The Department of War’s Post-Quantum Cryptography (PQC) Strategy
The United States Department of War (DoW) recently released its Post-Quantum Cryptography (PQC) Strategy, detailing a framework to secure the department’s global networks against future quantum computing threats [1]. This strategy directly supports Executive Order 14409, “Securing the Nation Against Advanced Cryptographic Attacks,” signed by President Donald J. Trump on June 22, 2026 [2].
The strategy aims to counter the “harvest now, decrypt later” risk, where adversaries intercept encrypted data today with the intention of decrypting it once large-scale, fault-tolerant quantum computers become available [2] [3]. To mitigate this, the DoW mandates that all DoW systems must support PQC or be phased out by December 31, 2030, and all systems must use PQC by December 31, 2031 [4].
Executive Order 14409 and Federal Deadlines
Executive Order 14409 establishes a federal timeline for PQC migration across all High Value Assets and high-impact systems. The order sets specific deadlines:
- December 31, 2030: Transition to PQC for key establishment [2].
- December 31, 2031: Transition to PQC for digital signatures [2].
Furthermore, the Federal Acquisition Regulatory Council (FAR Council) is directed to publish a proposed rule requiring covered contractors to comply with National Institute of Standards and Technology (NIST) Federal Information Processing Standards (FIPS), including PQC algorithms, by December 31, 2030 [2].
DoW PQC Strategy Lines of Effort
The DoW strategy maps out five interconnected Lines of Effort (LOE) to execute this enterprise-wide transition [1] [4]:
| Line of Effort | Description |
|---|---|
| LOE 1: Optimize DoW Governance | Centralize oversight, update policies, and streamline National Security Agency (NSA) certification and evaluation processes to accelerate PQC compliance. |
| LOE 2: Baseline Inventory and Plan | Identify all cryptography in use across National Security Systems (NSS) and non-NSS, conduct impact assessments, and develop component-level migration roadmaps. |
| LOE 3: Develop and Analyze | Collaborate with NIST, NSA, and international standards organizations to mature PQC algorithms and promote cryptographic agility. |
| LOE 4: Integrate Commercial Solutions | Increase PQC support via the Commercial Solutions for Classified (CSfC) program and NIST, and update secure edge systems and software signing. |
| LOE 5: Deploy Quantum Resistant Devices | Modernize the Key Management Infrastructure (KMI), deploy secure data links, transport systems, space systems, and tactical radios. |
Technical Requirements and Standards
The DoW strategy requires that National Security Systems (NSS) support the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) [4]. CNSA 2.0, released by the NSA, updates cryptographic algorithms to protect national security data against both classical and quantum computers [5].
The transition relies on the finalized NIST PQC standards, specifically:
- FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM) for key establishment [6].
- FIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA) for digital signatures [6].
- FIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA) for digital signatures [6].
The DoW strategy explicitly prohibits the use of quantum communication technologies, such as quantum key distribution (QKD), as a means for achieving security for confidentiality or authentication [4].
References
[1] Department of War. (2026, June 23). Securing Global Dominance: DoW Unleashes Quantum Defense Strategy to Harden Networks and Empower the Joint Force. https://www.war.gov/News/Releases/Release/Article/4524599/securing-global-dominance-dow-unleashes-quantum-defense-strategy-to-harden-netw/
[2] Executive Office of the President. (2026, June 22). Executive Order 14409: Securing the Nation Against Advanced Cryptographic Attacks. Securing the Nation Against Advanced Cryptographic Attacks – The White House
[3] National Institute of Standards and Technology. (2024, August 13). What Is Post-Quantum Cryptography? What Is Post-Quantum Cryptography? | NIST
[4] Department of War. (2026, April 16). Department of War Post Quantum Cryptography Strategy. https://dowcio.war.gov/Portals/0/Documents/Library/DoW-PQC-Strategy.pdf
[5] National Security Agency. (2022, September 7). NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems. https://www.nsa.gov/Press-Room/News-Highlights/Article/Article/3148990/nsa-releases-future-quantum-resistant-qr-algorithm-requirements-for-national-se/
[6] National Institute of Standards and Technology. (2024, August 13). NIST Releases First 3 Finalized Post-Quantum Encryption Standards. NIST Releases First 3 Finalized Post-Quantum Encryption Standards | NIST
AI generated