U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act: dates and requirements ================================================================================ NSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process. Issued by: White House (NSM-10) and U.S. Congress (Public Law 117-260) Date: NSM-10: 2022-05-04; Act signed 2022-12-21; OMB M-23-02: 2022-11-18 Status: In force Milestones: 2022-05-04: NSM-10 issued; annual cryptographic inventories begin | 2022-12-21: Quantum Computing Cybersecurity Preparedness Act signed into law | 2035: Target for mitigating quantum risk across federal systems Source: https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/ Source page: https://pqaudit.org/timelines/us-nsm-10-quantum-act/ Compiled by: PQC Audit Index editors (https://pqaudit.org/about/) Last reviewed: 2026-09-12