Product1 publisher3 min readPublished
EO 14412 gives US agencies until Dec. 31, 2030 to fix key establishment on high-value assets
Executive Order 14412 sets Dec. 31, 2030 for high-value assets and one cryptographic function, while Australia's cyber agencies have asked for complete migration by the same year. The same certificate estate gets scoped twice.
The Product Desk · Product desk

What happened
- Executive Order 14412 requires US federal agencies to name post-quantum migration leads and to move high-value assets and high-impact systems to post-quantum key establishment by Dec. 31, 2030.
- Stokkan said countries are also developing different post-quantum standards, so organizations working across jurisdictions may have to accommodate changing algorithms and requirements.
- Wynn said there is no template for this work, and that she hopes for improved guidance on what counts as good enough by this time next year.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- constraint An inventory built to the US order's boundaries covers one asset class and one cryptographic function, so it will not answer an Australian request for complete migration without a second pass over the same systems.
- decision Multinationals have to pick a discovery scope before they can start, either building everything to the strictest jurisdiction or funding separate regional tracks with separate owners.
- cost Waiting for the clearer guidance Wynn described spends about a year of the roughly 51 months available, and the systems that go last are the ones with the longest vendor lead times.
- exposure Naming a migration lead puts an individual's name against a 2030 date for cryptography that mostly arrives inside other people's products.
Somebody at a multinational will open a certificate inventory this quarter and try to write one date at the top of it. That is where the two rules stop lining up. Executive Order 14412 attaches its obligation to high-value assets and high-impact systems, and to key establishment specifically, with a date of Dec. 31, 2030 [1]. Australia has asked for the whole estate.
"The Australian Signals Directorate and the Australian Cyber Security Centre have requested full PQC compliance and complete migration by 2030," said Naomi Wynn, chief executive of National Energy Public Key Infrastructure [2][4]. "When it comes to PQC, we're actually leading the charge in terms of a regulatory sense," she said [3]. Wynn spoke alongside Jostein Stokkan of Atea Norge to DigiCert's Dean Coclin at DigiCert's World Quantum Readiness Day, an event where theCUBE is a paid media partner [11].
The regional differences set the scope of discovery, and scope decides what gets found. Inventory only the high-value assets because the US order names them, and an Australian requirement for complete migration sends the same people back over the same systems with a wider net and less time left. Scandinavian and Baltic organizations are working to a third shape, generally following EU timelines for roadmaps and high-risk systems, according to Wynn and Stokkan [5].
Underneath the deadlines, the algorithms may not agree either. Stokkan said countries are developing different post-quantum standards, and that organizations operating across jurisdictions may need to accommodate changing algorithms and requirements [6]. "But if we can help organizations to become more crypto agile, to be able to adapt to different types of encryption as they become important or just change, I think everything will be smoother and easier for all parties," he said [7].
Then there is the calendar. From the Sept. 17, 2026 interview to the deadline is about 51 months [12][13]. Wynn said, "There is no one-size-fits-all; there is no template," and added that she hopes to see improved guidance by this time next year on what the expectations are, what is good enough and what will actually meet the requirements [8][9]. A team that waits for that guidance before starting discovery has roughly 39 months left [14].
Two tests sort most of an inventory. First, whether any jurisdiction you operate in requires the system migrated, not merely documented, by 2030. Second, whether the cryptography is yours to change or arrives inside a vendor's product. Required and yours is the 2030 program. Required and vendor-supplied is a contract conversation at the next renewal. Not required and yours is where crypto agility work pays back. Not required and vendor-supplied gets a note and a review date. An organization that operates in Australia and scopes discovery to the Australian requirement everywhere pays more up front, and it migrates systems the US order would have let it leave until later.
What to watch
- Whether the improved guidance Wynn hopes for by late 2027 defines what counts as good enough for high-value assets.
- Whether EU member state timelines for roadmaps and high-risk systems land before or after Dec. 31, 2030, which the interview did not date.
- Whether certificate management vendors ship tooling that can hold two jurisdictional scopes in one inventory.