PQC Audit IndexLast reviewed 2026-09-12

U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act

Direct answerNSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process.
Issued by
White House (NSM-10) and U.S. Congress (Public Law 117-260)
Date
NSM-10: 2022-05-04; Act signed 2022-12-21; OMB M-23-02: 2022-11-18
Status
In force
Source
https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/

Milestones

Algorithms this timeline points to

ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS / HSS, XMSS / XMSS^MT

Who can help you meet it

Cryptography audit firms listed on this index: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec. See the audit checklist for what a migration review covers.