Inventory all algorithms, keys, certs, and protocols. Produce CBOM. (Ch5, NIST SP 1800-38B)
☐
Quantum risk assessment
Score all systems using Appendix D methodology. Identify P0 systems.
☐
Establish CCOE
Cross-functional team per Ch6 model. Assign executive sponsor.
☐
Update cryptographic policies
Incorporate PQC requirements into procurement, development, and security policies.
☐
Enable hybrid TLS key exchange
X25519MLKEM768 on internet-facing load balancers/CDN. (Ch7 bridge architecture)
☐
Verify SSH key exchange
Confirm OpenSSH 10.0+ default (mlkem768x25519). Update if needed.
☐
Begin dual-signing firmware
Sign new firmware/SBOMs with both classical + ML-DSA. (CNSA 2.0 “prefer by 2025”)
☐
Name a PQC migration lead
Federal civilian agencies: report a lead to the OMB Director and National Cyber Director within 30 days of EO 14409. Align the migration plan to its 2030/2031 deadlines.
Federal agencies and federal service integrators should apply the following items in addition to the timeline-based actions above. These align PQC migration activities with the existing Risk Management Framework (NIST SP 800-37 Rev 2) rather than creating a parallel compliance track.
☐
Action
Reference
☐
Include PQC in System Security Plans (SSPs)
Document PQC control selection, implementation timeline, and residual risk per NIST SP 800-37 Rev 2.
☐
Track PQC migration in POA&Ms
Record quantum-vulnerable systems and their migration milestones in the Plan of Action and Milestones for continuous monitoring.
☐
Submit annual quantum-vulnerable IT system inventory
Required by NSM-10 for federal agencies. (Ch 5 Note 1)
☐
M-23-02 cryptographic inventory reporting
FCEB agencies submit annual cryptographic inventory to CISA per OMB Memorandum M-23-02. (Ch 5 Note 1)
☐
FedRAMP continuous monitoring for cloud offerings
Include PQC posture and migration progress in FedRAMP ConMon deliverables.
☐
Reauthorize systems after PQC migration
Treat hybrid/PQC deployment as a significant change triggering ATO reauthorization per NIST SP 800-37 Rev 2 Monitor step.
☐
Embed PQC in procurement language
Apply PQC readiness requirements to acquisition clauses. USDA/AGAR provides a model; the EO 14409 FAR rule will make FIPS/PQC compliance contractual by 2030. (Ch 9 Note 9)
☐
Clear DoW CIO PQC Directorate gates
DoW Components: obtain cryptographic intake and deployment approval before piloting, buying, or fielding PQC technology. (DoW CIO memo, Nov 2025; DoW PQC Strategy, Apr 2026)