This executive order recites the fact that large scale quantum computers pose a significant threat to widely used cryptographic security systems and that adversaries of the United States may begin collecting information now and decrypting it later once large scale, quantum computers are operational. Therefore, the executive order sets out a process for steps to be taken to strengthen the cryptographic protections for the country’s sensitive data, critical infrastructure and digital economy. The order directs the director of the Office of Management and Budget (OMB) and the national cyber director to lead the strategic coordination and oversight of a national Post-Quantum Cryptography (PQC) migration program. It also directs the secretary of commerce to provide agencies on an ongoing basis with comprehensive technical guidance on PQC implementation.
The director of OMB is to issue guidance to each agency involved for (a) reviewing their inventory of high value assets (HVAs); (b) transition of all HVA‘s and high impact systems to use PQC for key establishment by Dec. 31, 2030; (c) transition of all HVAs and high impact systems to use PQC for digital signatures by Dec. 31, 2031; and (4) development and submission to the director of OMB and the national cyber director a plan to accomplish this directive. All agencies that serve as sector risk management agencies are to work with the Department of Homeland Security to assist critical infrastructure, owners and operators in developing their PQC migration plans; and the secretary of state is to identify and engage foreign governments and industry groups in key countries to encourage their transition to PQC algorithms standardized by National Institute of Standards and Technology. The Federal Acquisition Regulatory Council is directed to publish a rule amending the Federal Acquisition Regulation (FAR) to require covered contractors to comply with approved federal information processing standards for PQC by Dec. 31, 2030. Finally, the Federal Acquisition regulatory Council is directed to publish a proposed rule amending the FAR requirements and contract clauses for contractor vulnerability disclosure policies.