The White House accelerates post-quantum cryptography

The White House sets PQC deadlines. Learn what IT and security teams must prepare, and how Applivery already protects the MDM channel.
The White House accelerates Post-Quantum Cryptography

Post-quantum cryptography has moved beyond technical forecasting. It is now becoming a regulatory priority. On June 22, 2026, the White House signed Executive Order 14412, setting clear deadlines for U.S. federal agencies to migrate their most critical systems to cryptographic algorithms designed to resist quantum computing attacks.

For IT and cybersecurity teams, the message is clear: the PQC transition is no longer a future conversation. It affects devices, communications, technology providers, audits, and data that must remain protected for years.

At Applivery, we have been working on this since September 2025.

The White House sets a deadline for the PQC transition

When the White House turns a technological threat into an executive mandate, the message goes far beyond the U.S. public sector. It sets a direction for agencies, contractors, technology providers, and regulated organizations.

Executive Order 14412, titled Securing the Nation Against Advanced Cryptographic Attacks, explicitly recognizes the risk of harvest now, decrypt later attacks. In other words, attackers may capture encrypted data today with the intention of decrypting it in the future, once quantum computing has enough power to break part of today’s cryptography.

The order sets a specific timeline:

RequirementKey date
Appoint a PQC migration lead for each agency30 days from the order
Publish guidance for federal agencies90 days from the order
Migrate high-impact systems and high-value assets to PQC for key establishmentDecember 31, 2030
Migrate high-impact systems and high-value assets to PQC for digital signaturesDecember 31, 2031
Define the minimum elements of a Cryptographic Bill of Materials, or CBOM270 days from the order
Proponer requisitos FAR para contratistas cubiertosDecember 31, 2030

This is not a theoretical security debate. It is a regulatory roadmap with dates, responsibilities, and procurement implications.

Why the risk starts before quantum computers arrive

The post-quantum threat does not begin on the day a quantum computer becomes powerful enough to break RSA or ECC at scale. It begins earlier.

The reason is the harvest now, decrypt later model. An attacker can collect encrypted data today, store it for years, and wait until technology makes it possible to decrypt. This risk is especially relevant for organizations that manage information with a long shelf life: public administration, healthcare, defense, banking, insurance, critical infrastructure, or technology providers with access to sensitive environments.

If a piece of data will still be confidential in five, ten, or fifteen years, the protection strategy cannot focus only on today’s threats. It must anticipate the cryptographic landscape that is coming next. That is why the transition to post-quantum cryptography is not only a compliance issue. It is a matter of continuity, resilience, and risk management.

The role of NIST, FIPS, ML-KEM, and ML-DSA

The White House order builds on NIST standards, which have already introduced the first standardized post-quantum algorithms.

The most relevant ones include:

  • ML-KEM, standardized as FIPS 203, for key establishment.
  • ML-DSA, standardized as FIPS 204, for digital signatures.
  • SLH-DSA, standardized as FIPS 205, also for digital signatures.

These standards matter because they turn the PQC transition into something that can be applied to real products, audits, contracts, and architectures. This is no longer only about cryptographic research. It is about standards that organizations can start requiring from their technology providers.

For IT and security teams, the question is changing. It is no longer only about which devices they manage, which applications they deploy, or which policies they enforce. It is also about which cryptography protects those channels, identities, and communications.

Applivery already protects the MDM channel on Apple devices

In September 2025, before the White House set an official timeline for PQC migration, Applivery had already implemented post-quantum cryptography in the MDM communication channel for Apple devices.

The implementation focused on protecting the exchange of data between managed devices and Applivery’s infrastructure. To do this, Applivery integrated hybrid post-quantum public key encryption using X25519MLKEM768, which combines traditional elliptic-curve cryptography with ML-KEM-768, one of the algorithms standardized by NIST.

The channel runs on TLS 1.3 and uses the quantum security capabilities introduced by Apple in iOS 26, iPadOS 26, and macOS Tahoe 26, as long as the server also supports the corresponding post-quantum negotiation.

Diagram of Apple Devices connecting through TLS 1.3 with HPKE to Cloudflare and to a server/API point.

For IT teams, the most important part is that the update was transparent. There was no need to reconfigure policies, manually intervene on devices, or change existing management workflows. Data in transit between managed Apple devices and Applivery’s servers moved to a model prepared for post-quantum threats without adding operational complexity.

Why hybrid encryption matters

The term “hybrid” is not marketing. It describes an engineering decision with a clear security rationale.

Post-quantum algorithms are new compared to traditional standards such as RSA or ECC. Although they have gone through a rigorous standardization process, cryptography also matures over time, through real-world use and through attempts to break it.

That is why many current implementations combine a well-established classical algorithm with a post-quantum algorithm. The goal is to keep the proven robustness of traditional cryptography while adding protection against future quantum attacks.

In practice, this approach makes it possible to move toward PQC without immediately abandoning mechanisms that have already proven reliable for years. It is a responsible way to manage the transition: adopt what is coming next without prematurely giving up what still provides security today.

Android 17 confirms that the standard is consolidating

Android 17 reinforces the same signal: post-quantum cryptography is starting to move deeper into the platform.

Google has announced progress in key areas such as Android Verified Boot, remote attestation, Android Keystore, and Google Play Signing. Together, these changes point to a scenario where post-quantum protection will not be an external add-on, but part of the trust mechanisms built into the operating system.

Three-layer diagram of Android's post-quantum chain of trust from hardware to ecosystem: bottom hardware/silicon with Android Verified Boot and KeyMint VS; middle OS/APIs with Android Keystore and ML‑DSA SDKs; top ecosystem with APK Signing and Google Play App Signing.

This move matters for any team managing Android devices at scale. If the operating system itself starts integrating PQC into boot integrity, attestation, keys, and app signing, the market is sending a clear message: post-quantum security is becoming a platform expectation.

On Android, however, the challenge has an additional layer. The move toward PQC does not depend only on the operating system. It also depends on hardware, manufacturers, and the implementation of secure components such as KeyMint across each device ecosystem.

This explains why the transition will not happen overnight. It requires coordination between operating systems, manufacturers, hardware providers, management platforms, and IT teams.

What this means for IT and security teams

The executive order introduces a concept that will gain relevance in audits and procurement processes: the Cryptographic Bill of Materials, or CBOM.

The idea is simple. Just as an SBOM documents the software components of an application, a CBOM documents cryptographic assets: which algorithms are used, where they are used, what function they serve, and whether they are ready to resist quantum threats.

For IT and security leaders, this anticipates questions that will soon become more common:

  • Do you know which cryptography protects your devices?
  • Can you identify which channels still depend on classical algorithms?
  • Are your providers ready for PQC?
  • Can you prove it to an auditor, a customer, or a regulator?

Device management can no longer be understood only as inventory, application deployment, or policy enforcement. In regulated environments, devices are a critical layer of security, identity, and access. They are also part of the organization’s cryptographic map.

Europe is also moving toward PQC

Although the executive order applies to the U.S. federal government, its impact may reach much further.

What is required today in the U.S. public sector often becomes a reference point for major providers, procurement processes, audits, and international security frameworks. In Europe, the post-quantum transition is also moving forward through recommendations, roadmaps, and guidance from organizations such as the European Union, the United Kingdom’s NCSC, and national cybersecurity authorities.

For Spanish and European organizations, this is especially relevant in sectors subject to ENS, NIS2, DORA, ISO 27001, or public procurement requirements. The question is not whether post-quantum cryptography will reach assessment and compliance processes. The question is when it will start to be required more explicitly.

Organizations that start earlier will have more time to take inventory, prioritize, validate providers, and migrate without urgency.

The post-quantum transition starts with devices

Cryptographic migration is not solved in a matter of weeks. It requires inventory, planning, validation, provider updates, and gradual deployment. Organizations that wait until it becomes mandatory often find that the real timelines are shorter than they expected.

Corporate devices are a good place to start because they concentrate access to data, applications, identities, and critical communications. They are also one of the layers where a UEM platform can provide more visibility, control, and deployment capacity.

At Applivery, post-quantum cryptography is already part of the evolution of our platform. We have incorporated it to protect the MDM channel on compatible Apple devices and to keep preparing device management for a new stage of enterprise security.

The White House has put dates on the table. Apple, Android, and NIST standards are already setting the technical direction. For IT and security teams, the time to prepare does not start in 2030. It starts now.

If you want to understand how Applivery fits into your device security strategy, talk to our team.

Applivery

Stay Connected
Explore more posts