The Office of Management and Budget (OMB) has issued government-wide guidance directing federal agencies to accelerate their migration to post-quantum cryptography (PQC), requiring agencies to prioritize their most critical systems and submit detailed migration plans within 120 days. The June 24 memorandum implements President Donald Trump’s June 22 executive order on securing the nation against advanced cryptographic attacks. The guidance excludes national security systems. Federal agencies are instructed to mitigate “as much quantum risk as feasible” by Dec. 31, 2030. “Strong cryptography has enabled the United States Government to protect Federal information, securely deliver critical services to the American people, and guard against cyber-enabled fraud,” OMB Director Russell Vought wrote in the memo. “The Trump-Vance Administration has made support of strong cryptography throughout the Government and private sector a priority.” The guidance reflects growing concern that future cryptographically relevant quantum computers could eventually break many of today’s widely deployed public-key encryption algorithms. While such computers are not yet known to exist, OMB said advances in quantum computing could make current encryption vulnerable within the next decade, requiring agencies to begin transitioning now to National Institute of Standards and Technology (NIST)-approved post-quantum cryptographic algorithms. In August 2024, NIST unveiled its first set of encryption algorithms designed to withstand cyberattacks from a quantum computer, which agencies can implement immediately. OMB directed agencies to prioritize the migration of high impact systems, high value assets, and any other systems containing highly sensitive information or deemed particularly vulnerable to quantum-enabled attacks. Agencies are also instructed to establish governance structures that extend responsibility beyond chief information officers and chief information security officers to agency leadership more broadly. Each agency must submit a PQC migration plan to OMB and the Office of the National Cyber Director within 120 days. Plans must include a risk-based system prioritization strategy,