Securosys Says U.S. Order Sets 2030 Deadline for Contractor Quantum Security

December 31, 2030, is the date by which U.S. federal contractors must comply with updated NIST standards, including post-quantum cryptography, or risk losing federal business, as mandated by Executive Order 14412. The Federal Acquisition Regulatory Council has 180 days following June 22, 2026, to propose a rule enforcing this compliance throughout the government’s supply chain. This directive extends beyond U.S. borders, impacting international technology suppliers and cloud providers who work with the U.S. government. According to Robert Rogenmoser, CEO of Securosys, Executive Order 14412 was written for U.S. federal agencies, but its impact extends further, as it also compels the U.S. to encourage adoption of NIST-standardized algorithms globally.

Executive Order 14412 Drives Global Post-Quantum Cryptography Adoption

The increasing threat of quantum computers breaking current encryption standards has triggered a swift international response, driven by a U.S. executive order with far-reaching implications. Executive Order 14412, signed on June 22, 2026, mandates a transition to post-quantum cryptography (PQC) for U.S. federal agencies, but its influence extends well beyond national borders, compelling a global shift in cryptographic practices. The order establishes a firm deadline of December 31, 2030, for U.S. government entities, directly or indirectly, creating a ripple effect across the global technology ecosystem. The U.S. government is also actively working to encourage the adoption of NIST-standardized PQC algorithms internationally, enlisting the Secretary of State, NIST, and other agencies to engage with foreign governments and industry groups. Securosys SA, a Swiss cybersecurity firm, has already positioned itself to address this evolving situation.

The company confirms its hardware security modules (HSMs) currently support the PQC algorithms standardized by NIST, offering a potential solution for organizations facing the 2030 compliance deadline. Rogenmoser also notes the directive compels the U.S. to encourage global adoption of NIST standards. Securosys is supporting this transition with its CloudHSM Sandbox, a secure environment allowing organizations to validate PQC migration strategies. The Sandbox supports algorithms including ML-KEM, ML-DSA, SLH-DSA, HSS-LMS, and XMSS, and provides industry-standard APIs for integration testing. The company offers limited-time free access to the Sandbox, enabling organizations to experiment with PQC algorithms without production risk, and includes engineering support for detailed debugging and collaboration. Securosys asserts that an organization’s HSM plays a central role in this process, facilitating testing, hybrid deployments, and preparation for the larger key sizes inherent in PQC.

Executive Order 14412 was written for U.S. federal agencies, but it doesn’t stop there. It puts a concrete requirement on government contractors, and directs the Secretary of State to actively engage foreign governments and industry groups to encourage their adoption of the same NIST-standardized PQC algorithms.

Robert Rogenmoser, CEO of Securosys
Stay current

See today’s quantum computing news on Quantum Zeitgeist for the latest breakthroughs in qubits, hardware, algorithms, and industry deals.

Avatar of Ivy Delaney

Ivy Delaney

Ivy Delaney has been working with neural networks and machine learning since the mid-nineties, back when a couple of hidden layers and a long afternoon of training counted as ambitious. She has watched the field go from academic curiosity to the thing quietly running underneath everything, and she brings that long view to quantum computing. For Quantum Zeitgeist she covers the ground where the two fields meet. That means quantum machine learning and the variational algorithms it leans on, and it also means the less glamorous but more interesting story of classical machine learning already doing real work inside quantum machines, decoding error-correcting codes, calibrating noisy hardware and learning the error models that simulators depend on. She writes about the hardware those algorithms have to run on too, and about the post-quantum cryptography scramble that the same hardware has set off. Her stories typically start with the paper, whether that is peer-reviewed work, conference proceedings or an arXiv preprint, with the source linked so you can hold a claim up against the research it came from. She is unimpressed by benchmarks that will not say what they beat, and by demonstrations that only work in the press release.

Latest Posts by Ivy Delaney: