United States Policy on Encryption Upgrades

Explore top LinkedIn content from expert professionals.

Summary

The United States policy on encryption upgrades refers to government-driven initiatives and regulations that require organizations to transition from current encryption methods to quantum-resistant alternatives, in order to protect sensitive data against the future threat posed by quantum computers. These upgrades aim to safeguard national security, critical infrastructure, and business communications from "harvest now, decrypt later" attacks and ensure systems stay secure as technology evolves.

  • Inventory cryptographic assets: Start by identifying where encryption is used across your organization, including legacy systems and third-party integrations, to understand which areas need upgrading.
  • Develop migration plans: Create a prioritized roadmap to transition vulnerable systems to quantum-resistant cryptography, factoring in business impact, upgrade feasibility, and vendor dependencies.
  • Build crypto agility: Design IT and security architectures that can quickly swap encryption algorithms as new standards emerge, allowing you to respond to changing threats without major disruptions.
Summarized by AI based on LinkedIn member posts
  • View profile for Keith King

    Former White House Lead Communications Engineer, U.S. Dept of State, and Joint Chiefs of Staff in the Pentagon. Veteran U.S. Navy, Top Secret/SCI Security Clearance. Over 20,000+ direct connections & 55,000+ followers.

    55,502 followers

    Headline: Quantum Threats Extend to Orbit as Space Systems Face Urgent Security Overhaul Introduction: The approaching “Q-Day,” when quantum computers can break current encryption, is no longer theoretical. Experts warn that space systems—long considered secure by distance—are now highly exposed, forcing governments and industry to accelerate a complex transition to post-quantum cryptography. Key Developments: Breaking the Illusion of Space Security Recent cyber incidents, including satellite hacks and data interceptions, prove space is not inherently secure Adversaries can already intercept and store satellite communications for future decryption Threats include spoofing, jamming, command hijacking, and denial-of-service attacks Quantum Race and Strategic Risk U.S. and China are competing to achieve quantum breakthroughs with national security implications Concerns persist that China may gain a first-mover advantage while obscuring progress Q-Day could render current encryption across space and terrestrial systems obsolete Mandated Transition to Post-Quantum Security U.S. policy requires migration to quantum-resistant cryptography under CNSA 2.0 Deadlines: quantum-secure systems by 2035, with major milestones in 2025 and 2027 NIST standardized key algorithms in 2024, enabling immediate transition efforts Operational Challenges in Space Space systems face constraints in size, weight, power, and compute capacity Post-quantum keys are larger, complicating deployment in constrained environments Satellites have long lifecycles, making hardware upgrades difficult or impossible Emerging Solutions and Industry Response Emphasis on crypto agility to enable software-based updates without hardware replacement Manufacturers are embedding post-quantum security directly into hardware and onboard systems New quantum-secure space infrastructure, including routers and communication modules, is under development Immediate Risk Factors “Harvest now, decrypt later” exposes sensitive data already in transit or storage Side-channel attacks and key extraction are already feasible in some scenarios Delay in migration increases long-term exposure and potential mission compromise Why It Matters: Space is now a contested digital domain where encryption integrity underpins national security, economic infrastructure, and military operations. The transition to post-quantum cryptography is not optional—it is a strategic imperative. Organizations that fail to act risk systemic vulnerability across satellite networks that cannot be easily repaired once deployed. The broader implication is clear: future resilience will depend on proactive architecture, crypto agility, and the ability to secure systems against threats that have not fully materialized—but are already inevitable. I share daily insights with tens of thousands followers across defense, tech, and policy. Keith King https://lnkd.in/gHPvUttw

  • View profile for Aus Alzubaidi

    Group CIO & CISO | Enterprise Technology & Transformation | Cybersecurity, AI, Cloud & Mission-Critical Platforms

    30,092 followers

    A lot of post-quantum cryptography advice sounds like either panic or a sales pitch. Here is the practical version after a year of hearing many of the same questions from enterprise technology and cybersecurity teams. The questions that keep coming up: “Quantum computers are nowhere near breaking RSA. Isn’t this ten years away?” Possibly. Nobody can give you an exact date. But that is the wrong planning question. A cryptographically relevant quantum computer does not exist today and a large enterprise cannot discover, replace, test and migrate all its cryptography in a few months either. “Is the risk already here because attackers can harvest encrypted data now and decrypt it later?” For some organizations, yes. If your data must remain confidential for ten or twenty years, the exposure window may already have opened. “Will every encrypted database and Bitcoin wallet suddenly be exposed?” No. That is an oversimplification. The primary exposure is in public-key cryptography such as RSA and elliptic-curve cryptography. Symmetric encryption has a different risk profile and Bitcoin is more nuanced than the headlines suggest. “So should we start buying quantum-safe products now?” Also no. Start with visibility. Build a living inventory of where cryptography actually sits. The biggest dependencies are often the least visible: code signing, machine identities, embedded devices, legacy integrations and third-party products with unclear ownership. Then rank the risk. Which data must remain protected longest? Which systems cannot be upgraded easily? Which vendors control your migration timeline? Ask your cloud, identity, PKI, HSM, network and application providers, for real roadmaps. Which standards will they support and in which release? Will they offer hybrid cryptography during the transition? Which hardware, certificates and integrations will need replacing & what may break? From there, create a risk-based migration pipeline and build crypto-agility into the cloud, identity, application and infrastructure programs already underway. This is why the latest US and UAE moves matter. On 24 June, the US OMB gave federal agencies 120 days to submit PQC migration plans. The initial work focuses on governance, inventory, discovery and prioritization before wider migration begins. The UAE is moving in the same practical direction. The National Encryption Policy requires approved transition planning, while the UAE Cyber Security Council, Technology Innovation Institute and QuantumGate are advancing national readiness, cryptographic discovery and implementation capability. My view is simple. Do not panic. Do not wait. And do not buy a product because “quantum-safe” is written on the slide. Before debating when quantum may break RSA, calculate how many years your organization will need to find and safely replace vulnerable cryptography without breaking the business. That timeline may be the bigger risk. Sources are in the first comment.

  • View profile for Anna Ribeiro

    News Editor at Industrial Cyber

    26,306 followers

    The U.S. White House issued on Monday two executive orders, ‘Securing the Nation Against Advanced Cryptographic Attacks’ and ‘Ushering in the Next Frontier of Quantum Innovation,’ aimed at strengthening the country’s position in the quantum era by pairing long-term technology investment with urgent #cybersecurity safeguards. Together, the orders outline a dual-track strategy: accelerating domestic quantum research, infrastructure, and workforce development while preparing federal systems for the security risks posed by increasingly advanced cryptographic attacks. A central focus of the new directives is the growing threat that quantum computing could render current encryption methods obsolete, exposing sensitive government, enterprise, and critical infrastructure data to future compromise. By combining broader quantum innovation policy with mandates to accelerate post-quantum cryptography adoption, the administration signals that cybersecurity has become inseparable from quantum strategy, as agencies race to defend against ‘harvest now, decrypt later’ attacks and secure critical digital assets against next-generation threats. Commenting on the executive orders, Henry Young, BSA senior director of policy, wrote in an emailed statement that these executive orders advance many of the priorities BSA has highlighted in its quantum policy work, including the need for a refreshed national #quantumstrategy, stronger public-private collaboration, greater focus on commercialization and deployment, coordinated government leadership, working with like-minded partners, enhanced protection of critical #quantumresearch and supply chains, and the upgrade to post-quantum #cryptography. He added that the order’s direction to update the National Quantum Strategy, establish agency roadmaps, expand public-private partnerships, and reconstitute the National Quantum Initiative Advisory Committee, as well as updating the timelines for government agencies to upgrade to #PQC, will help create a more coordinated framework for advancing quantum innovation as well as a safer and more secure nation. “This executive order sends an unambiguous signal to every organization doing business with the federal government: the clock is ticking and maybe running out for some. The 2030 deadline for key establishment is a tangible compliance deadline, and the gap between where most organizations are today and where they need to be is significant,” Garfield Jones, D.Eng., executive vice president for strategy and research at QuSecure, wrote in an emailed statement. “Agencies and contractors that haven’t started a cryptographic inventory are already behind. The organizations that move now will have options. The ones that wait will find themselves managing a crisis.” More at: https://lnkd.in/ehnbF6tg

  • The White House has issued a new Executive Order accelerating the Federal Government's transition to Post-Quantum Cryptography (PQC). In short, this order outlines steps to protect against cryptographic attacks: requiring cryptography inventorying, quantum-vulnerable system identification, building crypto-agility into architectures, vendor compliance steps, and advanced planning initiatives. Today's encryption protects everything from military communications and critical infrastructure to financial transactions and sensitive government data. However, adversaries are currently collecting encrypted information with the expectation that future quantum computers will be able to decrypt it later: "harvest now, decrypt later." Think of this order as changing the locks, not rebuilding the house. The focus is on replacing today's quantum-vulnerable cryptographic algorithms (such as RSA and ECC) with quantum-resistant alternatives before the threat becomes reality. Key actions directed by the Executive Order: • Every Federal agency must designate a Post-Quantum Cryptography (PQC) Migration Lead within 30 days. • Agencies must inventory High Value Assets (HVAs) and High Impact Systems and develop prioritized migration plans. • All Federal HVAs and High Impact Systems must transition to PQC for key establishment and digital signatures. • NIST will continue developing implementation guidance and launch a Federal PQC pilot program. • CISA and Sector Risk Management Agencies will support critical infrastructure owners and operators in developing migration plans. • The FAR will be updated to require covered contractors to comply with NIST-approved PQC standards by 2030. • New requirements will improve visibility into cryptographic assets through cryptographic bills of materials and enhanced vulnerability disclosure programs. This Executive Order establishes a roadmap for securing Federal systems and critical infrastructure against the next generation of cryptographic threats.

  • View profile for Mihaela Curca

    Cybersecurity Project Manager | Researcher | Political analyst | Human

    22,205 followers

    Public Draft “Post-Quantum Cryptography: Migration to Quantum-Resistant Cryptography” It’s published by NIST (National Institute of Standards and Technology) and serves as official U.S. federal guidance for how organizations—especially those in the public sector and critical infrastructure—should plan for and execute a secure migration to post-quantum cryptographic systems. It outlines best practices, strategies, and risk considerations for migrating from classical public-key cryptography (like RSA and ECC) to quantum-resistant (post-quantum) cryptography, due to the future threat posed by quantum computers. 🔹Key topics include: 1. Motivation • Quantum computers, once large and stable enough, will be able to break many of today’s encryption systems. • Organizations must prepare in advance to avoid exposure to “harvest now, decrypt later” attacks. 🔹2. Migration Phases The roadmap proposed by NIST follows a structured lifecycle: • Discovery: Identify where cryptography is used and what algorithms are vulnerable. • Assessment: Evaluate the importance and sensitivity of assets protected by vulnerable cryptography. • Planning: Develop detailed migration strategies. • Implementation: Deploy quantum-resistant algorithms while ensuring interoperability, resilience, and compliance. 🔹3. Risk Management • Encourages organizations to adopt a risk-based approach to migration. • Urges the use of cryptographic agility, i.e., the ability to quickly switch algorithms when needed. 🔹4. Compliance and Governance • Supports U.S. federal mandates and global standardization efforts (especially aligned with NIST’s own PQC standardization process). • Calls for integration with existing cybersecurity frameworks and supply chain management. 🔹Relevance and Domain This document is highly relevant in the following domains: 🔹Public Sector / Government • Federal agencies are the primary audience, but the roadmap sets the tone for all government-affiliated organizations and contractors handling sensitive data. 🔹Cybersecurity & Cryptography • Core guidance for security architects, CISOs, and cryptographic engineers preparing for PQC implementation. 🔹Critical Infrastructure & Industry • Utilities, telecom, finance, and health sectors need to plan their transition to ensure continuity, compliance, and long-term security. 🔹Policy & Compliance • Helps regulatory bodies and enterprise compliance officers understand what will become mandatory in the future (especially in the U.S. and allied nations).

  • View profile for Anthony L.

    CEO, Light Rider Inc. | Ex-NSA | Former US Army

    31,649 followers

    U.S.-Allied Militaries Must Prepare for the Quantum Threat to Cryptography By Edward Parker | Originally published by Just Security, May 28, 2025 Quantum computers could eventually break the cryptographic systems that currently secure everything from personal data to classified military secrets. The NSA (National Security Agency) has been at the forefront of addressing this threat and shaping U.S. policy. NSA’s Position on the Quantum Threat The NSA has publicly warned that adversarial use of quantum computers could be "devastating to National Security Systems and our nation." In response, the NSA has taken a clear stance favoring Post-Quantum Cryptography (PQC) as the primary defense. It explicitly prohibits the use of Quantum Key Distribution (QKD) to secure U.S. national security information, citing cost, complexity, and scalability concerns. Under National Security Memorandum 10, issued by President Biden, the NSA is directing a government-wide upgrade to PQC by 2035. PQC vs. QKD – NSA’s Preference PQC is software-based and aligns with current cryptographic practices. The NSA, through collaboration with NIST, has helped lead the global effort to standardize PQC algorithms. QKD, while promising in theory and backed by nations like China, is seen by the NSA as impractical for widespread defense use due to its reliance on expensive and fragile hardware. International Landscape & NSA Leadership Unlike the NSA, most allied intelligence agencies have not published detailed timelines or implementation strategies for quantum-safe encryption. The UK and France have taken similar positions to the NSA, supporting PQC over QKD, especially for classified military communications. In contrast, countries like Canada, South Korea, and Japan are pursuing both PQC and QKD, potentially creating interoperability challenges. The Call to Action The NSA’s transparent and proactive approach should serve as a model for other allied militaries. Interoperability between allied forces is at risk if nations don’t align on cryptographic defenses. Differing systems (e.g., PQC vs. QKD) may block secure communication between forces. To avoid fragmentation, allied nations should clarify their strategies and coordinate with NSA guidelines—especially regarding the security of shared national security information. Final Thought While quantum attacks may still be years away, the NSA recognizes that adversaries may already be collecting encrypted data to decrypt in the future. The sooner allied militaries follow the NSA’s lead in adopting clear, harmonized post-quantum strategies, the more secure and united the defense alliance will be. https://lnkd.in/eBvjX2EN

  • View profile for Richard Entrup

    Managing Director, Enterprise Innovation & Head of Emerging Solutions at KPMG US | Commercializing Quantum, AI & Frontier Tech | Startup & VC Advisor | Executive Convener | Ecosystem Builder | Gladwell Connector

    13,638 followers

    As quantum computing advances, classical encryption faces new risks, making Post-Quantum Cryptography (PQC) a critical priority. With the US and EU rolling out robust PQC regulations, businesses must act now to secure their data against "harvest now, decrypt later" threats. Let’s dive into the top US PQC regulations and how to stay ahead! I’ll dig into EU regulations in a later post. 🇺🇸 US Regulations and Policies on Post-Quantum Cryptography (PQC) 🇺🇸 In the US, PQC efforts are driven by federal agencies like NIST, CISA, NSA, and DHS, focusing on standardization, migration planning, and procurement mandates. As of September 2025, these emphasize immediate preparation for quantum threats, including the "harvest now, decrypt later" risk. Key elements include: 🇺🇸NIST Standardization Process: NIST's Post-Quantum Cryptography Standardization Project, initiated in 2016, has finalized core standards. On August 13, 2024, NIST published FIPS 203 (ML-KEM for encryption/key establishment), FIPS 204 (ML-DSA for digital signatures), and FIPS 205 (SLH-DSA for digital signatures). On March 11, 2025, HQC was selected as a backup encryption algorithm for standardization, providing diversity in mathematical foundations. A draft transition plan (NISTIR 8547, November 2024) outlines deprecating vulnerable algorithms by 2030 and prohibiting them after 2035. Organizations are urged to begin migrating now. 🇺🇸DHS and CISA Roadmap: DHS's September 2021 memorandum "Preparing for Post-Quantum Cryptography" requires agencies to inventory cryptographic systems, identify quantum-vulnerable ones, and prioritize migration. CISA's PQC Initiative (launched 2023) unifies interagency efforts, including a 2023 roadmap with NIST and NSA for critical infrastructure across 55 National Critical Functions. By mid-2025, CISA mandated listing product categories supporting PQC in acquisitions. Estimated federal migration costs: $7.1 billion from 2025–2035. 🇺🇸OMB and Procurement Mandates: OMB Memorandum M-23-02 (2023) directs federal agencies to migrate to PQC. A May 2025 directive requires incorporating PQC standards into government acquisitions to protect sensitive data. Within one year of NIST's 2024 standards release, OMB must issue migration guidance and report progress to Congress (per the 2022 Quantum Computing Cyber Preparedness Act). 🇺🇸NSA CNSA 2.0: The NSA's Commercial National Security Algorithm Suite 2.0 (updated 2022) endorses PQC algorithms like ML-KEM for national security systems, with migration timelines aligning to 2030–2035. 🇺🇸Legislative Actions: The August 2025 National Quantum Cybersecurity Migration Strategy Act (bipartisan bill) requires the White House Office of Science and Technology Policy to develop a national strategy, including pilots for high-impact systems and performance metrics for agencies. US PQC rules are set! Act now to secure data before quantum hits. KPMG US can help! DM for more info! #PQC #KPMGQuantum https://lnkd.in/e-BPE_u3

  • View profile for Michael Duffy

    U.S. Federal CISO (Acting), Office of Management and Budget

    4,960 followers

    This week, the Administration made clear that quantum technology is both a strategic opportunity and a cybersecurity imperative. One Executive Order accelerates U.S. quantum innovation, while the other advances the nation's transition to post-quantum cryptography. For the CISO community, the security decisions we make today must withstand the computing advances of tomorrow. With the release of OMB M-26-15, the federal government is moving from planning to execution in its migration to PQC. It is critically important for the Federal Enterprise to act decisively on this topic, and this policy memo translates strategy into action. Over the past several years, agencies have focused on understanding cryptographic dependencies and assessing risk. This memo shifts the focus to action- prioritizing high value assets, sequencing tactical migration efforts, protecting long-lived sensitive data, and building the cryptographic agility needed to address future threats. Success will require more than replacing algorithms though. It will require enterprise-wide collaboration, industry partnership, and a commitment to modernizing the foundations of cybersecurity. Fortunately, the government's journey to quantum resilience is already underway. Special thanks to Alex Robert Kleiner, Nick Polk, and our interagency PQC working group for driving progress and helping to shape the way forward. #cybersecurity #PQC #federalcyber #FederalIT #Govtech

  • View profile for Duncan Jones

    General Manager at Quantinuum

    9,301 followers

    For US government agencies, the release of post-quantum standards triggers clauses within NSM-10. Deprecation timelines are due in 90 days: "Within 90 days of the release of the first set of NIST standards for quantum-resistant cryptography... the Secretary of Commerce, through the Director of NIST, shall release a proposed timeline for the deprecation of quantum-vulnerable cryptography in standards, with the goal of moving the maximum number of systems off quantum-vulnerable cryptography within a decade of the publication of the initial set of standards." Purchasing of solutions is also unlocked: "Until the release of the first set of NIST standards for quantum-resistant cryptography referenced in subsection 3(a) of this memorandum, the heads of FCEB Agencies shall not procure any commercial quantum-resistant cryptographic solutions for use in IT systems supporting enterprise and mission operations." You can revisit NSM-10 here: https://lnkd.in/e23JNbBR #quantum #cybersecurity #cryptography #pqc

  • View profile for Creus Moreira Carlos

    Founder and CEO WISeKey.com NASDAQ:WKEY and SEALSQ.com NASDAQ:LAES | Best-selling Author| Former Cybersecurity UN Expert

    18,101 followers

    While the transition to PQC will be complex, it is already taking shape. National Security Memorandum 10 (NSM-10) set a target date of 2035 for migrating federal systems to quantum-resistant cryptographic methods. However, certain systems vulnerable to ‘save now, decrypt later’ attacks, such as government communications or secure financial transactions, may require earlier adoption due to their heightened risk profiles. The NIST recommends prioritizing quantum-resistant key-establishment schemes in protocols like TLS and IKE, which underpin secure communications on the internet.

Explore categories