The Department of War's Post-Quantum Cryptography (PQC) Strategy

The Department of War’s Post-Quantum Cryptography (PQC) Strategy

The United States Department of War (DoW) recently released its Post-Quantum Cryptography (PQC) Strategy, detailing a framework to secure the department’s global networks against future quantum computing threats [1]. This strategy directly supports Executive Order 14409, “Securing the Nation Against Advanced Cryptographic Attacks,” signed by President Donald J. Trump on June 22, 2026 [2].

The strategy aims to counter the “harvest now, decrypt later” risk, where adversaries intercept encrypted data today with the intention of decrypting it once large-scale, fault-tolerant quantum computers become available [2] [3]. To mitigate this, the DoW mandates that all DoW systems must support PQC or be phased out by December 31, 2030, and all systems must use PQC by December 31, 2031 [4].

Executive Order 14409 and Federal Deadlines

Executive Order 14409 establishes a federal timeline for PQC migration across all High Value Assets and high-impact systems. The order sets specific deadlines:

  • December 31, 2030: Transition to PQC for key establishment [2].
  • December 31, 2031: Transition to PQC for digital signatures [2].

Furthermore, the Federal Acquisition Regulatory Council (FAR Council) is directed to publish a proposed rule requiring covered contractors to comply with National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS), including PQC algorithms, by December 31, 2030 [2].

DoW PQC Strategy Lines of Effort

The DoW strategy maps out five interconnected Lines of Effort (LOE) to execute this enterprise-wide transition [1] [4]:

Line of Effort Description
LOE 1: Optimize DoW Governance Centralize oversight, update policies, and streamline National Security Agency (NSA) certification and evaluation processes to accelerate PQC compliance.
LOE 2: Baseline Inventory and Plan Identify all cryptography in use across National Security Systems (NSS) and non-NSS, conduct impact assessments, and develop component-level migration roadmaps.
LOE 3: Develop and Analyze Collaborate with NIST, NSA, and international standards organizations to mature PQC algorithms and promote cryptographic agility.
LOE 4: Integrate Commercial Solutions Increase PQC support via the Commercial Solutions for Classified (CSfC) program and NIST, and update secure edge systems and software signing.
LOE 5: Deploy Quantum Resistant Devices Modernize the Key Management Infrastructure (KMI), deploy secure data links, transport systems, space systems, and tactical radios.

Technical Requirements and Standards

The DoW strategy requires that National Security Systems (NSS) support the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) [4]. CNSA 2.0, released by the NSA, updates cryptographic algorithms to protect national security data against both classical and quantum computers [5].

The transition relies on the finalized NIST PQC standards, specifically:

  • FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) for key establishment [6].
  • FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) for digital signatures [6].
  • FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) for digital signatures [6].

The DoW strategy explicitly prohibits the use of quantum communication technologies, such as quantum key distribution (QKD), as a means for achieving security for confidentiality or authentication [4].

References

[1] Department of War. (2026, June 23). Securing Global Dominance: DoW Unleashes Quantum Defense Strategy to Harden Networks and Empower the Joint Force. https://www.war.gov/News/Releases/Release/Article/4524599/securing-global-dominance-dow-unleashes-quantum-defense-strategy-to-harden-netw/

[2] Executive Office of the President. (2026, June 22). Executive Order 14409: Securing the Nation Against Advanced Cryptographic Attacks. Securing the Nation Against Advanced Cryptographic Attacks – The White House

[3] National Institute of Standards and Technology. (2024, August 13). What Is Post-Quantum Cryptography? What Is Post-Quantum Cryptography? | NIST

[4] Department of War. (2026, April 16). Department of War Post Quantum Cryptography Strategy. https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf

[5] National Security Agency. (2022, September 7). NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3148990/nsa-releases-future-quantum-resistant-qr-algorithm-requirements-for-national-se/

[6] National Institute of Standards and Technology. (2024, August 13). NIST Releases First 3 Finalized Post-Quantum Encryption Standards. NIST Releases First 3 Finalized Post-Quantum Encryption Standards | NIST

AI generated