A FAR Rule Due in December Will Put Post-Quantum Cryptography Into US Federal Contracts. Mauritz Kop Named That Route in 2025.
By our Editor
Before the end of this year, the council that writes United States federal contracting rules is due to publish a draft rule requiring government suppliers to meet post-quantum cryptography standards by the end of 2030. Post-quantum cryptography is the replacement for the encryption that a sufficiently powerful quantum computer would break, and the United States is putting it into contracts rather than into a cybersecurity statute. That is the part European suppliers should read carefully: the requirement will reach them through a purchase order long before it reaches them through a regulator.
The deadline sits in Executive Order 14412 of June 22, 2026. Its section 6(c) gives the Federal Acquisition Regulatory Council 180 days, so until roughly December 19, 2026, to propose an amendment to the Federal Acquisition Regulation binding covered contractors to NIST's standards, including those incorporating post-quantum algorithms, by December 31, 2030. Two months earlier, on August 24, 2026, the General Services Administration published "GSA Leads the Transition to Quantum-Resistant Technology", describing a laboratory that evaluates whether badge readers and employee credentials can survive a quantum-capable adversary, and an approved products list that federal buyers work from in that category. Neither document creates an obligation for a European company today. Together they show where the obligation is being built, and it is the purchasing channel we have followed before in the attack nobody publishes.
A FAR Rule Due in December Will Put Post-Quantum Cryptography Into US Federal Contracts. Mauritz Kop Named That Route in 2025 in his Bletchley Park article for War on the Rocks.
What Mauritz Kop wrote in War on the Rocks on 6 November 2025, and which agency he named
The idea of driving this through purchasing, rather than through a cybersecurity statute, was set out in print nine months before GSA's announcement, and it named the agency that would do it. On November 6, 2025, Mauritz Kop, founder of the Stanford Center for Responsible Quantum Technology, published "A Bletchley Park for the Quantum Age" in War on the Rocks. Its second domestic action reads: "The General Services Administration, the Office of Management and Budget, and agency chief acquisition officers should condition federal purchases on Federal Information Processing Standard 140-3-validated modules." Its third set the evidentiary standard: "Third, test what is deployed, not what vendors promise," paired with a call to stand up a federal test-and-evaluation network demonstrating "that new systems are based on measured performance, not just vendor promises."
Ten months on, the machinery those two propositions call for is being assembled by the agency the essay named. GSA runs the laboratory that decides which access-control products qualify and says it is starting to incorporate quantum-resistant algorithms into that testing, and module validation is being accelerated by executive order. The alignment is partial and it is worth being exact about the gap: no post-quantum purchasing condition is in force yet, and the federal test-and-evaluation network for fielded systems that the essay asked for does not exist as such. What exists is the route through which such a condition would travel, in the hands of the named agency. The companion analysis on Quentir takes that story from the policy side. The legal question, and the one that matters to a supplier, is which instrument carries the force.
The record deserves one qualification, because a claim that ignores it is easy to break. GSA was active before that essay: on June 4, 2025 it published its own post-quantum article and issued a buyer's guide pointing agencies at contract vehicles for cryptographic inventory work. That earlier material offers pathways. The November 2025 essay supplies the condition and the test.
Which three American rules carry the obligation: FAR 4.1302, memo M-26-15 and executive order 14412
FAR 4.1302 governs the acquisition of personal identity verification products and services and directs agencies to approved products, while expressly permitting acquisition outside the named GSA process where the agency independently ensures FIPS 201 compliance. It is a strong default rather than an absolute bar. Advice that describes it as a closed door will not survive contact with a contracting officer.
OMB Memorandum M-26-15 of June 24, 2026 supplies the schedule. Agencies must mitigate as much quantum risk as feasible by December 31, 2030 and submit migration plans to OMB and the Office of the National Cyber Director within 120 days, which falls on October 22, 2026. The memorandum does not require those plans to be published. Its mandatory prioritisation covers high impact systems, High Value Assets and other systems an agency judges particularly vulnerable; logical access control systems built on asymmetric cryptography appear in the softer register, as systems agencies "should include". The memorandum also directed GSA to convene an interagency working group on federal identity within 60 days. That group first met on August 12, 2026, with 40 participants from 17 agencies.
Executive Order 14412 of June 22, 2026, which the memorandum implements, directs the National Institute of Standards and Technology to revise the Cryptographic Module Validation Program to accelerate module validation. Note who does what, because the two evaluation routes are often merged in commentary and they are legally distinct. NIST runs module validation. GSA runs the FIPS 201 evaluation programme and the approved products list for physical access control. The executive order accelerates the first. It does not itself impose a purchasing condition of the kind the November 2025 essay proposed, and agencies are told to align their plans with NIST IR 8547, which remains an initial public draft rather than a standard in force.
The same executive order contains the provision that speaks most directly to the purchasing question, and it deserves to be read closely. Section 6(c) requires the Federal Acquisition Regulatory Council, within 180 days, to publish a proposed rule amending the Federal Acquisition Regulation to require covered contractors to comply by December 31, 2030 with NIST's Federal Information Processing Standards, including all applicable standards incorporating post-quantum algorithms. That clock runs out around December 19, 2026. A proposed rule is a notice inviting comment rather than an operative purchasing condition, and the covered-contractor definition will decide much of its reach. It is nonetheless the instrument in which a general condition on federal purchases would live, and it is being drafted now.
The practical consequence for a supplier is the ordinary one in regulated procurement. As quantum-resistant algorithms enter the FIPS 201 evaluation suite, a product that cannot demonstrate them loses the default route to federal buyers in the covered category, and the proposed FAR rule would extend a comparable expectation well beyond access control. That reading is analysis rather than settled law, and its timing depends on when the suite changes and what the FAR Council actually proposes. Suppliers who followed export control reaching the API will recognise the pattern: the obligation arrives through the commercial channel before it arrives through a regulator.
Why Europe runs through NIS2 and the Cyber Resilience Act, and what that changes for a supplier
European policy points at the same end state and arrives by a different road. The Commission issued its post-quantum cryptography recommendation in April 2024, and the NIS Cooperation Group published the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, released on the Commission’s library page on June 23, 2025. Its milestones are widely quoted: national implementation plans by the end of 2026, high-risk use cases migrated by 2030, the transition completed by 2035. Those are coordination targets addressed to Member States. They are not, by themselves, binding deadlines that a supervisory authority enforces against a company.
The binding layer sits elsewhere and reaches post-quantum work only by implication. Article 21 of NIS2, as transposed nationally, requires essential and important entities to take risk-management measures including policies on cryptography and, where appropriate, encryption. It does not name post-quantum cryptography or set a migration date. What it does is create a supervised duty whose content follows the state of the art, which is the channel through which a national authority could in time expect a migration plan. The same duty is what turned a twenty-four-hour notification into a two-year board problem. Dutch entities meet the same duty through the Cyberbeveiligingswet, which we covered when the register arrived before the obligation.
The Cyber Resilience Act works on products rather than operators, with risk-based, state-of-the-art security requirements in its annexes rather than a post-quantum mandate. Its timing matters for planning: the reporting obligations in Article 14 apply from September 11, 2026, and the main body of obligations from December 11, 2027. A manufacturer that has to show state-of-the-art cryptographic design from late 2027 will find the post-quantum question arriving inside a conformity assessment rather than inside a procurement catalogue.
That is the structural difference worth carrying away. American agencies remain separate buyers, but they share a centralized federal approval route: one evaluation programme and one approved products list able to convert a test result into a condition that reaches a whole category of purchases. Europe has distributed public procurement across twenty-seven Member States, a recommendation, and two horizontal instruments whose cryptographic requirements are drafted to follow the state of the art. The American route produces a fast, category-wide effect on suppliers. The European route produces a slower and broader one that eventually reaches private operators no American purchasing rule touches.
Which three questions to put to your own products and suppliers before 2027
A vendor selling access control, credentials or identity infrastructure into both markets faces two clocks that are close enough to plan against together. The American clock runs on validated modules and an evaluated products list. The European clock runs on risk-management duties, product requirements and national plans expected at the end of this year. The overlap is the useful part: an inventory of asymmetric cryptography in the identity and access layer serves both, and so does the ability to show measured performance rather than a datasheet.
Three questions belong in supplier due diligence now. Which asymmetric algorithms sit in the product today, and in which components. What the update path looks like when an algorithm has to be replaced, and whether it requires new hardware. And what independent evidence exists that the fielded configuration performs as described. That last one is the November 2025 instruction restated as contract practice, and most datasheets cannot answer it.
Five dates between September 2026 and December 2027 that set the timetable
Five dates carry the coming year. Around December 19, 2026, when the FAR Council’s proposed post-quantum contracting rule is due under Executive Order 14412. September 11, 2026, when the Cyber Resilience Act's reporting obligations begin. October 22, 2026, when American agency migration plans are due to OMB and ONCD, though publication is not required and evidence may surface later. The end of 2026, when EU Member State national post-quantum plans are expected. And December 11, 2027, when the main Cyber Resilience Act obligations apply. Running quietly underneath is the moment quantum-resistant algorithms formally enter the FIPS 201 evaluation programme, which is what converts a laboratory capability into a purchasing condition.
For organisations that would rather see this mapped onto their own agreements than read as policy, our contract scan is a fixed-scope review that puts these questions to supplier contracts and product documentation and returns them as concrete clauses and gaps.
Sources, consulted August 26, 2026. Primary materials: GSA, "GSA Leads the Transition to Quantum-Resistant Technology" (August 24, 2026); OMB Memorandum M-26-15 (June 24, 2026); Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks" (June 22, 2026); FAR 4.1302; NIST IR 8547 (initial public draft); GSA, "GSA and Post-Quantum Cryptography" (June 4, 2025); NIS Cooperation Group, Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (released June 23, 2025); Directive (EU) 2022/2555 (NIS2), Article 21; Regulation (EU) 2024/2847 (Cyber Resilience Act), Articles 14 and 71 and Annex I. Commentary: Mauritz Kop, "A Bletchley Park for the Quantum Age," War on the Rocks (November 6, 2025).