Collocated
Events

Y2Q Summit News

July 14, 2026

The 30-Day Deadline Nobody's Talking About But Should


Everyone is fixated on 2030 and 2031 as the quantum migration deadlines. Those are the last things that happen, not the first. The White House's June 22 executive orders set off a cascade of near-term obligations — and the very first one, naming an agency PQC migration lead, is due this week. If you run cryptography anywhere in a federal supply chain, the clock started when nobody was watching.


The number that matters isn't 2030. It is 30 days.

On June 22, 2026, two executive orders reset the federal quantum clock. EO 14413 launched a national push to build a discovery-scale quantum computer. Its companion, EO 14412 “Securing the Nation Against Advanced Cryptographic Attacks,” did something quieter and, for anyone in security, far more consequential: it put hard dates on post-quantum cryptography (PQC) migration and pulled them years ahead of the old 2035 target.

The headline numbers are real:

  • Dec 31, 2030 — high-value assets and high-impact systems must transition to PQC for key establishment (the part that keeps data confidential).
  • Dec 31, 2031 — the same systems must transition for digital signatures (the part that proves a message or system is who it claims to be).

But here's the trap: everyone is planning backward from 2030. That is the wrong end of the timeline. The deadlines are the last thing that happen. The obligations start almost immediately.

The cascade nobody put on a calendar.

Read the order as a countdown, not a due date. The first deadline isn't three-and-a-half years out. It's a personnel assignment due within a month of signing — and for most agencies, that window closes this week.

Why this reaches far past the .gov boundary?

If you're thinking, "I'm not a federal agency, this isn't my problem," look again at the contractor line. The FAR Council has 180 days to publish a proposed rule requiring covered contractors to comply with NIST PQC-related FIPS standards by Dec 31, 2030. The Pentagon has gone further, publishing a 25-page PQC strategy that will bake quantum-resistant requirements into CMMC — meaning the entire defense industrial base inherits the timeline whether it's ready or not.

It isn't only Washington driving the clock. On July 7, the European Central Bank told the CEO of every significant institution that PQC adoption "must start now," turning what was once advice into a supervisory expectation. Microsoft pulled its own quantum-safe deadline forward to 2029.

The reason for the urgency: harvest now, decrypt later.

The order names the threat directly — "adversaries collecting United States information now and decrypting it later once large-scale quantum computers are operational. The data being exfiltrated today with a 20-year sensitivity horizon is already lost if it isn't quantum-safe. That's why the ECB called the harvest-now, decrypt-later risk "no longer theoretical" and why AWS's plan to put hundreds of logical qubits on Braket by 2028 shortens every organization's runway.

The takeaway

The 2030 deadline is a milestone. The 30-day deadline is a starting gun. If you lead security at an agency, a contractor, or any organization that touches a federal or financial supply chain…

The question this week is not "how do we get to 2030?" It is "who owns this, and have we named them yet?"

The organizations that treat July 2026 as the start of the work — not December 2029 — are the ones that will still have a migration plan instead of a compliance emergency.




Edited by Erik Linask

Get stories like this delivered straight to your inbox. [Free eNews Subscription]


More News

#TECHSUPERSHOW MEDIA SPONSORS