Mental model
In M8 you saw PQC’s technical impact at the protocol layer. This module answers “when must it be done” with the real dates of real regulators. This first lesson summarizes the US side with three documents: one binding and signed (EO 14412), one binding and already seen in M6/M8 (CNSA 2.0), and one still a draft (NIST IR 8547).
EO 14412: binding, signed, year-end dates
Executive Order 14412 (“Securing the Nation Against Advanced Cryptographic Attacks”), signed on 22 June 2026, sets two binding dates for federal High Value Asset (HVA) and high-impact systems. (It is a legal document; since the seven StatusBadge values are mainly designed for technical standards, we use the date directly here instead of a badge.) PQC key establishment by 31 December 2030SOURCED, PQC digital signatures by 31 December 2031SOURCED. These dates were verified directly against the Federal Register’s own text, not secondary law-firm summaries.
A real error found during this research shows how easily dates can be “rounded”: one research file wrote the signature date as “2031 Q1” (the first quarter of 2031) in one place by mistake, while both the EO’s own text and every other place in the same file correctly say “31 December 2031” (year-end). A one-quarter error can make a significant planning difference (almost a whole year); as you saw in M9/M10, it is another example of why even a “corrected” figure needs re-checking.
CNSA 2.0: a reminder of dates you have already seen
The CNSA 2.0 timeline you saw in M6 and M8 applies here too: from 1 January 2027 new national security system acquisitions must be CNSA 2.0 compliant; software/firmware signing must move exclusively to CNSA 2.0 by 2030SOURCED, and OS/web/cloud services by 2033SOURCED. This lesson adds nothing new; it just makes clear that CNSA 2.0 is in the same “US federal, binding” category as EO 14412.
NIST IR 8547: a recommendation, a draft, not binding
The third document is in a different category: NIST IR 8547 contains a proposed deprecation timeline for classical key establishment and signature algorithms (dates around 2030/2035), but it has DRAFT2024-11-12 status, still an Initial Public Draft. A live check (while preparing this lesson, directly on NIST’s own page) shows that it was published on 12 November 2024SOURCED, its own comment period closed on 10 January 2025, and more than 19 months have passed since then without a second draft or a final.
This document is one of the clearest examples of this course’s “say what you could not verify” discipline: a third-party tracker site (pqcmandates.com) claimed IR 8547 was finalized in 2025; the corpus checked this directly on CSRC and recorded “independent verification failed” instead of taking the easy but wrong answer. When presenting IR 8547’s dates to an architect, keep clear that they are recommendations, not binding like EO 14412 or CNSA 2.0.
Update, October 2026: how ready are agencies?
On 6 October 2026 the US Government Accountability Office published an audit (GAO-27-108740) of the 24 CFO Act agencies against three preparatory practices: a prioritized cryptographic inventory, a migration funding estimate, and PQC testing. None of the 24 fully addressed all three, and the sensitive version of the report made 89 recommendations to 23 agencies. Read alongside EO 14412’s deadlines, the gap is not in the algorithms but in inventory, funding and expertise; the discovery work in M12 and the program work in M13 address exactly those. Details on the news desk.