cryptography Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cryptography/ Breaking news about the market for products, systems and services for the U.S. intelligence community Mon, 18 May 2026 12:53:32 +0000 en-US hourly 1 https://wordpress.org/?v=7.0 https://intelligencecommunitynews.com/wp-content/uploads/2018/10/cropped-ICN-square-logo-400-32x32.jpg cryptography Archives - Intelligence Community News https://intelligencecommunitynews.com/tag/cryptography/ 32 32 59882712 Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now https://intelligencecommunitynews.com/ic-insiders-44593-2/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-44593-2 Mon, 18 May 2026 12:53:32 +0000 https://intelligencecommunitynews.com/?p=44593 From IC Insider Thales Trusted Cyber Technologies By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies Has your agency begun...

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
From IC Insider Thales Trusted Cyber Technologies

By Gina Scinta, Deputy CTO, Thales Trusted Cyber Technologies

Has your agency begun its strategy for transitioning to post-quantum cryptography (PQC)? If you’re not fairly far along now, you’re actually a bit behind. New guidance from the administration this past March, along with a memo from the Department of War last year, is ramping up the urgency. In fact, some of the stalwart cryptographic solutions used in the federal sector will be given the axe in the next five years.

Fortunately, there are some simple steps you can follow to start gearing up for your PQC transition. We’ll address those steps in a moment, but let’s first understand the context of this increasingly pressing need for dealing with security in a post quantum world.

Cyber Strategy and the Push for Infrastructure Security

March 2026 saw the release of this administration’s Cyber Strategy for America. The strategy organizes priorities around six “pillars of action,” each of which has direct implications for both federal contractors and agency cybersecurity teams. Two of those pillars are particularly relevant to this discussion: securing critical infrastructure and modernizing and securing federal government networks.

The modernization pillar in particular calls for accelerating the adoption of cybersecurity best practices, PQC, zero-trust architecture, and the transition to the cloud. This is part of the administration’s desire to have decisions made and implemented at the agency level more quickly.

PQC is becoming essential in securing federal networks. And, the Cyber Strategy comes as the Department of War has announced prioritization of solutions using NIST- approved, CNSA 2.0-listed PQC algorithms in lieu of previously-accepted quantum resistant solutions that make use of symmetric key management protocols. The Department will cease to test, pilot, use, or procure commercial solutions using these symmetric key technologies for quantum resistance. So, for agencies and contractors still relying on any of those solutions, the clock is running.

Why the urgency? Experts project the first cryptographically relevant quantum computers could emerge as early as the next decade.

Protecting systems from the quantum computing threat can’t wait until 2030. Harvest now, decrypt later schemes involve collecting data encrypted with classical algorithms today and decrypting it once a sufficiently powerful quantum computer exists. Intelligence, personnel records, and operational communications being transmitted right now are being targeted with this in mind. This is not a future problem.

Meanwhile, past cryptographic migrations across federal landscape have taken over a decade. From a purely historical perspective, things are already behind schedule.

On top of all this guidance, it’s important to remember that NIST released its first finalized PQC standards in August 2024, and is now in the process of deprecating specific cryptographic primitive algorithms and schemes on a set schedule. Agencies that have not migrated before those cutoff dates will be running deprecated cryptography in critical systems.

A Migration Memo to the Department of War

Back in November 2025, the Department of War released a memo titled, “Preparing for Migration to Post Quantum Cryptography.” The memo was directed to senior Pentagon leadership, combat commands and field activity directors, and laid the groundwork for migrating to PQC. (This guideline memo builds on the Quantum Computing Cybersecurity Preparedness Act of 2022, which requires agencies develop a PQC transition timeline based on their assessment of how they use potentially vulnerable cryptography.)

“Advancements of Quantum Information Science (QIS) and cryptanalytically relevant quantum computers requires expedited migration to quantum-resistant cryptography to safeguard the Department’s information systems, communications, and personnel,” the November 2025 memo reads.

It goes on to say, “The migration to post quantum cryptography (PQC) must not only be planned and executed with deliberate urgency to maintain warfighter lethality and information dominance in the DoW global ecosystem, but also strategically coordinated…To achieve this level of coordination, we must identify PQC migration points of contact for information sharing and create processes for streamlining intake and prioritization of PQC solutions to support certification activities and timelines.”

The Department’s memo stresses that agencies must receive cryptographic intake and deployment approval before testing, evaluating, piloting, investing in, using, or deploying any quantum-resistant or quantum-resilient technologies. It also bans outright a set of technologies for use in providing confidentiality, authenticity, or integrity on DoD networks:

  • Quantum Key Distribution (QKD)
  • Solutions combining QKD with other cryptographic keys
  • Quantum communications or networking
  • Non-local quantum randomness generation
  • Non-FIPS random number generation

 

Providing quantum resistance in solutions using cryptographic pre-shared keys (PSK) not provisioned through NSA Key Management Infrastructure for Type 1 devices will be sundowned on December 31, 2030. Symmetric Key Establishment, Agreement, and Distribution Protocols will be eliminated a year later, on December 31, 2031.

For future solutions, underlying technology must include crypto agility.

Crypto Agility: The Requirement Behind the Requirement

As organizations prepare for the post‑quantum era, crypto agility becomes essential—enabling systems to adopt PQC algorithms rapidly, minimize operational disruption, and remain resilient as cryptographic standards evolve. Many long‑established cryptographic programs have already internalized these principles, giving them the architectural headroom to absorb PQC’s larger key sizes and increased computational demands with minimal friction. NIST’s Cybersecurity White Paper CSWP 39 reinforces this need by detailing the tradeoffs, operational challenges, and interoperability considerations inherent in achieving true cryptographic agility.

For agencies, the actionable takeaway is clear: every modernization or procurement decision should explicitly require demonstrable crypto‑agility, ensuring that systems acquired today can adapt to tomorrow’s PQC mandates instead of becoming tomorrow’s technical debt. This shifts crypto agility from an abstract aspiration to a concrete acquisition criterion that safeguards mission longevity.

As organizations transition into the post‑quantum era, crypto agility becomes essential—enabling systems to rapidly adopt PQC algorithms, minimize operational disruption, and stay resilient against evolving cryptographic threats.

Seven Steps to a PQC Transition Strategy

So what are the steps agencies must take in developing their PQC transition strategy? There are seven:

  • Awareness
  • Inventory technology/prioritize systems
  • Automate crypto discovery
  • Automate inventory
  • Set up a PQC test environment
  • Practice crypto agility
  • Apply quantum key generation and implement quantum-resistant algorithms

 

Let’s take a quick look at each step.

Awareness. Your transition strategy is a top-down initiative. Leadership must be fully aware of the challenge: not only the risks, but the specific actions required to meet them. The harvest now, decrypt later threat means that PQC migration isn’t a future budget line, it’s an active operational risk.

Inventory cryptographic technologies and prioritize high-risk systems. The Office of the National Cyber Director (ONCD) provided specific instructions to federal agencies on inventorying their cryptographic systems. ONCD directed agencies to submit prioritized cryptographic inventories by May 2023. For many, unfortunately, that was a paper exercise. A manual process is less precise than one using available electronic tools, and your cryptographic footprint has grown since that submission.

Automate crypto discovery. Crypto inventory is not a one-time task. Organizations continuously create new cryptographic instances across their environments. Automated discovery is the only practical way to maintain an accurate picture. You cannot migrate what you have not mapped.

Automate discovery and inventory. Multiple vendors offer automated cryptographic discovery tools. Assess what is available and match tools to your environment. Automated tooling surfaces cryptographic dependencies that manual processes miss entirely.

Set up a PQC test environment. Now that the NIST standards are finalized, it is time to upgrade your environment for testing. As previously noted, PQC algorithms generate larger keys, and the performance impact of those larger keys could affect your systems in ways you had not anticipated. Test before you deploy at scale.

Practice crypto agility. Supporting both classical and PQC algorithms simultaneously is what makes an organization crypto agile. Devices and platforms being procured today must be capable of this. If they are not, you have to begin modernizing those systems now.

Apply quantum key generation and implement quantum-resistant algorithms. The foundation of encryption is the quality of the cryptographic keys. Organizations should leverage a quantum random number generator (QRNG) to produce high-quality entropy as the basis for all keys and cryptographic operations. Encryption solutions must use the standardized NIST PQC algorithms, or be crypto-agile with a clear and near-term upgrade path to them.

The administration’s Cyber Strategy, the Department of War phase-out deadlines, and the NIST deprecation schedule all point in the same direction: Cryptographically dangerous quantum computers are coming, and the threat is real.

Agencies should plan their transition strategies now work. Automate your crypto discovery, stand up a PQC test environment, require crypto agility in new procurements, and prioritize migration on your highest-risk systems first.

Industry has been working on this for years. Agencies need to close the gap.

About Thales TCT

Thales Trusted Cyber Technologies, a business area of Thales Defense & Security, Inc., protects the most vital data from the core to the cloud to the field. We serve as a trusted, U.S. based source for cyber security solutions for the U.S. Federal Government. Our solutions enable agencies to deploy a holistic data protection ecosystem where data and cryptographic keys are secured and managed, and access and distribution are controlled.

For more information, visit www.thalestct.com

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Transitioning to Post-Quantum Cryptography: What Federal Agencies Must Do Now appeared first on Intelligence Community News.

]]>
44593
ISARA and Carahsoft partner https://intelligencecommunitynews.com/isara-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=isara-and-carahsoft-partner Tue, 27 Jan 2026 14:41:53 +0000 https://intelligencecommunitynews.com/?p=43695 On January 22, ISARA Corporation and Carahsoft Technology Corp. announced a partnership. Under the agreement, Carahsoft will serve as ISARA’s public sector...

The post ISARA and Carahsoft partner appeared first on Intelligence Community News.

]]>
On January 22, ISARA Corporation and Carahsoft Technology Corp. announced a partnership. Under the agreement, Carahsoft will serve as ISARA’s public sector distributor, making the company’s quantum readiness solutions available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), The Interlocal Purchasing System (TIPS), National Association of State Procurement Officials (NASPO) ValuePoint, OMNIA Partners, E&I Cooperative Services Contract and The Quilt contracts.

Together, the companies will help federal agencies accelerate quantum-safe cryptography readiness by implementing autonomous cryptographic posture management with Post-Quantum Cryptography (PQC) implementations to prepare for the post-quantum era.

“As the Department of War’s (DoW) recent memorandum makes clear, the migration to post quantum cryptography is an urgent national security priority that begins with comprehensive cryptographic discovery and inventory, aligned with OMB Memorandum 23-02 and CNSS Policy 15,” said Jim Sortino, CRO of ISARA. “As the quantum computing security threat becomes more imminent, enterprises and agencies are moving from reactive defense to proactive resiliency in order to comply with U.S. cryptographic modernization mandates.”

ISARA, in partnership with Carahsoft, will enable DoW components and U.S. federal agencies to quickly gain visibility into their cryptography so they can move with confidence toward quantum resistant solutions, crypto agility and architectural validation.

The partnership aligns with the government’s growing emphasis on quantum readiness and supports efforts to enhance ZTA plans by safeguarding national digital infrastructure and mission-critical systems from emerging threats. It combines ISARA’s expertise in cryptographic risk management and quantum-safe enablement with Carahsoft’ expertise in cybersecurity, large-scale technology transformation and Federal mission operations.

Through ISARA’s partnership with Carahsoft, federal agencies will gain access to a full suite of quantum readiness services, including cryptographic inventory, assessments, prioritization through cryptographic posture management, roadmap development, quantum-safe operational technology (OT) enablement, PQC implementations and crypto-agility solutions, the companies said.

“Together with ISARA and our network of reseller partners, we can help our federal clients proactively defend against future-state risks while modernizing their cybersecurity infrastructure in alignment with evolving federal mandates,” said Brian O’Donnell, vice president of cybersecurity solutions at Carahsoft. “We’re providing a practical, phased approach to quantum readiness, one that helps agencies manage cryptographic risk today and strengthen their security for tomorrow.”

Source: Carahsoft

Start 2026 ahead of the competition with a paid subscription to IC News. You’ll get full access to our searchable archive of 15,000+ articles, plus new articles each weekday.

The post ISARA and Carahsoft partner appeared first on Intelligence Community News.

]]>
43695
SandboxAQ and DoW CIO partner https://intelligencecommunitynews.com/sandboxaq-and-dow-cio-partner/?utm_source=rss&utm_medium=rss&utm_campaign=sandboxaq-and-dow-cio-partner Thu, 11 Dec 2025 15:34:33 +0000 https://intelligencecommunitynews.com/?p=43379 On December 10, SandboxAQ announced that it is providing its technology and expertise to the Department of War (DoW) Chief...

The post SandboxAQ and DoW CIO partner appeared first on Intelligence Community News.

]]>
On December 10, SandboxAQ announced that it is providing its technology and expertise to the Department of War (DoW) Chief Information Officer (CIO) to accelerate the discovery and inventory of cryptographic assets within the DoW’s environment. This is a foundational step for a managed transition to post-quantum cryptography (PQC) and supports overall cyber readiness.

Building on SandboxAQ’s successful demonstration of its advanced capabilities in quantum-resistant cryptography during a prototype project with DISA Emerging Technology’s QRC PKI program, the DoW CIO is now leveraging the company’s AQtive Guard platform for comprehensive, automated cryptographic discovery and inventory (ACDI) across its systems. This strategic move comes as organizations face increasing pressure to modernize their cybersecurity infrastructure in the face of sophisticated AI-powered attacks, a proliferation of non-human identities, and the looming threat of quantum computing.

AQtive Guard provides a centralized platform for managing cryptographic security, empowering organizations to efficiently discover and inventory cryptographic assets and dependencies within their environment. This agreement paves the way for other DoW agencies to access and implement AQtive Guard, enabling a foundational understanding of their cryptographic footprint across the department. AQtive Guard provides agencies with continuous visibility into cryptographic assets, enabling them to anticipate and counter emerging threats as AI adoption accelerates and systems increase in complexity.

“The DoW CIO is dedicated to modernizing its cybersecurity practices as attacks increase in both intensity and sophistication,” says Jack Hidary, CEO of SandboxAQ. “This agreement underscores the government’s commitment to advance cryptographic standards that address both AI-driven and quantum threats. SandboxAQ is proud to support DoW CIO as it works to ensure our defense systems remain resilient, interoperable, and agile.”

Source: SandboxAQ

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post SandboxAQ and DoW CIO partner appeared first on Intelligence Community News.

]]>
43379
Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era https://intelligencecommunitynews.com/ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-inside-the-mission-automating-cryptographic-discovery-and-risk-for-the-quantum-era Wed, 10 Dec 2025 13:01:13 +0000 https://intelligencecommunitynews.com/?p=43372 From IC Insider Tychon Manual Cryptography Inventory: A Hidden Operational Burden Across the Intelligence Community (IC), cybersecurity teams have faced...

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

Manual Cryptography Inventory: A Hidden Operational Burden

Across the Intelligence Community (IC), cybersecurity teams have faced an unexpected challenge: finding and cataloging every instance of encryption in use. Whether it’s a TLS certificate, a VPN configuration, or an embedded algorithm in a mission system, each represents a potential vulnerability in a quantum future.

Most agencies today rely on spreadsheets, manual scripts, and ad hoc tools to attempt discovery, an approach that consumes thousands of analyst hours, delays compliance with OMB M-23-02 and NSM-10, and leaves decision-makers blind to emerging risks.

The problem isn’t effort. It’s visibility.

The Need for Continuous, Automated Discovery

Every encryption key, certificate, and cipher suite deployed across an enterprise is a potential weak point once quantum computers arrive. Agencies need more than one-time inventories; they need continuous visibility and risk scoring.

Automation is the only viable path forward. Without it, cryptographic inventories grow stale within weeks, and remediation plans are based on outdated assumptions.

Tychon Quantum Readiness delivers exactly that. Continuous, automated cryptography discovery, inventory, and risk assessment that’s built for scale and designed for the complexity of IC networks.

Engineered for Mission Simplicity

Unlike legacy cryptography management tools that require heavy infrastructure, agents, or separate consoles, Tychon deploys as a stateless binary. It runs with no persistent services or external dependencies, and it integrates directly with existing endpoint and systems management tools including BigFix, Intune, SCCM, and Ansible.

This design makes Tychon ideal for secure and air-gapped environments:

  • No new agents or network appliances required
  • No proprietary dashboards to train on
  • Deployment measured in hours, not months
  • Zero operational friction across classified and unclassified domains
  • No additional servers, databases, or external calls
  • Extensive reporting options to include CBOM, CSV, JSON and more

A SIEM-First Design for Real-Time Insight

Tychon’s architecture reflects a SIEM-first philosophy that is designed to feed cryptographic visibility directly into mission systems that already exist.

It integrates natively with BigFix, Elasticsearch, Splunk, Axonius, and Armis, streaming continuous diagnostics and cryptography risk telemetry into the same dashboards security teams already use.

Pre-built dashboards instantly surface:

  • Protocols and ciphers in use
  • Certificates nearing expiration or using deprecated algorithms
  • Key lengths and curve types
  • Cryptographic libraries and binaries detected in applications

 

No retraining. No console switching. No data silos.

From Static Spreadsheets to Continuous Compliance

Federal policy has accelerated the demand for live cryptographic visibility. Under OMB M-23-02, agencies must not only complete a one-time cryptography inventory but also report ongoing progress and risk posture.

Tychon automates this requirement, generating NIST-aligned reports and dashboards for OMB, NSM-10, and CISA CDM compliance frameworks.

By automating data collection, normalization, and scoring, Tychon reduces cryptographic inventory costs by up to 90 percent, eliminating more than 1,200 staff hours per reporting cycle.

Risk Scoring that Speaks the Language of Mission Owners

Not all cryptography carries equal risk. Tychon’s integrated scoring engine quantifies exposure based on algorithm age and strength, key length, implementation type, system criticality, and quantum vulnerability.

This NIST-aligned scoring model helps agency leaders to mission program managers prioritize mitigation efforts and budget allocations.

It also supports hardware readiness analysis by identifying systems unable to support PQC algorithms. This is a crucial insight for hardware budget lifecycle and modernization planning.

Security Without Trade-Offs

Security and simplicity rarely coexist, but Tychon achieves both. The self-contained binary includes all required libraries internally, eliminating dependency risks. It’s easy to hash, verify, and attest for supply-chain integrity.

Data never leaves the customer’s environment. Role-based access, audit logging, and FIPS-validated components ensure that the system meets the security bar expected by DoW, IC, and FCEB environments.

Proven at Mission Scale

Tychon’s technology is battle-tested at scale. The same engine that underpins Tychon Quantum Readiness has been operational across the U.S. Army’s global enterprise, more than 800,000 endpoints, for over eight years.

In classified and disconnected environments, Tychon continues to deliver real-time cryptographic telemetry with unmatched performance and reliability.

For the IC, this means confidence that the same solution proven in the world’s largest defense networks can extend securely into sensitive mission systems.

Why It Matters to the Intelligence Community

Quantum readiness is not a compliance checkbox, it is an operational continuity issue. Encryption is the foundation of every IC mission: protecting data at rest, authenticating users, securing communications, and maintaining trust in classified networks.

Losing confidence in that foundation could have cascading effects on national security operations.

By automating the discovery and management of cryptography, Tychon helps IC organizations transition from fragmented, manual visibility to continuous, data-driven assurance.

A New Seamless Path to PQC Readiness for BigFix Customers

BigFix customers now have the option to activate Tychon’s Quantum Readiness capabilities as a native BigFix offering, eliminating the need for additional tools or integrations. This direct integration allows agencies to perform automated cryptographic discovery and risk assessment using the same BigFix workflows they already trust for endpoint management. By leveraging BigFix’s deployment scale, agencies gain immediate visibility into quantum-vulnerable algorithms, certificates, and keys across every managed system. This new offering, known as BigFix Quantum Risk Analyzer, dramatically accelerates compliance efforts and enables a seamless path to PQC transition planning. This combined new solution will be generally available to BigFix customers for trial or purchase in January 2026.

The Future: Continuous Cryptography Intelligence

The next era of cybersecurity will not simply monitor threats, it will monitor the integrity of cryptography itself. With Tychon, agencies stream cryptographic telemetry into their preferred SIEM, business intelligence, and big data platforms for continuous diagnostics and mitigation, aligning perfectly with Zero Trust and PQC transition initiatives.

Request a live demonstration to see Tychon Quantum Readiness in action. Automate your cryptography visibility within hours, not months. Contact info@tychon.io or visit tychon.io.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post Inside the Mission – Automating Cryptographic Discovery and Risk for the Quantum Era appeared first on Intelligence Community News.

]]>
43372
Patero and Carahsoft partner https://intelligencecommunitynews.com/patero-and-carahsoft-partner/?utm_source=rss&utm_medium=rss&utm_campaign=patero-and-carahsoft-partner Tue, 09 Dec 2025 02:09:24 +0000 https://intelligencecommunitynews.com/?p=43355 On December 8, Carahsoft Technology Corp. and Patero Inc., a pioneer in cryptographic inventory and post-quantum encryption, announced a partnership to...

The post Patero and Carahsoft partner appeared first on Intelligence Community News.

]]>
On December 8, Carahsoft Technology Corp. and Patero Inc., a pioneer in cryptographic inventory and post-quantum encryption, announced a partnership to distribute Patero’s cryptography discovery, inventory, quantum risk assessment, and compliance reporting solution, PanoQoR, to the public sector. Under the agreement, Carahsoft will serve as Patero’s Master Government Aggregator, making the company’s quantum computing solutions available to the public sector through Carahsoft’s reseller partners and NASA Solutions for Enterprise-Wide Procurement (SEWP) V, Information Technology Enterprise Solutions – Software 2 (ITES-SW2), National Association of State Procurement Officials (NASPO) ValuePoint and OMNIA Partners contracts.

“The shift to post-quantum cryptography is not theoretical, it’s operational,” said Peter Bentley, chief operating officer at Patero. “Agencies must know what encryption they have today before they can protect what matters tomorrow. Carahsoft’s unmatched public sector network makes them the ideal partner to scale this capability in the U.S. and Canada.”

Sufficiently powerful quantum computers could crack the asymmetric encryption currently used by governments and civilian organizations worldwide. In May 2022, the White House issued National Security Memorandum 10 to address the risk posed by quantum computing to encrypted data and information systems. Subsequently, OMB issued Memorandum M-23-02, which requires agencies to submit an annual prioritized inventory of information systems and assets that contain cryptographic systems vulnerable to quantum attacks.

Carahsoft’s Quantum Solutions Team now distributes Patero’s PanoQoR cryptography inventory solution to help meet this mandatory inventory requirement for its Federal, defense, and critical infrastructure customer base. Establishing a cryptography inventory, quantum risk assessment, and compliance reporting solution not only meets Federal and civilian regulatory requirements but also represents the first step toward migrating from legacy encryption methods to post-quantum cryptography (PQC) for protecting sensitive data and systems.

“Quantum computing will redefine cybersecurity,” said Troy Meraw, quantum solutions program manager at Carahsoft. “By bringing Patero’s cryptographic inventory and PQC remediation tools to our government and enterprise customers, Carahsoft and our reseller partners are enabling security leaders to take proactive steps now to meet mandates.”

Source: Carahsoft

Don’t miss out — become a paid subscriber to IC News, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post Patero and Carahsoft partner appeared first on Intelligence Community News.

]]>
43355
The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now https://intelligencecommunitynews.com/ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now/?utm_source=rss&utm_medium=rss&utm_campaign=ic-insiders-the-urgency-of-quantum-readiness-what-the-intelligence-community-needs-to-know-now Thu, 20 Nov 2025 02:52:13 +0000 https://intelligencecommunitynews.com/?p=43223 From IC Insider Tychon The Quantum Countdown Quantum computing has moved from theoretical curiosity to technological inevitability and with it...

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
From IC Insider Tychon

The Quantum Countdown

Quantum computing has moved from theoretical curiosity to technological inevitability and with it comes one of the largest security transitions in modern history. When Dr. Peter Shor unveiled his algorithm in 1994, the world learned that quantum computers could one day break the public-key encryption that protects everything from battlefield communications to classified research and national intelligence data.

That day, commonly known as “Q-Day,” may be closer than many think. Dr. Michele Mosca, one of the world’s foremost experts in quantum computing timelines, gives Q-Day a 1-in-7 chance by 2026 and a 50 percent chance by 2031. For the Intelligence Community (IC), where adversaries continuously collect encrypted traffic to decrypt later (“Harvest Now, Decrypt Later”), this risk is immediate.

There will be an immediate impact if large scale quantum computers emerge

  • Breaking RSA, Diffie–Hellman, and ECC – the algorithms that protect most classified and unclassified government communications.
  • Compromising diplomatic, military, and IC networks that still rely on classical public-key cryptography.
  • Identity theft of government credentials, including digital signatures.

Harvest Now, Decrypt Later Is Already Here

Adversaries do not need to wait for Q-Day. Many already intercept and store encrypted communications today with the expectation that they can decrypt them once quantum computing power matures. Data collected now such as diplomatic cables, SIGINT and HUMINT communications, Intelligence sharing arrangements or even sensitive personnel records may be exposed years later. What is at risk, historical operational TTPs, sources, networks, covert methods, OPSEC, and more to provide our adversaries with a greater understanding of U.S. Intelligence.

The only defense is proactive migration to quantum-safe algorithms, known collectively as Post-Quantum Cryptography (PQC).

PQC Mandates Are in Motion

Federal and IC organizations are not starting from scratch. A series of policies and directives are already shaping the national PQC roadmap:

  • OMB M-23-02 – Requires agencies to inventory and assess cryptography, report on quantum-susceptible algorithms, and establish PQC transition plans.
  • NSM-10 – Directs agencies to protect National Security Systems (NSS) from quantum threats.
  • NIST PQC Standards – Algorithms like CRYSTALS-Kyber and CRYSTALS-Dilithium are being standardized into Federal Information Processing Standards (FIPS) for broad adoption.

 

Together, these mandates demand one critical capability: knowing what cryptography you have, where it resides, and whether it’s quantum-vulnerable.

The Four Phases of Quantum Readiness

Every organization, from mission system owners to intelligence analysts, will need to navigate four core phases of quantum readiness:

  1. Information Discovery: Identify systems, data flows, and communication channels using encryption.
  2. Cryptography Inventory: Locate every algorithm, key, and certificate in use.
  3. Risk Assessment & Analysis: Determine which assets are quantum-susceptible and prioritize remediation.
  4. Remediation & Migration: Replace vulnerable cryptography and modernize systems for PQC.

 

Manually completing these steps across hundreds of thousands of endpoints and applications could take years, time the IC cannot afford.

Automating Readiness with Tychon

Tychon Quantum Readiness automates cryptography discovery, inventory, and risk assessment across endpoints, networks, containers, and cloud environments. The lightweight, stateless utility deploys seamlessly through tools IC agencies already use such as BigFix, Intune, SCCM, or Ansible, with no new agents or consoles to manage.

Within hours, mission owners can see where vulnerable cryptography lives, score their risk using NIST-aligned metrics, and generate dashboards suitable for compliance reporting to OMB M-23-02 and NSM-10.

Field-proven on more than one million U.S. Government systems, Tychon demonstrates scalability that matches IC mission environments.

Risk Management, Not Reinvention

Cybersecurity has always been about risk management. Tychon brings that same maturity to quantum readiness. Helping agencies measure, analyze, mitigate, and manage cryptographic risk without disrupting existing operations or retraining staff.

Because data never leaves the customer environment and Tychon runs within existing security stacks, it aligns naturally with classified, air-gapped, and compartmented networks.

The Time to Act Is Now

Quantum readiness is no longer a research initiative. It’s a national security imperative. Agencies that begin automated cryptographic discovery today gain the time and clarity needed to meet federal timelines and stay ahead of adversaries already collecting data for future decryption. Taking action now is necessary and beneficial to agencies as it:

  • Gives leaders the facts needed to plan as early inventory provides the scope, scale, and complexity necessary to build accurate PQC budgets, staffing models, and modernization timelines.
  • Enables smart prioritization by knowing which systems use quantum-vulnerable algorithms lets agencies focus first on the highest-risk, highest-impact assets.
  • Creates leverage with vendors and integrators exposing dependencies on third-party products, giving agencies time to secure roadmaps, upgrades, and contract modifications.

 

Learn where your cryptography stands. Visit tychon.io to schedule a Quantum Readiness Assessment and receive your no-cost 90-day pilot.

About Tychon

TYCHON is a NIST NCCoE consortium collaborator and proven cybersecurity innovator delivering automated cryptography discovery and quantum-readiness solutions across U.S. Federal, DoW, and commercial enterprises. Tychon provides instant cryptographic visibility, risk assessment, and compliance reporting for the post-quantum era.

Sponsored content provided by Tychon LLC, a NIST NCCoE consortium collaborator for PQC.

About IC Insiders

IC Insiders is a special sponsored feature that provides deep-dive analysis, interviews with IC leaders, perspective from industry experts, and more. Learn how your company can become an IC Insider.

The post The Urgency of Quantum Readiness – What the Intelligence Community Needs to Know Now appeared first on Intelligence Community News.

]]>
43223
QuSecure names Garfield Jones SVP https://intelligencecommunitynews.com/qusecure-names-garfield-jones-svp/?utm_source=rss&utm_medium=rss&utm_campaign=qusecure-names-garfield-jones-svp Fri, 14 Nov 2025 15:24:14 +0000 https://intelligencecommunitynews.com/?p=43174 On November 12, QuSecure Inc. announced that Garfield Jones has joined the company as senior vice president, research and technology...

The post QuSecure names Garfield Jones SVP appeared first on Intelligence Community News.

]]>
On November 12, QuSecure Inc. announced that Garfield Jones has joined the company as senior vice president, research and technology strategy. A renowned technical advisor and test and systems engineering manager with extensive knowledge of IT and DoD systems, Dr. Jones will lead QuSecure’s technology strategy to meet U.S. federal government mission and security requirements, and build and nurture partnerships with stakeholders to drive strategic planning and continuous innovation for cryptographic management.

“Garfield’s deep expertise and proven track record are critical to our growth plans,” said Rebecca Krauthamer, CEO, QuSecure. “His experience in working with government agencies as they shift to post-quantum cryptography is invaluable. I am thrilled to welcome Garfield to QuSecure and look forward to working together as we continue to develop first-mover solutions that enable organizations to quickly and seamlessly remediate cryptographic risk and enhance zero-trust security.”

Prior to joining QuSecure, Dr. Jones served as associate chief of strategic technology for the Cybersecurity and Infrastructure Security Agency (CISA). In this role, he developed the strategy and guidance on using innovative, leading-edge technology across CISA, including articulating and documenting the future technology vision to achieve mission objectives and goals. Dr. Jones led the post-quantum cryptography initiative at CISA, consulting with executive branch level staff on crafting and disseminating guidance for federal agencies and national policy on research development and adoption of PQC technology.

Specifically, Dr. Jones worked with the Office of Management and Budget (OMB), Office of National Cyber Director (ONCD), and various federal agencies to execute tasks outlined in executive orders 14306 (Sustaining Select Efforts to Strengthen the Nation’s Cybersecurity) and 14144 (Strengthening and Promoting Innovation in the Nation’s Cybersecurity) and memos such as OMB 23-02 (Migrating to Post-Quantum Cryptography) issued by the Executive Branch.

He also held the position of deputy program manager for the Continuous Diagnostics and Mitigation (CDM) Program, responsible for systems engineering, architecture, and testing. Before joining DHS, he was a systems engineer developing complex weapons, geographic, and information systems for agencies such as Office of Naval Intelligence (ONI), National Geospatial Intelligence Agency (NGA), and the Naval Criminal Investigative Service (NCIS). In 2018, he retired from the Army Reserves after serving 16 years active duty and nine years reservist as an Information Systems Warrant Officer.

Dr. Jones holds a doctor of engineering in industrial and systems engineering with a concentration in machine learning and artificial intelligence, and he continues to serve as a professor at Morgan State University and University of Maryland, where he teaches computer science and systems engineering. In 2023, he received a patent for a system and method for monitoring and routing of computer traffic for cyber threat risk embedded in electronic documents. Additionally, Dr. Jones has filed a patent application for a system and method for generating a high fidelity model of a cyber physical human system.

“With the onset of quantum computing and evolving threats, organizations need to start preparing for post-quantum cryptography, yet conventional cryptographic algorithms are not enough,” said Jones. “As the pioneer in cryptographic agility, QuSecure is providing organizations with the most advanced protection so that they can see their vulnerabilities and protect against threats. I am excited to join the team and look forward to expanding our footprint as we help organizations maintain cryptographic hygiene at scale.”

Source: QuSecure

Time is running out — become a paid subscriber to IC News today, and lock in subscription rates at 2025 prices. You’ll get full access to breaking news from across the IC contracting space, with new articles each weekday.

The post QuSecure names Garfield Jones SVP appeared first on Intelligence Community News.

]]>
43174
SandboxAQ launches Open Cryptography https://intelligencecommunitynews.com/sandboxaq-launches-open-cryptography/?utm_source=rss&utm_medium=rss&utm_campaign=sandboxaq-launches-open-cryptography Mon, 03 Nov 2025 14:29:04 +0000 https://intelligencecommunitynews.com/?p=43083 On October 30, SandboxAQ launched OpenCryptography.com, the first public database mapping cryptographic assets, weaknesses, and risks across the digital ecosystem. The free...

The post SandboxAQ launches Open Cryptography appeared first on Intelligence Community News.

]]>
On October 30, SandboxAQ launched OpenCryptography.com, the first public database mapping cryptographic assets, weaknesses, and risks across the digital ecosystem. The free resource translates raw cryptographic findings into clear risk signals, helping security teams identify exploitable vulnerabilities and prioritize remediation. It also gives enterprises, researchers, and policymakers unprecedented visibility into real-world cryptographic deployments across the internet, enabling them to uncover weaknesses, strengthen defenses, and modernize for the post-quantum era.

Global regulators have made it clear: organizations must act now to modernize their cryptographic foundations and reduce supply chain risk. As the Cybersecurity and Infrastructure Security Agency (CISA), National Security Agency (NSA), and National Institute of Standards and Technology (NIST) jointly stated, “It is imperative for all organizations, especially critical infrastructure, to begin preparing now for migration to post-quantum cryptography. Without open, transparent tools, enterprises remain vulnerable to attacks that exploit outdated or misconfigured encryption.”

“OpenCryptography reflects our conviction that the status quo is no longer acceptable,” said Marc Manzano, general manager of the cybersecurity group at SandboxAQ. “Cryptography needs to stop being seen as a black box or as a vendor-related problem. It is the foundational building block for digital trust. We cannot secure what we can’t see. By making this database available to everyone, we are ending cryptographic blind spots and giving the community what it needs to act now, pinpoint actual vulnerabilities faster, and accelerate post-quantum readiness.”

The initiative draws on more than a year of intensive SandboxAQ research to assemble a continuously updated inventory of cryptographic assets from widely used software and infrastructure. SandboxAQ’s database already contains almost one billion entries spanning open-source repositories, software containers, and operating system distributions. This launch will release thousands of those entries, enabling users to pinpoint weaknesses, understand how risks evolve over time, and track the adoption of next-generation cryptographic algorithms and protocols.

“The power of community has always been central to cryptography,” said Manzano. “Just as global cryptographers contributed to the U.S. National Institute of Standards and Technology (NIST) process to establish new post-quantum cryptography (PQC) standards, OpenCryptography creates a shared foundation for improving the security posture of the Internet.”

Source: SandboxAQ

Help IC News continue to bring you breaking news from across the IC and IC contracting landscape. Join our paid subscribers today.

The post SandboxAQ launches Open Cryptography appeared first on Intelligence Community News.

]]>
43083
Viasat chosen for space cryptography solution https://intelligencecommunitynews.com/viasat-chosen-for-space-cryptography-solution/?utm_source=rss&utm_medium=rss&utm_campaign=viasat-chosen-for-space-cryptography-solution Mon, 22 Sep 2025 12:55:55 +0000 https://intelligencecommunitynews.com/?p=42764 On September 18, Viasat, Inc. announced that it is developing a new space-based encryption solution to support data security for...

The post Viasat chosen for space cryptography solution appeared first on Intelligence Community News.

]]>
On September 18, Viasat, Inc. announced that it is developing a new space-based encryption solution to support data security for U.S. Space Force (USSF) Space Systems Command (SSC). Under this multi-year development award, Viasat’s encryption team within its Defense and Advanced Technologies segment will build a next-generation cryptography solution for satellite applications allowing the government to better protect critical space assets from cybersecurity threats.

Selected for the program during its 2024 fiscal year, Viasat will develop an end-to-end encryption solution to secure sensitive data from space-to-ground. This will include the development of space-qualified encryption hardware and leverage Viasat’s certified terrestrial encryption equipment for the ground system test terminal.

Viasat’s space-to-ground encryption solution will deliver an End Cryptographic Unit (ECU) designed with prelaunch and on-orbit functionality to quickly address various communications and transmission security requirements, optimizing size, weight and power. Viasat’s space ECU development builds on a long history providing secure communications solutions for the government and complements a terrestrial portfolio of proven edge-to-cloud, tactical and embedded high assurance encryption products.

Compared to traditional solutions, Viasat will develop and produce a high speed, multi-channel, certified Ground Operating Equipment (GOE) for use in testing future communications payloads and terminals. As part of this effort, the GOE will be enhanced to support the demands of unique key and algorithm requirements that add resiliency. Viasat cryptographic solutions also deliver a flexible, multi- function design that supports multiple security functions via ground and space devices.

“Viasat is proud to partner with the U.S. Space Force on modern crypto solutions to address current and evolving threat environments,” said David Schmolke, vice president of mission connections and cybersecurity, Viasat Government. “We are committed to supporting future capabilities of integrated space-crypto solutions to ensure that mission critical data and satellite access controls are protected. This contract award further solidifies Viasat’s position as a trusted partner providing highly secure, resilient space-based communications solutions to a broad range of applications.”

Source: Viasat

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post Viasat chosen for space cryptography solution appeared first on Intelligence Community News.

]]>
42764
PQCC publishes PQC Inventory Workbook https://intelligencecommunitynews.com/pqcc-publishes-pqc-inventory-workbook/?utm_source=rss&utm_medium=rss&utm_campaign=pqcc-publishes-pqc-inventory-workbook Tue, 05 Aug 2025 22:44:57 +0000 https://intelligencecommunitynews.com/?p=42363 On July 31, the Post-Quantum Cryptography Coalition (PQCC) published its Post-Quantum Cryptography (PQC) Inventory Workbook to assist organizations of all sizes in creating a centralized...

The post PQCC publishes PQC Inventory Workbook appeared first on Intelligence Community News.

]]>
On July 31, the Post-Quantum Cryptography Coalition (PQCC) published its Post-Quantum Cryptography (PQC) Inventory Workbook to assist organizations of all sizes in creating a centralized inventory to track cryptographic migration efforts.

“As highlighted within the coalition’s PQC Migration Roadmap, building an inventory is essential for effective migration planning and long-term success,” said Wen Masters, vice president of cyber technologies, MITRE. “The workbook serves as a resource to help organizations achieve their migration goals.”

The workbook provides a streamlined set of fields to assess PQC needs, plan system life cycles, and prioritize assets for migration. Organizations can use the workbook as-is or customize it to meet their specific needs, including adding fields to track additional data over time.

“The coalition continues to provide new resources to the greater cyber community to help them better manage their transition to quantum-resistant cryptographic systems,” said Matt Mickelson, lead coordinator of the PQCC and senior cyber principal for science and technology, MITRE. “This spring, the Coalition published the PQC Migration Roadmap. Now we have the inventory workbook, and we plan to publish quantum risk assessment materials later this year.”

Source: MITRE

Stay in the know with breaking news from across the IC and IC contracting landscape by becoming a paid subscriber to IC News. Your support makes our work possible.

The post PQCC publishes PQC Inventory Workbook appeared first on Intelligence Community News.

]]>
42363