White House Executive Order Sets 2030-2031 Deadlines for Post-Quantum Crypto Migration
The U.S. government has signed an executive order mandating federal agencies transition to post-quantum encryption by 2030 and authentication by 2031, accelerating the timeline for Q-Day preparedness.

On June 22, 2026, President Trump signed Executive Order 14412, requiring federal agencies to migrate their most sensitive systems to post-quantum cryptography by the end of 2030 for encryption and 2031 for authentication. The order targets High Value Assets (HVAs) and high-impact systems—the government's crown jewels—and also compels federal contractors to comply with NIST's post-quantum FIPS standards by 2030.
This is a significant acceleration. Cloudflare, which has been running post-quantum experiments since 2019, notes that the timeline for Q-Day—when quantum computers can break current public-key cryptography—has been pulled forward. In April 2026, Cloudflare moved its own full post-quantum security target to 2029, following breakthroughs from Google and Oratomic. The new EO updates earlier NIST guidance from 2024, which had suggested deprecating RSA and ECC by 2030 and disallowing them by 2035.
Two migrations, two deadlines
The EO splits the migration into two phases: post-quantum key establishment (encryption) by December 2030, and post-quantum digital signatures and certificates (authentication) by December 2031. This reflects the current state of the industry—post-quantum encryption is already widely deployed, with over two-thirds of browser traffic to Cloudflare's network using it. Post-quantum authentication, however, is still in early stages.
The encryption deadline addresses the immediate threat of harvest-now-decrypt-later attacks, where adversaries collect encrypted traffic today and decrypt it once quantum computers become powerful enough. The authentication deadline, set for 2031, signals that the U.S. government considers a cryptographically-relevant quantum computer (CRQC) a non-negligible possibility by that time.
Why authentication is harder
Post-quantum authentication faces several challenges that encryption does not. ML-DSA digital signatures are larger than their classical counterparts, which can impact performance in short-lived TLS connections. Cloudflare is working with Google Chrome on Merkle Tree Certificates to address this. The dependency chain for authentication is also longer, requiring coordinated upgrades across clients, servers, certificate authorities, certificate transparency logs, root stores, and browsers. Ecosystem deployment of post-quantum authentication is still minimal compared to encryption.
The EO explicitly excludes National Security Systems, which operate on a separate classified track managed by the NSA with deadlines between 2030 and 2033, already set in 2022. It also focuses on NIST-standardized algorithms rather than Quantum Key Distribution (QKD), which Cloudflare argues does not operate at Internet scale due to its need for specialized hardware and dedicated physical links.
Cloudflare, which has been doing this work since 2019, sees the EO as an excellent foundation but notes opportunities for OMB to strengthen and facilitate cost-effective migration. The company provides its own roadmap for agencies and organizations to advance their transition effectively, emphasizing that both migrations should begin now—encryption to stop harvest-now-decrypt-later attacks, and authentication to prepare for the eventual arrival of CRQCs.
Discussion
0 Comments
Be the first to start the discussion.