Government Policies Are Accelerating PQC Adoption: What It Means for Suppliers
Why PQC readiness, cryptographic visibility and hardware-based trust need to move into transition planning and action now.
Microchip’s PQC Momentum
In 2025, Microchip released its first Post-Quantum Cryptography (PQC) capable embedded controller, helping embedded system designers prepare for the initial application timeline benchmarks of the Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) PQC transition. Since then, we have continued expanding our PQC-ready portfolio with Trust Shield Family including the TS500, TS501 and OCP compliant TS1800 TrustFLEX External Root of Trust (ERoT) controllers.
That product momentum now aligns with a broader policy shift. Governments are becoming more active in the PQC transition by connecting security expectations for high-value assets, high-impact systems and security products to procurement and certification requirements.
What the New Government Policies Are Asking For
In June 2026, both the United States and France announced policy actions intended to accelerate the transition to PQC. Both actions recognize the risk that sensitive encrypted data could be collected today and decrypted later when large-scale quantum computers become operational.
The U.S. Executive Order directs federal agencies to identify PQC migration leads, review inventories of High Value Assets and High Impact Systems and begin planning migration to NIST-approved PQC standards. It also establishes transition deadlines for federal High Value Assets and High Impact Systems: PQC for key establishment by December 31, 2030, and PQC for digital signatures by December 31, 2031.
The order also directs CISA and NIST to develop guidance for a cryptographic bill of materials (CBOM), reinforcing a core requirement of any PQC transition: organizations need visibility into where cryptography exists across systems, devices, firmware, software and supply chains.
France is also moving toward a certification-driven transition. ANSSI announced that it will stop certifying security products that do not include quantum-resistant encryption beginning in 2027 and stated that businesses should be purchasing only quantum-safe products by 2030.
The Executive Order also directs NIST to initiate a PQC migration pilot project within 180 days on an appropriate subset of NIST-owned or operated information systems, with the pilot to be completed no later than December 31, 2027.
Who and What This Affects
Federal procurement may become one of the most important drivers of PQC adoption beyond federal agencies. These policies directly affect government technology ecosystems, critical infrastructure operators, organizations responsible for High Value Assets or High Impact Systems and suppliers building hardware, software, embedded systems or connected devices for government environments.
That reach can extend beyond prime contractors. Any company supplying products into government buildings, government networks, critical infrastructure environments or systems connected to high-value assets may need to understand how PQC expectations affect product roadmaps, security architecture, procurement requirements and lifecycle support.
The impact also extends to the products and systems these suppliers provide. For embedded and connected devices, PQC migration is not simply a software update or algorithm swap; it can affect product architecture, lifecycle planning, certification readiness and long-term support. Because many of these devices remain deployed for years or decades, even products that are not themselves classified as High Value Assets may need PQC transition planning if they protect, connect to or support higher-value systems.
What Organizations Should Do Now
The first step is visibility. Organizations should identify where cryptography is used across products, systems and supply chains, then prioritize high-value assets, high-impact systems and long-life devices that may be difficult to update after deployment.
Next, organizations should evaluate whether their hardware security architecture can support long-term migration. A hardware root of trust can help establish trusted device identity, authenticated firmware, protected key material and a stronger foundation for secure lifecycle management.
Building on a Hardware Root of Trust Foundation
Microchip’s Trust Shield family represents our ERoT approach for helping customers build stronger security foundations for high-value assets and long-life systems. Trust Shield devices can help customers anchor trust at the device level as they prepare for PQC migration, cryptographic inventory expectations and future quantum-resistant architectures.
For organizations building or supplying secure systems for government, critical infrastructure or high-value environments, now is the time to identify cryptographic dependencies, plan for PQC migration and build on a hardware root of trust foundation designed for long-term resilience.
Want More?
For more information, visit our Post-Quantum Cryptography web page.