What's Happening?
Federal agencies are encountering significant hurdles in their efforts to migrate to post-quantum cryptography (PQC), particularly concerning the integration with smart identity cards like Personal Identity Verification (PIV) and Common Access Cards (CACs).
The Office of Management and Budget (OMB) and the Office of the National Cyber Director have mandated that agencies submit their PQC migration plans by the end of October. However, experts from the Department of Defense (DoD), Cybersecurity and Infrastructure Security Agency (CISA), and the National Institute of Standards and Technology (NIST) indicate that many agencies are behind schedule. A primary issue is the lack of a comprehensive inventory of cryptographic systems, which is crucial for effective planning and risk assessment. Patrick Manley, CISA's lead for quantum security, highlighted that current inventory processes are often inconsistent and treated as mere compliance checks rather than tools for true visibility. Britta Hale, DoD's director of PQC, emphasized that if an agency's public key infrastructure (PKI) cannot support PQC, then other migration goals become unattainable. This is especially critical for PIV and CACs, which must incorporate new algorithms, requiring all core PKI infrastructure to be PQC-ready by 2030.
Why It's Important?
The successful migration to post-quantum cryptography is vital for national security and the protection of sensitive government data. The current cryptographic systems are vulnerable to attacks from advanced quantum computers, which could compromise classified information, critical infrastructure, and federal operations. The inability of agencies to integrate PQC with smart identity cards by the 2030 deadline poses a severe risk, as it could lead to widespread loss of access for federal personnel if their PIV and CACs become incompatible with updated systems. This transition is not merely a technical upgrade but a fundamental re-architecture of federal cybersecurity infrastructure. The lack of adequate funding and a clear understanding of inventory and costs further exacerbates the problem, potentially leaving federal systems exposed to future cyber threats. The integrity of federal identity management, which underpins access to secure facilities and networks, is directly tied to this migration. Failure to meet these deadlines could have cascading effects, impacting operational continuity and public trust in government security measures.
What's Next?
Federal agencies are expected to continue refining and implementing their PQC migration plans, with a strong emphasis on completing comprehensive inventories of their cryptographic assets. The OMB's guidance outlines a phased approach, with the period between 2026 and 2027 focusing on inventory, strategy definition, and awareness training. The subsequent phase, from 2027 to 2028, will involve pilot programs and early migrations of prioritized systems. NIST and the General Services Administration (GSA) are actively working on solutions for the PIV/CAC challenge, including updating NIST Special Publication (SP) 800-73 and 800-78 to support PQC standards. The GSA's Federal Identity, Cybersecurity and Access Management (FICAM) program is in its second phase, developing a deployable, standards-aligned PQC PKI certification authority service blueprint. Agencies must prioritize PQC funding in their budget requests for fiscal years 2027 and 2028 to ensure the necessary resources are available for this critical transition. The ultimate goal is to have all high-value assets and systems PQC-ready by 2030, with a complete migration for all other systems by 2035.
Beyond the Headlines
The PQC migration extends beyond technical implementation, touching upon broader issues of organizational readiness, resource allocation, and strategic foresight within the federal government. The challenges highlighted, such as inconsistent inventory processes and insufficient funding, point to systemic issues in how federal agencies approach large-scale technological transitions. The reliance on 'box-checking' compliance rather than genuine visibility into cryptographic assets suggests a need for cultural shifts towards proactive risk management and continuous improvement. Furthermore, the complexity of integrating PQC into existing identity management systems like PIV and CACs underscores the intricate web of dependencies within federal IT infrastructure. This transition will likely necessitate significant workforce development and training to equip federal employees with the skills needed to manage and maintain quantum-resistant systems. The success of this migration will not only secure federal data against future quantum threats but also serve as a critical test of the government's ability to adapt to rapidly evolving technological landscapes and maintain its cybersecurity posture in an increasingly complex digital world.













