What Mauritz Kop wrote on 6 November 2025, and what GSA announced on 24 August 2026
On August 24, 2026 the General Services Administration described a laboratory that evaluates whether badge readers and employee credentials can survive a quantum-capable adversary, and an approved products list that federal buyers work from in the covered category. Driving this through purchasing rather than through a statute was set out in print nine months earlier, with the agency named: on November 6, 2025 Mauritz Kop, founder of the Stanford Center for Responsible Quantum Technology, published "A Bletchley Park for the Quantum Age" in War on the Rocks, asking that the General Services Administration, OMB and agency chief acquisition officers condition federal purchases on validated cryptographic modules, and that deployed systems be tested rather than vendor claims accepted. Ten months on, the machinery those propositions call for is being assembled by that agency, and the alignment is worth stating exactly: no post-quantum purchasing condition is in force yet, and GSA says the laboratory is starting to incorporate quantum-resistant algorithms. What exists is the route through which such a condition would travel.
Which American rules carry the obligation, and why Europe arrives through NIS2 instead
FAR 4.1302 directs agencies acquiring personal identity verification products to approved products, while permitting acquisition outside the named GSA process where compliance is independently ensured. OMB Memorandum M-26-15 supplies the schedule, with migration plans due on October 22, 2026 and access control systems built on asymmetric cryptography named among the systems agencies should include. Executive Order 14412 directs NIST to accelerate module validation, a route legally distinct from the FIPS 201 programme GSA runs, and its section 6(c) requires the FAR Council to propose a contracting rule tying covered contractors to post-quantum standards by December 31, 2030. Europe arrives differently. Article 21 of NIS2 requires policies on cryptography and, where appropriate, encryption, without naming post-quantum cryptography or fixing a migration date, and the Cyber Resilience Act works on products with reporting duties from September 11, 2026 and its main obligations from December 11, 2027. A centralized federal approval route can convert a test result into a category-wide condition. Distributed European procurement and horizontal regulation produce a slower and broader effect that reaches operators no purchasing rule touches.
Meer lezen