up:: The Mandates MOC
NSPM-12
NSPM-12, “National Policy for the Cybersecurity of National Security Systems,” is the presidential memorandum signed on June 12, 2026 that replaced the governance framework for cybersecurity across U.S. national security systems. It rescinds 2 foundational directives at once, National Security Directive 42 from 1990 and National Security Memorandum 8 from 2022, and puts a single updated structure of authorities and accountability in their place.
Its relevance to the post-quantum transition is indirect and load-bearing. NSPM-12 sets no post-quantum deadline and contains no explicit mention of post-quantum cryptography at all. What it does is restate where cryptographic authority for national security systems sits, and name the policy that constitutes the commercial cryptographic standard those systems are held to. The dates themselves continue to come from CNSA 2.0.
The short version:
- Signed June 12, 2026, establishing the cybersecurity policy framework for national security systems across the Department of War, the Intelligence Community, and federal civilian executive-branch agencies.
- It rescinds NSD-42 (July 5, 1990) and NSM-8 (January 19, 2022), which is unusually clean: 2 foundational directives replaced by 1 document.
- It contains no explicit mention of post-quantum cryptography, so it changes no migration deadline.
- It names CNSSP 15, or successor policy, or interim guidance from the National Manager, as the commercial cryptographic standard for national security systems.
- The National Manager holds the cryptologic authority, including designing, building, testing, delivering, and protecting cryptographic key and code capabilities, and approving and publishing security standards for NSS.
- For a migration program, the practical read is that the authority chain was restated while the dated obligations stayed where they were.
What does NSPM-12 actually do?
It establishes a national cybersecurity policy framework for national security systems and assigns the governance, oversight, and accountability structures that go with it. National security systems are the classified and defense-adjacent systems carved out of the civilian federal rules, which is why they answer to a separate policy line from OMB M-23-02 and NIST IR 8547.
The rescissions are the structural news. NSD-42 dated from July 5, 1990 and governed the security of national security telecommunications. NSM-8 dated from January 19, 2022 and covered improving the cybersecurity of defense and intelligence systems. NSPM-12 replaces both.
Source: The White House, “National Security Presidential Memorandum/NSPM-12,” June 12, 2026, whitehouse.gov.
What does it say about cryptography?
It places the cryptologic authority for national security systems with the National Manager. Section 5(b) provides that the National Manager shall “design, build, test, deliver, and protect cryptographic keys and codes capabilities; review, approve, and publish standards related to the security of NSS.”
The memorandum also specifies, in section 3(c)(ii)(B), that “CNSS Policy (CNSSP) 15, or successor policy, or interim guidance from the National Manager, will constitute the commercial cryptographic standard for NSS.”
Source: The White House, “National Security Presidential Memorandum/NSPM-12,” June 12, 2026, §§ 3(c)(ii)(B) and 5(b), whitehouse.gov.
That second sentence is the one a migration program cares about. National security systems are measured against a Committee on National Security Systems policy rather than the civilian FIPS 140-3 and NIST approved-algorithm chain that reaches everyone else, which is the same split that makes CNSA 2.0 rather than NIST IR 8547 the operative schedule for those systems.
Does NSPM-12 change any post-quantum deadline?
No. The memorandum contains no explicit mention of post-quantum cryptography or quantum-resistant algorithms, and it sets no migration date.
The national security system dates continue to come from CNSA 2.0: post-quantum algorithms required in all new national security system acquisitions from January 1, 2027, exclusive use for software and firmware signing and traditional networking equipment by 2030, and web browsers, servers, cloud services, and operating systems by 2033.
Source: NSA, “CNSA 2.0 FAQ,” media.defense.gov. ⚠️ The 2030 exclusive-use and 2033 dates are NOT in the FAQ; they belong to the September 2022 CNSA 2.0 algorithms advisory, media.defense.gov. The FAQ’s own dates are 1 Jan 2027, 31 Dec 2030 and 31 Dec 2031.
This distinction is worth holding precisely, because NSPM-12 was published a week before the Quantum USA 2026 conference and was characterized there as redefining governance for national-security information and calling out cryptography. Both halves of that characterization are accurate. Neither makes it a post-quantum instrument, and citing it as one is an error a reader with the document in front of them will catch.
How does it sit alongside the other U.S. instruments?
| Instrument | Scope | What it sets |
|---|---|---|
| NSM-10 | Whole of government | The 2035 policy goal, hedged with “as is feasible” |
| NSPM-12 | National security systems | Governance, authorities, and the naming of CNSSP 15 as the NSS commercial cryptographic standard |
| NSA CNSA 2.0 | National security systems | The dated algorithm requirements: 2027, 2030, 2031 in the FAQ; the per-sector 2033 dates are in the 2022 advisory |
| OMB M-23-02 | Federal civilian agencies | The annual algorithm-level cryptographic inventory |
| Executive Order 14412 | Federal civilian executive branch | Key establishment by December 31, 2030, signatures by December 31, 2031 |
| NIST IR 8547 | Federal systems, and anyone bound to validated cryptography | The retirement schedule, in an initial public draft |
The pattern the table shows is that the U.S. runs 2 parallel tracks. National security systems answer to NSA policy and CNSS instruments, and federal civilian systems answer to OMB and NIST. NSPM-12 is a governance rewrite on the first track that leaves the second untouched.
Why does a governance memorandum matter to a migration?
Because migrations stall on ownership rather than on algorithms, and this memorandum is about who owns what.
A national security system migration needs a named authority that can approve a standard, certify a technology, and be held accountable for the schedule. Restating that chain cleanly, and rescinding 2 overlapping directives that had accumulated across 32 years, removes a class of ambiguity that programs otherwise spend real time resolving. The same principle appears at organizational scale in Cryptographic Ownership and Why Is Quantum Readiness a Governance Problem.
Common misconceptions
- “NSPM-12 is a post-quantum mandate.” It contains no explicit mention of post-quantum cryptography and sets no migration date. The NSS dates come from CNSA 2.0.
- “It replaces CNSA 2.0.” It names the commercial cryptographic standard for NSS and leaves the algorithm suite and its dates in place.
- “It reaches federal civilian agencies.” Its subject is national security systems. Civilian agencies answer to OMB M-23-02, Executive Order 14412, and the NIST schedule.
- “It’s the same thing as NSM-10.” NSM-10 is the 2022 whole-of-government quantum directive with the 2035 goal. NSPM-12 is a 2026 NSS cybersecurity governance memorandum.
- “Rescinding NSD-42 and NSM-8 weakened the rules.” It consolidated them. The memorandum replaces both with an updated structure rather than removing the obligations.
Questions people ask
When was NSPM-12 signed? June 12, 2026.
What did it rescind? National Security Directive 42, dated July 5, 1990, and National Security Memorandum 8, dated January 19, 2022.
Does it mention post-quantum cryptography? No. It contains no explicit mention of post-quantum cryptography or quantum-resistant algorithms.
What standard does it name for NSS cryptography? CNSSP 15, or successor policy, or interim guidance from the National Manager, as the commercial cryptographic standard for national security systems.
Who holds cryptologic authority under it? The National Manager, whose responsibilities under § 5(b) include designing, building, testing, delivering, and protecting cryptographic key and code capabilities, and reviewing, approving, and publishing standards related to NSS security.
Does it change my organization’s deadline? Only if you operate or sell into national security systems, and even then the dates come from CNSA 2.0 rather than from this memorandum.
Why does it keep coming up in post-quantum discussions? It was published within days of a high-profile policy essay on the quantum threat and shortly before a major Washington conference, so the 2 got discussed together. The memorandum itself is a governance instrument.
Go deeper
- NSA CNSA 2.0: the dated algorithm requirements that actually bind national security systems.
- The Mandates MOC: the full index of instruments, U.S. and international.
Everything here is the map, given freely. When your team needs the instruments that actually bind it identified, sequenced, and turned into a migration plan, that’s the work I do.
Last verified 2026-07-30 · Updated 2026-08-25 · Maintained by Addie LaMarr, LaMarr Labs.