惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

www.infosecurity-magazine.com
www.infosecurity-magazine.com
Security Archives - TechRepublic
Security Archives - TechRepublic
TaoSecurity Blog
TaoSecurity Blog
Cloudbric
Cloudbric
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
N
News and Events Feed by Topic
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Securelist
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
D
DataBreaches.Net
S
Schneier on Security
L
LangChain Blog
Jina AI
Jina AI
M
MIT News - Artificial intelligence
Recent Announcements
Recent Announcements
T
Tenable Blog
B
Blog RSS Feed
V
Visual Studio Blog
Simon Willison's Weblog
Simon Willison's Weblog
G
Google Developers Blog
T
The Exploit Database - CXSecurity.com
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
WordPress大学
WordPress大学
W
WeLiveSecurity
I
InfoQ
The Hacker News
The Hacker News
雷峰网
雷峰网
月光博客
月光博客
P
Privacy & Cybersecurity Law Blog
O
OpenAI News
Hacker News: Ask HN
Hacker News: Ask HN
T
Threat Research - Cisco Blogs
GbyAI
GbyAI
The Last Watchdog
The Last Watchdog
P
Privacy International News Feed
Cyberwarzone
Cyberwarzone
S
SegmentFault 最新的问题
L
Lohrmann on Cybersecurity
人人都是产品经理
人人都是产品经理
V
V2EX
V
Vulnerabilities – Threatpost
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
C
Cybersecurity and Infrastructure Security Agency CISA
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Troy Hunt's Blog
Application and Cybersecurity Blog
Application and Cybersecurity Blog
阮一峰的网络日志
阮一峰的网络日志
SecWiki News
SecWiki News
Microsoft Azure Blog
Microsoft Azure Blog

Featured Blogs - Forrester

Inclusive Design Is Automotive’s Overlooked Growth Opportunity B2B Social Media Influencers Have More Influence Than Ever Comcast Split Puts NBCUniversal In Play What Technology Leaders Should Not Miss At Technology & Innovation Forum Central Why Your AI Strategy Needs A DEXM Solution: Lessons From Nexthink Masters Of Experience The Dawn Of The Accidental Developer The Next Era Of B2B Events: 8 Data-Backed Shifts Defining 2026 The Next Era Of B2B Events: Eight Data-Backed Shifts Defining 2026 Identiverse 2026 Recap: Identity Security for Agentic AI Dominates Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And…AI Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement EO 14409 Makes PQC Migration A Multi-Year Operational Program For Federal Security Leaders New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum Answer Engines Will Select Your Content. Your Digital Experience Has To Do More. Meta Gambles With Its Trust In Prediction Markets The EU’s Digital Markets Act Meets The Mobile OS, Round 2 Don’t Just Hear About The IT Singularity — Work Through It At Our Austin Tech Forum Don’t Just Hear About The IT Singularity — Work Through It At Our NYC Tech Forum The Cost Of AI Productivity Is Less Creativity Dollars And Sense At FinOps X 2026: Is AI Value Management Bigger Than FinOps? Quantum Security Is No Longer Optional: A Practical Blueprint For Successful Implementation The AI Orchestration Layer In Banking Is The New Battleground The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing AI Forces A Redesign Of How Marketing And Agencies Work The IT Singularity Is Here: Announcing Forrester’s 2026 Technology Events Nuvei Makes Its B2B Cross-border Payment Move: The Payoneer Acquisition Google Dethrones OpenAI As Agencies’ Preferred AI Partner When Algorithms And LLMs Become Sellers, Your Commerce Strategy Must Change Google Goes All-In: An AI-Operated System, Not AI-Assisted Products Cisco’s Platform Push: Big Vision, Real Questions Retail's Incremental Total Experience Shift: Select Brands See Significant Improvement It's Time To Elevate Journeys Into Decision Systems AI Agents Need Real-Time Context: Data Streaming Is How You Are Going To Get It Tackle Enterprise AI’s Hardest Question At Forrester’s AI Forums Building The Human Foundation For AI At CX Forum East What Separates Scalable AI-Driven Innovation From Promising Experiments Hyland CommunityLive 2026: A Call To Action for Enterprise Content Management Leaders Call For Entries: Forrester’s B2B Forum EMEA 2026 Awards AI Agents Are Your New Customer. But Can You Target and Grow Their Trust in Your Brand? Survey Insights: How Business Applications Are Purchased Governance: New Strategy, Old Hands On The Wheel … US Health Insurers Show Experience Improvements Announcing The 2026 Forrester Wave™ On Accounts Payable Invoice Automation Announcing The Forrester Wave™: Accounts Payable Invoice Automation Software, Q2 2026 US Banks’ Total Experience Is Improving, But Most Still Have Work To Do UK Social Media Ban Forces Platform Accountability Total Recall: A Cautionary Fable Of Anthropic And The US Government Consumers Aren’t Ready To Delegate Payments To AI Agents Fox Makes $22B Roku Acquisition Bet Secure The Future Of Internet Traffic As Agents Take Over Coupa’s Inspire 2026 Unveils A Strategy And Acquisition Spree To Build The Autonomous Spend Management “Network” A Fake PLG Strategy Is Exposed Through Your Digital Commerce Experiences Conway’s Law: Your Operating Model Matters More Than The AI Model Turn Application Portfolio Rationalization Into A Continuous Optimization Capability Healthcare And Life Sciences: Turning AI Momentum Into Lasting Value How To Build A Loyalty Team That Scales With Your Program Align B2B Marketing Teams To Thrive In A Buyer-Centric World OpenAI’s Proposed IPO Opens A Trifecta Of Opportunities For It, But Don’t Lock In Just Yet Retention-As-A-Service Is An Intriguing Idea — Here’s What It Actually Means Customer Success And Customer Experience: The Difference Is More Than Semantic How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk Announcing Forrester’s Top Cybersecurity Threats For 2026 Your AI Bill Is A Context Problem Build The Human Foundations Before You Scale AI The State Of Agentic AI In 2026: Companies Are Chasing, Few Are Catching Move Over WAF. The Web Application Protection Platform Takes Over Microsoft Build 2026: Pushing The Frontier With A More Opinionated AI Playbook Anthropic’s Proposed IPO Will Change The Economics Of Enterprise AI AI Is Forging A New RevOps Identity AI Is Forging A New RevOps Identity Build Meaning Before Machines: Why Semantics, Ontologies, And Knowledge Graphs Matter For Agentic AI Red Hat Summit 2026: Can Red Hat Win Its Claim As The Hybrid AI Control Plane? Ad Creative Is A Technology Problem And Opportunity The State Of Portfolio And Product Marketing In 2026 Miro’s Big Bet: Can A Whiteboard Company Become The AI Decisioning Layer For The Enterprise? Agents Are In The Aisle: The 2026 NRF APAC Innovators To Watch Italy’s B2B Marketing Challenge Is Not Strategy — It’s Focus And Alignment If Buyers Change How They Search, Marketing Must Change How It Shows Up European B2B Marketing Has A Data Problem, Not A Vision Problem The AppGen And Low-Code Platforms Landscape, Q2 2026, Is Out! What Anthropic’s Two Recent Announcements Mean For Manufacturers Agentic AI In Insurance: Stop Chasing Autonomous Agents. Start Engineering Trust. The Consolidation Wars: M&A Is Rewriting Finance Automation Seven Ways To Turn CX Forum East Analyst Time Into Real Momentum Seven Ways To Turn CX Forum West Analyst Time Into Real Momentum Leading With Intention: What Women Leaders Told Us About AI And The Future Of Work Redesign B2B2C Digital Strategy For The AI Era Marketplace Platforms Aren’t One Market Anymore: Announcing Forrester’s Two Landscapes For 2026 The State Of Agentic Commerce In Mid-2026 If Your Employees Aren’t Ready For AI, Neither Is Your Business Announcing The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026 Financial Well-Being Is Under Pressure — A Strategic Priority For Banks TeamViewer Connect: A Pragmatic Look At How IT Can Level Up DEX Freshworks Signals A More Practical Future For AI Service Management Zendesk Relate 2026 Showed Why Agentic Customer Service Starts With Knowledge
Use EO 14409 As A Canary For Enterprise PQC Migration And Procurement
Heidi Shey · 2026-06-25 · via Featured Blogs - Forrester

On June 22, 2026, the White House issued Executive Order 14409, “Securing the Nation Against Advanced Cryptographic Attacks.” While it has direct implications for federal agencies, there are parts that are worth paying attention to for enterprise security and risk leaders. Here’s what’s worth your attention, whether or not you hold a federal contract.

You Now Have A Clear Operating Assumption With An Accelerated Timeline

The order opens with “harvest now, decrypt later” as its rationale: adversaries collecting encrypted sensitive data today to decrypt it once large-scale quantum computers exist. It commits the US government to migrating to NIST’s PQC standards by end of 2030 for key establishment and by end of 2031 for digital signatures for high value assets and high impact systems. This is a notable departure from the previous target of 2035 across Federal systems overall.

What this means: The “should we start now” debate is settled for any organization sitting on data with a long confidentiality shelf life. The order generates greater urgency surrounding this risk. Data exfiltrated today is exposed the day a cryptographically relevant quantum computer arrives (Q-Day!) — and you don’t control when that is. Determine the shelf life of your sensitive data. What holds longer term value is specific to your organization, from source code, health and biometric records, authentication credentials, to trade secrets. Identify where long-lived sensitive data intersects with vulnerable public-key cryptography, external exposure, and third-party dependencies.

The FAR Rule Has Takeaways For Non-Contractors Too

Section 6 directs the Federal Acquisition Regulatory (FAR) Council to publish a proposed rule to amend the FAR, within 180 days, requiring covered contractors to comply by December 31, 2030, with NIST’s FIPS, including the PQC-compliant algorithms. This deadline is not unique: other governments internationally have mandated similar timelines for PQC migration.

What this means: Even if you do not sell to the federal government, you should treat 2030 (for key establishment) and 2031 (for digital signatures) as the de facto benchmark for your own security program. Named deadlines for PQC migration from governments will influence regulatory and sector-specific deadlines, as well as third-party partner requirements and technology vendor roadmaps. If you sell to the federal government, PQC becomes a contract term with a date attached. The proposed rule — not the final rule — is the thing to watch, because that’s where scope and definitions get set. File your comments while they still count.

Cryptographic Bill of Materials (CBOMs) Will Be SBOM’s Sequel

Section 5 directs CISA and NIST to publish, within 270 days, the minimum elements for a cryptographic bill of materials (CBOM) which is a structure designed to let you automatically assess the cryptographic assets inside a piece of hardware or software. This starts us down the path for a new vendor risk management and procurement requirement.

What this means: You can’t migrate what you can’t see, and most enterprises have no current inventory of where and how cryptography is used across their environment. The CBOM will help. Even more important to note: the SBOM made after the 2021 cybersecurity EO, went from being a niche artifact to a procurement expectation. If you sell hardware or software, stay tuned for the published elements to come so a CBOM is something you can produce for buyers. Today, we see open source solutions like CBOMkit from IBM Research leading CBOM creation. Your own third-party risk management processes must include revising SLAs and procurement agreements to ask vendors to disclose their own products’ CBOMs. CBOMs for legacy hardware will likely be unobtainable and will either require a waiver or hardware replacement or firmware upgrade.

Your Vulnerability Disclosure Now Covers Weak Cryptography

Section 6 also directs the FAR Council to propose, within 270 days, rules requiring covered contractors’ vulnerability disclosure programs to capture cryptographic vulnerabilities — explicitly including testing for the absence of encryption and the use of non-FIPS-approved algorithms.

What this means: “We didn’t encrypt that” and “we used a non-approved algorithm” move from being audit findings to being reportable vulnerability classes. Cryptographic hygiene is now a continuous vulnerability-management best practice rather than a periodic compliance check. If you run a VDP or a bug bounty, your scope, intake, and triage logic need to account for cryptographic findings and your remediation SLAs need a place to put them. This raises the bar for your security vendors in this area as well; begin to assess this as a part of your procurement due diligence going forward. These disclosures will likely extend to areas including IAM, CIAM, tokenization, data protection, unified messaging, and other domains.

Critical Infrastructure Gets a Partner, Not a Mandate — Yet

Section 5 directs every federal agency that serves as a Sector Risk Management Agency to work through CISA to help critical infrastructure owners and operators build their PQC migration plans.

What this means: If you are a security leader for a utility, hospital system, bank, pipeline, wastewater system, or any other critical infrastructure operator, take note. Your sector agency and CISA are now tasked with assisting you in developing your PQC migration plans. Watch to see if any assistance in the form of “voluntary” sector guidance comes through, which may eventually turn into a baseline that regulators and insurers later expect. Engage early so you have greater input into shaping your migration plan. Start with identifying and prioritizing critical and high-consequence functions: remote access into OT environments, identity and certificate infrastructure, encrypted data flows between operators and third parties, firmware and software signing, backup and recovery systems, and communications tied to incident response or safety operations.

Assemble Your Team For PQC Migration

The federal government is treating PQC as an execution program, not a standards update. Enterprises should do the same. The hardest parts will be ownership, sequencing, validation, and dependency management. Cryptographic discovery and inventory will be uncomfortable for many organizations because cryptography is often embedded in products, protocols, libraries, APIs, certificates, HSMs, identity systems, and vendor-managed services that security teams do not fully own. Including more PQC questions in RFPs and contract renewals, third-party risk reviews, cyber insurance discussions, and board-level risk conversations also requires coordination with other internal stakeholders.

Ensure that stakeholders recognize that timelines can change. We’ve seen deadlines become progressively more aggressive in the last 18 months and teams must be prepared for the idea that that could continue. Forrester clients can check out the full initiative blueprint to help drive their quantum security migration, or schedule a guidance session or inquiry with us.