Executive Order 14412 is signed.
“Securing the Nation Against Advanced Cryptographic Attacks” puts the federal post-quantum migration on explicit dates and directs the creation of minimum CBOM guidance.
United States transition timeline
These dates are not speculative. They are published federal directives, acquisition requirements and standards-transition milestones.
The 2027–2031 operational deadlines are established by federal policy. NIST’s 2030 and 2035 algorithm milestones remain a published draft transition plan and are labeled accordingly below.
2026 → 2035
Every entry links to the government source behind it. Labels distinguish binding policy direction from NSA transition requirements and NIST’s still-draft algorithm schedule.
“Securing the Nation Against Advanced Cryptographic Attacks” puts the federal post-quantum migration on explicit dates and directs the creation of minimum CBOM guidance.
All new acquisitions for National Security Systems are required to be CNSA 2.0 compliant unless an NSA-published exception applies.
EO 14412 §5(d) gives CISA, working with NIST, 270 days from 22 June 2026 to publish guidance on the minimum elements of a Cryptographic Bill of Materials. The calendar result is approximately 19 March 2027.
EO 14412 §4(c) directs NIST to complete a pilot testing post-quantum migration methods and automated discovery and inventory tools by the end of 2027.
High-value assets and high-impact federal systems are directed to use post-quantum key establishment by this date. EO 14412 also directs a proposed FAR rule with a no-later-than 2030 transition date for covered contractors. Separately, draft NIST IR 8547 proposes deprecating 112-bit-strength RSA/ECC signatures and key-establishment schemes after 2030.
EO 14412 §4(b) directs high-value assets and high-impact federal systems to use post-quantum digital signatures by the end of 2031.
NSM-10 set a 2035 national objective for mitigating quantum risk, and NSA’s CNSA 2.0 schedule targets all NSS as quantum-resistant by 2035. Draft NIST IR 8547 proposes disallowing quantum-vulnerable RSA/ECC and other public-key algorithms after 2035.
The inventory layer
A Cryptographic Bill of Materials is a structured, machine-assessable inventory of cryptographic assets: algorithms, key sizes, hash functions, protocol versions, implementations and libraries. It gives security teams a map of what must be evaluated, replaced or retired.
An SBOM inventories software components. A CBOM inventories the cryptography within and across those systems. EO 14412 explicitly brings CBOM into federal policy and directs CISA and NIST to define its minimum elements.
Talero is a public testnet, not a National Security System. This timeline describes policy direction and architectural alignment; it does not assert federal certification, procurement eligibility or a formal conformity assessment.
Read how Talero turns cryptographic configuration into verifiable consensus evidence, then inspect the public testnet live.