Skip to content

The mandate differs.
The cryptography problem doesn't.

Every sector below holds long-lived data on systems that cannot be recoded. QuProtect answers each one's regulator with the same platform.

Terms on this page

  • CISA Cybersecurity and Infrastructure Security Agency

    The National Coordinator for Critical Infrastructure Security and Resilience, which leads the national effort to understand, manage and reduce risk to cyber and physical infrastructure. EO 14412 directs CISA to issue the guidance agencies follow when migrating their systems.

    Source: CISA , About CISA (www.cisa.gov)

  • CNSA Commercial National Security Algorithm Suite

    A specific set of cryptographic algorithms and key strengths that may be used to protect classified and unclassified national security systems. The suite was announced in 2015, replacing the former release of Suite B algorithms; CNSA 2.0 is the current revision.

    Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)

  • EO 14412 Executive Order 14412

    Securing the Nation Against Advanced Cryptographic Attacks, the Executive Order directing federal agencies to move to post-quantum cryptography. It requires agencies to transition all high value assets and high impact systems to PQC for key establishment by 31 December 2030, and for digital signatures by 31 December 2031, excluding national security systems.

    Source: Federal Register , Executive Order 14412, signed 22 June 2026 (www.federalregister.gov)

  • GLBA Gramm-Leach-Bliley Act

    The federal statute placing “an affirmative and continuing obligation” on each financial institution to respect its customers’ privacy and to protect the security and confidentiality of their nonpublic personal information. The safeguards its regulators require are where cryptography in transit and at rest comes in.

    Source: U.S. Code , 15 U.S.C. 6801 (www.govinfo.gov)

  • HIPAA Health Insurance Portability and Accountability Act

    A federal statute that called on the Department of Health and Human Services to establish regulatory standards protecting the privacy and security of individually identifiable health information.

    Source: NIST , NIST SP 800-66r2 (csrc.nist.gov)

  • HVA High value asset

    Federal information or a federal information system designated as a high value asset under OMB Memorandum M-19-03 or any successor document. HVAs are the systems EO 14412 puts first in the migration, alongside high impact systems.

    Source: Federal Register , Executive Order 14412, section 4(d) (www.federalregister.gov)

  • IoT Internet of Things

    The network of devices containing the hardware, software, firmware and actuators that allow them to connect, interact and exchange data. IoT devices are often the hardest part of an estate to migrate, because many cannot be updated in place.

    Source: NIST , NIST SP 800-172r3 (csrc.nist.gov)

  • NIS2 NIS 2 Directive

    The European directive on measures for a high common level of cybersecurity across the Union, replacing the 2016 NIS Directive. It sets baseline cybersecurity risk-management and incident-reporting obligations across sectors including energy, transport, water and digital infrastructure.

    Source: EUR-Lex , Directive (EU) 2022/2555 (eur-lex.europa.eu)

  • NIST IR 8547 Transition to Post-Quantum Cryptography Standards

    NIST’s report describing its expected approach to moving from quantum-vulnerable algorithms to post-quantum signatures and key-establishment schemes. It names the existing standards that are quantum-vulnerable and the quantum-resistant ones products will need to transition to, which is what makes it the document a migration plan is written against.

    Source: NIST , NIST IR 8547: Transition to Post-Quantum Cryptography Standards (csrc.nist.gov)

  • NIST SP 800-208 Recommendation for Stateful Hash-Based Signature Schemes

    NIST’s recommendation for stateful hash-based signatures, specifying the Leighton-Micali Signature system and the eXtended Merkle Signature Scheme along with their multi-tree variants. Stateful schemes suit firmware and code signing, where a signer can track state; SLH-DSA is the stateless alternative for general use.

    Source: NIST , NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes (csrc.nist.gov)

  • NSM-10 National Security Memorandum 10

    The 2022 policy directive setting United States government policy on migrating to quantum-resistant cryptography. It is the mandate that predates EO 14412 and is usually cited alongside CNSSP 15 for national security systems.

    Source: The White House , National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, 4 May 2022 (bidenwhitehouse.archives.gov)

  • NSS National Security System

    A system whose function involves intelligence activities, cryptologic activities related to national security, command and control of military forces, or equipment integral to a weapons system, or which is protected at all times by procedures for classified information. National security systems are governed separately from ordinary federal systems, which is why CNSA applies to them rather than the civilian baselines.

    Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)

  • NYDFS 500 NYDFS Part 500

    The New York Department of Financial Services regulation establishing cybersecurity requirements for financial services companies. It applies to Covered Entities licensed in New York, which is why it reaches institutions headquartered elsewhere.

    Source: NYDFS , 23 NYCRR Part 500 (www.dfs.ny.gov)

  • PCI DSS Payment Card Industry Data Security Standard

    The payment security standard intended for entities that store, process or transmit payment account data, and for developers and manufacturers of the software and devices used in those transactions.

    Source: PCI Security Standards Council , PCI Security Standards Council (www.pcisecuritystandards.org)

  • SBIR Small Business Innovation Research

    A federal program awarding non-dilutive, equity-free funding to American small businesses to develop technology and chart a path toward commercialization.

    Source: SBIR , America's Seed Fund program overview (www.sbir.gov)

  • SCADA Supervisory control and data acquisition

    A computerized system that gathers and processes data and applies operational controls over long distances, typically across power transmission and distribution or pipeline systems. SCADA equipment is often long-lived and cannot be modified, which is what makes cryptography it depends on hard to change.

    Source: NIST , NIST SP 800-82r3 (csrc.nist.gov)

See the full glossary

Somewhere else?

If your sector holds long-lived data in motion, the platform applies. Talk to a solutions engineer about your environment.