Skip to content

Insights

OMB M-23-02: The Memo That Made Federal Cryptographic Inventory a Requirement

M-23-02 required agencies to inventory quantum-vulnerable cryptographic systems annually from May 2023, and named the fields each entry carries.

5 min read

Federal post-quantum guidance is usually discussed through its deadlines, and the deadlines have moved. The memo that turned cryptographic inventory from good practice into a reporting obligation is older than the dates most people cite, and its requirements describe what an inventory has to contain more precisely than anything that followed.

What M-23-02 required

OMB Memorandum M-23-02, Migrating to Post-Quantum Cryptography, was issued on 18 November 2022 and signed by OMB Director Shalanda D. Young. It exists to carry out National Security Memorandum 10, published on 4 May 2022, which set the goal of mitigating as much quantum risk as is feasible by 2035.

Its central instruction is a submission. By 4 May 2023, and annually after that until 2035, agencies were directed to send a prioritized inventory of information systems and assets containing cryptographic systems vulnerable to a cryptanalytically relevant quantum computer to the Office of the National Cyber Director and to CISA. National security systems are excluded.

Three kinds of system are in scope: high impact information systems, agency high value assets, and anything else the agency judges likely to be particularly vulnerable. The memo asks agencies to consider two cases under that last heading, and both are about exposure rather than classification. One is any system holding data expected to remain mission-sensitive in 2035, which is the harvest-now-decrypt-later problem stated as a scoping rule. The other is logical access control built on asymmetric encryption, naming public key infrastructure directly.

What counts as a cryptographic system

The definition is narrower than the phrase suggests, and it is the part worth reading closely. M-23-02 defines a cryptographic system as an active software or hardware implementation of one or more cryptographic algorithms providing at least one of three services: creating and exchanging encryption keys, encrypted connections, or creating and validating digital signatures.

Two words in that definition do most of the work. Active excludes implementations that are present but not in use, and the memo defines the test generously: a cryptographic system counts if it is possible for it to be employed during operation, even where it is only reached to support legacy clients. And a single system usually holds several, which the memo says explicitly, so the unit of inventory is the implementation rather than the application.

Each entry then carries nine fields, including the FISMA system identifier, the FIPS 199 categorization, the high value asset identifier where one applies, and for every vulnerable implementation the algorithm, the service it provides and the key or module length. Beyond the cryptography, an entry records whether the implementation arrives inside a commercial or government off-the-shelf package and from which vendor, the operating system and version, whether the system is hosted on-premises or by a commercial or government cloud provider, and the lifecycle of the data it protects, including how long that data needs protection.

That last field is the one that turns an inventory into a migration plan. A record of how long data has to stay confidential, set against the algorithm protecting it, is what ranks a system by risk rather than by convenience.

The parts that were not the inventory

Four further requirements sat alongside it, and they say what the inventory was for.

Agencies had 30 days to designate a cryptographic inventory and migration lead. Within 30 days of each annual submission, they owed ONCD and OMB an assessment of the funding needed to migrate the inventoried systems in the following fiscal year, which is how an inventory becomes a budget line rather than a report.

The memo also commissioned work from the agencies that support the others. CISA, with NSA and NIST, was to publish a strategy on automated tooling for assessing PQC adoption within a year, covering discovery of both internet-accessible and internal systems. NIST, with CISA and the FedRAMP program office, was to establish a mechanism for exchanging results from testing pre-standardized PQC, which agencies were encouraged to run in production environments alongside approved algorithms. A cryptographic migration working group chaired by the Federal CISO was to coordinate the whole effort.

Read together, those four say the authors expected manual inventory to be insufficient and said so in 2022, before automated discovery became the assumption in later guidance.

What has changed since 2022

The 2035 horizon M-23-02 inherited from NSM-10 is no longer the date agencies plan against. Executive Order 14412, signed 22 June 2026, requires high value assets and high impact systems to move to post-quantum key establishment by 31 December 2030 and to post-quantum digital signatures by 31 December 2031. OMB M-26-15, issued 24 June 2026, sets out the objectives agencies execute against and asks for an inventory that is automated and continuously updated rather than assembled annually.

M-23-02 anticipated this. Its own instruction runs annually until 2035 or as directed by superseding guidance, which is the clause later memoranda have been written into. The requirement did not lapse so much as get absorbed, and what was absorbed was the shape of the record rather than the cadence.

Why the 2022 requirement still describes the work

An agency that built the M-23-02 inventory properly has most of what the newer mandates ask for. The nine fields are close to the contents of a cryptographic bill of materials: algorithm, service, key length, where it runs, who supplied it, and how long the data behind it matters. What has changed is that a list compiled once a year cannot keep pace with an estate that changes weekly, which is the gap crypto-agility and continuous discovery close.

QuProtect produces that record from live traffic rather than from a survey. Reconnaissance identifies cryptographic implementations in use, including the asymmetric access-control dependencies M-23-02 singles out, and Reporting exports the result as evidence an agency can submit. Resilience is what makes the funding question smaller, because algorithms can be changed by policy across existing infrastructure rather than through the application rewrites the 2022 cost assessments had to assume.

Ready to take command of your cryptography?

Get a personalized briefing from our team and see QuProtect R3 in action.