{"id":361669,"date":"2026-06-23T16:30:57","date_gmt":"2026-06-23T23:30:57","guid":{"rendered":"https:\/\/www.paloaltonetworks.com\/blog\/?p=361669"},"modified":"2026-06-23T17:19:36","modified_gmt":"2026-06-24T00:19:36","slug":"new-executive-order-accelerates-post-quantum-readiness-amid-the-cryptographic-reset","status":"publish","type":"post","link":"https:\/\/www2.paloaltonetworks.com\/blog\/2026\/06\/new-executive-order-accelerates-post-quantum-readiness-amid-the-cryptographic-reset\/","title":{"rendered":"New Executive Order Accelerates Post-Quantum Readiness Amid the Cryptographic Reset"},"content":{"rendered":"<p><span style=\"font-weight: 400;\">The <\/span><a href=\"https:\/\/www.whitehouse.gov\/presidential-actions\/2026\/06\/securing-the-nation-against-advanced-cryptographic-attacks\/\" rel=\"nofollow,noopener\" ><span style=\"font-weight: 400;\">White House Executive Order<\/span><\/a><span style=\"font-weight: 400;\"> on securing the nation against advanced cryptographic attacks accelerates the mandatory timeline for post-quantum readiness.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">For years, post-quantum cryptography has been discussed as an important, yet abstract future technical migration. Because of the uncertain timeline for quantum computing, it has been difficult for most organizations to prioritize quantum readiness against more immediate security demands.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That is changing.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Signed on June 22, 2026, the Executive Order mandates the transition of federal information systems to post-quantum cryptography and establishes a national policy to migrate them to NIST-approved standards. It also extends the urgency beyond government by directing support for critical infrastructure owners and operators, advancing requirements for federal contractors, and calling for cryptographic bill of materials guidance.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The order directly addresses harvest now, decrypt later risk and sets transition milestones for federal high-value assets and high-impact systems: 2030 for key establishment and 2031 for digital signatures.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">While the order directly applies to U.S. Federal civilian agencies, it should be seen as a signal of broader policy and procurement momentum. Organizations that do business with the government, support critical infrastructure, or operate in regulated industries such as energy, financial services, and healthcare should expect post-quantum readiness expectations to accelerate.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Quantum risk has shifted from a long-term research concern to a national cybersecurity priority tied to sensitive data, critical infrastructure, federal systems, procurement, and the broader digital economy. For security teams, the challenge now is turning that urgency into an operational plan.<\/span><\/p>\n<h2><b>Operationalizing the quantum mandate<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">As quantum computing advances, widely used public-key cryptography will become vulnerable to future attacks. Even before a cryptographically relevant quantum computer exists, adversaries can capture encrypted data now with the goal of decrypting it later.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This \u201charvest now, decrypt later\u201d risk is especially concerning for organizations that protect sensitive information with a long shelf life. The response cannot wait until the threat fully materializes.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The broader ripple effect matters because compliance alone will not equal readiness. As requirements flow into federal acquisition rules and contractor obligations, the vendor ecosystem will be pushed to support quantum-safe capabilities in the products and services that enterprises, critical infrastructure organizations, and regulated industries rely on.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Adding support for post-quantum algorithms is not the same as safely migrating to them. Support means a system can use new algorithms. Readiness means the organization knows where cryptography exists, which systems are exposed, which dependencies matter most, and how to execute changes without creating disruption or new risk.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">That matters because post-quantum migration can affect more than cryptographic libraries. Larger cryptographic objects, new protocol behaviors, hybrid modes, hardware acceleration requirements, interoperability constraints, and legacy system limitations can create real performance, availability, and compatibility challenges if changes are made blindly.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">This is why cryptographic visibility must lead to actionable migration planning.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Security teams cannot migrate what they cannot see. But visibility by itself is not enough. They also need to classify exposure, prioritize high-value systems and long-lived data, understand operational dependencies, and plan changes in a way that avoids disruption, downgrade risk, or incomplete migration.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Cryptographic bill of materials guidance will be an important step toward mapping cryptographic assets. But a CBOM should be the starting point, not the finish line. An inventory can show where cryptography exists, but readiness requires understanding business impact, migration complexity, interoperability risk, ownership, and the order in which changes should happen.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">Post-quantum readiness is not just an algorithm swap. It is an operating model for managing cryptographic change at scale.<\/span><\/p>\n<h2><b>Five actions for post-quantum readiness<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The path forward starts with five practical actions.<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>First, see cryptographic exposure<\/b><span style=\"font-weight: 400;\">. Organizations must gain visibility into cryptographic usage across all environments to mitigate the risks associated with undocumented encryption.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Second, prioritize what matters most. <\/b><span style=\"font-weight: 400;\">Cryptographic exposure varies in urgency. Organizations should prioritize protecting authentication, high-value assets, and long-lived sensitive data based on risk and business impact.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Third, modernize trust infrastructure. <\/b><span style=\"font-weight: 400;\">Existing systems rely on fixed cryptographic assumptions. Post-quantum readiness demands flexible infrastructure and trust services that support evolving standards.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Fourth, automate cryptographic change. <\/b><span style=\"font-weight: 400;\">Manual tracking with spreadsheets provides an incomplete, point-in-time snapshot that quickly becomes outdated and is insufficient for the coming changes. Automation allows organizations to manage cryptographic updates and trust operations in a consistent, controlled manner.<\/span><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><b>Fifth, govern readiness over time.<\/b><span style=\"font-weight: 400;\"> Post-quantum migration requires continuous governance to track progress, align ownership, and adapt to evolving threats and standards.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400;\">These actions help security leaders move from awareness to readiness.<\/span><\/p>\n<h2><b>What this means for cybersecurity now<\/b><\/h2>\n<p><span style=\"font-weight: 400;\">The Cryptographic Reset is already underway, driven by post-quantum risk, shorter certificate lifecycles, machine identity growth, fragmented cryptographic ownership, CA distrust events, and expanding digital infrastructure.<\/span><\/p>\n<p><span style=\"font-weight: 400;\">The organizations that move first will not simply be the ones that adopt new algorithms the fastest. They will be the ones that build the visibility, operating model, and governance needed to manage cryptographic change continuously.<\/span><\/p>\n<h2><b>Take the next step<\/b><\/h2>\n<p><a href=\"https:\/\/www.paloaltonetworks.com\/resources\/guides\/the-post-quantum-readiness-race-is-on\"><span style=\"font-weight: 400;\">Read the guide:<\/span><\/a><span style=\"font-weight: 400;\"> The Post-Quantum Readiness Race Is On: Five Actions Security Leaders Can Take to Accelerate Crypto Agility.<\/span><\/p>\n<h2><b>More resources<\/b><\/h2>\n<ul>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><span style=\"font-weight: 400;\">Blog: <\/span><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2026\/03\/cryptographic-reset-has-begun\/\"><span style=\"font-weight: 400;\">The Cryptographic Reset Has Begun<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.paloaltonetworks.com\/quantum-safe\"><span style=\"font-weight: 400;\">Watch: Palo Alto Networks Quantum<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2025\/08\/paves-way-for-quantum-ready-security\/\"><span style=\"font-weight: 400;\">Blog: Palo Alto Networks Leads the Way with Quantum and Multicloud Security<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2026\/01\/introducing-quantum-safe-security\/\"><span style=\"font-weight: 400;\">Blog: Introducing Palo Alto Networks Quantum-Safe Security<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.paloaltonetworks.com\/blog\/2025\/08\/securing-the-quantum-age\/\"><span style=\"font-weight: 400;\">Blog: Palo Alto Networks Announces New Quantum Security Innovations<\/span><\/a><\/li>\n<li style=\"font-weight: 400;\" aria-level=\"1\"><a href=\"https:\/\/www.paloaltonetworks.com\/company\/press\/2025\/palo-alto-networks-delivers-enterprise-wide-quantum-security-readiness-for-all-customers\"><span style=\"font-weight: 400;\">Press Release: Palo Alto Networks Delivers Enterprise Wide Quantum Security Readiness for All Customers<\/span><\/a><\/li>\n<\/ul>\n","protected":false},"excerpt":{"rendered":"<p>The White House Executive Order on securing the nation against advanced cryptographic attacks accelerates the mandatory timeline for post-quantum readiness. For years, post-quantum cryptography has been discussed as an important, yet abstract &hellip;<\/p>\n","protected":false},"author":840,"featured_media":361671,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_memberships_contains_paid_content":false,"footnotes":""},"categories":[308,155,6724],"tags":[9722],"coauthors":[7076],"class_list":["post-361669","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-announcement","category-cybersecurity","category-points-of-view","tag-quantum-security"],"jetpack_featured_media_url":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-content\/uploads\/2026\/06\/Quantum_readiness_blog_featured-scaled.jpeg","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/361669","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/users\/840"}],"replies":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/comments?post=361669"}],"version-history":[{"count":2,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/361669\/revisions"}],"predecessor-version":[{"id":361684,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/posts\/361669\/revisions\/361684"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media\/361671"}],"wp:attachment":[{"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/media?parent=361669"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/categories?post=361669"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/tags?post=361669"},{"taxonomy":"author","embeddable":true,"href":"https:\/\/www2.paloaltonetworks.com\/blog\/wp-json\/wp\/v2\/coauthors?post=361669"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}