A useful evidence package records inventory scope, discovery methodology, source provenance, exclusions, quantum-relevant assets, owners, dependencies, priorities, migration state and verification evidence. It supports plan preparation; it is not the agency plan, an OMB submission or a compliance certificate.
What M-26-15 requires in the initial plan
Appendix B lists system prioritization, timelines and milestones, inventory methodologies and automated tools, crypto-agile architecture, third-party coordination, resources, risk management and governance roles among the minimum plan contents.
The memorandum treats the plan as a dynamic document and places strategy, planning, discovery, governance and risk assessment in the 2026–2027 first phase.
What a migration evidence package should preserve
| Evidence package section | Required discipline |
|---|---|
| Scope and coverage | List direct sources, imported declarations, unknowns and not-scanned environments |
| Methodology and tools | Name deterministic methods, parser/scanner versions and limitations |
| Inventory and risk | Retain normalized properties, source evidence, confidence and versioned risk rules |
| Ownership and dependencies | Separate manual accountability from imported or observed technical facts |
| Migration state | Separate planned, configured and deployed assertions from externally verified outcomes |
| Change history | Keep source-specific diff and drift without treating absence as complete removal |
How Cipher Discovery supports the work—and where it stops
The private Migration Register can export a structured PQC Migration Evidence Pack covering retained public TLS observations, imported CycloneDX declarations, management context, versioned risk and verification state.
The export does not submit anything to OMB, determine agency applicability, prove complete inventory coverage or certify compliance. Federal teams remain responsible for governance, prioritization, resources, internal systems, supplier coordination and the final plan.
Frequently asked questions
What is the M-26-15 plan deadline?
The memorandum is dated June 24, 2026 and requires submission within 120 days, which is October 22, 2026. Agencies should use OMB instructions as the controlling source.
Does an automated scanner create the complete plan?
No. Automation supports inventory and monitoring. The plan also requires governance, prioritization, milestones, third-party coordination, resources, risk management and architecture decisions.
Is the Cipher Discovery evidence pack an OMB compliance report?
No. It is structured supporting evidence from the current private workspace, with explicit gaps and provenance. It is not an OMB submission, legal opinion or compliance certificate.