ポスト量子暗号化の行政命令は重要なマイルストーン、今こそ実務へ
本文の状態
日本語全文を表示中
詳細モードで約23分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
Cloudflare Blog
トランプ大統領が署名した行政命令により、連邦機関は2030年までに最も機密性の高いシステムをポスト量子暗号化へ移行し、認証も2031年までに完了するよう義務付けられた。クラウドフレアはこの方針を歓迎している。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るSource Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
2026 年 6 月 22 日、トランプ大統領は「高度な暗号化攻撃からの国の保護」と題する行政命令第 14409 号に署名しました。この命令では、連邦機関に対し、最も機密性の高いシステムをポスト量子暗号へ移行するための期限を 2030 年 12 月 31 日とし、ポスト量子認証への移行期限を 2031 年 12 月 31 日と定めています。また、この行政命令は連邦請負業者に対し、2030 年末までにポスト量子の連邦情報処理基準(FIPS)に準拠するよう指示しています。
私たちはこの行政命令を歓迎します。米国政府は、連邦主導と調達を通じて業界全体における新技術の普及を推進するという長い実績を持っています。IPv6 やルーティングセキュリティ、リソース公開鍵インフラストラクチャ(RPKI)、DNSSEC においてその成功を見てきた私たちは、ポスト量子暗号においてもこの伝統が続くことを嬉しく思います。
この大統領令は、インターネット全体で使用されている公開鍵暗号を量子コンピュータが破る日である「Q-Day」のタイムラインが加速しているという点で、特に今まさに重要な局面にあります。2026 年 4 月、Google や Oratomic による研究における画期的な進展を受け、Cloudflare は完全なポスト量子セキュリティ(post-quantum security)の実現目標を 2029 年に引き上げました。この大統領令は、2024 年のガイダンスを更新するものです。当時、米国国立標準技術研究所(NIST)は、インターネット全体で使用されている古典的な公開鍵暗号(具体的には、強力な量子コンピュータが利用可能になった際に破られる可能性のある RSA および楕円曲線暗号)を 2030 年までに廃止し、2035 年以降の使用を禁止すべきだと述べていました。
インターネットのポスト量子暗号化への移行は順調に進んでいますが、ポスト量子認証への移行はまだ始まったばかりです。現在、Cloudflare ネットワークへのブラウザトラフィックの 3 分の 2 以上がポスト量子暗号化によって保護されており、当社の製品のほとんどがポスト量子鍵合意に対応しています。SASE プラットフォームである Cloudflare One は、TLS、MASQUE、IPsec を含む主要なオンランプおよびオフランプすべてでポスト量子暗号化を提供しています。私たちは最近、ポスト量子認証の展開を開始し、2029 年までに完全なポスト量子セキュリティを実現することを目指しています。この行政命令(EO)は優れた基盤であり、過去 2 つの政権による取り組みの上に成り立っています。私たちは 2019 年から、この行政命令が連邦機関に対して求めている作業を実行しており、同命令が適切に定めた点についていくつかの考えを持っています。また、予算管理庁(OMB)がコスト効果の高い機関移行を強化し促進する機会も見ています。さらに、組織や機関がいかにして移行を最も効果的に進めるかというロードマップも提示します。
連邦システムに対する行政命令(EO)の要件
EO の拘束力のある要件の大部分は、2 つのカテゴリーの連邦システムを対象としています。すなわち「高価値資産(HVAs)」と「高インパクトシステム」です。HVAs とは、OMB によって政府の「王冠の宝石」として指定された連邦情報またはシステムを指し、その侵害が国家安全保障、外交関係、あるいは国民の信頼に重大な影響を与える可能性のあるシステムです。これには数百万人の連邦職員記録を保持するデータベースや、機密情報を処理するシステム、連邦財務取引を管理するプラットフォームなどが含まれます。一方、「高インパクトシステム」とは、FIPS 199 の基準において機密性、完全性、または可用性が「高い」と評価されたシステムを指し、侵害が発生した場合に人命の喪失、巨額の経済的損害、あるいは機関がその任務を果たす能力の著しい低下など、深刻な被害をもたらす可能性があります。
この EO は連邦機関に対して拘束力を持ちますが、他の組織(つまり重要インフラ、州・地方・先住民族・領土政府、学術界、市民社会)には適用されません。そのため、本 EO が設定する期限は連邦機関のみを対象としています:
日付
要件
2026 年 7 月
各連邦機関の長が後量子暗号(PQC)移行の責任者を特定し、その氏名と連絡先を OMB および国家サイバーディレクターに提出する。
2026 年 9 月
OMB がガイダンスを発出し、各機関に対して以下の事項を要求する:(1) HVA および高インパクトシステムの在庫レビューを行うこと、(2) PQC 移行の計画を立てること、(3) その計画を OMB および国家サイバーディレクターに提出すること。
2030 年 12 月
すべての高価値資産(HVA)および高影響システムは、鍵確立のために後量子暗号(PQC)への移行が必須です。
2031 年 12 月
すべての高価値資産(HVA)および高影響システムは、デジタル署名のために後量子暗号(PQC)への移行が必須です。
国家安全保障システムはこれらの期限から明示的に除外されています。これらは NSA が管理する別個の機密トラックにあり、2030 年から 2033 年までの期限はすでに 2022 年に設定されています。
二つの移行:暗号化と認証。どちらも今すぐ開始すべきです。
エグゼクティブ・オーダー(EO)は、後量子暗号(PQC)の移行を二つのフェーズに分割しています。2030 年までに後量子鍵確立(暗号化)、そして 2031 年までに後量子デジタル署名と証明書(認証)です。これは、今日のインターネット上で利用可能な後量子暗号の状況を正確に反映したものです。我々自身の完全な後量子対応(認証を含む)のための期限は 2029 年ですが、業界では最も早期採用者の一つです。
また、エグゼクティブ・オーダー(EO)が NIST 標準化された後量子暗号アルゴリズムに焦点を当てており、量子鍵配送(QKD)には言及していない点も嬉しく思います。なぜなら、QKD は送信者と受信者の間に専用の物理リンクと特殊なハードウェアが必要であるため、インターネット規模では動作しないからです。
それでは、エグゼクティブ・オーダー(EO)で求められ、必要とされている二つの移行、すなわち後量子暗号化と後量子認証について、より深く見ていきましょう。
量子耐性暗号化は、今日収集した暗号化トラフィックを将来、量子コンピュータが十分な性能に達した際に解読する「 Harvest Now, Decrypt Later」攻撃を防ぐために今日必要とされています。政府機関、銀行、医療組織、防衛請負業者、通信事業者など、3〜10 年後も敵対勢力にとって価値を持つデータを扱う組織にとって、量子耐性暗号化は特に重要です。
量子耐性認証は、量子コンピュータを保有する敵対者がサーバーのなりすましのために証明書を偽造したり、悪意のあるコード署名を生成したり、システムへの不正アクセスを得たりすることを防ぎます。量子耐性認証は、暗号的に重要な量子コンピュータ(CRQC)が存在した場合にのみ可能となる攻撃を防ぐためのものであり、Q-Day のリスクが現実化した後に必要となります。
移行期間のスケジュールを量子コンピューティングの進展と文脈化して理解することが重要です。昨日発表された量子耐性セキュリティに関する大統領令に加え、トランプ大統領はまた、量子コンピューティング、センシング、およびネットワークの展開と商業化を加速させるための別の大統領令にも署名しました。その大統領令が量子耐性認証に対して 2031 年までの期限を設定している事実は、重要な示唆を含んでいます:米国政府は、CRQC がその時期に運用可能となる可能性が無視できないほどあると考えているのです。

これらの 2 つの技術の現状はどうでしょうか。ポスト量子認証への移行は、いくつかの理由からポスト量子暗号化よりも大きな課題です。具体的には以下の通りです。
ポスト量子 ML-DSA(Machine Learning Digital Signature Algorithm)デジタル署名は、従来のデジタル署名よりもサイズが大きくなるため、一部のシステムの性能に影響を及ぼす可能性があります。例えば、短期間の TLS 接続においてその影響が顕著になります。そのため、TLS のパフォーマンス問題を解決するために、私たちは Google Chrome と共同で Merkle Tree Certificates(メルカー木証明書)の開発に取り組んでいます。
ポスト量子認証の依存チェーンはより長く、クライアント、サーバー、証明機関、証明透明性ログ、ルートストア、ブラウザ全体にわたる調整されたアップグレードが必要です。
これまでのところ、ポスト量子暗号化が非常に広く展開されているのに対し、ポスト量子認証のエコシステムにおける展開は限定的です。
興味深いことに、EO(Encryption Obligation)では、暗号化と認証の期限の間に 1 年のギャップを設けています。追加される 1 カ年の時間はタイトなため、この作業を順次進めることはできません。エコシステムはこれらの 2 つの目標に対して並行して取り組みを開始する必要があり、そうしなければ 2031 年の期限を見逃すことになります。
インターネット全体における暗号化の導入は、インターネットエンジニアリングタスクフォース(IETF)が開発した標準規格なしには実現できません。同団体は、そのプロトコルをポスト量子暗号へ移行する作業を進めています。TLS コミュニティは先行しており、IETF の PLANTS ワーキンググループが TLS 用のポスト量子証明書について着実に進展を遂げています。ここで行うべき作業は多くありますが、私たちは IETF の取り組みをサポートすることを楽しみにしています。
サプライチェーンにおける圧力が皆に役立つ
この行政命令(EO)には連邦政府の請負業者に対する要件が含まれており、これが EO の中で最も影響力のある部分となる可能性があります。
具体的には、FAR カウンシルは、2030 年 12 月 31 日までに「対象請負業者」が NIST FIPS に組み込まれたポスト量子暗号(PQC)アルゴリズムを遵守するよう求める規則案を公布する必要があります(第 6(c) 条)。また、FAR カウンシルは、暗号的脆弱性を含む脆弱性情報開示プログラムを実装することを請負業者に義務付ける規則案も公布する必要があります(第 6(d) 条)。これらの規則案にはパブリックコメント手続きを経る必要がありますが、行政命令で定められた 2030 年 12 月 31 日という期限は依然として重要です。この期限は、連邦機関がポスト量子認証への移行を完了する必要がある時期よりも 1 年前であり、これにより連邦請負業者が各機関の期限に間に合うように準備を整えることができます。
連邦機関が後量子暗号(PQC)へ移行できるのは、購入する製品が PQC をサポートしている場合に限られます。これを具体化するため、CISA は「後量子暗号基準を利用する技術の製品カテゴリ」を公開し、すでに PQC が「広く利用可能」な技術と、まだ「移行中」にある技術を明確に区別しました。「広く利用可能」リストには、クラウドプラットフォーム(IaaS、PaaS)、ウェブブラウザおよびサーバー、チャット・メッセージングソフトウェア、フルディスク暗号化などのエンドポイントセキュリティ製品が含まれます。これらのカテゴリについて、CISA のガイダンスは明確です:組織は PQC 対応の製品のみを調達すべきです。一方、「移行中」リストには、まだ PQC が広く利用されていないネットワーク機器(ルーター、ファイアウォール、スイッチ)、ID およびアクセス管理システム(HSM、認証局、ID プロバイダー)、メールサーバーおよびクライアント、データベースシステムが含まれています。
契約業者に対して2030年までにPQC(耐量子暗号)準拠製品を提供するよう指示し、成熟市場においてPQC対応ベンダーを即座に優先させるよう機関に命令することで、連邦枠組みはベンダー生態系に対し、固定されたタイムラインでPQC対応製品の出荷を強制的に要求しています。連邦要件に基づいてベンダーが構築した製品は、最終的に病院、銀行、大学、中小企業によって使用されることになります。これにより、PQCサポートがより広く利用可能になります。Cloudflareもこれらの要件の対象となる多くのベンダーの一つですが、ネットワークソフトウェアとクラウドサービスはすでにCISA(サイバーセキュリティ・インフラストラクチャ・セキュリティ庁)によって広く利用可能なPQCカテゴリとして指定されているため、追加費用なしで当社の製品の大半に耐量子暗号を実装済みです。
重要インフラとすべての人へのPQ
この行政命令はまた、エネルギー、金融サービス、水道、交通、通信、医療など、機能停止が国に対して深刻または重大な影響を及ぼす可能性のある他のシステムを含む重要インフラについても言及しています。連邦政府の行政命令には重要インフラの所有者および運営者に対する厳格な移行期限は設けられていませんが、特定の連邦機関に対し、重要インフラの所有者および運営者のPQC移行計画を支援するよう指示しています(第5条(a)項)。
この大統領令は主に米国の連邦機関および重要インフラに焦点を当てていますが、ポスト量子暗号化はインターネット接続を持つすべての個人や組織にとって重要です。現在も「 Harvest-now-decrypt-later(今収集し後で解読)」攻撃のリスクが存在します。そして Q-Day 以降、量子コンピュータを装備した敵対者による不正アクセスのリスクが、大規模な企業から小規模な組織に至るまであらゆる組織に影響を及ぼすことになります。
2014 年に無料のユニバーサル SSL を開始した際、当社の CEO マシュー・プリンスは次のように述べていました:
最先端の暗号化技術が小さなブログにとって重要に見えないかもしれないとしても、それはインターネットの「デフォルトで暗号化された未来」を推進する上で極めて重要です。インターネット上を流れるあらゆるバイト(データ単位)が、たとえ些細なものに見えるものであっても、それを暗号化して通過させることは、ウェブを傍受・スロットリング(速度制限)・検閲しようとする者たちにとってより困難になります。
私たちはポスト量子暗号化についても同じ考えを持っています。そのため、私たちが構築するすべてのポスト量子アップグレードは、すべての顧客に対して、あらゆるプランで、追加費用なしに利用可能です。

OMB の実施ガイダンスにおける機会
本行政令は方向性を定めたものであり、今や OMB は連邦機関全体にわたる最も効果的な PQC(耐量子暗号)移行を達成するために、重要な明確化と運用ガイダンスを提供する 90 日間の猶予期間に入りました(第 4(b) 条)。私たちが自らの PQC 移行から得た教訓に基づき、このガイダンスに含めるべき要素としていくつか提案します。
「移行」の意味を定義すること。本行政令は機関に対しシステムを PQC に「移行」するよう求めていますが、「移行」という言葉の定義は一切示されていません。これはシステムが PQC アルゴリズムをサポートすることを意味するのか、それとも優先的に採用することを意味するのか、あるいは古典暗号を完全に無効化することを意味するのか。
これらは非常に異なるセキュリティ姿勢です。ML-KEM をサポートしつつも古典暗号のみによる TLS ハンドシェイクを許可するシステムは、ダウングレード攻撃に対して脆弱です。トラフィックを傍受できる敵対者は、接続を古典的な鍵交換へと強制的にダウングレードさせることができます。そのシステムは名目上 PQC に「移行」したことになりますが、行政令が防止しようとしているのと同じ量子攻撃に対して依然として脆弱なままです。
歴史は教訓を与えてくれます。2014 年の POODLE 攻撃後に SSLv3 が廃止された際、サーバーは後方互換性の維持のために SSLv3 を有効に置いたままであり、攻撃者が接続をダウングレードさせて SSLv3 の弱点を悪用することを可能にしていました。生態系全体が実際に SSLv3 をオフにするまでには数年を要しました。このパターンを繰り返さないためには、「完了」の明確な定義が必要であり、そこにはダウングレードを防ぐために量子耐性のない暗号化を無効化することが含まれるべきです。
暗号の俊敏性:暗号の俊敏性とは、システムを再設計することなく暗号化アルゴリズムを交換できる能力のことです。大統領令は特定の NIST 暗号基準への移行を義務付けていますが、将来これらのアルゴリズムに変更が必要になった場合に暗号化アルゴリズムを交換できるシステムを構築することについては言及していません。暗号の俊敏性とは、すべてのアルゴリズムを同時にサポートすることを意味するのではなく、将来コミュニティがより優れたアルゴリズムに収束した際に、アップグレードが再設計ではなく設定変更で済むようなシステムを構築することを意味します。OMB はこの点をガイダンスに含めるべきです。
CBOM あるいは量子影響インベントリ?大統領令は、CISA と NIST に、暗号化部品表(CBOM)の最小要素に関するガイダンスを 270 日以内に公表するよう指示しています(第 5(d) 条)。CBOM は、特定のハードウェアまたはソフトウェア製品で使用されている暗号化アルゴリズム、プロトコル、実装のインベントリであり、ソフトウェア部品表(SBOM)に類似したものです。
理論的には、暗号資産のビルドオブジェクト(CBOM)は優れたアイデアです。しかし実際には、包括的な暗号資産の棚卸しを行動の前提条件として扱うことには注意が必要です。すべての製品内のすべてのライブラリに含まれるすべてのアルゴリズムの詳細な CBOM を作成するには長い時間がかかり、連邦機関にとっては発見ツールの導入とコンサルティングを含めた調達サイクル全体を要する可能性があり、棚卸しが完了した時点ですでに陳腐化している恐れもあります。また、CBOM には暗号化を使用すべきだが実際には使用されていないシステムは記載されません。さらに、CBOM は鍵の目的を理解せずに単に鍵を列挙するだけであるため、量子耐性のある鍵に関連するリスクを理解しようとする組織にとっては有用性が低下します。
私たちは、量子インパクト棚卸しの方がより生産的な枠組みになると考えています。システムまたはそのデータが侵害された場合の影響はどのようなものか?それが起こる可能性はどの程度か?リスクを軽減するための対策として、差し込み型代替品の導入、ソフトウェアの更新、または大量のポスト量子接続(post-quantum connection)によるトラフィックのトンネリングやインターネットからの隔離といった補完的制御措置など、どのような手段が講じられる可能性があるか。各オプションの実現可能性はどの程度で、それがどのような依存関係チェーンを生み出すのか。これらの要素を特定することが、まずどこに行動を集中させるべきかを判断する根拠となります。組織にとって適切であれば、後から完全な CBOM の詳細を埋めていくことも可能ですが、まずは最も露出度が高く、影響の大きいシステムを発見することから始めるべきです。
ポスト量子暗号をすべての人が利用できるようにする。ポスト量子暗号がゲート付きの贅沢品として扱われ、普遍的な基準と見なされない場合、真の国家的レジリエンスは失敗します。OMB の政策は、資金不足の重要インフラを置き去りにしたり、連邦機関の技術的負債を増やしたりするようなベンダーロックインや通行料徴収に抵抗すべきです。
今すぐ何をすべきか:2030 年まで待たない
2030 年を待つ必要も、包括的な暗号資産目録を作成するまでもありません。移行を開始することは可能です。歴史が示すように、暗号の更新は難しく、長い時間を要することがあります。他の組織も同様に自らの移行の整理を始めるべきです。したがって、連邦機関向けの OMB ガイドラインが出るのを待っている間、すべての組織に対して以下の推奨事項を示します。
インターネットトラフィックを今すぐ保護してください。まず、公衆インターネットを横断するトラフィックから始めましょう。これは現在、敵対者にとって収集が最も容易であり、最も即座にリスクにさらされているからです。ウェブトラフィックが Cloudflare を経由している場合、その接続は主にポスト量子暗号化によって保護されています。エンタープライズネットワークで Cloudflare One を使用している場合、プライベートネットワークのトラフィックも同様に保護されます。プロバイダーがポスト量子暗号化をサポートしていない場合は、サポートするプロバイダーに切り替えてください。ネットワーク内で実行されている個々のアプリケーションがまだアップグレードされていない場合でも、個々のシステムがまだ目録化されておらずアップグレードされていないとしても、トラフィックをポスト量子暗号化されたインフラ経由でトンネリングして一括保護を開始してください。
翻訳全文
調達方針の見直し。すべての技術調達において、「追加費用なしで標準的にポスト量子暗号化を採用し、ポスト量子認証および暗号アジリティのための明確なロードマップを持つこと」を要件として明記してください。ベンダーがポスト量子セキュリティに対して追加料金を請求する場合や、ロードマップ・計画を持っていない場合は、その理由を問いただすか、別のベンダーを探してください。
量子影響インベントリの作成。プライベートネットワークの境界内に留まり、パブリックインターネットに露出していないトラフィックについては、攻撃者がネットワーク内に侵入してデータを捕捉する必要があるため、「今収穫し後で復号化」というリスクは低くなります。ただし、移行計画を立てるために内部システムが使用する暗号方式を把握しておく必要があります。量子影響インベントリを活用して取り組みの優先順位をつけましょう。例えば、機密データを扱うシステムやパブリックインターネットに露出している接続に焦点を当てることが有効です。
認証のための計画を今すぐ開始する。ポスト量子認証の期限である 2031 年は、思っているよりも早く訪れます。長期使用される鍵(long-lived keys)、ルート証明書、コード署名インフラストラクチャの特定を始めてください。これらは量子攻撃者にとって最優先の標的であり、アップグレードに必要な依存チェーンが最も長くなります。ポスト量子証明書がまだエコシステム内で利用可能でない場合でも、ソフトウェアライブラリの更新や証明書のプロビジョニング自動化を行う絶好の機会です。また、ベンダーが迫り来るポスト量子認証期限に対応する計画を持っていることを確認してください。
技術用語訳注:
- ポスト量子暗号化 (post-quantum encryption)
- ポスト量子認証 (post-quantum authentication)
- 暗号アジリティ (crypto agility)
- 量子影響インベントリ (quantum impact inventory)
- 「今収穫し後で復号化」リスク (harvest-now-decrypt-later risk)
- ルート証明書 (root certificates)
- コード署名インフラストラクチャ (code-signing infrastructure)
政策と国際基準の整合性
同時に、各国政府の政策を国際基準に合わせる作業も今すぐ開始すべきです。国務省が外国政府や業界団体と連携し、NIST 標準化された PQC(耐量子暗号)アルゴリズムの採用を促すよう指示した Section 5(b) の内容を確認できたことを嬉しく思います。
これがなぜ重要なのか。暗号技術の移行は、各国が自国の国境内だけで完結させるような孤立した状況では実行できません。米国在住者と海外のサーバー間の TLS 接続
原文を表示
On June 22, 2026, President Trump signed Executive Order 14409, "Securing the Nation Against Advanced Cryptographic Attacks." The order sets a December 31, 2030, deadline for federal agencies to transition their most sensitive systems to post-quantum encryption, and a December 31, 2031, deadline for post-quantum authentication. The EO also directs federal contractors to comply with post-quantum Federal Information Processing Standards (FIPS) by the end of 2030.
We welcome this executive order. The U.S. government has a long track record of using federal leadership and procurement to drive adoption of new technologies across the broader industry. We've seen this work with IPv6, with routing security and the Resource Public Key Infrastructure (RPKI), and with DNSSEC, and we’re glad to see this tradition continue with post-quantum cryptography.
The EO is especially important at this moment because the timeline for Q-Day, the day that quantum computers can break the public-key cryptography used across the Internet, has been accelerated. In April 2026, Cloudflare moved our own target for full post-quantum security to 2029, following research breakthroughs from Google and Oratomic. This EO updates guidance from 2024, when the National Institute of Standards and Technology (NIST) stated that the classical public key cryptography used across the Internet (namely RSA and Elliptic Curve Cryptography, which can be broken once powerful quantum computers become available) should be deprecated by 2030 and disallowed by 2035.
The Internet’s transition to post-quantum encryption is well underway, while the transition to post-quantum authentication has only just begun. Today, over two-thirds of browser traffic to Cloudflare's network is protected with post-quantum encryption, and most of our products support post-quantum key agreement. Our SASE platform, Cloudflare One, provides post-quantum encryption across all major on-ramps and off-ramps, including TLS, MASQUE, and IPsec. We've recently started deploying post-quantum authentication and aim to be fully post-quantum secure by 2029. The EO is an excellent foundation and builds on work from the previous two Administrations. We've been doing the work the EO is asking federal agencies to do since 2019, we have some thoughts on what the order gets right, we see opportunities for the Office of Management and Budget (OMB) to strengthen and facilitate cost-effective agency migration, and we provide a roadmap for how organizations and agencies can advance their transition most effectively.
The EO’s requirements for federal systems
The bulk of the EO's binding requirements are aimed at two categories of federal systems: High Value Assets (HVAs) and high impact systems. HVAs are federal information or systems designated by OMB as the government's crown jewels: systems whose compromise would significantly affect national security, foreign relations, or public confidence. These include databases that hold millions of federal employee records, systems that process classified intelligence, or platforms that manage federal financial transactions. Meanwhile, high impact systems are those where confidentiality, integrity, or availability is rated "high" under FIPS 199, meaning a breach could cause severe harm including loss of life, major financial damage, or significant degradation of an agency's ability to carry out its mission.
The EO has the power to bind federal agencies, but not other organizations (i.e., critical infrastructure, state, local, tribal and territorial governments, academia, civil society). That’s why the EO only gives these deadlines to federal agencies:
Date
Requirement
July 2026
Each federal agency head identifies a PQC migration lead and provides their name and contact details to OMB and the National Cyber Director.
September 2026
OMB issues guidance requiring each agency to: (1) review their inventory of HVAs and high impact systems; (2) plan for PQC migration; and (3) submit that plan to OMB and the National Cyber Director.
December 2030
All HVAs and high impact systems must be transitioned to PQC for key establishment.
December 2031
All HVAs and high impact systems must be transitioned to PQC for digital signatures.
National Security Systems are explicitly excluded from these deadlines. They are on a separate, classified track managed by the NSA with deadlines between 2030 and 2033 already set in 2022.
Two migrations: encryption and authentication. Both should begin now.
The EO splits the PQC migration into two phases: post-quantum key establishment (encryption) by 2030, and post-quantum digital signatures and certificates (authentication) by 2031. This accurately reflects the availability of post-quantum encryption across the Internet today. Our own deadline for full post-quantum readiness (including authentication) is 2029, but we are amongst the earliest adopters in the industry.
We are also happy to see the EO focusing on NIST-standardized post-quantum cryptographic algorithms and not Quantum Key Distribution (QKD), since QKD does not operate at Internet scale due to its need for specialized hardware and dedicated physical links between sender and receiver.
Now let’s have a deeper look at the two migrations called for and required in the EO: post-quantum encryption and post-quantum authentication.
Post-quantum encryption is needed today to stop harvest-now-decrypt-later attacks, where an adversary collects encrypted traffic today and decrypts it later once quantum computers are powerful enough. Post-quantum encryption is especially valuable for organizations handling data that will still have value to adversaries 3-10 years from now, like government agencies, banks, healthcare organizations, defense contractors, and telecom providers.
Post-quantum authentication stops an adversary that has a quantum computer from forging certificates to impersonate servers, generating malicious code signatures, or gaining unauthorized access to systems. Post-quantum authentication is needed only after Q-Day risk materializes, because it stops attacks that are possible only once a cryptographically-relevant quantum computer (CRQC) exists.
It’s important to put the migration timelines in context with advancements in quantum computing. In addition to yesterday’s EO on post-quantum security, President Trump also signed an EO to accelerate deployment and commercialization of quantum computing, sensing, and networking. The fact that the EO sets a 2031 deadline for post-quantum authentication tells us something important: the U.S. government believes there is a non-negligible chance that a CRQC could be operational around that time.
image
What about the state of these two technologies? The migration to post-quantum authentication is a bigger challenge than post-quantum encryption for a few reasons, including:
Post-quantum ML-DSA digital signatures are larger than classic digital signatures, which could have an impact on performance of some systems, for instance in short-lived TLS connections. That’s why we are working with Google Chrome on Merkle Tree Certificates to solve the performance problem for TLS.
The dependency chain for post-quantum authentication is longer, requiring coordinated upgrades across clients, servers, certificate authorities, certificate transparency logs, root stores, and browsers.
There is only limited ecosystem deployment of post-quantum authentication so far, as compared to the much broader deployment of post-quantum encryption.
It is interesting that the EO sets a one-year gap between the encryption and authentication deadlines. One extra year of calendar time is tight, so this work cannot proceed sequentially. The ecosystem needs to start working on both of these targets concurrently, or we will miss this 2031 deadline.
Cryptographic deployment across the Internet cannot happen without standards developed by the Internet Engineering Task Force (IETF). They are working to transition their protocols to post-quantum cryptography. The TLS community is ahead, with the IETF PLANTS working group making good progress on post-quantum certificates for TLS. There is much work to do here and we look forward to supporting the IETF in its efforts.
Supply chain pressure that helps everyone
The EO includes requirements for federal contractors, which may turn out to be the most impactful part of the EO.
Namely, the FAR Council must publish proposed rules requiring "covered contractors" to comply with NIST FIPS incorporating PQC algorithms by December 31, 2030 (Sec. 6(c)). The FAR Council must also publish proposed rules requiring contractors to implement vulnerability disclosure programs that cover cryptographic vulnerabilities (Sec. 6(d)). These proposed rules need to go through notice-and-comment rulemaking, but the EO has a December 31, 2030 target which is still important. This deadline is one year earlier than federal agencies are required to complete their post-quantum authentication migration, so that federal contractors will be ready before agencies hit their own deadlines.
Federal agencies can only migrate to PQC if the products they buy support PQC. To put this into practice, CISA released its Product Categories for Technologies That Use Post-Quantum Cryptography Standards, drawing a clear line between technologies where PQC is already "widely available" versus those still "transitioning." The "widely available" list includes cloud platforms (IaaS, PaaS), web browsers and servers, chat and messaging software, and endpoint security products like full disk encryption. For these categories, CISA's guidance is clear: organizations should procure only PQC-capable products. The "transitioning" list, where PQC is not yet widely available, includes networking hardware (routers, firewalls, switches), identity and access management systems (HSMs, certificate authorities, identity providers), email servers and clients, and database systems.
By telling contractors their products must be PQC-compliant by 2030, and directing agencies to immediately favor PQC-capable vendors in mature markets, the federal framework forces the vendor ecosystem to ship PQC-capable products on a fixed timeline. Products that vendors build to federal requirements will end up used by hospitals, banks, universities, and small businesses, which makes PQC support more broadly available. Cloudflare is among the many vendors subject to these requirements, and because networking software and cloud services are already designated by CISA as widely available PQC categories, we've already shipped post-quantum encryption across most of our products at no extra cost.
Critical infrastructure and PQ for everyone
The EO also speaks to critical infrastructure: energy, financial services, water, transportation, telecommunications, healthcare, and other systems whose failure would have a serious or significant impact on the country. While the EO has no hard migration deadline for critical infrastructure owners and operators, the EO directs certain federal agencies to "assist" critical infrastructure owners and operators with their PQC migration plans (Sec. 5(a)).
While the EO focuses mostly on federal agencies and critical infrastructure in the U.S., post-quantum cryptography is important to every Internet-connected individual and organization. Harvest-now-decrypt-later attacks are a risk today. And after Q-Day, the risk of unauthorized access by an adversary armed with a quantum computer will impact any organization, big or small. When we launched free universal SSL in 2014, our CEO Matthew Prince wrote:
Having cutting-edge encryption may not seem important to a small blog, but it is critical to advancing the encrypted-by-default future of the Internet. Every byte, however seemingly mundane, that flows encrypted across the Internet makes it more difficult for those who wish to intercept, throttle, or censor the web.
We feel the same way about post-quantum cryptography. That’s why every post-quantum upgrade we build is available to all customers, on every plan, at no additional cost.
image
Opportunities for OMB’s implementation guidance
The EO sets the direction, and now OMB has 90 days to provide important clarifications and operational guidance to achieve the most effective PQC migration across federal agencies (Sec. 4(b)). Based on what we've learned from our own PQC migration, here are a few elements that we suggest that guidance should include:
Define what it means to “transition.” The EO requires agencies to "transition" their systems to PQC, but it never defines what "transition" means. Does it mean the system supports PQC algorithms? That it prefers them? Or that classical cryptography has been disabled entirely?
These are very different security postures. A system that supports ML-KEM but still allows a classical-only TLS handshake is vulnerable to downgrade attacks. An adversary capable of intercepting traffic could force the connection back to classical key exchange. The system would have "transitioned" to PQC in name, but still be vulnerable to the same quantum attacks the order is trying to prevent.
History is instructive. When SSLv3 was deprecated after the POODLE attack in 2014, servers kept SSLv3 enabled for backwards compatibility, allowing attackers to force connections to downgrade and then exploit SSLv3's weaknesses. It took years for the ecosystem to actually turn SSLv3 off. To avoid repeating this pattern, we need a clear definition of “done” that includes disabling quantum-vulnerable cryptography to prevent downgrades.
Crypto agility: Crypto agility is the ability to swap cryptographic algorithms without re-architecting your systems. The EO mandates migrating to specific NIST crypto standards, but says nothing about building systems that can swap cryptographic algorithms if these algorithms need to change in the future. Crypto agility doesn't mean supporting every algorithm at once. It means building systems so that when the community converges on a better algorithm in the future, the upgrade is a configuration change, not a re-architecture. The OMB should include this in its guidance.
CBOM or quantum impact inventory? The EO directs CISA and NIST to publish guidance on the minimum elements for a cryptographic bill of materials (CBOM) within 270 days (Sec. 5(d)). A CBOM is an inventory of the cryptographic algorithms, protocols, and implementations used in a given hardware or software product, similar to a software bill of materials (SBOM).
In theory, CBOMs are a good idea. In practice, we'd caution against treating exhaustive cryptographic inventories as a prerequisite for action. A detailed CBOM of every algorithm in every library in every product takes a long time to produce, it can take federal agencies an entire procurement cycle of discovery tooling and consulting, and it potentially becomes stale by the time the inventory is complete. Also, a CBOM doesn’t list systems that should be using cryptography but are not. And a CBOM lists keys without an understanding of their purpose, making them less useful for organizations trying to understand the risk associated with a quantum-vulnerable key.
We think that a quantum impact inventory is a more productive framing. What would be the impact if the system or its data is compromised? How likely is that to happen? What measures can be taken to mitigate the risk, whether a drop-in replacement, a software update, or a compensating control like tunneling traffic over bulk post-quantum connection or isolating it from the Internet? How feasible is each option and what dependency chain does it create? Identifying these informs where to take action first. You can fill in the details of a full CBOM over time if that makes sense for your organization, but you should start by discovering your most exposed and impactful systems.
Making post-quantum cryptography affordable to all. True national resilience fails if post-quantum cryptography is treated as a gated luxury rather than a universal baseline. OMB policy must resist vendor lock-in or toll booths that leave underfunded critical infrastructure behind or increase technical debt at federal agencies.
What to do now: don't wait for 2030
You do not have to wait for 2030 or an exhaustive cryptographic inventory to start your migration. History has shown that updating cryptography is hard and can take a long time; other organizations should start sorting out their migrations as well. So as we wait for OMB guidance for federal agencies, here’s what we recommend for all organizations:
Protect your Internet traffic now. Start with traffic that crosses the public Internet, because that is the easiest for adversaries to harvest now and the most immediately at risk. If your web traffic flows through Cloudflare, your connections are largely protected with post-quantum encryption. If your enterprise network uses Cloudflare One, your private network traffic is also protected. If your provider doesn't support post-quantum encryption, switch to one that does. Even if the individual applications running inside your network haven't been upgraded yet, start tunneling your traffic through post-quantum encrypted infrastructure to protect it in bulk, even if individual systems are not yet inventoried and upgraded.
Update procurement. Make "post-quantum encryption by default, at no additional cost, with a clear roadmap for post-quantum authentication and crypto agility" a requirement in every technology procurement. If your vendor charges extra for post-quantum security or doesn't have a roadmap or plan, ask why or find another vendor.
Quantum impact inventory. For traffic that stays inside your private network perimeter and is not exposed to the public Internet, the harvest-now-decrypt-later risk is lower because an adversary would need to be on your network to capture it. But you still need to know what cryptography your internal systems use, so you can plan your migration. Use a quantum impact inventory as a tool to prioritize your efforts, for example focusing on systems or connections that handle sensitive data or are exposed on the public Internet.
Plan for authentication now. The 2031 deadline for post-quantum authentication will come faster than you think. Start identifying your long-lived keys, root certificates, and code-signing infrastructure. These are the highest-priority targets for a quantum attacker, and they have the longest dependency chains to upgrade. Now is a great time to update your software libraries and automate certificate provisioning even if post-quantum certificates are not yet available in your ecosystem. And make sure your vendors are planning to be ready for the looming post-quantum authentication deadline.
Aligning policy and international standards
At the same time, work should also start now on aligning global government policy with international standards. We were glad to see that Section 5(b) directs the State Department to engage foreign governments and industry groups to encourage adoption of NIST-standardized PQC algorithms.
Here’s why this matters. Cryptography migrations cannot be run in a vacuum, with each country operating within its own borders. A TLS connection between a U.S. person and a server abroa
関連記事
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み