National security data has the longest secrecy horizon there is, and the dates are no longer advisory. Executive Order 14412 (June 22, 2026) sets federal deadlines for post-quantum key establishment and signatures, and directs contractors to comply with post-quantum FIPS. NSM-10 and CNSA 2.0 supply the mandate and the algorithms. Secuur measures where you stand against each, and sequences the work.
Controlled Unclassified Information and program data are exactly what a well-resourced adversary harvests today to read tomorrow. CNSA 2.0 exists because the threat model assumes capability is coming — and the data must survive it.
We map your environment to each, and sequence your migration to the published timelines — not to a date you guess at.
Signed June 22, 2026. High value assets and high impact systems must use post-quantum cryptography for key establishment by December 31, 2030 and for digital signatures by December 31, 2031. It also directs federal contractors to comply with post-quantum FIPS by the end of 2030 — a requirement expected to reach you through the FAR.
The National Security Memorandum directing migration to quantum-resistant cryptography across national security systems and their supply chain.
The NSA suite naming the required algorithms and the phased timeline — with key classes expected to be PQC by the end of the decade.
Phase 2 third-party assessments are suspended — the DoD class deviation of September 3, 2026 directs contracting officers to strip those requirements from solicitations. Phase 1 has not changed: applicable contracts still require a Level 1 or Level 2 self-assessment, and a contracting officer still cannot award without a current CMMC status in SPRS. The assessor went away; the affirmation did not.
With third-party assessment on hold, your CMMC status in SPRS rests on what you affirmed about yourself. That affirmation is a representation to the government.
A Level 1 or Level 2 self-assessment and its SPRS score are asserted by you, not verified by an assessor. Nobody else is now checking the arithmetic before award.
A score accurate on the day you posted it stops being accurate when a control lapses. Cryptographic posture drifts quietly — a downgraded TLS library, a replaced load balancer — and the posted score does not follow it.
The suspension halts third-party assessment; it does not touch civil False Claims Act exposure for an inaccurate cybersecurity representation. DOJ's Civil Cyber-Fraud Initiative has pursued exactly this fact pattern.
We map where controlled data lives and moves, and grade the cryptography protecting each enclave.
Your stack measured against the required algorithm suite and the published migration timeline.
Dated technical evidence behind the cryptographic controls in your Level 1 / Level 2 self-assessment, so the SPRS score you affirm is defensible — and re-provable when third-party assessment returns.
Watch maintains a signed, auditor-facing posture record as mandates and deadlines advance.
A cleared-program-experienced assessor will scope your review against NSM-10, CNSA 2.0 and your CMMC level. A conversation, handled with the discretion the work requires.
An assessor will reach out within one business day to scope your review.