惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

爱范儿
爱范儿
腾讯CDC
博客园 - 司徒正美
A
About on SuperTechFans
H
Help Net Security
J
Java Code Geeks
C
Check Point Blog
B
Blog RSS Feed
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MongoDB | Blog
MongoDB | Blog
U
Unit 42
Hugging Face - Blog
Hugging Face - Blog
Last Week in AI
Last Week in AI
MyScale Blog
MyScale Blog
V
Visual Studio Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
I
InfoQ
H
Hackread – Cybersecurity News, Data Breaches, AI and More
F
Fortinet All Blogs
博客园 - 聂微东
酷 壳 – CoolShell
酷 壳 – CoolShell
GbyAI
GbyAI
博客园 - 【当耐特】
雷峰网
雷峰网

Yubico

Yubico expands OpenAI partnership to new countries as hardware-backed passkey mandate begins for Trusted Access for Cyber program Beyond overload: Yubico's measured approach to AI adoption Code and connections: Inside Yubico’s YubiKey 5.8 Hackathon Leading Yubico forward: Q2 reflections and securing the AI frontier What the European Central Bank’s October 2026 AI cyber mandate means for bank identity security The ‘Air-Gap Conundrum’: When Password Managers Meet the Data Center Floor The Defense Industrial Base Has a New #1 Cybersecurity Priority: Phishing-Resistant MFA RIP SMS: Microsoft transitioning to passkeys as default authentication method for Entra ID Beyond the login: Top 3 things developers need to know about YubiKey 5.8 OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members to log into ChatGPT accounts Works with YubiKey Spotlight: Translating YubiKey logistics into enterprise cyber resilience with EgoMind’s Appterix Google Play Services adds support for NFC-enabled FIDO2 security keys: How Yubico makes Android passkey authentication seamless Salesforce enforces MFA for all employee logins: Here’s what you need to know Secure it Forward Spotlight: Cyber defenders as a force for resilience New Executive Order on AI: Identity as a critical foundation for trusted AI YubiKey 5 FIPS Series and YubiHSM 2 FIPS are now FIPS 140-3 validated: What it means for high assurance security Secure It Forward Spotlight: Securing independent journalism with Radio Free Europe / Radio Liberty The passkey spectrum: Importance of user choice in digital security journeys OpenAI’s Advanced Account Security program: Top 5 things Codex users need to know New to OpenAI’s Advanced Account Security program? Here’s how to add your YubiKey to ChatGPT accounts Leading Yubico forward: Q1 reflections and securing the AI frontier Building a safer AI journey: How to add your YubiKey to ChatGPT accounts OpenAI partners with Yubico: What it means for the future of AI-based workflows and the role of the human Works with YubiKey Spotlight: Securing the AI frontier and high-assurance infrastructure Yubico’s commitment to securing the future of digital identities: Reflecting on RSAC 2026 YubiKey as a Service expands to Ping Identity with pre-configured security keys Securing agentic AI: Why automation still needs human oversight Yubico officially lands in Singapore: Opening our third global headquarters Welcome to YubiNation Partners: Reimagining the Future of Channel Partnership to Secure Identity at Scale Yubico’s Clifton Slater recognized as a CRN 2026 Channel Chief
Post-quantum cryptography is now a federal mandate: Here’...
Joe Scalone · 2026-06-26 · via Yubico

Earlier this week, the White House issued Executive Order 14409, “Securing the Nation Against Advanced Cryptographic Attacks.” This new executive order represents a watershed moment for federal cyber policy as the first binding, executive-level mandate requiring civilian federal agencies to migrate their high-value systems to NIST-approved post-quantum cryptographic standards. 

For years, the federal government has engaged in discussions surrounding post-quantum cryptography (PQC). With EO 14409, advisory memos are officially over and compliance dates are now law. This marks the first binding, executive-level mandate requiring civilian federal agencies to migrate their high-value systems (HVAs) to NIST-approved post-quantum cryptographic standards.

The urgency behind this directive is real: The EO highlights how sophisticated adversaries are actively engaging in “harvest-now-decrypt-later” tactics, collecting encrypted U.S. government data today with the intent of decrypting it once capable quantum computers emerge. 

Key requirements and timelines of the new Executive Order

At a high level, agencies are being asked to inventory their cryptographic assets, designate leadership accountability, and migrate their most critical systems on a firm timeline.

DeadlineRequirementStandard / Reference
30 daysDesignate a PQC Migration Lead reporting to the agency CIOEO § 4(a)
90 daysComplete cryptographic inventory of all HVAs and high impact systems; submit migration plan to OMBEO § 4(b)
Dec. 31, 2027NIST completes pilot PQC migration projectEO § 4(c)
Dec. 31, 2030All HVAs and high impact systems migrate key establishment to PQC (ML-KEM / FIPS 203). Covered contractors comply.EO § 4(b)(ii); § 6(c)
Dec. 31, 2031All HVAs and high impact systems migrate digital signatures to PQC (ML-DSA / FIPS 204)EO § 4(b)(iii)

What this all now means is that three separate things are now required, not just recommended.

First, accountability is personal. Every agency must name one person responsible for PQC migration within 30 days. That person reports to the CIO and owns the cryptographic inventory, the migration plan, and cross-agency coordination; there is no more diffuse responsibility here.

Second, agencies need to know what they have before they can migrate it. The EO establishes a cryptographic bill of materials (CBOM) standard — an inventory of every cryptographic asset in your hardware and software. CISA and NIST have 270 days to publish minimum elements. Agencies that have not started their inventory are already behind.

Finally, this EO extends to vendors. A proposed FAR rule will require covered contractors to comply with NIST PQC standards by December 31, 2030. If your supply chain is not quantum-safe, your system is not quantum-safe. The perimeter is the full acquisition chain.

Navigating immigration gaps of the Executive Order

While the direction of the EO is clear, the implementation path has notable challenges. It is less clear on two points that will determine whether agencies actually hit these dates: Funding and module validation throughput. 

The EO is explicitly “subject to the availability of appropriations,” leaving smaller agencies with tight IT budgets at risk of falling behind. Without dedicated budget authority, smaller agencies with constrained IT budgets will miss the 2030 deadline simply due to a lack of resources.

Second, NIST’s Cryptographic Module Validation Program (CMVP) historically faces multi-year queues. The EO directs NIST to accelerate validations, but throughput requires NIST capacity investment. If certified PQC modules are not available at scale by 2029, agencies will face a severe compliance bottleneck.

One notable omission: the EO has no binding mandate for private critical infrastructure. Sector Risk Management Agencies are directed to “assist” private operators in developing migration plans — but there is no enforcement mechanism and no deadline for utilities, financial institutions, and telecom providers that adversaries are also targeting today.

What your agency should do now

PQC migration is fundamentally an infrastructure overhaul, and waiting for final guidance is a luxury agencies cannot afford. To stay ahead of the deadlines, IT and security leaders should prioritize the following actions:

  1. Appoint accountability immediately: Establish your PQC Migration Lead this week to ground subsequent inventory and planning efforts. The 30-day clock started June 22. Designating ownership is the fastest action you can take and the one that makes every subsequent step possible.
  2. Start your cryptographic inventory now: Discovery is the longest phase; do not wait for CISA’s CBOM guidance. Use the 270-day window to begin cataloguing where RSA, ECC, and other quantum-vulnerable algorithms live in your HVAs and high impact systems. 
  3. Audit your hardware authentication layer: PQC migration is not only a software problem. Hardware security keys, smart cards, and tokens used in your authentication stack need to support PQC algorithms ML-KEM and ML-DSA. Evaluate whether your current hardware is updatable or will require replacement before 2030.
  4. Assess your contractor cryptographic posture: Identify covered contractors whose systems touch your HVAs. The 2030 FAR rule will require their compliance — and aligning vendors takes longer than aligning your own agency.
  5. Plan for the CMVP queue: Identify which cryptographic modules you will need and check their validation status today. If they are not yet validated, factor that lead time into your 2030 plan.

In 2026, harvest-now-decrypt-later is not a theoretical threat model – it is an active collection. The encryption protecting your agency’s most sensitive data has a timer on it, and EO 14409 sets the policy. Execution is your agency’s responsibility.

As a trusted leader in high-assurance identity and cryptographic standards, Yubico is dedicated to helping organizations future-proof their security architecture against quantum threats. Securing the federal enterprise requires a robust combination of data encryption and resilient human authentication. Reach out to our team for questions and to see how you can get started today.