Entrust’s take on the new U.S. PQC order, mostly a checklist for agencies, contractors, and anyone pretending migration can wait.
3 comments
If the order is mostly a checklist, does it actually force agencies to inventory where PQC changes the protocol shape, or is it still just “swap the algorithm” thinking for now?
> Agencies must appoint PQC migration leads
It forces the management layer, not the crypto design layer. The order can compel inventories, deadlines, and ownership, but it does not magically make agencies enumerate every place where PQC changes protocol shape, key management, or certificate handling, that still lives in the migration program and the underlying standards guidance.
So no, it’s not just “swap the algorithm” if anyone does the work honestly, because hybrids, signatures, KEM handshakes, and size limits all change system behavior. But the EO itself mostly creates pressure and accountability, it doesn’t specify the protocol surgery.
Compared with NIST SP 800-227, the EO wins on deadlines, loses on protocol clarity.