up:: The Mandates MOC

M-26-15 vs M-23-02

What is the difference between M-26-15 and M-23-02?

OMB M-23-02 tells federal civilian agencies to find their quantum-vulnerable cryptography and keep reporting it. OMB M-26-15 tells them to migrate it, on dated phases. One produces knowledge, the other produces change.

⚠️ The newer memo does not supersede the older one. M-23-02’s annual inventory obligation runs to 2035, and M-26-15 assumes that inventory exists.

The short version:

  • M-23-02, November 18, 2022: an annual prioritized inventory of quantum-vulnerable systems to ONCD and CISA, plus a funding assessment 30 days after each one.
  • M-26-15, June 24, 2026: a PQC Migration Plan within 120 days, then phased execution to 2035.
  • Both bind federal civilian executive branch agencies. Both carve out national security systems.
  • M-23-02 sits inside FISMA, so a missed inventory is a reportable deficiency rather than a missed suggestion.
  • Neither binds a private organization, and both function as the template regulators and insurers model on.

What is M-23-02?

“Migrating to Post-Quantum Cryptography,” the OMB memorandum of 18 November 2022 that operationalizes NSM-10 for federal civilian executive branch agencies.

Its central requirement is an annual prioritized inventory of quantum-vulnerable cryptographic systems, submitted to ONCD and CISA, first due 4 May 2023 and annually thereafter until 2035, with a funding assessment due 30 days after each submission.

It has teeth because it sits inside FISMA. The FISMA system identifier is the first field of every inventory entry, so failure to submit is a reportable FISMA deficiency.

Appendix A was corrected on 8 January 2024 to clarify that the inventory and funding-assessment requirements apply to all agencies, though not to national security systems.

Source: OMB, “Migrating to Post-Quantum Cryptography,” M-23-02, M-23-02 PDF.

What is M-26-15?

“Execution of the Migration to Post-Quantum Cryptography,” the OMB memorandum of 24 June 2026, addressed to the heads of executive departments and agencies.

It directs every covered agency to submit a PQC Migration Plan to OMB and the Office of the National Cyber Director within 120 days, and sets phased milestones running to 2035, including post-quantum key establishment on priority systems and a requirement that systems be made cryptographically agile.

It carries exactly one explicit exclusion, stated verbatim: “This memorandum does not apply to national security systems.”

Source: OMB, M-26-15, M-26-15 PDF.

The two memos at a glance

DimensionM-23-02M-26-15
Full titleMigrating to Post-Quantum CryptographyExecution of the Migration to Post-Quantum Cryptography
Date18 November 202224 June 2026
What it asks forAn annual prioritized inventory of quantum-vulnerable systems, plus a funding assessment 30 days laterA PQC Migration Plan within 120 days, then phased execution
VerbFind and reportReplace
CadenceAnnual, through 2035Phased milestones to 2035
First deadline4 May 2023120 days from issue
Enforcement anchorFISMA. A missed inventory is a reportable deficiencyDirective to agency heads, with plans filed to OMB and ONCD
Who it bindsFederal civilian executive branch agenciesThe same
National security systemsCarved outExplicitly excluded
Vendor reachCovers agency-operated and vendor-operated systemsPulls vendors in through the FedRAMP shared-responsibility model and CISA’s product categories for procurement
Still in force?Yes. The annual obligation runs to 2035Yes

Sources: OMB M-23-02 and OMB M-26-15 in this Guide, each citing its own memorandum.

How do they actually differ?

They are consecutive stages of one program rather than competing instruments.

M-23-02 is a visibility instrument. It assumes nothing about what an agency will do next and requires only that the agency know, in a structured and reportable form, where its quantum-vulnerable cryptography lives. That is why its cadence is annual: an inventory is a state that decays, and reporting it once would have produced a snapshot rather than a program.

M-26-15 is an execution instrument. It presumes the inventory exists, asks for a plan against it, and attaches dated phases to the replacement work.

The dependency runs one way and it is strict. A migration plan cannot be written against systems nobody has enumerated, which is why the 2022 memo had to come first and why its obligation continues underneath the newer one.

Where do they agree?

Same issuer, same addressees, same population. Both are OMB memoranda to the heads of executive departments and agencies, binding federal civilian executive branch agencies.

Both exclude national security systems, which migrate under CNSA 2.0 instead. See CNSA 2.0 vs the NIST Civilian Track.

Both reach vendors, one by covering vendor-operated systems in the inventory and the other through procurement and FedRAMP.

Both share the 2035 horizon, in line with NSM-10.

And neither binds a private organization directly, while both function as the template that sector regulators, insurers and procurement offices adopt with a lag.

Did M-26-15 replace M-23-02?

No, and assuming otherwise is the expensive mistake available here.

M-23-02’s inventory obligation is annual and runs to 2035. An agency that reads the 2026 memo, files a migration plan, and stops submitting inventories has created a FISMA deficiency while believing it upgraded its compliance posture.

The two obligations also feed each other. Each annual inventory updates the picture the migration plan is executed against, and the phases in the newer memo change what the next inventory should show. Treating either as a one-time filing breaks both.

Common misconceptions

“The new memo supersedes the old one.” The annual inventory obligation continues to 2035.

“The inventory is a one-time exercise.” It is annual, with a funding assessment 30 days after each submission.

“Missing the inventory is a paperwork issue.” It sits inside FISMA, so it is a reportable deficiency.

“These memos cover the whole federal government.” Both exclude national security systems.

“M-26-15 is the first federal post-quantum requirement.” The inventory requirement has been in force since 2022, and NSM-10 precedes both.

“They apply to our company.” Neither binds a private organization directly. Both reach the private sector through procurement, and through regulators and insurers modeling on them.

Questions people ask

Do we still have to file the annual inventory? For federal civilian agencies, yes, through 2035.

Which one has the deadlines everyone quotes? The 2030 and 2035 dates most often quoted come from the NIST IR 8547 transition schedule rather than from either memo, and M-26-15 carries its own phase milestones.

What goes in the migration plan? M-26-15 names the required elements, including a plan for implementing a cryptographically agile architecture. See OMB M-26-15 and Crypto-Agility vs Migration.

Which applies to a contractor? Neither binds a contractor directly. Both reach contractors through the systems they operate for agencies and through procurement requirements.

What if we run national security systems too? Those sit outside both memos and under CNSA 2.0, and an organization operating both answers to both regimes.

Is there anything before 2022? NSM-10 is the national security memorandum both operationalize.

Should a private organization follow these anyway? Many do, because the sequencing of inventory before execution is sound independent of who it binds, and because the federal template tends to arrive later through regulators and customers.


Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs. Work with Addie at lamarrlabs.com.