800-171 Evidence

October 06, 2026

What Does NSA's Post-Quantum Announcement Mean for Contractors?

Your encrypted data may already sit in an attacker's storage. It waits for a future computer to read it.

On October 1, 2026, the National Security Agency announced new post-quantum cryptography resources. Post-quantum cryptography means encryption algorithms that survive quantum computers. NSA is the agency that sets cryptographic policy for national security systems. National Security Systems (NSS) are the systems that support national security missions. The defense industrial base (DIB) is the network of companies that build systems for the Defense Department.

The announcement restates two dates that now anchor every migration plan. Starting in 2027, all new commercial NSS must support quantum-resistant algorithms. Legacy systems that cannot support them are to be phased out by 2030. Both dates come from Committee on National Security Systems Policy 15 (NSA press release, October 1, 2026).

Why is NSA talking about quantum computers now?

A large enough quantum computer could break the public key cryptography that protects most encryption today. That includes RSA, the algorithm behind most certificates and TLS connections. TLS is the protocol that encrypts data in transit between systems.

NSA says adversaries already use a "harvest now, decrypt later" strategy. They collect encrypted traffic today and store it. They plan to decrypt it once a quantum computer can do the job. Data with a long shelf life is at risk right now, not later.

NSA also names a second risk: "trust now, exploit later." Attackers could undermine authentication and signatures, not just encryption. That widens the problem. Certificates, firmware signing, and code signing are all in scope, not just stored secrets.

What did NSA actually launch?

A Post-Quantum Cryptography Resource Hub for Department of War, NSS, and DIB stakeholders. It gathers guidance for moving to algorithms that can survive quantum computers. The launch sits under Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks."

The algorithms NSA wants already exist. NIST published three post-quantum algorithm standards in 2024: FIPS 203, FIPS 204, and FIPS 205. FIPS is the Federal Information Processing Standards series, the federal crypto rulebook (NIST post-quantum cryptography project).

What does 800-171 require today?

Requirement 3.13.11 of NIST SP 800-171 Revision 2 requires validated cryptography to protect the confidentiality of controlled unclassified information (CUI). CUI is Controlled Unclassified Information: government data that is sensitive but not classified. "Validated" means the module passed FIPS 140 validation testing (NIST SP 800-171 Rev. 2).

So the NSA announcement is not a new compliance rule for contractors. It is a deadline for the tools you will eventually need. Your 800-171 requirement today is still FIPS-validated crypto. Tomorrow's FIPS-validated crypto will be quantum resistant.

What should you do this month?

Do these four things, in order.

1. List where your cryptography lives. Certificates, TLS libraries, VPNs, code signing keys, firmware signing, encrypted archives. You cannot migrate what you have not found.

2. Rank by data lifetime. Encrypted backups and archives with a 10 year retention window face the harvest now, decrypt later risk today. Short-lived sessions are less urgent.

3. Ask your vendors one question. Which quantum-resistant algorithms does the product support? Can it switch algorithms without a full replacement? The ability to swap algorithms is called crypto agility.

4. Watch the hub. NSA says more resources for DIB stakeholders are coming. The hub is the source of record for NSS timelines. Check it the same week you review your POA&M. A POA&M is a Plan of Action and Milestones: the list of known gaps with fix dates.

What if your product ships into national security systems?

If your product goes into an NSS environment, the 2027 date is a procurement fact, not a suggestion. New commercial NSS must support quantum-resistant algorithms starting in 2027. Start vendor conversations now if your product ships into NSS environments.

Sources

Next step

A crypto inventory is also 800-171 evidence. See how PolicyCortex maps your Azure evidence to 800-171 automatically.