OMB Memorandum M-23-02: Migrating to Post-Quantum Cryptography

ActiveUS FederalDirective
Effective date
Jan 18, 2023
Published date
Jan 18, 2023

Summary

OMB Memorandum M-23-02 directs federal agencies to inventory cryptographic systems and prioritize migration to post-quantum cryptography in accordance with NIST standards. Agencies must identify systems that use public-key cryptography and create actionable migration plans. The memo responds to National Security Memorandum NSM-10 and aligns with OMB's broader zero-trust strategy. All inventory and migration plan deadlines have now passed.

Milestones (3)

DeadlineLabelTypeHardNotes
OVERDUEJul 18, 2023Agency cryptographic inventory submission to CISA and NSAInventoryAgencies required to submit inventories of public-key cryptographic systems within 180 days of memo issuance.
OVERDUEJan 18, 2024Cryptographic agility requirements in new procurementsCrypto AgilityAll new federal IT procurements must require cryptographic agility and PQC readiness from vendors, effective one year from memo issuance.
OVERDUEApr 18, 2024Agency PQC migration plans submittedMigration PlanAgencies required to submit prioritized migration plans based on the completed cryptographic inventory.

Algorithm references (2)

  • ML-KEMFIPS 203Required

    Replaces: RSA, ECDH

    Agencies must plan migration to NIST-approved PQC KEMs for key exchange in federal systems.

  • ML-DSAFIPS 204Required

    Replaces: RSA, ECDSA

    Agencies must plan migration to NIST-approved PQC signature schemes for authentication in federal systems.

PKI Impact

HIGH
TLSCode SigningEmail/S-MIME

M-23-02 required all federal agencies to inventory and plan migration of every public-key cryptographic system — including all certificate-dependent services. All deadlines have passed, placing agencies with incomplete inventories or migration plans in active non-compliance with OMB direction.

Migration guidance

  • If the cryptographic inventory is incomplete, prioritize internet-facing TLS certificates and long-lived code-signing certificates as the highest-risk assets for harvest-now-decrypt-later attacks.
  • Update PQC migration plans to reference finalized FIPS 203/204/205/206 standards; plans drafted before August 2024 will have referenced draft versions.
  • Flag any certificate with a validity period extending past 2030 for early renewal, aligning with the NIST IR 8547 deprecation deadline for classical algorithms.
  • Engage your internal or commercial CA about its FIPS 203/204/205/206 issuance roadmap and confirm timeline alignment with your migration plan.

Changelog (2)

DateTypeDescription
Mar 1, 2025ClarificationOMB confirmed ongoing M-23-02 compliance monitoring in alignment with final NIST IR 8547 publication, reinforcing agency obligations to update migration plans to reflect finalized FIPS 203/204/205/206 standards.
Jan 18, 2023NewOMB M-23-02 issued, directing federal agencies to inventory cryptographic assets and plan migration to NIST PQC standards.

Issuer

Office of Management and BudgetOMB

Type: GOVERNMENT

Region: US

Visit website →