The National Security Agency announced on October 1 a set of post-quantum cryptography measures for U.S. National Security Systems, centered on a new online Post-Quantum Cryptography Resource Hub. The hub collects explainers, technical guidance and white papers for the Department of War, owners of National Security Systems and the Defense Industrial Base. Source: NSA

Post-quantum cryptography means new public-key algorithms built to resist attack by a future quantum computer while running on today’s hardware. Our explainer covers how post-quantum cryptography works.

The deadlines NSA restated

The announcement does not set new dates. It repeats the timeline in the Committee on National Security Systems Policy 15 (CNSSP 15): starting in 2027, all new commercial National Security Systems must be able to support quantum-resistant algorithms, and legacy systems that cannot do so are to be phased out by 2030.

The algorithms in question are the NSA’s Commercial National Security Algorithm Suite 2.0. The NSA’s CNSA 2.0 advisory sets dates by product type: traditional networking equipment such as VPNs and routers is to use CNSA 2.0 exclusively by 2030, while web browsers, servers, cloud services and operating systems have until 2033. The agency expects the overall transition to be complete by 2035.

NSA frames the measures as part of Executive Order 14412, signed on June 22, 2026. That order sets separate dates for civilian federal systems, which exclude National Security Systems: high-value assets and high-impact systems are to use post-quantum key establishment by December 31, 2030, and post-quantum signatures by December 31, 2031. It also requires the NSA director to report on the migration status of National Security Systems within 180 days of the order and every year after.

Two threats in focus

The press release names “harvest now, decrypt later,” in which adversaries collect encrypted data today to decrypt once quantum computers can, and a second risk to authentication. A hub article published the same day calls it “trust now, forge later”: once quantum-vulnerable algorithms such as RSA and elliptic-curve cryptography can be broken, the certificates and signatures that systems rely on for trust could be forged. The press release itself words it as “trust now, exploit later.”

“The quantum threat is an existential threat to the digital ecosystem, but we have the tools today to combat it,” said Morgan Stern, the NSA’s effort lead for quantum resistance, in the release.

Who is affected

The requirements apply to National Security Systems and the companies that sell into them, not to consumer devices. For vendors, the practical route is product certification: the NSA says the National Information Assurance Partnership is working with industry on CNSA 2.0-compliant Protection Profiles, and that the agency is partnering with NIST and industry at NIST’s National Cybersecurity Center of Excellence.

The underlying algorithms come from NIST’s post-quantum standards, finalized in August 2024. Consumer software has been adopting the same family of algorithms on its own timeline, which our explainer describes.

Hardware progress is the other half of the story. Recent results, such as Infleqtion’s 30 logical qubits, show steady work on error-corrected machines; none of them has demonstrated the ability to break today’s public-key encryption.