Definition

A useful evidence package records inventory scope, discovery methodology, source provenance, exclusions, quantum-relevant assets, owners, dependencies, priorities, migration state and verification evidence. It supports plan preparation; it is not the agency plan, an OMB submission or a compliance certificate.

What M-26-15 requires in the initial plan

Appendix B lists system prioritization, timelines and milestones, inventory methodologies and automated tools, crypto-agile architecture, third-party coordination, resources, risk management and governance roles among the minimum plan contents.

The memorandum treats the plan as a dynamic document and places strategy, planning, discovery, governance and risk assessment in the 2026–2027 first phase.

Official sourcesWhite House OMB M-26-15: Execution of the Migration to Post-Quantum Cryptography

What a migration evidence package should preserve

Evidence package sectionRequired discipline
Scope and coverageList direct sources, imported declarations, unknowns and not-scanned environments
Methodology and toolsName deterministic methods, parser/scanner versions and limitations
Inventory and riskRetain normalized properties, source evidence, confidence and versioned risk rules
Ownership and dependenciesSeparate manual accountability from imported or observed technical facts
Migration stateSeparate planned, configured and deployed assertions from externally verified outcomes
Change historyKeep source-specific diff and drift without treating absence as complete removal

How Cipher Discovery supports the work—and where it stops

The private Migration Register can export a structured PQC Migration Evidence Pack covering retained public TLS observations, imported CycloneDX declarations, management context, versioned risk and verification state.

The export does not submit anything to OMB, determine agency applicability, prove complete inventory coverage or certify compliance. Federal teams remain responsible for governance, prioritization, resources, internal systems, supplier coordination and the final plan.

Review QSPMUnderstand the continuous operating model behind inventory and migration control.Build a migration registerSee how evidence, owners, dependencies, targets and verification fit together.Inspect public TLS evidenceStart with a bounded authorized public endpoint and explicit coverage limitations.

Frequently asked questions

What is the M-26-15 plan deadline?

The memorandum is dated June 24, 2026 and requires submission within 120 days, which is October 22, 2026. Agencies should use OMB instructions as the controlling source.

Does an automated scanner create the complete plan?

No. Automation supports inventory and monitoring. The plan also requires governance, prioritization, milestones, third-party coordination, resources, risk management and architecture decisions.

Is the Cipher Discovery evidence pack an OMB compliance report?

No. It is structured supporting evidence from the current private workspace, with explicit gaps and provenance. It is not an OMB submission, legal opinion or compliance certificate.