Cyber Resilience for
Complex Ecosystems

Menu Close

Case Studies

Preparing a Federal Agency for the Post-Quantum Cryptography Readiness Deadline

In an environment where federal guidance on Post-Quantum Cryptography (PQC) requirements are still being finalized, one federal civilian Agency was determined to implement a Strategic Quantum Readiness program to protect its data from adversary hands. ShorePoint was engaged to build an enterprise-wide PQC program, taking on policy, engineering, acquisitions, and governance under one team. ShorePoint developed and began executing the Agency’s prioritized PQC migration plan months before Office of Management and Budget (OMB) Memorandum M-26-15 introduced a formal submission requirement, putting the Agency’s PQC program ahead of where many agencies currently stand.

THE CHALLENGE

What Regulatory Deadlines Accelerated This Agency’s PQC Plans?

No one knows the exact date on which cryptographically relevant quantum computers will arrive. Even so, adversaries using strategies such as “harvest now, decrypt later” prompted Agency leaders to start exploring post-quantum cryptography solutions.

Executive Orders 14412 and 14413, paired with OMB Memo M-26-15, established and accelerated timelines for implementation as quantum computing advances continue to happen more rapidly. The regulations require federal agencies to inventory their cryptographic assets and migrate to quantum-resistant systems by 2030, sharpening an earlier 2035 target set under a 2022 national security memorandum.

Now facing a compressed timeline, the Agency needed a roadmap to follow. Guidance on what a compliant PQC plan actually needed to contain was still being finalized even as agencies were expected to produce their inventories. Cryptographic inventory collection was still largely manual, and the market for automated discovery tools remained thin, with few FedRAMP-authorized options available.

The Agency needed a partner who could build a PQC program from scratch, and fast, without the benefit of a mature playbook to follow.

THE SOLUTION

What Did the Strategic Quantum Readiness Program Include?

ShorePoint took ownership of the Agency’s PQC program end-to-end, spanning policy, engineering, acquisitions, strategy, migration planning, and governance under a single integrated team. The work began in the governance phase: identifying ownership, timelines, and stakeholders, then running risk assessments to determine which systems needed to migrate first.

From there, ShorePoint built out the operational backbone of the program:

  • Early groundwork on automated cryptographic inventory. Beginning the shift off manual, spreadsheet-driven inventory collection and through a proof-of-concept Automated Cryptographic Discovery and Inventory (ACDI) tool, the first step toward the continuous, risk-driven visibility the program is working toward.
  • A cryptographic risk-based framework. A structured method for prioritizing which systems migrate first, based on criticality and exposure and aligned with the EO’s direction to prioritize high-value assets (HVAs).
  • A cost estimation methodology. A repeatable way to estimate system investment and labor costs, ranging from simple certificate reissuance to full system overhauls, built out through FY30 for budget forecasting.
  • Procurement safeguards. Department-wide policy and procurement language designed to keep quantum-vulnerable hardware and software out of future acquisitions.
  • Compliance reporting. Ongoing internal reporting to Agency leadership, plus external reporting that demonstrates the Agency’s compliance with executive order requirements.

THE RESULTS

What Results Has the PQC Program Delivered?

While many federal agencies are still interpreting what a compliant PQC program needs to include, the Agency’s program has moved several pieces ahead of schedule.

  • A PQC Migration Plan built early and executed continuously. ShorePoint developed the Agency’s PQC migration plan months before OMB Memorandum M-26-15 introduced a formal submission requirement. The plan was submitted to the Agency, and the Department has been executing against it as an active PQC program ever since, well ahead of any external mandate to do so.
  • Early groundwork toward automated cryptographic visibility. ShorePoint conducted a proof-of-concept to identify an enterprise ACDI solution, laying the foundation for continuous risk-driven visibility.
  • A migration sequence grounded in risk reduction. The cryptographic risk framework ensures the Agency’s highest-value, highest-risk systems are first in line for migration.
  • A budget methodology. The cost estimation methodology gives the Agency a defensible basis to appropriately budget for the PQC transition costs to meet the 2030 deadline.
  • Continuous compliance reporting. ShorePoint now owns both internal progress reporting to Agency leadership and the external reporting that demonstrates compliance with executive order requirements.

WHAT’S NEXT

Where is the Program Headed Next?

ShorePoint’s Maturity Roadmap for Cryptographic Visibility is designed to give the Agency visibility it can act on operationally. Layering passive network monitoring, which surfaces cryptographic algorithms actually observed in use, with endpoint-based discovery through ACDI tooling combines network-level evidence with system-resident cryptographic assets and configurations into a single, continuously updated picture.

As the ACDI tool scales to full enterprise deployment, ShorePoint is building toward Mission-Impact Reporting, visibility into whether the program is protecting the Agency’s highest-value data without disrupting operations. This goes beyond demonstrating compliance to show, in concrete terms, that the security investment is working. ShorePoint is refining the specific metrics needed to support this kind of reporting as the tool’s visibility expands.

Together, these efforts move the program toward continuous, risk-driven visibility that proves out its value to the mission.

Why This PQC Case Study Matters for Federal Agencies Facing the Same Deadline

The Agency’s program stands as one of the more mature examples of proactive PQC planning in the federal civilian space. ShorePoint built a migration plan and program governance ahead of formal requirements, getting ahead of the mandate before it arrived. It offers a model other agencies can follow as they work through the same 2030 deadline. Build governance and risk prioritization first, begin automating inventory early, and address compliance requirements while making demonstrable improvements to agency security posture in protecting critical data assets from compromise.