top of page

Demand has a date. Supply has a register.

Writer: Brian Couzens
Brian Couzens
2 minutes ago
8 min read

Author: Brian Couzens

Publish date: 23 September 2026


Illustration of demand has a date

Where post-quantum migration stands in September 2026

As at 21 September 2026, sixteen FIPS 140-3 certificates on the NIST Cryptographic Module Validation Program record carry a post-quantum algorithm family inside the validated boundary. That count treats LMS, the stateful hash-based signature scheme standardised in NIST SP 800-208, as a post-quantum family. It is a count of validated post-quantum capability, not a count of ML-KEM or ML-DSA deployments.

That single number is a more useful description of the state of the transition than any threat model. The standards question is closed. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) were published in August 2024 and have now been in force for over two years. The implementation, validation, procurement and inventory questions are not closed. Algorithm choice is no longer the open question for organisations that fall under NIST, and increasingly for those that do not.

The binding constraint on migration has moved. It now sits in three places, and each can be measured. The first is the date an obligation falls due. The second is the validated supply available to meet it. The third is the visibility an organisation has of its own cryptographic estate. None of the three is a mathematical problem. Each is a governance, procurement or evidence problem, and risk now accumulates in the gaps between them.

1. The obligation now has instruments behind it

Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, was signed on 22 June 2026 and published at 91 FR 38483 on 25 June. Its operative provisions are specific.

Section 4(a) required every agency head to name a PQC migration lead within 30 days. Section 4(b) required OMB to issue guidance obliging agencies to transition their high value assets and high impact systems to PQC for key establishment by 31 December 2030, and for digital signatures by 31 December 2031. National Security Systems sit outside that provision and are reported on separately by the NSA under Section 5(c).

OMB issued that guidance as M-26-15, Execution of the Migration to Post-Quantum Cryptography, on 24 June, two days after signature against a 90-day allowance. The memorandum sets a five-phase schedule running from 2026 to 2035, requires agency migration plans within 120 days, and expects an automated, continuously updated cryptographic inventory. The 120-day window closes in late October 2026.

The provision with the widest reach is Section 6(c). Within 180 days of the order, the FAR Council must publish a proposed rule amending the Federal Acquisition Regulation to require covered contractors to comply with NIST FIPS, including the FIPS that incorporate PQC algorithms, by 31 December 2030. Section 6(d) goes further. It directs a second proposed rule under which contractor vulnerability disclosure policies must accept reports of cryptographic weaknesses, including the use of non-FIPS approved algorithms. Once those rules are in force, a non-approved algorithm in a supplier's product becomes a reportable finding rather than a technical debt item.

Outside the United States the direction of travel is the same, even where the instruments are less binding. The EU coordinated implementation roadmap agreed through the NIS Cooperation Group in 2025 calls on member states to start the transition by the end of 2026 and to move high-risk use cases to PQC as soon as possible, and no later than the end of 2030. On 3 September 2026 the G7 Cybersecurity Working Group, led by ANSSI under the French G7 presidency and co-released by agencies including NCSC, BSI and the Canadian Centre for Cyber Security, published Preparing for the Post-Quantum Era: A Call to Action. It urges public and private organisations to adopt a phased, risk-based approach now: inventory, identification of critical systems, dependency mapping and transition planning. It sits alongside the January 2026 G7 Cyber Expert Group roadmap for the financial sector, which states that it sets no regulatory expectations but frames the same timeline.

The consequence is that in the United States these are no longer advisory timelines. They are dated obligations with named owners, and the contractor provisions carry them into the commercial supply chain. Elsewhere they are converging expectations that supervisors will reference.

2. Supply is countable

The SITG-Consulting PQC register, built from the CMVP record as at 21 September 2026, can be read in full in an afternoon.

It holds five Level 3 hardware security modules with a PQC family inside the validated boundary: Kryptus, Thales Luna T7, Thales Luna M7, Crypto4A and Sansec. It holds four software lineages: Geomys, AWS-LC, Dell BSAFE and Chainguard. The count is by certificate, not by vendor, product family or deployment. That is the validated pool a FIPS-bound procurement draws on today.

Three points follow.

First, a product that supports ML-KEM and a product with ML-KEM inside a validated boundary are different things. Support is a roadmap statement about code. Validation is evidence that a specific module, at a specific version, has been tested and certified with that algorithm inside the boundary the certificate describes. A procurement that accepts the first in place of the second is accepting a claim it cannot audit.

Second, the certificate matters, not the brand. A vendor may hold a validated PQC module in one product line and ship another product line, or another version, that has none. Readiness has to be established at the level of the module and the certificate number, not the vendor name.

Third, the pool is concentrated. When an obligation applies across a whole sector at once and the validated supply is this narrow, the constraint shows up as lead times, pricing and supplier leverage long before it shows up as a compliance finding.

The order recognises the bottleneck itself. Section 6(b) directs the Secretary of Commerce, through NIST, to revise the processes of the Cryptographic Module Validation Program within 180 days to accelerate validations. That deadline falls on 19 December 2026. When a presidential order has to instruct the validation programme to move faster, the supply constraint is on the record. Whatever NIST publishes in December will change the rate at which the register grows. It will not change the fact that procurement decisions being made now have to be made against the register as it stands.

3. Visibility is the next constraint

The third constraint is the one organisations control directly and understand least.

M-26-15 expects agencies to maintain an automated, continuously updated inventory and to name the tools they will use to build it. That turns tool selection from a technical preference into an accountable element of the migration plan. Section 5(d) of the order gives CISA, working with NIST, 270 days to publish minimum elements for a cryptographic bill of materials that enable automated assessment of hardware and software. That falls due in March 2027. Until it lands, there is no common definition of what a complete CBOM contains.

Discovery tooling on the market today sees network and certificate cryptography far more clearly than cryptography executing inside applications, libraries and runtime environments. CBOM outputs from different tools are not yet comparable with one another, because there is no agreed definition of the elements they should contain. The practical result is that organisations are being asked to produce an inventory against a deadline using instruments whose blind spots are known to specialists and seldom disclosed to buyers.

That matters because the inventory is the foundation for every later phase. An inventory that omits runtime and embedded cryptography will produce a migration plan that looks complete and is not. The gap will surface at the point of cutover, when a dependency nobody recorded fails, rather than at the point of planning, when it could have been scheduled.

The governance response is straightforward to state. Treat the inventory as evidence with a known coverage boundary, in the same way a validation certificate has a known boundary. Record what the tool can see, what it cannot see, and how the gap is being closed. An inventory without a coverage statement is an assertion.

4. The 2030 roadmap starts in the supplier contract

If the FAR rule lands as the order directs, contractors will carry the 2030 obligation directly. A vendor's readiness claim is then bounded by what its modules are validated to do, and the contract is the only instrument that converts that claim into something enforceable.

Contracts signed or renewed this year will still be running when the dates arrive. They should require four things:

  • the CMVP certificate reference for each cryptographic module the product depends on

  • the algorithms and security functions inside the validated boundary for each certificate

  • current validation status, including modules in the queue and their expected dates

  • a dated remediation plan for any dependency that sits outside a validated boundary

Two further clauses follow from Section 6(d). The first is an obligation on the supplier to notify the customer when a module falls out of validation or a non-approved algorithm is found in the product. The second is the right to receive the supplier's CBOM for the delivered product once the CISA minimum elements are published.

A statement of intent is not a readiness position. A supplier that cannot answer the four questions above with certificate numbers and dates is telling the customer where its own migration stands.

5. What this means by reader

For boards, the obligation now has a date and an owner, and the evidence to ask for is specific: certificate references, inventory coverage statements and dated remediation plans. Assurance that rests on vendor roadmaps is not assurance.

For chief risk officers and chief financial officers, the concentration of validated supply is a supplier risk in its own right. It affects lead times, pricing and negotiating position, and it belongs in the supplier risk register alongside the technical programme.

For programme leads, the sequence has to be built against what can be bought and validated, not against what has been announced. Dependencies with no validated option should be identified now and carried as named exceptions with owners and dates.

For procurement, the contract is the control. The four requirements above can be inserted at renewal without waiting for the FAR rule, and they cost little to ask for.

For organisations outside the United States, the relevance is direct. Vendors ship common product lines across markets, multinationals that supply the US government will fall within the contractor rule, and Section 5(b) of the order commits the State Department to encouraging other governments towards the NIST algorithms. The FIPS register is becoming the reference point for supply well beyond US federal procurement.

6. Who owns the gap

The standards are settled and the obligations are dated. The open questions are about evidence and accountability.

The question for boards this month is a narrow one. For each critical dependency, who owns the interval between the date the obligation falls due and the date validated supply exists to meet it?

Where that interval has a named owner, it can be planned, funded and reported. Where it has no named owner, it has no plan. The obligation arrives on its date regardless.

References

  • Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, 22 June 2026, 91 FR 38483.

  • OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, 24 June 2026.

  • NIST FIPS 203, FIPS 204 and FIPS 205, August 2024.

  • NIST SP 800-208, Recommendation for Stateful Hash-Based Signature Schemes.

  • NIST Cryptographic Module Validation Program, validated modules record, as at 21 September 2026.

  • SITG-Consulting, FIPS 140-3 Thematic Review, January to September 2026 (Half-Year Edition), DOI 10.5281/zenodo.21423171.

  • G7 Cybersecurity Working Group, Preparing for the Post-Quantum Era: A Call to Action, 3 September 2026.

  • G7 Cyber Expert Group, Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector, January 2026.

  • NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, June 2025.

 
 
 

Comments


bottom of page