← All countries

United States

NIST bloc Standard-maker

The United States sets the global pace through NIST, which has published the first three final post-quantum standards (FIPS 203, 204 and 205) and selected HQC as a fifth algorithm to follow. A June 2026 executive order now directs an accelerated nationwide migration, requiring federal High Value Assets and high-impact systems to move key establishment to the NIST standards by the end of 2030 and digital signatures by 2031, with the Office of Management and Budget, the National Cyber Director, NIST, NSA and CISA tasked to deliver implementation guidance. CISA, the NSA, DHS and the Treasury direct agencies, critical infrastructure and the financial sector to inventory and migrate their cryptography, while National Security Systems follow the NSA CNSA 2.0 suite with full migration targeted by 2035. There is no economy-wide private-sector mandate.

Governance credibility

Governance credibility for United StatesA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 2.0 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for United States, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness2.0 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NSM-10 (2022) national Binding law
  • OMB M-23-02 cryptographic inventory (2022) national Binding law
  • Executive Order 14144 (2025; amended by EO 14306) national Binding law
  • Executive Order Securing the Nation Against Advanced Cryptographic Attacks (2026) national Binding law
  • FIPS 203/204/205 via CMVP validation for federal procurement national Binding (market access)
  • CNSA 2.0 for national security systems national Binding law

Federal agencies must inventory their cryptography, report annually, and migrate to the NIST FIPS algorithms on the mandated timelines; national security systems follow CNSA 2.0. There is no economy-wide private-sector mandate.

Standards and algorithms

Standard families
NIST FIPS 203, FIPS 204, FIPS 205
Algorithms
ML-KEM, ML-DSA, SLH-DSA, HQC

Hybrid stance

None stated

Migration timeline

today
2025
2030
2031
2035
20252036
  1. 2025Federal agencies take preparatory post-quantum transition actions (Executive Order 14144)
  2. 2030Federal High Value Assets and high-impact systems migrate key establishment to the NIST post-quantum standards
  3. 2031Federal High Value Assets and high-impact systems migrate digital signatures to the NIST post-quantum standards
  4. 2035National Security Systems complete migration to CNSA 2.0

Target completion: 2035

International standards processes

  • NIST PQC Standardization runs the process

Governmental and standards bodies

  • NIST National Institute of Standards and Technology, runs the post-quantum standardisation process
  • CISA Cybersecurity and Infrastructure Security Agency, leads migration guidance for critical infrastructure
  • NSA National Security Agency, sets CNSA 2.0 requirements for National Security Systems
  • DHS Department of Homeland Security, transition preparation guidance
  • OMB Office of Management and Budget, issues the binding federal migration memoranda
  • ONCD Office of the National Cyber Director, coordinates federal implementation of the post-quantum migration
  • U.S. Department of the Treasury financial-sector quantum risk guidance directing institutions to the NIST standards
  • GAO Government Accountability Office, oversight of the federal quantum threat mitigation strategy and migration cost

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →