Key Points
- The U.S. Executive Order issued in June 2026 accelerated the migration to post-quantum cryptography by setting concrete implementation requirements. To prepare for security risks posed by advances in quantum computing, the Trump administration set 2030–2031 migration deadlines for certain critical federal systems and directed each agency to designate a responsible official and develop a migration plan.
- Through federal procurement and international engagement, the United States is seeking to drive adoption of NIST’s PQC standards across industry and among foreign governments. As a result, some Japanese companies may need to migrate earlier than the 2035 target set by the Japanese government.
- No cryptographic method remains secure forever. As standards and security requirements evolve, companies need to build the capability to update their cryptography when necessary. This capability is known as crypto-agility.
Why PQC Migration Matters Now
Cryptography has traditionally been viewed as a technical issue for IT departments. Increasingly, however, it is becoming a management issue as well.
Cryptography is embedded in many everyday business activities, from electronic contracts and cloud services to payments and product and software authentication. It helps verify identities, protect sensitive data, and preserve data integrity. Together, these functions support the trust on which business transactions and data flows depend.
As noted in our previous report, quantum computers could eventually break some forms of widely used public-key cryptography. Because cryptographic migration can take years, companies need to begin transitioning to post-quantum cryptography (PQC) before quantum decryption becomes a practical threat.
A U.S. Executive Order issued in June 2026 has further accelerated PQC migration by moving the issue from preparation toward implementation. The order set 2030–2031 migration deadlines for certain critical U.S. government systems and launched the process of incorporating PQC readiness into federal procurement. As a result, some Japanese companies may need to act earlier than the Japanese government’s 2035 migration target.
Our previous report examined the risks quantum computers pose to existing cryptography, why PQC migration takes time, and NIST’s standardization efforts. This report focuses on how the Executive Order is moving PQC migration from policy to implementation, how it may affect Japanese companies, and how companies should decide when to act.
Why the United States Is Accelerating PQC Migration
The U.S. Executive Order of June 22, 2026 moved PQC migration from a long-term policy objective into an implementation phase with concrete deadlines and clear lines of responsibility.
In the United States, NIST published its PQC standards in 2024, and the federal government had already set a long-term goal of reducing quantum risk by 2035. Agencies were also conducting inventories of cryptographic systems and preparing for migration. The new Executive Order takes these efforts a step further by setting deadlines, assigning responsibility, and specifying how agencies are to proceed with migration.
This urgency stems from two related risks. First, future quantum computers could break widely used public-key cryptography. Second, adversaries may collect and store encrypted data today in order to decrypt it once sufficiently powerful quantum computers become available. Systems that rely on vulnerable public-key cryptography to protect highly sensitive information and critical infrastructure therefore need to migrate to PQC before quantum-enabled decryption becomes a practical threat. These risks are driving the U.S. government’s push to accelerate PQC migration.
On the same day, the administration issued a separate Executive Order to accelerate the research, development, and commercialization of quantum technologies. The order directs the government to update its government-wide quantum strategy, with a focus on quantum computing, sensing, and networking. It also calls for an assessment of the national security implications of advances in commercial quantum computing, including their potential impact on PQC migration. Taken together, the two orders pursue a dual objective of advancing U.S. quantum capabilities while preparing for the cryptographic risks those advances could create.
Although the Executive Order itself does not mention China by name, quantum technology is widely viewed in the United States as an important arena of U.S.–China technological competition. That broader strategic context is one factor behind the policy shift. Interviews with think-tank experts close to the administration also indicate that senior officials consulted experts from major technology companies on quantum commercialization and international competition before the order was issued.
Four Key Measures in the Executive Order
Against this backdrop, the Executive Order set out four key measures for PQC migration.
First, it set PQC migration deadlines for the U.S. federal government’s High Value Assets (HVAs) and high-impact systems. Agencies must migrate cryptographic key establishment for secure communications to PQC by the end of 2030 and digital signatures by the end of 2031. National Security Systems (NSS) are excluded from these deadlines.
Second, it required each federal agency to designate an official responsible for PQC migration and, after reviewing its inventory of High Value Assets and high-impact systems, to develop a prioritized migration plan. This establishes clear accountability and requires agencies to prioritize migration rather than treat cryptographic updates as an ad hoc task.
Third, the order begins the process of incorporating PQC readiness into federal procurement. This could extend PQC requirements through contract terms to companies that supply products and services to the federal government. To that end, the order directed the publication, within 180 days, of a proposed rule amending the Federal Acquisition Regulation (FAR) that would require covered government contractors, by the end of 2030, to comply with NIST’s Federal Information Processing Standards (FIPS), including standards that incorporate PQC algorithms.
The Executive Order does not itself impose new requirements on government contractors. The scope of covered contracts and contractors, including whether requirements will extend to subcontractors and suppliers, will become clearer when the proposed rule and subsequent final rule are issued.
Fourth, the order extends beyond federal agencies’ own migration by encouraging foreign governments and industry associations in other major countries to adopt NIST’s PQC standards. This signals a broader U.S. effort to promote international adoption of the standards it has institutionalized domestically. The timing and extent of adoption across individual countries and private markets, however, remain uncertain.
Table 1. Key Milestones for PQC Standardization and Migration in the United States
| Timing | Milestone |
| 2024 | NIST publishes its first PQC standards |
| June 2026 | U.S. Executive Order issued |
| Within 180 days of issuance | Deadline for publication of a proposed rule amending the FAR |
| End of 2030 | Deadline for migration of cryptographic key establishment in critical systems to PQC |
| End of 2031 | Deadline for migration of digital signatures in critical systems to PQC |
Source: Compiled by the author.
Taken together, the Executive Order established migration deadlines for critical federal systems, required agencies to designate responsible officials and prepare migration plans, and initiated steps to incorporate PQC readiness into federal procurement and promote NIST standards internationally. The specific procurement requirements and their scope, as well as the implications for supply chains involving Japanese companies, will depend on the proposed FAR rule, the final rule, and subsequent market responses.
These changes in policy and standards make the ability to update cryptography increasingly important. The next section examines why this capability matters for companies’ economic security.
Why Crypto-Agility Matters for Economic Security
The Executive Order also highlights a broader challenge for companies. As security assessments and technologies evolve, companies may need to update their cryptography repeatedly rather than treat PQC migration as a one-time exercise.
No cryptographic method remains secure forever. Even a newly deployed method can become vulnerable as technology advances. Replacing widely deployed cryptography can take many years. PQC migration should therefore be approached as part of a broader effort to build an enduring capability to adapt to future changes in cryptographic standards.
The ability to update cryptographic methods as needed is known as “crypto-agility.” It enables companies to respond as cryptographic security requirements and technologies change. Once cryptographic standards are reflected in government procurement, product specifications, and contract terms, the issue extends beyond system security to business continuity and market access. Crypto-agility is therefore not only an IT concern but also a management capability with direct implications for business continuity.
The United States is incorporating NIST’s PQC standards into government procurement and encouraging foreign governments and industry associations in other major countries to adopt them. If these standards are incorporated into national frameworks, industry standards, and procurement specifications, a company’s ability to respond could affect both market access and business continuity. A company unable to migrate quickly to secure cryptographic methods could find it harder to participate in government procurement or maintain existing business relationships. It could also face disruptions in product and service delivery and, in some cases, be forced to suspend part of its operations. Crypto-agility can therefore be viewed as an important economic security capability.
How U.S. PQC Policy May Affect Japanese Companies
The Japanese government also views PQC migration as an urgent priority, as advances in quantum computing could undermine the security of current public-key cryptography. The government aims, in principle, to complete the transition to PQC across government agencies and related entities by 2035 and plans to develop a detailed roadmap in fiscal year 2026.
Although the scope of their respective targets differs, Japan and the United States are now pursuing PQC migration on different timelines. The United States has set 2030–2031 deadlines for certain critical systems and is moving to incorporate PQC readiness into federal procurement. The two countries’ timelines are not directly comparable, but Japan’s forthcoming roadmap will be an important indicator of whether and how the new U.S. deadlines influence Japan’s approach.
Japan’s cooperation with the United States and South Korea on critical technologies also provides important context for assessing the implications of U.S. PQC policy. Japan and the United States are deepening cooperation on critical and emerging technologies, including quantum technologies, spanning R&D, technology protection, and supply-chain security. The three countries also discussed how to address threats to the quantum ecosystem at an intergovernmental meeting in September 2025. At a foreign ministers’ meeting in July 2026, they noted progress in economic security cooperation, including efforts to protect and promote critical and emerging technologies such as AI and quantum. Against this backdrop of policy coordination, changes in U.S. quantum and PQC policy could have implications for Japan as well.
The U.S. Executive Order does not currently impose uniform migration deadlines or specific PQC requirements on private-sector companies. However, as Table 2 shows, Japanese companies without direct U.S. government contracts could still be affected through federal procurement supply chains, changes in product and service specifications, or requests from overseas customers and business partners. Companies may therefore need to assess their PQC readiness and, where necessary, update affected products or systems.
Table 2. Channels Through Which U.S. PQC Policy Could Affect Japanese Companies
| Channel | Potentially Affected Companies | Possible Effects |
| Changes to government procurement rules | Companies that contract directly with the U.S. government or supply parts, equipment, software, maintenance services, or other inputs for government projects | May be required to comply with FIPS or demonstrate PQC readiness as a condition of a contract |
| Requests from overseas customers and partners | Companies that provide products and services overseas, do business with overseas customers or financial institutions, or participate in global supply chains | May be asked to explain their PQC readiness or comply with new product specifications or contract requirements |
| Changes to product and service specifications | Companies that use cloud services, software, network equipment, or digital certificates, or connect to business partners’ systems | May need to upgrade to compliant products, verify connectivity, or replace certificates and equipment |
Source: Compiled by the author.
The specific federal procurement requirements and their scope will become clearer as the FAR rulemaking process advances. It also remains uncertain how broadly PQC readiness will be reflected in product and service specifications, national frameworks, and commercial terms. Companies should therefore monitor not only the FAR process but also major vendors’ plans and evolving requirements from customers and business partners.
When Japanese Companies Should Begin Preparing for PQC
The United States has moved from preparation to implementation, setting concrete deadlines and beginning to incorporate PQC into federal procurement. This does not mean that all Japanese companies need to migrate immediately. It does, however, mean that companies should begin assessing where PQC requirements may affect them and how much lead time they would need to respond.
Companies that handle information requiring long-term confidentiality, such as R&D and design information or medical and financial information, may need to act before external requirements emerge. They should determine when to act based on the future risk of quantum decryption and the period for which their information must remain protected.
Japanese companies should consider two factors when deciding when to act. The first is their potential exposure to external PQC requirements through U.S. federal procurement, overseas customers and business partners, or major vendors’ migration plans. The second is their own information-protection needs, including whether they hold information requiring long-term protection and how long it will take to update relevant systems (Table 3).
Table 3. Key Considerations for Japanese Companies in Determining When to Act on PQC
| Consideration | Questions to Ask | Timing Implications |
| Potential Sources of External PQC Requirements | ||
| Exposure to U.S. government procurement | Whether the company contracts directly with the U.S. government or supplies products, parts, equipment, software, maintenance services, or other inputs for government projects | Review the FAR rulemaking process and assess early whether requirements could reach the company through contractors, customers, or business partners |
| Exposure to overseas customers and partners | Whether overseas customers, financial institutions, or business partners may require FIPS compliance or ask the company to demonstrate its PQC readiness | Assess and document the company’s current PQC readiness before such requests arise |
| Changes to product and service specifications | For cloud services, software, network equipment, and digital certificates the company uses or provides, whether vendors have announced PQC-related specification changes, migration timelines, supported versions, or equipment-replacement requirements | Track vendor plans and assess whether product or system updates, connectivity testing, or certificate and equipment replacement may be required |
| Internal Information-Protection Needs | ||
| Information requiring long-term protection | Whether the company holds information that must remain confidential over the long term, such as R&D and design information, medical and financial information, and personal information | Assess the implications early, taking into account the required confidentiality period and migration lead time |
| Systems and equipment with long upgrade cycles | Whether the company has proprietary systems, long-lived equipment, or systems connected to partners | Work backward from the time required for upgrades, validation, connectivity testing, and equipment replacement to determine when to begin |
| Integration with product development, contracts, and procurement | Whether PQC readiness should be incorporated into product development, system upgrades, procurement, and contract renewals | Align action with the next development cycle, system upgrade, procurement, or contract renewal |
| Governance for prioritization | Who is responsible for assessing the need for and prioritization of PQC measures for information and systems requiring protection | Establish with the responsible department or official when, and under what conditions, the assessment should be revisited, taking into account information-protection periods and system-upgrade timelines |
Source: Compiled by the author.
Crypto-Agility as an Economic Security Capability
It is difficult to predict when quantum computers will become capable of breaking today’s public-key cryptography. Yet the U.S. Executive Order has moved PQC migration from planning into implementation by setting concrete deadlines, assigning responsibility, and initiating changes to federal procurement. These developments could affect Japanese companies through government procurement, changes in product and service specifications, and relationships with overseas customers and business partners. Some companies may need to migrate before the Japanese government’s 2035 target. The first step is for companies to assess where they may be affected and how much time they will need to respond.
No cryptographic method remains secure forever. PQC policies, cryptographic standards, and product specifications will continue to evolve. Companies therefore need more than a plan for a single migration. They need the organizational capability to update their cryptographic systems as policies, standards, and technologies change. The essence of PQC migration is not simply to replace one cryptographic method with another, but to build the capacity to make such changes when necessary without disrupting operations. In this sense, crypto-agility should be understood as an economic security capability that supports business continuity.
(c) Official White House Photo by Joyce N. Boghosian
