Post-quantum cryptography whitepaper
The quantum clock is ticking
“Harvest now, decrypt later” attacks are already underway: adversaries are stockpiling encrypted data today to decrypt it the moment quantum computers can. Meanwhile, federal compliance deadlines land between September 2026 and January 2027. This whitepaper lays out the regulatory requirements, the hidden complexity of the Linux cryptographic stack, and a practical roadmap to post-quantum compliance.

Sept 2026
FIPS 140-2 certificates move to the CMVP Historical List
After September 21, only FIPS 140-3 modules are accepted for new government procurement
Jan 2027
CNSA 2.0 acquisition cutoff
All new national security system acquisitions must be compliant
$7.1B
White House estimate for the federal-agency PQC transition
2025 through 2035, per OMB M-23-02 agency cost submissions
500+ days
Average CMVP validation timeline from submission
Per NIST’s April 2025 status report, and increasing
The data you encrypt today is already being stolen for tomorrow
Quantum computers capable of breaking RSA and elliptic-curve cryptography don’t need to exist yet for the threat to be real. CISA, the NSA, and NIST have jointly described “harvest now, decrypt later” campaigns in which nation-state adversaries capture encrypted data and store it indefinitely until quantum computing can break it. The threat applies today to any organization holding data that needs to stay confidential for ten years or more, including financial records, health information, trade secrets, and defense contractor data.
This is a known deadline with a known fix like Y2K. But Y2K had a single fix: find the date field, patch it. Cryptographic dependencies are layered throughout software stacks, often invisible to the teams responsible for compliance. NIST finalized the post-quantum algorithm standards in August 2024. The compliance mandates built on them arrive between September 2026 and January 2027.
“We encourage system administrators to start integrating them into their systems immediately, because full integration will take time.”
Where most Linux environments stall, and where CIQ customers stand
Where most Linux environments stand today
- FIPS mode is mistaken for FIPS validation, but auditors ask for a CMVP certificate number
- Five cryptographic modules, OpenSSL, NSS, libgcrypt, GnuTLS, and the kernel, each on its own migration path
- Post-quantum algorithms ship only in the newest point releases, while LTS versions wait on vendor backports
- CMVP validation averages 500+ days from submission, and the queue is growing
Where CIQ customers stand
- Active FIPS 140-3 certificates across multiple Rocky Linux versions and cryptographic modules
- The first Enterprise Linux NSS module with CAVP-certified ML-KEM and ML-DSA, now in the CMVP queue
- A post-quantum roadmap across all five modules, including an OpenSSL 3.5 backport for LTS customers
- Binary compatibility that keeps applications certified and automation intact through the transition
What enterprises must know, and do, before regulatory deadlines arrive
The quantum threat, explained
The regulatory landscape
The FIPS 140-2 sunset
Five modules, five migration paths
Your compliance roadmap
Where CIQ leads
Read the full analysis
Get the complete regulatory timeline, the five-module breakdown of the Linux cryptographic stack, and the roadmap CIQ recommends before the deadlines arrive.
Map your deadline exposure before your auditor does
Bring your compliance requirements, and walk through exactly where your cryptographic stack stands against every deadline in the whitepaper.
- Schedule a technical briefing with a CIQ engineer
- Walk through your five-module migration path and FIPS validation status
- Get certificates your auditor can verify in the NIST CMVP database
More on cryptographic compliance
First to CAVP for post-quantum algorithms
CIQ’s NSS module is the first from an Enterprise Linux distribution to achieve CAVP certification for ML-KEM and ML-DSA.
The Enterprise Linux compliance platform
Validated cryptography, pre-applied hardening, and audit evidence across RLC Pro, RLC Pro Hardened, and Ascender Pro.