ransomware, cybersecurity, cyber, security, computer, technology, hacker, internet, privacy, protection, access, attack, safety, online, blue online, blue internet, blue security, blue safety, ransomware, ransomware, ransomware, ransomware, ransomware, cybersecurity, cybersecurity

GSA Expands Role in Federal Post-Quantum Cybersecurity Transition

The General Services Administration — GSA — announced in a blog post that it is expanding its role in the federal government’s transition to post-quantum cryptography, moving to update identity systems and test quantum-resistant technology used to control access to government buildings.

The effort is part of a broader push by the Trump administration to prepare federal systems for future quantum computers capable of breaking widely used forms of encryption. GSA said Monday that its Office of Government-wide Policy and Federal Identity & Cybersecurity Division will take on new responsibilities under federal cybersecurity policy and Office of Management and Budget guidance issued in June.

The work extends the post-quantum transition beyond conventional computer networks into systems that determine who can log into government resources, use employee credentials and enter federal facilities.

GSA is focusing initially on two areas: modernizing the Federal Identity, Credential and Access Management architecture, known as FICAM, and adding post-quantum security testing to the systems used for physical access to federal buildings.

GSA Updating Federal Identity Systems

FICAM provides a governmentwide framework for managing digital identities, credentials and access to federal systems and facilities. GSA said it is updating the architecture so agencies can adopt quantum-resistant algorithms while continuing to operate with existing technology during the transition.

A key part of that work is “crypto agility,” or designing systems so that one cryptographic method can be replaced with another without requiring the underlying technology to be rebuilt.

That capability has become an important part of post-quantum planning because the migration is expected to take years and cryptographic standards could continue to change as agencies deploy and test the technology.

The threat comes from sufficiently powerful quantum computers, which could eventually defeat several public-key cryptographic systems that protect data and communications today. Such machines do not yet exist at the scale needed to carry out those attacks, but the government is moving systems in advance because replacing encryption across large networks can take years.

There is also concern about so-called “harvest now, decrypt later” attacks, in which adversaries collect encrypted information today with the expectation that future quantum computers may allow them to decode it.

Quantum Security Moves Into Federal Buildings

GSA is also expanding the capabilities of its Physical Access Control System laboratory, which evaluates equipment used to secure federal facilities.

The lab operates as part of GSA’s Federal Information Processing Standards 201 Evaluation Program and tests products such as employee credential readers and other physical access-control technology.

Federal agencies generally procure physical access-control equipment from GSA’s Approved Products List, making the agency’s testing program an important point in the federal supply chain. GSA said the lab is beginning to incorporate quantum-resistant algorithms into its evaluation process so future approved systems can support post-quantum protections.

The new testing capability requires research and development because post-quantum cryptography must work not only in conventional software but also in credentials, readers and other hardware deployed across federal facilities.

GSA’s expanded role follows OMB Memorandum M-26-15, issued June 24, which set requirements for accelerating the federal transition to post-quantum cryptography.

The memorandum also directed GSA to establish an interagency group focused on modernizing FICAM. The group held its first meeting Aug. 12, bringing together 40 participants from 17 federal agencies, according to GSA.

Officials plan to meet every two weeks to address issues including automated systems, non-human identities and other identity-management requirements that will need to operate in a post-quantum environment.

The work is part of a wider federal effort following President Donald Trump’s June executive order directing agencies to accelerate migration toward cryptographic standards designed to withstand attacks from both conventional and quantum computers.

The transition will require agencies to identify vulnerable systems, replace or update cryptographic technology and coordinate procurement over several years.

GSA also plans to host its 2026 Post-Quantum Cryptography Summit, bringing federal officials, industry representatives and technical experts together to discuss migration strategy and implementation.

The agency said the combination of identity modernization, product testing and interagency coordination is intended to make the transition more orderly while reducing the risk that federal digital and physical security systems become vulnerable as quantum computing develops.

Leave a Comment

Your email address will not be published. Required fields are marked *