Garfield Jones, associate chief of strategic technology at the Cybersecurity and Infrastructure Security Agency, said CISA and other agencies hosted a call with over 600 federal IT officials to advance the adoption of post-quantum cryptographic standards in the acquisition process, Federal News Network reported Wednesday.
“The awareness part, we’re really pushing it,” Jones said at an event Tuesday. “As those vendors start to adopt it, we’re starting to talk to the agencies about putting this into your acquisition documentation.”
Post-Quantum Cryptography Products List
In January, former President Joe Biden signed a cybersecurity executive order directing CISA to publish by mid-July a list of product categories that support post-quantum cryptography, or PQC. Three months after the list is published, agencies should initiate steps to include PQC requirements in solicitations for any offering that could support PQC.
As CISA works on the PQC products list, Jones said the agency intends to collaborate with vendors to test their cryptographic platforms.
“We’re going to try to work with vendors to make sure that they have those elements in there,” Jones stated.
The CISA official also called on agencies to be prepared and understand potential challenges when implementing PQC algorithms.
“Work with your vendors to get their roadmap, roll it into your acquisition documentation and policy, so that you don’t have a surprise. It takes time to get it into the organization, getting the right architecture,” he added.