and the public.


Testing Quantum‑Resistant Building Access Systems
Physical security is just as vital as digital security, and GSA’s Federal Information Processing Standards (FIPS) 201 Evaluation Program, carried out through the Physical Access Control System (PACS) lab, is expanding its testing capabilities to evaluate quantum‑resistant solutions for federal buildings. The lab now assesses employee badges, visitor passes, and building access controls for resistance to future quantum attacks. To guarantee security and interoperability, the Federal Acquisition Regulation (FAR) mandates that federal agencies procure PACS equipment only from GSA’s Approved Products List (APL). GSA’s PACS lab testing determines which products qualify for the APL, making its role essential for governmentwide security. The lab is actively incorporating quantum‑resistant algorithms into its test procedures so that future APL‑listed products will remain secure against emerging quantum threats.


Looking Ahead: Coordination and Funding
Transitioning to quantum‑resistant security is a multiyear endeavor that demands careful coordination across government, sustained investment, and a clear funding strategy. GSA’s early actions—updating FICAM, enhancing PACS testing, and establishing governance structures—help mitigate risks and support an orderly migration that protects both digital systems and physical facilities. By leading this transition, GSA ensures that federal employees can continue to work securely while safeguarding sensitive information and infrastructure against the advent of practical quantum computers. The agency’s proactive stance also provides a model for other sectors seeking to future‑proof their identity and access‑management ecosystems.


Interagency Working Group on FICAM Modernization
To further accelerate its efforts, OMB Memorandum M‑26‑15 directed GSA to establish an interagency working group focused on FICAM modernization in the post‑quantum context. The group convened for the first time on August 12 2026, bringing together 40 representatives from 17 federal agencies. Its mandate includes addressing non‑human identities, automation, and other modern identity features that will arise in a PQC environment. The working group has committed to meeting bi‑weekly, fostering continuous dialogue, sharing best practices, and aligning agency timelines for adopting quantum‑resistant technologies. This collaborative forum is intended to break down silos, ensure consistent standards, and expedite the governmentwide shift to stronger cryptographic protections.


2026 Post‑Quantum Cryptography Summit
In addition to the working group, GSA will host the 2026 Post‑Quantum Cryptography Summit—a hybrid event that will gather federal leaders, industry partners, subject‑matter experts, and academic researchers. The summit aims to chart a clear path toward quantum‑resistant cryptography by showcasing the latest research, discussing implementation challenges, and identifying opportunities for public‑private collaboration. Sessions will cover topics such as algorithm selection, migration strategies, testing protocols, and policy considerations. By providing a neutral platform for knowledge exchange, the summit will help align disparate efforts across the government and accelerate the adoption of robust, future‑proof security measures.


Conclusion and Call to Action
Through a combination of architectural modernization, rigorous physical‑access testing, interagency coordination, and high‑visibility events like the Post‑Quantum Cryptography Summit, GSA is positioning itself as the linchpin of the federal government’s preparation for the quantum era. The actions outlined above not only fulfill the mandates of OMB Memorandum M‑26‑15 and the Executive Order on quantum innovation but also lay a resilient foundation for protecting federal identities, building access, and critical information assets. Agencies are encouraged to engage actively with GSA’s initiatives, leverage the evolving APL, participate in the working group, and contribute insights at the upcoming summit to ensure a unified, secure transition to post‑quantum cryptography.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here