惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

H
Help Net Security
The GitHub Blog
The GitHub Blog
F
Fortinet All Blogs
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
Simon Willison's Weblog
Simon Willison's Weblog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
Cisco Talos Blog
Cisco Talos Blog
P
Privacy & Cybersecurity Law Blog
I
Intezer
Y
Y Combinator Blog
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
N
Netflix TechBlog - Medium
The Hacker News
The Hacker News
AWS News Blog
AWS News Blog
aimingoo的专栏
aimingoo的专栏
A
About on SuperTechFans
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Stack Overflow Blog
Stack Overflow Blog
Hacker News: Ask HN
Hacker News: Ask HN
酷 壳 – CoolShell
酷 壳 – CoolShell
量子位
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
B
Blog
T
Tor Project blog
C
Cybersecurity and Infrastructure Security Agency CISA
云风的 BLOG
云风的 BLOG
博客园_首页
V2EX - 技术
V2EX - 技术
T
Threat Research - Cisco Blogs
腾讯CDC
宝玉的分享
宝玉的分享
博客园 - 叶小钗
罗磊的独立博客
S
Securelist
The Last Watchdog
The Last Watchdog
Google Online Security Blog
Google Online Security Blog
Scott Helme
Scott Helme
博客园 - 司徒正美
W
WeLiveSecurity
有赞技术团队
有赞技术团队
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Secure Thoughts
NISL@THU
NISL@THU
N
News and Events Feed by Topic
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
雷峰网
雷峰网
大猫的无限游戏
大猫的无限游戏
K
Kaspersky official blog
IT之家
IT之家

Featured Blogs - Forrester

Inclusive Design Is Automotive’s Overlooked Growth Opportunity B2B Social Media Influencers Have More Influence Than Ever Comcast Split Puts NBCUniversal In Play What Technology Leaders Should Not Miss At Technology & Innovation Forum Central Why Your AI Strategy Needs A DEXM Solution: Lessons From Nexthink Masters Of Experience The Dawn Of The Accidental Developer The Next Era Of B2B Events: 8 Data-Backed Shifts Defining 2026 The Next Era Of B2B Events: Eight Data-Backed Shifts Defining 2026 Identiverse 2026 Recap: Identity Security for Agentic AI Dominates Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And…AI Announcing The Forrester Wave™ On Extended Detection And Response Platforms: Platformization, AI, And … AI Use EO 14409 As A Canary For Enterprise PQC Migration And Procurement EO 14409 Makes PQC Migration A Multi-Year Operational Program For Federal Security Leaders New Executive Order Makes PQC Migration A Multiyear Operational Program For Federal Security Leaders AI Is Moving Fast, But Trust Is Struggling To Keep Up: Why Security And Risk Leaders Can’t Miss Forrester’s AI Forum Answer Engines Will Select Your Content. Your Digital Experience Has To Do More. Meta Gambles With Its Trust In Prediction Markets The EU’s Digital Markets Act Meets The Mobile OS, Round 2 Don’t Just Hear About The IT Singularity — Work Through It At Our Austin Tech Forum Don’t Just Hear About The IT Singularity — Work Through It At Our NYC Tech Forum The Cost Of AI Productivity Is Less Creativity Dollars And Sense At FinOps X 2026: Is AI Value Management Bigger Than FinOps? Quantum Security Is No Longer Optional: A Practical Blueprint For Successful Implementation The AI Orchestration Layer In Banking Is The New Battleground The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing The Canary in the CDP Mine: Databricks CustomerLake Is The Litmus Test For Agentic Marketing AI Forces A Redesign Of How Marketing And Agencies Work The IT Singularity Is Here: Announcing Forrester’s 2026 Technology Events Nuvei Makes Its B2B Cross-border Payment Move: The Payoneer Acquisition Google Dethrones OpenAI As Agencies’ Preferred AI Partner When Algorithms And LLMs Become Sellers, Your Commerce Strategy Must Change Google Goes All-In: An AI-Operated System, Not AI-Assisted Products Cisco’s Platform Push: Big Vision, Real Questions Retail's Incremental Total Experience Shift: Select Brands See Significant Improvement It's Time To Elevate Journeys Into Decision Systems AI Agents Need Real-Time Context: Data Streaming Is How You Are Going To Get It Tackle Enterprise AI’s Hardest Question At Forrester’s AI Forums Building The Human Foundation For AI At CX Forum East What Separates Scalable AI-Driven Innovation From Promising Experiments Hyland CommunityLive 2026: A Call To Action for Enterprise Content Management Leaders Call For Entries: Forrester’s B2B Forum EMEA 2026 Awards AI Agents Are Your New Customer. But Can You Target and Grow Their Trust in Your Brand? Survey Insights: How Business Applications Are Purchased Governance: New Strategy, Old Hands On The Wheel … US Health Insurers Show Experience Improvements Announcing The 2026 Forrester Wave™ On Accounts Payable Invoice Automation Announcing The Forrester Wave™: Accounts Payable Invoice Automation Software, Q2 2026 US Banks’ Total Experience Is Improving, But Most Still Have Work To Do UK Social Media Ban Forces Platform Accountability Total Recall: A Cautionary Fable Of Anthropic And The US Government Consumers Aren’t Ready To Delegate Payments To AI Agents Fox Makes $22B Roku Acquisition Bet Secure The Future Of Internet Traffic As Agents Take Over Coupa’s Inspire 2026 Unveils A Strategy And Acquisition Spree To Build The Autonomous Spend Management “Network” A Fake PLG Strategy Is Exposed Through Your Digital Commerce Experiences Conway’s Law: Your Operating Model Matters More Than The AI Model Turn Application Portfolio Rationalization Into A Continuous Optimization Capability Healthcare And Life Sciences: Turning AI Momentum Into Lasting Value How To Build A Loyalty Team That Scales With Your Program Align B2B Marketing Teams To Thrive In A Buyer-Centric World OpenAI’s Proposed IPO Opens A Trifecta Of Opportunities For It, But Don’t Lock In Just Yet Retention-As-A-Service Is An Intriguing Idea — Here’s What It Actually Means Customer Success And Customer Experience: The Difference Is More Than Semantic How Fable 5 And Mythos 5 Change AI Security, Data Retention, And Vendor Risk Announcing Forrester’s Top Cybersecurity Threats For 2026 Your AI Bill Is A Context Problem Build The Human Foundations Before You Scale AI The State Of Agentic AI In 2026: Companies Are Chasing, Few Are Catching Move Over WAF. The Web Application Protection Platform Takes Over Microsoft Build 2026: Pushing The Frontier With A More Opinionated AI Playbook Anthropic’s Proposed IPO Will Change The Economics Of Enterprise AI AI Is Forging A New RevOps Identity AI Is Forging A New RevOps Identity Build Meaning Before Machines: Why Semantics, Ontologies, And Knowledge Graphs Matter For Agentic AI Red Hat Summit 2026: Can Red Hat Win Its Claim As The Hybrid AI Control Plane? Ad Creative Is A Technology Problem And Opportunity The State Of Portfolio And Product Marketing In 2026 Miro’s Big Bet: Can A Whiteboard Company Become The AI Decisioning Layer For The Enterprise? Agents Are In The Aisle: The 2026 NRF APAC Innovators To Watch Italy’s B2B Marketing Challenge Is Not Strategy — It’s Focus And Alignment If Buyers Change How They Search, Marketing Must Change How It Shows Up European B2B Marketing Has A Data Problem, Not A Vision Problem The AppGen And Low-Code Platforms Landscape, Q2 2026, Is Out! What Anthropic’s Two Recent Announcements Mean For Manufacturers Agentic AI In Insurance: Stop Chasing Autonomous Agents. Start Engineering Trust. The Consolidation Wars: M&A Is Rewriting Finance Automation Seven Ways To Turn CX Forum East Analyst Time Into Real Momentum Seven Ways To Turn CX Forum West Analyst Time Into Real Momentum Leading With Intention: What Women Leaders Told Us About AI And The Future Of Work Redesign B2B2C Digital Strategy For The AI Era Marketplace Platforms Aren’t One Market Anymore: Announcing Forrester’s Two Landscapes For 2026 The State Of Agentic Commerce In Mid-2026 If Your Employees Aren’t Ready For AI, Neither Is Your Business Announcing The Forrester Wave™: Governance, Risk, And Compliance Platforms, Q2 2026 Financial Well-Being Is Under Pressure — A Strategic Priority For Banks TeamViewer Connect: A Pragmatic Look At How IT Can Level Up DEX Freshworks Signals A More Practical Future For AI Service Management Zendesk Relate 2026 Showed Why Agentic Customer Service Starts With Knowledge
Use The New Executive Order As A Canary For Enterprise PQC Migration And Procurement
Heidi Shey · 2026-06-25 · via Featured Blogs - Forrester

On June 22, 2026, the White House issued a new executive order (EO), Securing the Nation Against Advanced Cryptographic Attacks. While it has direct implications for federal agencies, there are parts that are worth paying attention to for enterprise security and risk leaders. Here’s what’s worth your attention, whether or not you hold a federal contract.

You Now Have A Clear Operating Assumption With An Accelerated Timeline

The order opens with the concept of harvesting now, decrypting later as its rationale — referring to adversaries collecting encrypted sensitive data today to decrypt it once large-scale quantum computers exist. It commits the US government to migrating to the National Institute of Standards and Technology’s (NIST’s) post-quantum cryptography (PQC) standards by the end of 2030 for key establishment and by the end of 2031 for digital signatures for high-value assets and high-impact systems. This is a notable departure from the previous target of 2035 across federal systems overall.

What this means: The “Should we start now?” debate is settled for any organization sitting on data with a long confidentiality shelf life. The order generates greater urgency surrounding this risk. Data exfiltrated today is exposed the day a cryptographically relevant quantum computer arrives (Q-day!) — and you don’t control when that is. Determine the shelf life of your sensitive data. What holds longer-term value is specific to your organization — from source code and health and biometric records to authentication credentials and trade secrets. Identify where long-lived sensitive data intersects with vulnerable public-key cryptography, external exposure, and third-party dependencies.

The FAR Rule Has Takeaways For Noncontractors, Too

Section 6 directs the Federal Acquisition Regulatory Council to publish a proposed rule to amend the Federal Acquisition Regulation (FAR) within 180 days, requiring covered contractors to comply by December 31, 2030 with NIST’s Federal Information Processing Standards (FIPS) — including the PQC-compliant algorithms. This deadline isn’t unique: Other governments internationally have mandated similar timelines for PQC migration.

What this means: Even if you don’t sell to the federal government, you should treat 2030 (for key establishment) and 2031 (for digital signatures) as the de facto benchmark for your own security program. Named deadlines for PQC migration from governments will influence regulatory and sector-specific deadlines, as well as third-party partner requirements and technology vendor roadmaps. If you sell to the federal government, PQC becomes a contract term with a date attached. The proposed rule — not the final rule — is the thing to watch, because that’s where scope and definitions get set. File your comments while they still count.

CBOMs Will Be SBOMs’ Sequel

Section 5 directs the Cybersecurity and Infrastructure Security Agency (CISA) and NIST to publish, within 270 days, the minimum elements for a cryptographic bill of materials (CBOM), which is a structure designed to let you automatically assess the cryptographic assets inside a piece of hardware or software. This starts us down the path for a new vendor risk management and procurement requirement.

What this means: You can’t migrate what you can’t see, and most enterprises have no current inventory of where and how cryptography is used across their environment. The CBOM will help. Even more important to note: The software bill of materials (SBOM) made after the 2021 cybersecurity EO went from being a niche artifact to a procurement expectation. If you sell hardware or software, stay tuned for the published elements to come so that you’ll be able to produce a CBOM for buyers. Today, we see open-source solutions like CBOMkit from IBM Research leading CBOM creation. Your own third-party risk management processes must include revising SLAs and procurement agreements to ask vendors to disclose their own products’ CBOMs. CBOMs for legacy hardware will likely be unobtainable and will either require a waiver, hardware replacement, or firmware upgrade.

Your Vulnerability Disclosure Now Covers Weak Cryptography

Section 6 also directs the Federal Acquisition Regulatory Council to propose, within 270 days, rules that require covered contractors’ vulnerability disclosure programs (VDPs) to capture cryptographic vulnerabilities — explicitly including testing for the absence of encryption and the use of non-FIPS-approved algorithms.

What this means: “We didn’t encrypt that” and “We used a non-approved algorithm” move from being audit findings to reportable vulnerability classes. Cryptographic hygiene is now a continuous vulnerability-management best practice rather than a periodic compliance check. If you run a VDP or a bug bounty, your scope, intake, and triage logic need to account for cryptographic findings and your remediation SLAs need a place to put them. This raises the bar for your security vendors, as well; begin to assess this as a part of your procurement due diligence going forward. These disclosures will likely extend to areas including identity access management, customer identity access management, tokenization, data protection, unified messaging, and other domains.

Critical Infrastructure Gets A Partner, Not A Mandate — Yet

Section 5 directs every federal agency that serves as a Sector Risk Management Agency to work through CISA to help critical infrastructure owners and operators build their PQC migration plans.

What this means: If you’re a security leader for a utility, hospital system, bank, pipeline, wastewater system, or any other critical infrastructure operator, take note. Your sector agency and CISA are now tasked with assisting you in developing your PQC migration plans. Watch to see if any assistance in the form of “voluntary” sector guidance comes through, which may eventually turn into a baseline that regulators and insurers later expect. Engage early so you have greater input in shaping your migration plan. Start with identifying and prioritizing critical and high-consequence functions: remote access into OT environments, identity and certificate infrastructure, encrypted data flows between operators and third parties, firmware and software signing, backup and recovery systems, and communications tied to incident response or safety operations.

Assemble Your Team For PQC Migration

The federal government is treating PQC as an execution program, not a standards update. Enterprises should do the same. The hardest parts will be ownership, sequencing, validation, and dependency management. Cryptographic discovery and inventory will be uncomfortable for many organizations because cryptography is often embedded in products, protocols, libraries, APIs, certificates, hardware security models, identity systems, and vendor-managed services that security teams don’t fully own. Including more PQC questions in RFPs and contract renewals, third-party risk reviews, cyber insurance discussions, and board-level risk conversations also requires coordination with other internal stakeholders.

Ensure that stakeholders recognize that timelines can change. We’ve seen deadlines become progressively more aggressive in the last 18 months, and teams must be prepared for that to continue. Forrester clients can check out the full initiative blueprint to help drive their PQC migration or schedule a guidance session or inquiry with us.