GSA Leads the Transition to Quantum-Resistant Technology
Post filed in: Emerging Technology | IT | Innovation | Technology | cybersecurity
As the Administration advances its updated Cyber Strategy [PDF] and new Executive Order on Ushering in the Next Frontier of Quantum Innovation, GSA’s Office of Government-wide Policy, Federal Identity & Cybersecurity Division has been entrusted with critical responsibilities for protecting federal identity and building access systems, including supporting the governmentwide migration to post-quantum cryptography outlined in OMB Memorandum M-26-15 [PDF].
This important guidance directs federal agencies to move faster toward quantum-resistant security measures, and tasks GSA with new interagency coordination responsibilities that help cement its role at the forefront of this essential cybersecurity initiative.
Understanding the Quantum Challenge
Today’s digital security relies on complex mathematical algorithms that are extremely difficult for current computers to solve. However, quantum computers, which use the principles of quantum physics, will eventually be powerful enough to break these encryption methods quickly. This means that the digital keys protecting everything from federal computer systems to federal building access systems could become vulnerable.
Think of it like this: if current encryption is a complex lock that would take thousands of years to pick, quantum computers could potentially pick that same lock in hours or days. This creates an urgent need to develop new types of quantum-resistant encryption “locks” before quantum computers become widely available.
GSA’s Comprehensive Response
GSA is taking a proactive approach across two critical areas to protect federal identity and access systems:
Modernizing the FICAM Architecture
The Federal Identity, Credential, and Access Management (FICAM) architecture serves as the backbone of federal identity systems. GSA is updating this framework to support quantum-resistant algorithms while maintaining compatibility with existing systems. This modernization ensures that agencies can transition smoothly to new security standards without disrupting daily operations.
Our approach emphasizes “crypto agility” — the ability to quickly switch between different encryption methods as threats evolve or new standards emerge. This flexibility will be crucial as quantum-resistant technology continues to develop.
Testing Quantum-Resistant Building Access Systems
Physical security is just as important as digital security. GSA’s Federal Information Processing Standards (FIPS) 201 Evaluation Program, executed through the Physical Access Control System (PACS) lab, is expanding its testing capabilities to evaluate quantum-resistant solutions for federal buildings. This ensures that employee badges, visitor passes, and building access controls will remain secure against future quantum threats.
The enhanced lab infrastructure represents an entirely new capability, requiring extensive research and development to test quantum-resistant technology for both physical access control systems and employee identification cards.
To ensure security and interoperability standards, the Federal Acquisition Regulation (FAR) dictates federal agencies order PACS equipment only from GSA’s Approved Products List (APL).
GSA’s PACS lab testing determines which products qualify for the APL, making GSA’s role in upholding strict security and interoperability standards essential for governmentwide security. The lab is starting to incorporate quantum-resistant algorithms into its testing process, so future approved products can protect against future quantum computing threats.
Looking Ahead
Transitioning to quantum-resistant security is a complex, multiyear process that requires careful coordination across government and a steady investment/funding strategy. GSA’s early action helps mitigate risks and supports a secure, orderly migration that protects both digital systems and physical facilities.
By leading this transition, GSA ensures that federal employees can continue to work securely while protecting sensitive government information and facilities against emerging threats.
Further, to help accelerate GSA’s efforts in this space, OMB Memorandum M-26-15 directed GSA to establish an interagency working group on FICAM modernization and GSA is proud to share that its first meeting took place on August 12, 2026. This initial session convened 40 participants representing 17 federal agencies. The inter-agency working group is aiming to meet bi-weekly to continue to tackle non-human identities, automation, and other modern identity features in the Post-Quantum Cryptography (PQC) environment.
Additionally, GSA will host the 2026 Post-Quantum Cryptography Summit — a hybrid event bringing together federal leaders, industry partners, and subject matter experts to chart the path toward quantum-resistant cryptography.
For more information about GSA’s federal identity management initiatives, visit https://www.idmanagement.gov.
U.S. General Services Administration
