CISA released an initial procurement-oriented list of hardware and software product categories that already support, or are expected to support, post-quantum cryptography (PQC) standards, aiming to help federal agencies and other organizations plan technology refreshes and investment strategies as quantum computing advances. The guidance highlights common government-purchased technology areas where PQC is described as “widely available,” including cloud services (PaaS/IaaS), collaboration and messaging software, web software (browsers/servers), endpoint security (e.g., full-disk and at-rest encryption), and networking hardware/software, with emphasis on PQC use for key establishment and digital signatures.
The publication aligns with US government direction to migrate high-value systems toward quantum-resistant cryptography, driven by concerns that adversaries may harvest encrypted data now for future decryption once a cryptographically relevant quantum computer emerges. Reporting also notes the list was developed in coordination with the NSA and is intended to be updated over time; some security professionals have questioned how actionable the guidance is for real-world procurement and migration planning, given the complexity and cost of transitioning cryptographic dependencies across large technology stacks.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
Following the guide's release, security experts said CISA's document lacked operational migration detail, including cryptographic inventories, timelines, hybrid deployment guidance, and clear definitions of what qualifies as 'PQC-capable.' They also warned that many products only partially implement PQC, leaving risks around signatures, authentication, and mixed-vendor environments.
On January 23, 2026, CISA released guidance and an initial list of hardware and software product categories that support, or are expected to support, post-quantum cryptography standards. Developed with NSA collaboration, the list identified areas where PQC is already broadly available and urged agencies to prioritize PQC-capable products in future acquisitions.
On June 6, 2025, Executive Order 14306 directed federal agencies to transition high-value systems and devices toward post-quantum cryptography and tasked CISA with identifying widely available products using PQC standards. The order set the broader policy framework for federal PQC modernization through 2035.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
4 references tracked. Mallory keeps watching after this page renders.
scworld.com
Open sourcecyberscoop.com
Open sourcecsoonline.com
Open sourceinfosecurity-magazine.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.