Read theMandate

DocumentsExecutive orders › 14412

Executive Order 14412

Securing the Nation Against Advanced Cryptographic Attacks

Signed June 22, 2026, printed at 91 FR 38483. 6 sections of substance, 1,605 words.

In plain English

This order is about code breaking. It warns that quantum machines could break todays codes. It tells agencies to switch to safer ones.

Read it at the Federal Register →

Sec. 1. Background and Policy

The advent of large- scale quantum computers, particularly in the hands of adversaries, will pose a significant threat to widely used cryptographic security systems. Ongoing cyber activity against our Nation also presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational. In light of these threats, the United States must take steps to strengthen cryptographic protections for the Nation's sensitive data, critical infrastructure, and digital economy. It is the policy of the United States to safeguard national security and maintain technological leadership by responsibly and effectively executing the transition of Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post- Quantum Cryptography (PQC), and to

The advent of large- scale quantum computers, particularly in the hands of adversaries, will pose a significant threat to widely used cryptographic security systems. Ongoing cyber activity against our Nation also presents the risk of adversaries collecting United States information now, and decrypting it later once large-scale quantum computers are operational. In light of these threats, the United States must take steps to strengthen cryptographic protections for the Nation's sensitive data, critical infrastructure, and digital economy. It is the policy of the United States to safeguard national security and maintain technological leadership by responsibly and effectively executing the transition of Federal information systems to National Institute of Standards and Technology (NIST)-approved Federal Information Processing Standards (FIPS) for Post- Quantum Cryptography (PQC), and to

In plain English

This states the case the order makes. It says large quantum computers will break current encryption. It says rivals may build them first. It says data stolen now could be read later. It says protection must be strengthened. Sensitive data is named. So is critical infrastructure. It sets a move to new standards. A standards agency approves them.

Sec. 2. Definitions

For purposes of this order: (a) the term ``agency'' has the same meaning as it has in 44 U.S.C. 3502(1); (b) the term ``critical infrastructure'' has the same meaning as it has in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)); (c) the term ``high impact system'' means an information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of ``high''; (d) the term ``high value asset'' or ``HVA'' means Federal information or a Federal information system designated as a high value asset under Office of Management and Budget (OMB) Memorandum M-19-03, ``Strengthening the Cybersecurity of Federal Agencies by Enhancing the High Value Asset Program,'' or any successor document; (e) the term ``information systems'' has the same meaning as it has in 6 U.S.C. 650(14); (f) the term

For purposes of this order: (a) the term ``agency'' has the same meaning as it has in 44 U.S.C. 3502(1); (b) the term ``critical infrastructure'' has the same meaning as it has in section 1016(e) of the USA Patriot Act of 2001 (42 U.S.C. 5195c(e)); (c) the term ``high impact system'' means an information system in which at least one security objective (i.e., confidentiality, integrity, or availability) is assigned a FIPS 199 potential impact value of ``high''; (d) the term ``high value asset'' or ``HVA'' means Federal information or a Federal information system designated as a high value asset under Office of Management and Budget (OMB) Memorandum M-19-03, ``Strengthening the Cybersecurity of Federal Agencies by Enhancing the High Value Asset Program,'' or any successor document; (e) the term ``information systems'' has the same meaning as it has in 6 U.S.C. 650(14); (f) the term

In plain English

This defines terms. Agency follows a records law. Critical infrastructure follows a 2001 law. A high impact system is one where a key goal is rated high. Keeping data secret is one goal. Keeping it true is another. Keeping it usable is a third. A high value asset follows a budget office memo. Two more terms follow other laws.

Sec. 3. Coordinating the PQC Transition

(a) The Director of OMB and the National Cyber Director, in consultation with the Assistant to the President for National Security Affairs and the Administrator of the Office of Electronic Government, OMB, shall lead the strategic coordination and oversight of the national PQC migration policy and strategy set forth in this order, ensuring its alignment with broader cybersecurity goals. (b) The Secretary of Commerce, through the Director of NIST, and in consultation with the Director of the National Security Agency (NSA) and the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), shall provide agencies on an ongoing basis with comprehensive technical guidance on PQC implementation, including best practices in implementation and risk management strategies.

(a) The Director of OMB and the National Cyber Director, in consultation with the Assistant to the President for National Security Affairs and the Administrator of the Office of Electronic Government, OMB, shall lead the strategic coordination and oversight of the national PQC migration policy and strategy set forth in this order, ensuring its alignment with broader cybersecurity goals. (b) The Secretary of Commerce, through the Director of NIST, and in consultation with the Director of the National Security Agency (NSA) and the Secretary of Homeland Security, through the Director of the Cybersecurity and Infrastructure Security Agency (CISA), shall provide agencies on an ongoing basis with comprehensive technical guidance on PQC implementation, including best practices in implementation and risk management strategies.

In plain English

This says who leads the move. The budget office and a cyber aide lead. A security aide is consulted. So is an electronic government office. They must keep the plan in line with wider cyber goals. Commerce gives the technical guidance. Its standards agency does that. Two security agencies are consulted. Guidance goes to agencies as work goes on.

Sec. 4. Accelerating the PQC Transition

(a) Within 30 days of the date of this order, each agency head shall identify its PQC migration lead and provide the name and contact details of the PQC migration lead to the Director of OMB and the National Cyber Director. (b) Within 90 days of the date of this order, the Director of OMB shall, in consultation with the Secretary of Homeland Security through the Director of CISA and the National Cyber Director, and consistent with 6 U.S.C. 1526(c), issue guidance requiring each agency to: (i) review their inventory of HVAs and high impact systems, excluding National Security Systems; (ii) transition all HVAs and high impact systems to use PQC for key establishment by December 31, 2030; (iii) transition all HVAs and high impact systems to use PQC for digital signatures by December 31, 2031; and (iv) develop and submit to the Director of OMB and the National Cyber Director a plan to

(a) Within 30 days of the date of this order, each agency head shall identify its PQC migration lead and provide the name and contact details of the PQC migration lead to the Director of OMB and the National Cyber Director. (b) Within 90 days of the date of this order, the Director of OMB shall, in consultation with the Secretary of Homeland Security through the Director of CISA and the National Cyber Director, and consistent with 6 U.S.C. 1526(c), issue guidance requiring each agency to: (i) review their inventory of HVAs and high impact systems, excluding National Security Systems; (ii) transition all HVAs and high impact systems to use PQC for key establishment by December 31, 2030; (iii) transition all HVAs and high impact systems to use PQC for digital signatures by December 31, 2031; and (iv) develop and submit to the Director of OMB and the National Cyber Director a plan to

In plain English

This speeds the move. Each agency head has 30 days. It must name its lead for the work. The name goes to two offices. The budget office has 90 days for guidance. Agencies must review their key systems. Those systems must use new key methods by the end of 2030. Signatures must follow by the end of 2031.

Sec. 5. Leading the PQC Transition

(a) All agencies that serve as Sector Risk Management Agencies, as defined by the National Security Memorandum 22 of April 30, 2024 (Critical Infrastructure Security and Resilience) or its successor, shall work with the Department of Homeland Security through the Director of CISA to assist critical infrastructure owners and operators in developing their PQC migration plans. (b) The Secretary of State shall work with the Director of NIST, the Secretary of Homeland Security, the National Cyber Director, the Secretary of War, and the Director of National Intelligence (DNI) to identify and engage foreign governments and industry groups in key countries to encourage their transition to PQC algorithms standardized by NIST. (c) Within 180 days of the date of this order and annually thereafter until PQC migration is complete, the Director of the NSA, in his capacity as the National Manager for

(a) All agencies that serve as Sector Risk Management Agencies, as defined by the National Security Memorandum 22 of April 30, 2024 (Critical Infrastructure Security and Resilience) or its successor, shall work with the Department of Homeland Security through the Director of CISA to assist critical infrastructure owners and operators in developing their PQC migration plans. (b) The Secretary of State shall work with the Director of NIST, the Secretary of Homeland Security, the National Cyber Director, the Secretary of War, and the Director of National Intelligence (DNI) to identify and engage foreign governments and industry groups in key countries to encourage their transition to PQC algorithms standardized by NIST. (c) Within 180 days of the date of this order and annually thereafter until PQC migration is complete, the Director of the NSA, in his capacity as the National Manager for

In plain English

This spreads the work wider. Agencies that watch over sectors must help. The cyber agency works with them. They help owners of critical systems plan the move. State must talk with governments abroad. Several agencies help. The aim is to get them to adopt the same standards. A security agency must report within 180 days.

Sec. 6. Procurement

(a) The Director of OMB, the Secretary of War, the Administrator of National Aeronautics and Space Administration, and the Administrator of General Services, in consultation with the Secretary of Homeland Security, the DNI, and the Director of NIST, shall coordinate efforts to identify cost-saving opportunities in implementing the national PQC migration policy and strategy, such as migration of cloud-based technologies, shared procurement of PQC tools, joint training programs, and centralized technical support. (b) Within 180 days of the date of this order, the Secretary of Commerce, through the Director of NIST, shall, to the extent appropriate and consistent with applicable law, revise the processes used by the Cryptographic Module Validation Program to accelerate validations of cryptographic modules. (c) Within 180 days of the date of this order, the Federal Acquisition Regulatory

(a) The Director of OMB, the Secretary of War, the Administrator of National Aeronautics and Space Administration, and the Administrator of General Services, in consultation with the Secretary of Homeland Security, the DNI, and the Director of NIST, shall coordinate efforts to identify cost-saving opportunities in implementing the national PQC migration policy and strategy, such as migration of cloud-based technologies, shared procurement of PQC tools, joint training programs, and centralized technical support. (b) Within 180 days of the date of this order, the Secretary of Commerce, through the Director of NIST, shall, to the extent appropriate and consistent with applicable law, revise the processes used by the Cryptographic Module Validation Program to accelerate validations of cryptographic modules. (c) Within 180 days of the date of this order, the Federal Acquisition Regulatory

In plain English

This covers buying. Four agencies must find ways to save money. Three others are consulted. Moving cloud systems is one path. Buying tools together is another. Joint training is a third. Shared technical help is a fourth. The standards agency has 180 days to speed its testing program. The buying council must act in 180 days too.

Sec. 7. General Provisions

Every order carries this. It is not what the order does.

(a) Nothing in this order shall be construed to impair or otherwise affect: (i) the authority granted by law to an executive department or agency, or the head thereof; or (ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals. (b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations. (c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person. [[Page 38486]] (d) The costs for publication of this order shall be borne by the Department of Commerce. <GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT> (Presidential Sig.) THE WHITE HOUSE, June 22,

(a) Nothing in this order shall be construed to impair or otherwise affect: (i) the authority granted by law to an executive department or agency, or the head thereof; or (ii) the functions of the Director of the Office of Management and Budget relating to budgetary, administrative, or legislative proposals. (b) This order shall be implemented consistent with applicable law and subject to the availability of appropriations. (c) This order is not intended to, and does not, create any right or benefit, substantive or procedural, enforceable at law or in equity by any party against the United States, its departments, agencies, or entities, its officers, employees, or agents, or any other person. [[Page 38486]] (d) The costs for publication of this order shall be borne by the Department of Commerce. <GRAPHIC(S) NOT AVAILABLE IN TIFF FORMAT> (Presidential Sig.) THE WHITE HOUSE, June 22,

In plain English

This is the closing clause that nearly every order carries. It says the order does not change what the law already allows. It also says no one can sue to enforce it.

How this order is quoted

Each section is quoted as the order prints it, under its own number and heading. Executive orders are United States government works and are not under copyright. Long sections are cut at a sentence and the whole order is a click away.