Post-Quantum Readiness
How Government Contractors Can Prepare for PQC Compliance
Government contractors face mandatory PQC migration under NSM-10, OMB M-23-02, and CNSA 2.0. Learn the compliance timelines, crypto inventory requirements, and how to start your readiness program.
How Government Contractors Can Prepare for PQC Compliance
Government contractors face the most aggressive PQC compliance timelines of any sector. NSM-10, OMB M-23-02, CNSA 2.0, and CMMC 2.0 are converging to mandate cryptographic inventories and migration plans on accelerated schedules. Federal agencies must submit prioritized cryptographic inventories annually under OMB M-23-02, working toward NSM-10's goal of mitigating as much quantum risk as feasible by 2035.
If you sell software, cloud services, or IT systems to the US federal government, your customers will soon require evidence that your cryptographic posture meets these mandates. Here is what contractors need to know and do.
The Key Mandates
NSM-10 (National Security Memorandum on Quantum Computing)
Issued in 2022 and operationalized through subsequent directives, NSM-10 requires federal agencies to:
- Inventory all cryptographic systems
- Develop a migration plan to PQC
- Begin migration for high-priority systems by 2028
- Complete migration for all systems by 2035
For contractors, NSM-10 matters because federal agencies flow these requirements down through contracts, RFPs, and security assessments. If you cannot demonstrate your PQC readiness, you risk losing federal business.
OMB M-23-02 (Annual Cryptographic Inventory)
OMB M-23-02 requires agencies to submit an annual inventory of all cryptographic assets — algorithms, certificates, protocols, and vendors. The inventory must classify each asset by quantum vulnerability and include a migration plan with milestones.
Contractors providing systems to federal agencies are expected to provide the cryptographic data that feeds these inventories. If an agency uses your platform, they need your CBOM.
CNSA 2.0 (Commercial National Security Algorithm Suite)
NSA's CNSA 2.0 specifies which algorithms are approved for national security systems. It mandates:
- ML-KEM-768 for key establishment (replacing RSA and ECDH)
- ML-DSA-65 or SLH-DSA for digital signatures (replacing RSA and ECDSA)
- AES-256 for symmetric encryption (unchanged)
- SHA-384 or SHA-512 for hashing (upgraded from SHA-256)
For contractors handling classified or controlled unclassified information (CUI), CNSA 2.0 compliance is mandatory.
CMMC 2.0 (Cybersecurity Maturity Model Certification)
CMMC 2.0 Level 2 and Level 3 include cryptographic requirements through NIST SP 800-171 controls. SC.L2-3.13.11 (cryptographic protection of CUI) and SC.L2-3.13.10 (cryptographic key establishment and management) are directly relevant. As PQC becomes the required standard, CMMC assessments will verify that contractors are migrating to approved post-quantum algorithms.
What Contractors Should Do Now
Month 1-2: Cryptographic Inventory
Run an external cryptographic posture assessment on every domain used in federal contract delivery. Inventory TLS certificates, algorithms, key sizes, and vendors. Identify every instance of RSA-2048, ECC P-256, and SHA-256 with RSA signatures.
CipherReady automates the external discovery layer — enter domains, run scans, and within minutes you have the certificate-by-certificate inventory that feeds NSM-10 and OMB M-23-02 requirements.
Month 2-3: Classify by CNSA 2.0 Compliance
Map every cryptographic asset to CNSA 2.0 requirements:
- Compliant: AES-256, SHA-384/512, ML-KEM-768, ML-DSA-65
- Non-Compliant but Migratable: RSA-2048, ECC P-256 (can be replaced with CNSA-approved algorithms)
- Non-Compliant and Blocked: Algorithms with no PQC replacement path yet (specialized hardware crypto, legacy OT systems)
Month 3-4: Vendor Cryptographic Assessment
Inventory every third-party service used in federal contract delivery. Send a structured PQC questionnaire to each vendor. Map vendor responses to your compliance obligations — a vendor with no PQC roadmap is a compliance gap.
Month 4-6: Migration Roadmap
Build a prioritized migration roadmap with:
- Quick wins (0-6 months): Reissue certificates with larger RSA key sizes (4096-bit) as an interim step. Enable TLS 1.3 across all endpoints. Decommission expired and unused certificates.
- Medium term (6-18 months): Begin hybrid TLS deployment (ECDHE + ML-KEM) on non-production environments. Test ML-DSA certificates in internal PKI.
- Long term (18-36 months): Production PQC deployment. Full CNSA 2.0 compliance for national security systems.
Month 6+: Executive Reporting
Produce a board-ready document covering current posture, CNSA 2.0 compliance gaps, vendor risk register, migration timeline, and resource requirements. This document serves as both internal governance and federal customer evidence.
Contractual Implications
Federal RFPs are already including PQC readiness questions. Expect to see:
- "Describe your cryptographic inventory process and current posture."
- "Provide your PQC migration roadmap and timeline."
- "List the NIST PQC algorithms your platform will support and the expected dates."
- "Provide a Cryptographic Bill of Materials (CBOM) for the proposed system."
Contractors who can answer these questions with evidence will have a competitive advantage. Those who cannot will be excluded.
FAQ
Q: Does CNSA 2.0 apply to all government contractors? A: CNSA 2.0 applies to national security systems specifically. However, NIST PQC standards (FIPS 203/204/205) apply broadly, and agencies are flowing PQC requirements into contracts even for non-NS systems.
Q: What if my product uses a cloud provider's TLS termination? A: Your cloud provider's PQC roadmap becomes your compliance dependency. AWS, Azure, and GCP have published PQC roadmaps. Track their timelines and communicate them to your federal customers.
Q: Is CMMC currently assessing PQC readiness? A: CMMC 2.0 assessments do not yet include explicit PQC criteria, but NIST SP 800-171 cryptographic controls will evolve as PQC becomes the standard. Contractors who begin migration now will be ahead when CMMC PQC criteria arrive.
Q: Can CipherReady help with NSM-10 compliance? A: CipherReady provides the external cryptographic inventory that feeds NSM-10 documentation. For full CNSA 2.0 compliance, external inventory is the first step; internal discovery and code-level analysis may also be required depending on system classification.
Start Free Readiness Scan →
Financial Services PQC →
Government Contractor PQC →