By

In June 2026, the White House signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks.” The EO sets two deadlines for federal agencies: key establishment, meaning encryption, must move to post quantum cryptography (PQC) by December 31, 2030, and digital signatures, meaning authentication, must follow by December 31, 2031.

Those dates are real, and if you sell to or support the federal government, they apply to you, too. Some people were surprised that federal contractors are expected to meet the same encryption deadline, but it makes sense- security is security.

I apologize for my honesty in advance but, organizations should have started this work already. The threat this order responds to, adversaries harvesting encrypted data now to decrypt once quantum computing catches up, isn’t new information. We knew a threat is coming but ignored it! If your organization hasn’t begun planning, you’re behind  and might pay more in the long run.

But behind is not the same as too late. The right move today is not panic, and it’s not pretending the deadline is further away than it is. It’s starting now, deliberately, with a plan you can actually execute.

Own your posture, then ask for help where it counts

Every organization should own its security posture. That doesn’t mean doing everything in house. It means you, not a vendor, decide what your risk looks like, what your priorities are, and where you genuinely need outside expertise. Asking for help in the areas where you lack depth is smart. Handing over your entire posture to someone else because they promised to handle it is not smart.

This is where I’ll say something that comes directly from years on the offensive side: an organization that has fully outsourced its cybersecurity is exactly the kind of target that stays compromised the longest. If you believe you’re secure because you signed a contract, and you never independently verified that was true, the outsourcing itself becomes the vulnerability. I’ve seen how long an adversary can operate inside an environment where the defenders trusted a vendor’s assurance instead of their own understanding.

Start with inventory, then build the right team around it

You cannot protect or replace cryptography you don’t know you have. That’s the first, unglamorous step, and it comes before anything else in this planning stage.

Once inventory is underway, bring in vendors and consultants, but understand why you need both, because they do different jobs. Vendors are generally built to discover: they run tools, scan environments, and produce a picture of what’s out there. The right consultant’s job is to look for what the vendor’s tooling missed, the edge cases, the legacy systems, and the places automated discovery doesn’t reach on its own.

Yep, I said a dirty secret out loud. The best tools do not find everything! An adversary doesn’t need to go after what you protected.  They go after the weakest link, what you forgot or ignored or didn’t see.

If a vendor tells you their platform discovers everything and no further verification is needed, that’s a signal to walk away. The combination that actually works is your internal team, a capable vendor, and an independent consultant checking the gaps between them. That’s what gets an organization through inventory successfully, and it’s the foundation everything else in this series builds on.

Remediation, what to actually do once you know what you have, is its own conversation. That’s coming later in this series. For now, the work is knowing where you stand, and building a team you can trust to tell you the truth.

Where MIL fits

MIL helps organizations assess cryptographic risk, build actionable migration roadmaps, and prepare for PQC through modular services tailored to their needs. Explore MIL’s approach to PQC readiness.