The Encryption Under Your Business Has an Expiration Date
On June 22, the White House signed an executive order that most business leaders haven't read — and every one of them should. "Securing the Nation Against Advanced Cryptographic Attacks" doesn't sound like something that belongs on a board agenda. But buried in its directives are hard deadlines that will reshape vendor contracts, IT budgets, and risk posture for any company that touches federal work.
Here's the short version: the encryption that protects your data today is on a countdown clock. And the federal government just set the timer.
What Actually Happened
The executive order directs a nationwide migration to post-quantum cryptography — new encryption standards designed to withstand attacks from quantum computers. Federal agencies must transition their most sensitive systems to quantum-resistant encryption by December 31, 2030, and to quantum-resistant authentication by December 31, 2031. Federal contractors must comply with the new cryptographic standards by the end of 2030 as well, through updated Federal Acquisition Regulation requirements.
That's not a suggestion. It's a procurement gate.
If you sell products or services to any federal agency, your cryptographic modules need to meet the new bar — or you're out. And there's a nearer cliff: on September 21, 2026, NIST moves all remaining FIPS 140-2 validation certificates to its Historical List. After that date, only FIPS 140-3 validated modules will be accepted for new federal procurement. That's two months from now.
Why This Matters Beyond Government Contracts
You might be thinking: We don't sell to the federal government. This doesn't apply to us.
In my experience, that's the wrong frame. Federal standards have a way of becoming the floor for everyone. NIST published its first three post-quantum cryptographic standards — FIPS 203, 204, and 205 — back in August 2024. Those aren't going away. NIST's own transition guidance, IR 8547, lays out the full deprecation timeline: RSA, elliptic-curve cryptography, and related algorithms will be deprecated after 2030 and completely disallowed after 2035. Not just for government — across NIST standards that underpin everything from HIPAA technical safeguards to FedRAMP authorization.
If your organization handles health data, financial data, or any information subject to federal compliance frameworks, this timeline applies to you whether you have a government contract or not.
The Threat That's Already Here
The executive order names the core problem directly: adversaries can collect encrypted data today and decrypt it later, once quantum computers mature enough to break current encryption. The intelligence community calls this "harvest now, decrypt later." The UK's National Cyber Security Centre said in its 2023 Annual Review that state actors are running data theft campaigns "for exploitation in years to come." The NSA has said the same thing since 2021.
This isn't theoretical. It's operational. If your company's encrypted M&A strategy documents, patient records, or intellectual property get intercepted today, the attacker doesn't need to crack them now. They store them. They wait. And the value of that stolen data doesn't decay the way a credit card number does — corporate strategy, trade secrets, and health records stay valuable for decades.
That's the scenario this executive order is designed to address. The question for business leaders isn't whether quantum computers will eventually break today's encryption. It's whether your organization's data will still be worth protecting when they do.
The Three Questions Every Board Should Ask
In Cyber Risk Is Business Risk, I lay out a framework for translating technical risk into business terms. It starts with three questions. Applied to post-quantum readiness, they look like this:
What do we have? Do you know where cryptography lives in your environment? Not just your VPN and email encryption — every TLS certificate, every API connection, every database at rest, every key management system. Most organizations don't have a complete cryptographic inventory. The executive order requires federal agencies to designate a PQC migration lead and inventory their high-value cryptographic assets. If the government needs to do this formally, your organization probably does too.
What could go wrong? A cryptographic migration is not a patch cycle. Previous major cryptographic transitions — SHA-1 to SHA-2, for example — took the better part of a decade to complete across large enterprises. Some organizations are still running SHA-1 in legacy corners. A migration to post-quantum algorithms will touch hardware security modules, embedded devices, third-party integrations, and code you didn't write. The risk isn't just "we get breached." It's "we can't sell to the government anymore," "our cyber insurance policy excludes quantum-vulnerable encryption," or "our compliance posture collapses."
What are we doing about it? Start with a cryptographic inventory. Identify your highest-value, longest-lived data assets. Ask your vendors — cloud providers, SaaS platforms, hardware manufacturers — what their PQC migration timelines look like. If they don't have one, that tells you something important about their risk management posture. And budget for this now, not in 2029. The Department of Commerce is required to complete a PQC pilot project by December 31, 2027. If the government is piloting in 2027, your planning window is today.
What to Ask Your CISO This Week
If you're on a board or in the C-suite, here's the conversation to start:
- Do we have a cryptographic asset inventory? If the answer is no, that's your first action item.
- Do any of our products or services depend on FIPS 140-2 validated modules? The September 21, 2026 Historical List deadline is imminent.
- What is our timeline for evaluating post-quantum algorithms? NIST says ML-KEM, ML-DSA, and SLH-DSA "can and should be put into use now."
- Are our federal contracts at risk? If you sell to government agencies, the FAR updates coming by 2030 will require PQC compliance. Procurement teams need to plan now.
This is a compliance conversation and a security conversation and a budget conversation, all at once. The organizations that treat it as just one of those will be the ones scrambling in 2029.
The Bottom Line
The encryption under your business has an expiration date. The federal government just published the timeline. Whether you're a federal contractor staring at hard deadlines or a private-sector company that handles sensitive long-lived data, the window to plan is open now — and it's shorter than most executives realize.
Previous cryptographic migrations took a decade. You don't have a decade. You have until 2030 to deprecate, 2035 to disallow. And if your data is worth stealing today, someone may already be storing it for tomorrow.
