Executive Order 14412 isn't a research initiative. It's a compliance mandate with timelines, forcing risk and compliance officers to answer a question most haven't faced: how do you protect data that won't be decrypted for another decade?
The problem is immediate. Adversaries are already harvesting encrypted data, assuming quantum computers will eventually break today's cryptographic protections. Your team can't wait for quantum computers to arrive to act.
Why This Matters Now
Executive Order 14412 sets specific timelines for post-quantum cryptography readiness across federal agencies and their contractors. This isn't theoretical planning. If your organization handles Controlled Unclassified Information under NIST SP 800-171 or operates systems subject to DFARS 252.204-7012, you're facing cryptographic inventory requirements, risk assessments, and migration planning that must align with federal schedules.
The "Harvest Now, Decrypt Later" threat model changes risk assessment. An adversary doesn't need to break your encryption today. They just need to store it until quantum decryption becomes feasible. For data with a 10-year sensitivity window, that exposure exists now. Your compliance posture must account for it.
What You Need Before Starting
Before building a post-quantum roadmap, you need visibility into your current cryptographic posture. Gather these items:
Cryptographic Inventory: Document every system that encrypts data at rest or in transit. Include VPNs, TLS implementations, database encryption, backup encryption, and key management systems. Identify the algorithm (RSA-2048, ECDSA P-256, AES-256), key exchange mechanism, and certificate authority for each.
Data Classification and Retention Schedules: Review your CUI handling procedures and data retention policies. Know which datasets remain sensitive beyond five years. If you're protecting technical specifications, personnel records, or acquisition documents, assume long sensitivity windows.
System Authorization Boundaries: Review your system security plans and authorization boundary diagrams. Identify which systems share cryptographic infrastructure. These dependencies will dictate your migration sequencing.
Compliance Artifacts: Collect your most recent NIST SP 800-171 assessment, System Security Plan, and Plan of Action and Milestones. If pursuing Cybersecurity Maturity Model Certification Level 2, review your readiness against control families SC (System and Communications Protection) and IA (Identification and Authentication).
Vendor Roadmaps: Contact your infrastructure vendors. Ask for their post-quantum migration timelines, especially for VPN appliances, HSMs, and identity platforms. If a vendor can't provide a roadmap, that's a risk finding.
Step-by-Step Implementation
Step 1: Conduct a Cryptographic Risk Assessment
Start with NIST SP 800-171 control 3.13.11 (cryptographic protection) and 3.13.16 (protection of CUI at rest). For each system handling CUI, document:
- Cryptographic algorithms protecting data in transit and at rest
- Key lengths and certificate validity periods
- Whether the data remains sensitive beyond the expected quantum threat horizon
- Whether the system uses FIPS 140-2 validated modules (you'll need FIPS 140-3 or quantum-resistant algorithms eventually)
Score each system using your existing risk matrix. A system protecting 15-year retention CUI with RSA-2048 certificates is higher risk than one protecting 90-day retention logs with the same algorithm.
Step 2: Prioritize Migration Based on Data Sensitivity and Lifespan
Create three migration tiers:
Tier 1 (Immediate): Systems protecting long-lived CUI or data subject to ITAR controls. These need hybrid cryptographic implementations (classical plus post-quantum) as soon as NIST finalizes the algorithms under its Post-Quantum Cryptography Standardization project.
Tier 2 (12-24 Months): Systems with moderate sensitivity windows (three to seven years) or those that feed into Tier 1 systems. Plan for migration once Tier 1 is stable.
Tier 3 (24-36 Months): Short-lived data and systems with no CUI exposure. These follow vendor roadmaps and federal guidance updates.
Document this prioritization in your Plan of Action and Milestones. Tie each tier to specific system authorization boundaries and data classification levels.
Step 3: Update Your System Security Plan
Add a section titled "Post-Quantum Cryptographic Transition Plan." Include:
- Your cryptographic inventory (reference as an appendix)
- Risk assessment findings tied to specific controls (SC-12, SC-13, SC-17)
- Migration timeline aligned with EO 14412 requirements
- Hybrid cryptographic approach during the transition period
- Testing and validation procedures for quantum-resistant algorithms
If you're operating under a Continuous Authorization model or preparing for CMMC Level 2 assessment, this documentation demonstrates proactive risk management. Assessors will ask about your quantum readiness plan.
Step 4: Implement Hybrid Cryptography Where Feasible
You can't wait for full quantum-resistant infrastructure. Implement layered protections now:
- Deploy TLS 1.3 with extended key sizes where possible
- Use AES-256 for symmetric encryption
- Implement certificate agility: automate certificate rotation so you can swap algorithms without manual system updates
- Test quantum-resistant algorithms in non-production environments as they become available in FIPS 140-3 validated modules
For systems under DFARS 252.204-7012, document these interim controls in your cybersecurity incident response plan. If you experience a breach involving encrypted CUI, you'll need to demonstrate what protections were active.
Step 5: Engage Your Supply Chain
If you're a prime contractor, your subcontractors' cryptographic posture is your exposure. Update your flow-down requirements to include post-quantum readiness:
- Require subcontractors to provide cryptographic inventories for systems handling your CUI
- Include quantum readiness timelines in subcontractor security reviews
- Update your Contractor Risk Assessment methodology to score quantum exposure
This isn't optional. CMMC assessments will evaluate how you manage subcontractor risk, and quantum-vulnerable encryption in your supply chain is a control gap.
Validation, How to Verify It Works
Run these checks quarterly:
Cryptographic Inventory Accuracy: Scan your network to verify your inventory matches deployed systems. Use tools like Nmap with SSL/TLS enumeration scripts or commercial vulnerability scanners that report cryptographic protocols. Flag any RSA-1024 or deprecated algorithms immediately.
Certificate Expiration Monitoring: Automate alerts for certificates expiring within 90 days. Your goal is zero expired certificates and a rotation process that can swap in quantum-resistant certificates when available.
Vendor Roadmap Tracking: Maintain a spreadsheet of vendor commitments. If a vendor misses a promised quantum-resistant release, escalate it as a supply chain risk and document compensating controls.
Assessment Artifact Review: Before your next CMMC or FedRAMP assessment, review your System Security Plan's quantum readiness section. Ensure it reflects current implementation status, not just your original plan.
Ongoing Tasks
Post-quantum readiness isn't a one-time project. Add these to your continuous monitoring program:
- Monthly: Review NIST's Post-Quantum Cryptography project updates and adjust your timeline if new guidance emerges
- Quarterly: Update your cryptographic risk assessment as systems change or data retention policies shift
- Annually: Conduct a tabletop exercise simulating a quantum decryption scenario against your Tier 1 systems; document gaps in your incident response plan
When NIST finalizes its quantum-resistant algorithm standards and FIPS 140-3 validated modules become available, you'll trigger your migration plan. Until then, your compliance posture depends on demonstrating that you've assessed the risk, prioritized your exposure, and built a roadmap that aligns with federal timelines.
That's what Executive Order 14412 requires. That's what assessors will validate.



