On June 22 2026, the White House released an executive order that sends a clear signal to the nation’s digital infrastructure: by the end of 2030 federal agencies and their contractors must have moved to post‑quantum cryptography (PQC) for key establishment, and by the end of 2031 all digital signatures must be quantum‑safe.

The order also directs the Federal Acquisition Regulation Council to issue a rule that will bind covered contractors to NIST‑approved PQC standards by December 31 2030. The deadlines target high‑value assets and high‑impact systems, but analysts warn the ripple effect will touch critical infrastructure, regulated industries, and the wider supply chain.

With the order in place, 2026 and 2027 become the crucial planning window for many organizations. They must inventory cryptographic dependencies, evaluate vendors, and sketch migration roadmaps before the federal checkpoints loom.

PQC is engineered to withstand attacks from quantum computers—machines that could break RSA and elliptic‑curve schemes in a single night. While practical quantum attacks are not yet a reality, the “harvest‑now, decrypt‑later” threat has pushed the conversation from academia into operational planning. NIST’s first three PQC standards, published in August 2024, give enterprises a vetted set of algorithms for key exchange and digital signatures.

The transition is not a one‑off upgrade. First, organizations must discover where cryptography lives across devices, applications, certificates, and protocols. Fortinet’s FortiManager, enhanced with FortiAI‑Assist, provides a discovery framework that scans managed Fortinet devices for unsafe or legacy algorithms, generating inventory checklists and flagging systems that rely on vulnerable components.

Once visibility is achieved, measurement follows. FortiAnalyzer monitors traffic for unsafe algorithm usage and reports on the adoption of quantum‑safe methods. The resulting data feeds into risk dashboards that help executives, security leaders, and compliance teams identify which systems pose the greatest exposure.

Protection focuses on the most vulnerable external pathways—site‑to‑site VPNs, partner channels, branch networks, and cloud integrations. FortiGate’s IPsec hardware acceleration secures these tunnels, allowing organizations to prioritize encryption of high‑value communications while limiting the amount of data that could be harvested for future decryption.

Modernization is the final piece: building crypto‑agility so that algorithms, certificates, and policies can evolve as PQC standards mature. Fortinet’s Security Fabric framework guides enterprises through a “Discover → Measure → Protect → Modernize” cycle, encouraging continuous adaptation rather than a one‑time switch.

Industry experts stress that the migration will span several years. The executive order’s 2030/31 deadlines are the first hard checkpoints, but practical rollout will demand incremental changes to infrastructure, procurement processes, and vendor contracts. The rule‑making process will formalize contractor compliance, potentially adding another layer of oversight.

In the coming months, federal agencies are expected to appoint transition officials, conduct readiness assessments, and begin testing PQC implementations in non‑mission‑critical environments. Private‑sector firms—especially those in regulated sectors—will likely accelerate their own assessments to avoid future compliance gaps.

The executive order marks a broader shift toward quantum‑resilient security. While quantum computers capable of breaking current cryptography remain theoretical, the combination of NIST standards, federal mandates, and industry tools like Fortinet’s security fabric is carving a structured path for organizations to prepare for the quantum era.

As of July 2026, the U.S. government has set the first definitive deadlines for PQC adoption. The next steps involve detailed inventory, risk measurement, targeted protection of high‑value external communications, and the gradual rollout of quantum‑safe algorithms across enterprise networks.