---
title: "CISA Guides Federal Procurement for Post-Quantum Cryptography Implementation"
url: https://daily.dev/posts/cisa-guides-federal-procurement-for-post-quantum-cryptography-implementation-5lj7cpvbx
source_url: https://daily.dev/posts/cisa-guides-federal-procurement-for-post-quantum-cryptography-implementation-5lj7cpvbx
type: collection
source: "Collections"
published: 2026-01-27T13:11:32.369Z
updated: 2026-03-15T04:57:19.856Z
tags: ["cloud", "cryptography", "cyber", "quantum-computing"]
reading_time: 2
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# CISA Guides Federal Procurement for Post-Quantum Cryptography Implementation

**[Collections](https://daily.dev/sources/collections)** · 2 min read · 0 upvotes · 0 comments

## Summary

CISA has released federal procurement guidance requiring agencies to prioritize post-quantum cryptography (PQC) capable products to protect against future quantum computing threats. The directive categorizes products based on PQC readiness: cloud services, web browsers, and endpoint security already have PQC implementations, while networking hardware, SaaS platforms, and telecommunications are still transitioning. All procured products must support NIST-standardized quantum-resistant algorithms including ML-KEM, ML-DSA, and SLH-DSA for key establishment and digital signatures. CISA will update the guidance as more technology categories adopt these standards.

## Content

The Cybersecurity and Infrastructure Security Agency (CISA) has issued new federal procurement guidance, directing agencies to prioritize post-quantum cryptography (PQC)-capable products in specific technology sectors. This guidance supports a 2025 executive order aimed at ensuring government systems are resilient against the potential future threat of quantum computing attacks. 

The directive outlines two categories of products: those with readily available PQC implementations and those still in the process of transitioning. Products like cloud services, web browsers, and endpoint security solutions fall into the former category, as these technologies have widely adopted PQC for key establishment. Other sectors, such as networking hardware, Software as a Service (SaaS) platforms, and telecommunications, are still moving towards full PQC integration.

Aligning with the National Institute of Standards and Technology (NIST)-standardized algorithms, the guidance mandates that all procured products must support quantum-resistant key establishment and digital signatures. Currently, several categories have made strides in PQC adoption, particularly for key establishment; however, there is less progress in integrating PQC standards for digital signatures and authentication.

The recommended algorithms include the Modular Lattice-based Key Encapsulation Mechanism (ML-KEM), the Modular Lattice-based Digital Signature Algorithm (ML-DSA), and the Supersingular Lattice Homomorphic Digital Signature Algorithm (SLH-DSA), as covered in NIST FIPS standards 203, 204, and 205. CISA plans to provide regular updates to this guidance as more technology categories mature in their adoption of these quantum-resistant solutions.

## Similar posts on daily.dev

- [PQC roadmap remains hazy as vendors race for early advantage](https://daily.dev/posts/pqc-roadmap-remains-hazy-as-vendors-race-for-early-advantage-gp8vfiiph) · CSO Online · 0 upvotes · 0 comments

---

Tags: [#cloud](https://daily.dev/tags/cloud), [#cryptography](https://daily.dev/tags/cryptography), [#cyber](https://daily.dev/tags/cyber), [#quantum-computing](https://daily.dev/tags/quantum-computing)

[View this post on daily.dev](https://daily.dev/posts/cisa-guides-federal-procurement-for-post-quantum-cryptography-implementation-5lj7cpvbx)
