Fact Sheet: President Donald J. Trump Secures the Nation Against Advanced Cryptographic Attacks
6/22/2026
Action Summary
- Objective: Safeguard America’s critical data, digital economy, and infrastructure against advanced cryptographic (quantum) attacks.
- Post-Quantum Cryptography (PQC) Migration:
- Directs an accelerated, nationwide migration to PQC led by OMB and the National Cyber Director.
- Mandates agencies to designate a PQC migration lead and transition high-value assets to PQC by 2030/2031 based on use case.
- Pilot Project Initiative: The Department of Commerce is to launch a pilot project for PQC migration, to be completed by December 31, 2027.
- International and Critical Infrastructure Support:
- Directs the State Department and other Federal agencies to support critical infrastructure operators, foreign governments, and industry groups in PQC transitions.
- Reinforces U.S. leadership on the global stage in secure technology.
- Cost Efficiency and Coordination:
- Mandates coordination among OMB, the Department of War, NASA, and the General Services Administration to identify cost-saving opportunities in the national PQC strategy.
- Federal Contractor Requirements: The Federal Acquisition Regulatory Council must enforce cybersecurity standards and vulnerability disclosure policies for covered contractors by the end of 2030.
- Broader Cybersecurity Leadership:
- Emphasizes America’s commitment to cyber defense by promoting advanced technology and sustained development in quantum and artificial intelligence sectors.
- Builds on previous executive actions and legislative achievements, including the National Quantum Initiative Act and past cybersecurity orders.
Risks & Considerations
- The Executive Order mandates a nationwide transition to post-quantum cryptography (PQC), which may require significant investments in technology and training for Vanderbilt University to adapt its systems and processes accordingly.
- There is a risk of non-compliance with federal cybersecurity standards, which could lead to penalties or loss of federal funding for research initiatives. This places a high importance on timely integration of PQC across all relevant university systems.
- As the migration to PQC is directed to be completed by 2030 and 2031, Vanderbilt will need to prioritize this transition to avoid disruptions in data security, especially in research areas involving sensitive information.
- Failure to adopt PQC could affect Vanderbilt’s collaborations with government agencies and industry partners, potentially hindering research and development opportunities.
Impacted Programs
- Vanderbilt’s School of Engineering may see increased demand for research and development in quantum technology and cybersecurity practices as the transition to PQC becomes a priority.
- Vanderbilt’s IT Department will need to enhance its infrastructure and protocols to comply with new federal cybersecurity standards, requiring both financial and human resources.
- The Office of Sponsored Programs may need to adjust its approach to funding applications, ensuring that they align with the federal emphasis on cybersecurity and technological advancements.
- Research initiatives involving sensitive data will need to reassess their security measures and protocols to ensure compliance with the new PQC requirements.
Financial Impact
- The need for investment in PQC technologies and training could strain Vanderbilt’s budget, particularly if additional federal funding does not accompany these mandates.
- Potential penalties for non-compliance with new cybersecurity standards could lead to financial liabilities, impacting overall university funding.
- Research funding opportunities may increase as federal agencies prioritize cybersecurity developments; however, Vanderbilt must be proactive in aligning its projects with these federal initiatives to capitalize on this funding.
- As federal requirements evolve, Vanderbilt may experience shifts in grant application strategies, necessitating a reassessment of current initiatives and partnerships.
Relevance Score: 4 (The order presents a need for potential major changes or transformations of programs.)
Key Actions
- The Office of Information Technology should establish a task force to prepare for the transition to post-quantum cryptography (PQC). This involves assessing current systems, identifying high-value assets, and designating a PQC migration lead to ensure compliance with the executive order timelines.
- Vanderbilt’s Research Administration should work closely with the Department of Commerce and other federal agencies to stay updated on guidance regarding PQC migration. Engaging in pilot projects and leveraging federal resources will be crucial for maintaining the university’s competitive edge in cybersecurity research and application.
- The School of Engineering should focus on developing research initiatives that align with PQC technologies. This includes proposing projects that enhance cybersecurity measures for critical infrastructure, ensuring that Vanderbilt remains at the forefront of technological advancements in this area.
- Vanderbilt’s Federal Relations Office should advocate for funding opportunities related to PQC migration, ensuring that the university is positioned to secure grants that support the transition and enhancement of cybersecurity infrastructure across campus.
- The Legal and Compliance Office should review and adapt Vanderbilt’s cybersecurity policies to align with the new federal standards set forth in the executive order. This includes implementing vulnerability disclosure policies and ensuring contractors meet federal cybersecurity requirements by the specified deadlines.
Opportunities
- The executive order presents an opportunity for Vanderbilt’s Cybersecurity Research Center to lead initiatives in PQC research and development, potentially influencing national standards and practices in cybersecurity.
- By investing in PQC, Vanderbilt can enhance its reputation as a leader in cybersecurity education and research, attracting top talent and funding in this critical field.
- There is potential for collaboration with federal agencies on pilot projects, which can provide valuable data and insights for both the university and its partners in critical infrastructure security.
- Engaging in research that supports the transition to PQC can open doors for interdisciplinary collaborations across various departments, fostering innovation and enhancing educational offerings in cybersecurity.
- The emphasis on securing critical infrastructure provides a unique opportunity for Vanderbilt to engage with local and state governments to offer expertise and solutions, ultimately benefitting the broader community.
Relevance Score: 4
Timeline for Implementation
- PQC Pilot Project: To be completed by December 31, 2027.
- High Value Asset Transition: Transition to PQC by 2030 for certain uses and by 2031 for other use cases.
- Contractor Compliance: Covered contractors must meet the cybersecurity standards by the end of 2030.
The shortest timeline is the PQC pilot project, with a deadline of December 31, 2027—which is well over 180 days away from the issuance date.
Relevance Score: 1
Impacted Government Organizations
- Office of Management and Budget (OMB): Charged with leading the accelerated, nationwide migration to post‐quantum cryptography (PQC) and coordinating cost-saving opportunities in the PQC migration strategy.
- National Cyber Director: Tasked with co-leading the PQC migration effort to protect sensitive data and critical infrastructure in the quantum era.
- Department of Commerce: Directed to deliver clear guidance on PQC migration, initiate a pilot project, and support cost-saving initiatives related to the transition.
- National Security Agency (NSA): Instructed to assist in providing practical guidance for accelerating the PQC migration to secure federal systems.
- Department of Homeland Security (DHS): Required to help agencies transition high value assets to PQC and ensure the security of America’s critical infrastructure.
- State Department: Expected to assist and encourage critical infrastructure operators, foreign governments, and industry groups in their transition to PQC, reinforcing U.S. global leadership.
- Department of War: Involved in coordinating efforts to identify cost-saving opportunities in the national PQC migration strategy.
- National Aeronautics and Space Administration (NASA): Responsible for coordinating efforts alongside other agencies to drive cost efficiencies in the PQC migration strategy.
- General Services Administration (GSA): Tasked with coordinating cost-saving measures as part of the national strategy for PQC migration.
- Federal Acquisition Regulatory Council: Required to enforce that covered contractors meet specified Federal cybersecurity standards and vulnerability disclosure policies by the end of 2030.
Relevance Score: 3 (Multiple Federal agencies across different domains are impacted by the order.)
Responsible Officials
- Office of Management and Budget (OMB) – Tasked with leading the accelerated, nationwide migration to post-quantum cryptography and coordinating with other agencies.
- National Cyber Director – Charged with co-leading the migration effort and advising on cybersecurity measures.
- Department of Commerce – Responsible for delivering practical guidance on PQC migration, initiating the pilot project by December 31, 2027, and coordinating cost-saving opportunities.
- National Security Agency (NSA) – Directed to provide clear guidance to agencies on effectuating and accelerating PQC migration.
- Department of Homeland Security (DHS) – Similarly directed to offer guidance on the PQC migration for high value assets.
- State Department – Tasked with assisting critical infrastructure operators, foreign governments, and industry groups with their transitions to PQC to reinforce U.S. leadership internationally.
- Department of War – Instructed to coordinate with other agencies (OMB, NASA, and GSA) in identifying cost-saving opportunities in the national PQC migration strategy.
- National Aeronautics and Space Administration (NASA) – Also involved in the coordination of cost-saving opportunities for the PQC strategy.
- General Services Administration (GSA) – Partners in the coordination of identifying cost-saving initiatives along the migration strategy.
- Federal Acquisition Regulatory Council – Required to mandate cybersecurity standards and vulnerability disclosure policies for covered contractors by the end of 2030.
Relevance Score: 5 (The directives affect senior agency heads and key cabinet-level officials critical to national cybersecurity and technological infrastructure.)
