>_ Skip to main content
Menu
Search
Post-Quantum Security

GSA Prepares Federal Identity Systems for Post-Quantum Security


The US General Services Administration (GSA) is updating federal identity and building-access systems to prepare for post-quantum cryptography. Indeed, on August 12, the agency convened a new interagency working group to facilitate this effort. This initiative aligns with OMB Memorandum M-26-15, which directs federal bodies to transition to quantum-resistant algorithms and designates the GSA for coordination. Currently, these efforts are in the planning and testing phases.

GSA’s announced initiatives

Specifically, GSA’s Office of Government-wide Policy has outlined two main areas of work in a recent press release. First, the agency is modernizing the Federal Identity, Credential, and Access Management (FICAM) architecture. This modernization aims to enable FICAM to support quantum-resistant algorithms alongside existing systems, enhancing “crypto agility,” which is the ability to adapt encryption methods as standards evolve. No specific timeline or budget for the FICAM update was provided.

Second, GSA is addressing physical access. Its FIPS 201 Evaluation Program, managed through its Physical Access Control System (PACS) lab, is now incorporating quantum-resistant algorithms into its testing protocols for badges, credentials, and building-entry equipment. Products that successfully pass these lab tests are added to GSA’s Approved Products List, which federal agencies are required to use under the Federal Acquisition Regulation. The GSA describes the upgraded lab as “an entirely new capability” requiring research and development, which indicates that testing is commencing.

Meanwhile, these initiatives stem from M-26-15, which falls under the administration’s updated Cyber Strategy and a June executive order on quantum innovation. The applicable algorithms are the finalized NIST standards FIPS 203, 204, and 205. The GSA’s release doesn’t specify which cryptographic schemes its lab will test, which leaves the particular cryptography unnamed.

Working group and unspecified details

M-26-15 mandated the GSA to establish an interagency working group for FICAM modernization. The inaugural meeting included 40 participants from 17 federal agencies, with plans to convene bi-weekly to address non-human identities, automation, and other identity features in a post-quantum environment. The formation of this working group represents a coordination step and does not establish deadlines, funding programs, or product certifications.

The GSA also plans to host a hybrid 2026 Post-Quantum Cryptography Summit for federal and industry attendees.

Presently, no fault-tolerant quantum computer capable of breaking existing encryption exists. Consequently, agencies are treating this as a “harvest-now, decrypt-later” risk. GSA’s preliminary testing and coordination align with this approach. The release doesn’t disclose funding amounts, completion dates, or which products have been qualified to date.