Webinar Description
Key Takeaways
- Virtual webinar addressing federal Post-Quantum Cryptography directives and their practical implementation
- Designed for government IT managers, cybersecurity officers, and compliance professionals
- Covers cryptographic inventory, discovery, and crypto-agility strategies
- Examines FIPS 140-3 validated cryptography and NIST-standardised PQC algorithms
- Provides guidance on developing risk-based PQC migration roadmaps
- Eligible for CPE credits
Introduction
From Policy to Practice: Navigating the Latest Federal PQC Directives is a virtual webinar designed to help government agencies translate emerging Post-Quantum Cryptography requirements into operational reality. The session targets IT and cybersecurity professionals working within federal, state, and local government who must prepare their organisations for the cryptographic transition ahead. With quantum computing advancing steadily, federal mandates now require agencies to inventory their cryptographic assets and develop migration strategies before quantum-capable adversaries can exploit current encryption methods.
About This Event
This one-hour virtual webinar brings together expertise from SafeLogic, Carahsoft, and Marion Square to address the practical challenges of PQC adoption within government environments. The session is offered at no cost and qualifies for Continuing Professional Education credits, making it suitable for professionals maintaining cybersecurity certifications. The group internet-based format allows participants to engage with the material remotely while accessing expert perspectives on federal cryptographic modernisation.
Federal PQC Directives and Their Implications
Recent federal directives have established clear expectations for how government agencies must approach the transition to quantum-resistant cryptography. These policies recognise that current public-key encryption methods, while secure against classical computers, will become vulnerable once sufficiently powerful quantum computers become operational. The webinar examines these directives in detail, explaining what they require and the timelines agencies must work within.
Understanding the policy landscape is essential because PQC migration is not simply a technology upgrade. It requires agencies to assess their entire cryptographic footprint, identify systems that rely on vulnerable algorithms, and prioritise remediation based on data sensitivity and operational criticality. The directives establish a framework for this work, but translating policy language into technical action plans remains challenging for many organisations.
Building Cryptographic Inventory and Achieving Crypto-Agility
A central theme of the webinar is the importance of cryptographic inventory and discovery. Before agencies can migrate to post-quantum algorithms, they must first understand where cryptography exists within their environments. This includes not only obvious applications like secure communications and data storage but also embedded cryptographic functions in legacy systems, third-party software, and hardware security modules.
The concept of crypto-agility receives significant attention. Crypto-agile systems can transition between cryptographic algorithms without requiring complete architectural overhauls. For agencies facing the PQC transition, building crypto-agility into current modernisation efforts reduces future migration costs and minimises operational disruption. The session explores how organisations can design systems that accommodate algorithm changes as standards evolve and new threats emerge.
FIPS 140-3 and NIST PQC Standards
Federal agencies operate under strict requirements to use validated cryptographic modules, making FIPS 140-3 compliance a prerequisite for any cryptographic implementation. The webinar addresses how FIPS 140-3 validated cryptography intersects with the emerging NIST-standardised PQC algorithms. NIST has finalised several post-quantum algorithms following years of evaluation, and agencies must now understand how to implement these algorithms within compliant frameworks.
The relationship between validation requirements and new algorithm adoption creates complexity. Agencies cannot simply deploy new algorithms without ensuring their implementations meet federal security standards. This session clarifies the current state of PQC algorithm validation and what agencies should expect as the ecosystem matures.
Who Should Attend
The webinar is particularly relevant for IT managers responsible for infrastructure modernisation, cybersecurity officers developing security roadmaps, procurement specialists evaluating cryptographic solutions, and compliance officers ensuring adherence to federal mandates. Technology leaders from federal, state, and local government organisations will find value in the practical guidance offered, especially those beginning to scope PQC migration projects or seeking to understand how recent directives affect their existing modernisation plans.
Developing Risk-Based Migration Strategies
Rather than advocating for immediate wholesale replacement of cryptographic systems, the webinar emphasises phased, risk-based migration strategies. Not all systems face equal exposure to quantum threats, and agencies must allocate limited resources effectively. Systems protecting long-lived secrets or sensitive national security information warrant earlier attention than those handling transient data with shorter confidentiality requirements. The session provides frameworks for assessing risk and prioritising migration activities accordingly.

