M11 / Regulation and timelines

The US timeline: EO 14412, CNSA 2.0, IR 8547

PractitionerAdvisor

After this lesson you can

  • State the real dates of EO 14412 (31 Dec 2030/2031), verified against the Federal Register text, correcting the corpus's own rounding error
  • Explain in the right frame the CNSA 2.0 timeline (seen in M6/M8) and the real current status of NIST IR 8547 (still an IPD, 19+ months past its own comment period)

Before thisM8: Protocols

Mental model

In M8 you saw PQC’s technical impact at the protocol layer. This module answers “when must it be done” with the real dates of real regulators. This first lesson summarizes the US side with three documents: one binding and signed (EO 14412), one binding and already seen in M6/M8 (CNSA 2.0), and one still a draft (NIST IR 8547).

EO 14412: binding, signed, year-end dates

Executive Order 14412 (“Securing the Nation Against Advanced Cryptographic Attacks”), signed on 22 June 2026, sets two binding dates for federal High Value Asset (HVA) and high-impact systems. (It is a legal document; since the seven StatusBadge values are mainly designed for technical standards, we use the date directly here instead of a badge.) PQC key establishment by 31 December 2030SOURCED, PQC digital signatures by 31 December 2031SOURCED. These dates were verified directly against the Federal Register’s own text, not secondary law-firm summaries.

A real error found during this research shows how easily dates can be “rounded”: one research file wrote the signature date as “2031 Q1” (the first quarter of 2031) in one place by mistake, while both the EO’s own text and every other place in the same file correctly say “31 December 2031” (year-end). A one-quarter error can make a significant planning difference (almost a whole year); as you saw in M9/M10, it is another example of why even a “corrected” figure needs re-checking.

CNSA 2.0: a reminder of dates you have already seen

The CNSA 2.0 timeline you saw in M6 and M8 applies here too: from 1 January 2027 new national security system acquisitions must be CNSA 2.0 compliant; software/firmware signing must move exclusively to CNSA 2.0 by 2030SOURCED, and OS/web/cloud services by 2033SOURCED. This lesson adds nothing new; it just makes clear that CNSA 2.0 is in the same “US federal, binding” category as EO 14412.

NIST IR 8547: a recommendation, a draft, not binding

The third document is in a different category: NIST IR 8547 contains a proposed deprecation timeline for classical key establishment and signature algorithms (dates around 2030/2035), but it has DRAFT2024-11-12 status, still an Initial Public Draft. A live check (while preparing this lesson, directly on NIST’s own page) shows that it was published on 12 November 2024SOURCED, its own comment period closed on 10 January 2025, and more than 19 months have passed since then without a second draft or a final.

This document is one of the clearest examples of this course’s “say what you could not verify” discipline: a third-party tracker site (pqcmandates.com) claimed IR 8547 was finalized in 2025; the corpus checked this directly on CSRC and recorded “independent verification failed” instead of taking the easy but wrong answer. When presenting IR 8547’s dates to an architect, keep clear that they are recommendations, not binding like EO 14412 or CNSA 2.0.

Update, October 2026: how ready are agencies?

On 6 October 2026 the US Government Accountability Office published an audit (GAO-27-108740) of the 24 CFO Act agencies against three preparatory practices: a prioritized cryptographic inventory, a migration funding estimate, and PQC testing. None of the 24 fully addressed all three, and the sensitive version of the report made 89 recommendations to 23 agencies. Read alongside EO 14412’s deadlines, the gap is not in the algorithms but in inventory, funding and expertise; the discovery work in M12 and the program work in M13 address exactly those. Details on the news desk.

Numbers to know

  • EO 14412 (signed 22 June 2026): for federal HVA/high-impact systems, PQC key establishment is mandatory by 31 December 2030 and PQC signatures by 31 December 2031; both are year-end dates, not quarters
  • CNSA 2.0 (seen in M6/M8): new NSS acquisitions must be compliant from 1 January 2027, software/firmware signing exclusively PQC by 2030, OS/web/cloud exclusively PQC by 2033
  • NIST IR 8547 is still an Initial Public Draft as of September 2026 (since 12 November 2024); its own comment period closed on 10 January 2025, and for 19+ months there has been no second draft or final

Lab: Check IR 8547's live status and EO 14412's real text

[not run] This is a live verification exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Open csrc.nist.gov/pubs/ir/8547/ipd
Recorded output
You still see 'Initial Public Draft' status, with no link to a second draft or final
shell
# Search for EO 14412 on federalregister.gov and find section 4(b)
Recorded output
You see the dates 31 December 2030 (key establishment) and 31 December 2031 (signatures), as year-end dates, in the full text

At the table

How to say this in a bank meeting.

To an executive
For US federal systems PQC is no longer a recommendation but a binding requirement under a signed executive order (EO 14412); banks integrated with US federal agencies or with systems subject to CNSA 2.0 should reflect these dates in their own timelines.
To an architect
EO 14412 and CNSA 2.0 are both binding, dated requirements; NIST IR 8547 is still a draft, not binding, only a recommendation (it contains 2030/2035 dates but has no official status). When presenting all three to an architect, separate clearly which is binding and which is a recommendation.
Objection
“"I heard EO 14412's signature date was the first quarter of 2031. Now you say year-end?"”
Answer
This is a real corpus error this course found: one research file wrote this date as '2031 Q1' in one place by mistake, but the EO's own text and every other place in the same file correctly say '31 December 2031' (year-end). We checked the Federal Register's own text directly: the correct date is year-end, not a quarter.

Sources

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What are EO 14412's two key dates, and which is for key establishment and which for signatures?

  2. 02Recall

    What status does NIST IR 8547 have today, and how long has it had it?

  3. 03Scenario

    A colleague has noted EO 14412's signature date as '2031 Q1'. How do you correct this, and which source do you show?

  4. 04Hostile

    An auditor asks 'Are NIST IR 8547's 2030/2035 dates binding?' Answer using the status difference between EO 14412 and IR 8547.

Project linkThe basis of the US side of the regulatory timeline sections of Project 3 (crypto inventory and prioritization) and Project 4 (capstone).