Video companion
After CISA: federal PQC migration playbook for private sector
CISA's PQC initiative and industry panels stress the same message: start migration planning now, prioritize discovery, and treat HNDL as a present-day risk.
What the guidance gets right
CISA's PQC initiative aligns public and private sector migration:
- HNDL is the primary justification for acting now — not waiting for quantum computers to appear in headlines.
- Hybrid approaches combine classical and PQC algorithms during transition to avoid security regressions.
- Automated discovery replaces manual spreadsheets for crypto inventory.
The CISA quantum readiness factsheet summarizes migration steps for executives. NSM-10 and CNSA 2.0 add national-security timelines contractors must track.
The embedded panel discussion covers NIST's three finalized algorithms and DNS/routing implications.
What it does not cover
Policy documents define "what"; your program needs signed evidence of "done." CBOM exports and verify links support audit conversations without claiming formal attestation.
This quarter
- Distribute the CISA factsheet to GRC and infrastructure leads.
- Automate external TLS inventory with algorithm classification.
- Map findings to CNSA 2.0 tiers if you serve federal customers.
Continue on the Q-Day hub: PQC deadlines guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- CISA Post-Quantum Cryptography InitiativeCISA · 2024US government guidance on quantum risk, migration planning, and PQC adoption.
- CISA Quantum Readiness: Migration to Post-Quantum CryptographyCISA · 2024Executive factsheet on PQC migration steps for public and private sector organizations.
- National Security Memorandum on Post-Quantum Cryptography (NSM-10)White House · 2022-05Federal mandate requiring migration away from quantum-vulnerable algorithms by 2035.
- Commercial National Security Algorithm Suite 2.0 (CNSA 2.0)NSA · 2022NSA migration tiers for national security systems through 2030–2033.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.