

On June 22, 2026, President Trump signed Executive Order 14412, accelerating the federal government’s transition to post-quantum cryptography. The order brings key migration deadlines forward from 2035 to 2030-2031 for high-value and high-impact systems. The Department of War followed with its own Post-Quantum Cryptography (PQC) Strategy, which sets additional deadlines and warns that a cryptographically relevant quantum computer is an existential threat to military missions.
For the teams that operate the hybrid network, these are not policy documents. They are a migration schedule for network infrastructure that has never been fully documented.
Between the two mandates, three obligations land on the network team. The executive order requires federal high-value assets and high-impact systems to transition to PQC for key establishment by 2030 and digita; signatures by 2031, and any agency that misses the new date reports to the Office of Management and Budget (OMB) and explains why it happened.
The DoW strategy sets its own clock: every defense system must support post-quantum cryptography or is phased out by December 31, 2030, and every system must run PQC, unless otherwise specified, by December 31, 2031.
Underneath both sit the requirement that makes the first two possible. The strategy directs system owners to identify all cryptography in use across National Security Systems (NSS) and non-NSS assets, determine which of it is quantum-vulnerable, and assess exposure to a cryptographically relevant quantum computer. For risk and compliance teams, that same inventory can become the evidence base for RMF control assessments and ATO packages.
Adversaries are already collecting encrypted traffic and storing it, waiting for a quantum computer capable of breaking it. A tactic security researchers call harvest now, decrypt later. The data your network transmits today is already a target for that strategy. The right response isn't dread. It's visibility: knowing exactly which links carry that exposure, so you can fix the ones that matter first.
That makes the first job an inventory job, not a cryptography job. Before you can replace vulnerable encryption, you must know where it is running.
Federal networks make that hard by design. These networks are usually:
And even a perfect asset inventory would not answer the question. For network infrastructure, cryptographic posture does not live in a CMDB, it lives in device configuration.
Neither deadline is reachable until you can answer one question: what cryptography is running on my network right now, and where? In most agencies, that answer does not exist in any single place. It is spread across device configurations; no one has read end-to-end.
Forward Enterprise’s vendor-agnostic platform builds an accurate mathematical digital twin of your entire hybrid network. It collects configuration and state from network devices and cloud platforms, parses them into a single normalized model, and computes every path traffic can take. Not what the diagram says. What the network does.
Because every device configuration is parsed into that model, cryptographic posture becomes something you query instead of something you audit by hand. The whole estate, in minutes, not months.
Your inventory will produce thousands of findings, and you cannot fix them all before the deadline. So, which do you fix first?
Forward's Network Query Engine inventories every cryptographic configuration across your network devices, then checks it against vendor PQC support matrices, what's compliant today, what needs a software update, and what must be replaced outright.
A weak cipher on an isolated management segment and a weak cipher carrying classified traffic to a partner's site look the same in a spreadsheet.
Forward Enterprise computes every path traffic can take, so you can prioritize your remediation efforts by where the data actually goes: what leaves a trusted enclave, where encryption ends, and traffic continues in the clear, and which links carry data worth harvesting today to read in ten years. That is a priority list you can defend to an inspector, attach to an ATO package, and report to OMB.
The executive order puts civilian agencies on a tighter clock and requires them to explain any slip to OMB. The DoW strategy puts defense components on 2030 and 2031. Different audiences, different dates, same buried assumption: that you already have a complete, current record of the cryptography running on your network.
Without that record, you plan against an estimate and report progress against a spreadsheet.
Meet the post-quantum deadlines with a verifiable record of your own cryptography. Book a 1:1 demo with a Forward product expert to see how