U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act
Direct answerNSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process.
- Issued by
- White House (NSM-10) and U.S. Congress (Public Law 117-260)
- Date
- NSM-10: 2022-05-04; Act signed 2022-12-21; OMB M-23-02: 2022-11-18
- Status
- In force
- Source
- https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/
Milestones
- 2022-05-04NSM-10 issued; annual cryptographic inventories begin
- 2022-12-21Quantum Computing Cybersecurity Preparedness Act signed into law
- 2035Target for mitigating quantum risk across federal systems
Algorithms this timeline points to
ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS / HSS, XMSS / XMSS^MT
Who can help you meet it
Cryptography audit firms listed on this index: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec. See the audit checklist for what a migration review covers.