WASHINGTON — The Department of Defense (DoD) published a 25-page Post-Quantum Cryptography (PQC) Strategy in June, initiating a PQC migration to defend its systems against quantum threats. The strategy mandates that all DoD systems must support post-quantum cryptography by the end of 2030 and employ it before the end of 2031.
The PQC Strategy calls for new Cybersecurity Maturity Model Certification (CMMC) requirements that incorporate quantum-resistant algorithms. The DoD issued an amendment formally starting the transition to CMMC Revision 3 on Wednesday, which introduces the option to leverage quantum standards for defined values. The CMMC program, which the Pentagon began enforcing in 2025, established a tiered cybersecurity framework based on National Institute of Standards and Technology (NIST) standards, requiring contractors to demonstrate adequate security controls for sensitive DoD information.
The PQC Strategy also encourages the defense industrial base (DIB) to adopt post-quantum cryptography alongside the DoD. The document states, "To ensure the security of [Department of War] information hosted on DIB systems, the DoW will ensure that the DIB migrates to PQC across the enterprise." It adds, "The DoW will also collaborate with DIB partners to ensure interoperability during the migration to PQC."
Thomas Graham, chief information security officer at Redspin, stated that CMMC was designed to be dynamic. "The department's strategy reinforces an important point: CMMC was never intended to remain static," Graham said. He added, "As cybersecurity threats evolve, the requirements will evolve as well."
Michael Gruden, a cybersecurity lawyer at Crowell & Moring, indicated that the DIB might not be prepared for this mandate. "The fact that we're seeing this sort of charge to implement [PQC] within CMMC would come as a shock to the broader defense industrial base, and I do not think that the majority would be ready at this point," Gruden said. He added, "Post-quantum cryptography is definitely the future, I just don't know if the core technology and implementation is there yet in terms of widespread commercial adoption — or, at least, commercial adoption within the defense industrial base."
Why It Matters
This strategy indicates a shift in the Department of Defense's approach to cybersecurity, moving to address potential threats from quantum computing. The integration of quantum-resistant cryptography into the CMMC framework extends these requirements to defense contractors, potentially impacting a broad range of businesses within the defense industrial base. The established deadlines for supporting and employing post-quantum cryptography by the end of 2030 and 2031, respectively, set a clear timeline for this transition across DoD systems.
forum Comments (0)
No comments yet. Be the first to comment.