The Contract Just Changed

Most weeks I write about things you should do. This week I am writing about something that is about to be required.

The June 22 executive order on quantum enabling technologies set a lot of things in motion. The NIST manufacturing center was one of them. The $2 billion in domestic foundry letters of intent was another. The one that will land on your desk in a different way is the FAR update moving through rulemaking right now.

Federal Acquisition Regulation. The rulebook that governs what every company selling to the federal government has to do. When FAR moves, primes move. When primes move, their supply chains move. A significant portion of your clients are somewhere in that chain, whether they think of themselves as federal contractors or not.

What the Ruling Is Expected to Require

The short version… Federal contractors will be required to demonstrate cryptographic compliance with NIST post-quantum standards as a condition of contract award and renewal. The mechanism mirrors how CMMC worked for cybersecurity… staged requirements, contractor attestation, and eventual third party verification for sensitive contracts.

The ruling is not final. But the comment period is closing and the direction is not ambiguous. Agencies have already been directed under the EO to inventory their own cryptographic dependencies. The FAR update is the extension of that directive into the contractor base.

Translation for the Monday morning reader… clients who hold federal contracts or who are two or three tiers deep in a prime’s supply chain, are going to receive compliance questions they cannot answer with a vague “we’re working on it.”

Why This One Is Different

Everything in this series until now has been about risk posture. Harvest now decrypt later is real. The Q-Clock is moving. NIST published the standards. All true. All good reasons to act.

But “good reason to act” and “required to act to keep the contract” are different conversations. One happens in a strategy meeting. The other happens in a legal review before a renewal.

The clients who have been nodding along for six months and deferring to next quarter’s budget cycle are going to get a document from a prime contractor asking them to attest to their cryptographic posture. Some of them are going to forward that document to you with a short message that says “What do I tell them?”

You want to already have the answer when that message arrives.

Keeping It Light

Look…federal rulemaking is not anyone’s idea of exciting content. The FAR is a document that makes tax code look breezy. I am not going to walk you through the regulatory text.

What I will say is this, the MSPs who built CMMC practices before the audits started had a very different Q1 than the ones who scrambled when clients started panicking. That movie has a known ending. This is the same movie.

The quantum version of “I got a CMMC questionnaire and I have no idea what to say” is coming. The FAR ruling is the mechanism that delivers it.

What You Actually Need to Know Right Now

Three things, then I’ll let you get to your week.

Who this touches first. Defense contractors, federal civilian agency suppliers, and anyone in a prime’s vendor list for sensitive or classified work. Healthcare adjacent to CMS and VA. Financial institutions with federal partnerships. If a client has a government contract number anywhere in their business, they are in scope.

What the attestation will likely ask. Mirror of the EO agency inventory directive. What encryption algorithms are in use for data at rest and in transit, what your key management infrastructure looks like, and whether your software and hardware vendors have published PQC migration roadmaps. Sound familiar? It should. That is exactly what the four question vendor test and the cryptographic inventory methodology have been building toward.

The timing question. Comment period closing does not mean the rule is tomorrow. Rulemaking takes time. But “takes time” in federal acquisition means the requirement arrives before most contractors have prepared for it, not after. Get ahead of it now or explain to a client later why you did not.

Monday Morning Move

Identify two clients with any federal contract exposure. Send one sentence today: “There is a FAR update in rulemaking tied to the June quantum EO…once it finalizes, federal contractors will need to attest to their cryptographic posture. Worth a short call to make sure you are positioned?”

That is it. No alarm. No technical deep dive in the email. Just the signal that you are watching the right things, which is exactly what a trusted advisor is supposed to do.

The contract just changed. Make sure your clients know you saw it first.

Stay sharp.

The Quantum Guy

 

The information in this post is provided for general informational purposes only and does not constitute professional, legal, technical, or security advice. Readers act on this content at their own discretion and risk; IoTSSA assumes no liability for any loss or damage arising from its use.