Before You Can Migrate to Post-Quantum Cryptography, You Have to See What You Have: Network Visibility and Executive Order 14412

Post-Quantum Cryptography

On June 22, 2026, the White House issued Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks. It sets firm deadlines for the federal transition to post-quantum cryptography (PQC): federal high value assets and high impact systems must move to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. It directs every agency to name a PQC migration lead responsible for agency-wide cryptographic inventory management and a prioritized migration plan. And through forthcoming Federal Acquisition Regulation changes, it extends FIPS and PQC expectations to covered contractors by the end of 2030.

The order is about cryptography. NetFlow Optimizer is not a cryptography product, and this blog will be precise about that boundary throughout. But every PQC migration lead faces the same first problem before any algorithm is touched, and it is not a cryptography problem. It is a visibility problem: you cannot migrate, prioritize, or inventory what you cannot see.

What the Order Requires, and Where the Hard Part Starts

EO 14412 makes cryptographic inventory a central obligation. The PQC migration lead is responsible for knowing what cryptographic assets exist across the agency, prioritizing them, and planning the move. The order also directs CISA to publish, within 270 days, guidance on the minimum elements of a cryptographic bill of materials (CBOM) that would enable automated assessment of the cryptographic assets used by a hardware or software element.

Cryptographic inventory is where the difficulty concentrates. You cannot inventory the cryptography on systems you have not identified, and you cannot prioritize migration for communications you cannot see. In practice, the sequence is: identify the systems in scope, understand what is actually communicating with what, then determine the cryptographic posture of those communications and systems. The cryptographic determination is the specialized part. The identify-and-understand steps that come before it are a network visibility problem, and they are where many programs stall before the crypto work even begins.

To be clear about the boundary: NetFlow Optimizer does not perform cryptographic discovery, does not identify algorithms or cipher suites, does not generate a cryptographic bill of materials, and does not validate FIPS compliance. It provides the systems-and-traffic visibility that the inventory and migration effort depends on before, during, and after the cryptographic work.

The Visibility Layer Underneath the Inventory

A cryptographic inventory rests on a systems-and-communications inventory. Before an agency can catalog the cryptography protecting a system, it has to know the system exists, know what it talks to, and know over which ports and protocols. This is the layer where NetFlow Optimizer (NFO) contributes.

Discovering the systems in scope.

NFO’s SNMP auto-discovery maintains a current inventory of network devices rather than relying on a manually maintained list that drifts out of date. Enriched flow telemetry then shows which systems are actually communicating, resolved to user identity and application context. This is direct input to scoping the high value assets and high impact systems the order puts in scope. As covered in How NFO’s SNMP Auto-Discovery Eliminates Inventory Blind Spots, visibility gaps in the device inventory are exactly the blind spots that undermine any downstream program built on top of it.

Seeing what is actually communicating, over which ports and protocols.

Flow telemetry records every conversation: source, destination, port, protocol, application, volume, and duration. This does not reveal the cryptographic algorithm in use, flow data does not inspect payloads or cipher suites, but it does reveal the communications map that a migration plan must prioritize. It surfaces traffic on ports and protocols associated with legacy or unencrypted services, flagging candidates for the cryptographic review that specialized tools then perform.

Monitoring the transition over its multi-year span.

PQC migration is not a single cutover. It runs for years, across 2030 and 2031 deadlines, and during that time teams need to see whether traffic is actually moving to the intended endpoints, whether legacy services that were supposed to be retired are still active, and whether systems that were meant to be migrated are still communicating in the old pattern. Continuous flow telemetry provides that operational view throughout the transition.

PQC migration activityHow network visibility contributes
Scope HVAs and high impact systemsAuto-discovered device inventory, enriched flow of what communicates
Prioritize the migration planCommunications map: what talks to what, over which ports
Flag legacy / unencrypted candidatesTraffic on legacy protocol ports surfaced for review
Monitor the multi-year transitionContinuous view of whether traffic actually moved
Visibility First

In every row, the specialized cryptographic determination, which algorithm, whether it is FIPS-approved, whether it is quantum-resistant, is done by dedicated cryptographic discovery and CBOM tooling. NFO provides the visibility foundation those tools and those migration leads work on top of.

Why This Matters for Contractors, Not Just Agencies

EO 14412 does not stop at federal agencies. It directs the Federal Acquisition Regulatory Council to publish a proposed rule requiring covered contractors to comply with NIST FIPS, including PQC-compliant algorithms, by December 31, 2030, and a further rule extending vulnerability disclosure to cover cryptographic weaknesses, including testing for lack of encryption and the use of non-FIPS-approved algorithms.

For the defense industrial base and other federal contractors, this places the same inventory-and-migration burden on private systems that handle federal information. The same visibility prerequisite applies: a contractor cannot demonstrate progress on cryptographic posture without first knowing what systems it runs and what they communicate with. This is consistent with the network-visibility foundation NFO already provides for other federal frameworks, as discussed in CUI on the Wire and Detecting Harvest Now, Decrypt Later.

NFO is software-only, deploys on-premises with zero data egress, and has been in production in air-gapped federal and DoD environments since 2016. The visibility it provides for PQC migration scoping happens entirely inside the deployment boundary, with no external data dependency, which matters for the classified and controlled environments where much of this migration work will occur.

The Bottom Line

Executive Order 14412 sets hard PQC deadlines and makes cryptographic inventory a named responsibility. The cryptographic work is specialized, and NetFlow Optimizer does not do it: no algorithm identification, no CBOM, no FIPS validation. What NFO does is answer the question every migration lead hits first: what systems do we have, and what is actually communicating with what? That systems-and-traffic visibility is the foundation the inventory, the prioritization, and the multi-year transition are all built on.

You cannot migrate what you cannot see. Network visibility is where the migration starts, well before the cryptography does.

Building the visibility foundation for your PQC migration? Start a free 60-day trial of NetFlow Optimizer or schedule a technical demo with a NetFlow Logic engineer.

Start Free Trial  |  Schedule a Demo  |  Government Solution Brief  |  NFO Documentation

Scroll to Top