Secuur / For / Defense & Government
For primes & subcontractors

The PQC deadlines are now in an executive order.

National security data has the longest secrecy horizon there is, and the dates are no longer advisory. Executive Order 14412 (June 22, 2026) sets federal deadlines for post-quantum key establishment and signatures, and directs contractors to comply with post-quantum FIPS. NSM-10 and CNSA 2.0 supply the mandate and the algorithms. Secuur measures where you stand against each, and sequences the work.

FExposed
Threat brief · the adversary is a nation-state

Controlled Unclassified Information and program data are exactly what a well-resourced adversary harvests today to read tomorrow. CNSA 2.0 exists because the threat model assumes capability is coming — and the data must survive it.

The mandates

Four documents set your clock.

We map your environment to each, and sequence your migration to the published timelines — not to a date you guess at.

EO 14412

The federal deadlines

Signed June 22, 2026. High value assets and high impact systems must use post-quantum cryptography for key establishment by December 31, 2030 and for digital signatures by December 31, 2031. It also directs federal contractors to comply with post-quantum FIPS by the end of 2030 — a requirement expected to reach you through the FAR.

NSM-10

National mandate

The National Security Memorandum directing migration to quantum-resistant cryptography across national security systems and their supply chain.

CNSA 2.0

Algorithms & dates

The NSA suite naming the required algorithms and the phased timeline — with key classes expected to be PQC by the end of the decade.

CMMC — current state

What you still affirm

Phase 2 third-party assessments are suspended — the DoD class deviation of September 3, 2026 directs contracting officers to strip those requirements from solicitations. Phase 1 has not changed: applicable contracts still require a Level 1 or Level 2 self-assessment, and a contracting officer still cannot award without a current CMMC status in SPRS. The assessor went away; the affirmation did not.

authorityAlgorithm selections follow the NIST Post-Quantum Cryptography Program ↗ — FIPS 203, 204 and 205.
The exposure that did not pause

A suspended assessment is not a suspended obligation.

With third-party assessment on hold, your CMMC status in SPRS rests on what you affirmed about yourself. That affirmation is a representation to the government.

Self-assessment

Your score is your claim

A Level 1 or Level 2 self-assessment and its SPRS score are asserted by you, not verified by an assessor. Nobody else is now checking the arithmetic before award.

SPRS accuracy

Drift makes it stale

A score accurate on the day you posted it stops being accurate when a control lapses. Cryptographic posture drifts quietly — a downgraded TLS library, a replaced load balancer — and the posted score does not follow it.

False Claims Act

Where the risk now sits

The suspension halts third-party assessment; it does not touch civil False Claims Act exposure for an inaccurate cybersecurity representation. DOJ's Civil Cyber-Fraud Initiative has pursued exactly this fact pattern.

what we doWe produce dated, reproducible technical evidence for the controls we can actually measure, so the score you affirm is one you can show your work for. We are not a law firm, and nothing here is legal advice.
The assessment

Stay on the contract. Stay ahead of the mandate.

01

CUI & enclave review

We map where controlled data lives and moves, and grade the cryptography protecting each enclave.

02

CNSA 2.0 alignment

Your stack measured against the required algorithm suite and the published migration timeline.

03

CMMC self-assessment evidence

Dated technical evidence behind the cryptographic controls in your Level 1 / Level 2 self-assessment, so the SPRS score you affirm is defensible — and re-provable when third-party assessment returns.

04

Continuous attestation

Watch maintains a signed, auditor-facing posture record as mandates and deadlines advance.

Enterprise · sales-assisted

Book a confidential assessment.

A cleared-program-experienced assessor will scope your review against NSM-10, CNSA 2.0 and your CMMC level. A conversation, handled with the discretion the work requires.

  • CUIControlled Unclassified Information handled appropriately throughout.
  • CNSA 2.0Mapped to the required suite and published timeline.
  • CMMCEvidence behind the self-assessment you affirm in SPRS.
Request a confidential assessment

Received, confidentially.

An assessor will reach out within one business day to scope your review.