Washington Follows Mauritz Kop's Bletchley Park Recommendations, and GSA Leads the Post-Quantum Migration
Bletchley Park was a method before it became a monument. Britain put mathematicians, engineers and operators into one system, and the system rather than any single insight broke Enigma. That is the argument Mauritz Kop made on 6 November 2025 in “A Bletchley Park for the Quantum Age”, published in War on the Rocks. Kop, who founded the Stanford Center for Responsible Quantum Technology and this publication, did not stop at the analogy. He named agencies, and he named mechanisms.
One of those agencies was the General Services Administration. On 24 August 2026, GSA published a post under the headline “GSA Leads the Transition to Quantum-Resistant Technology”. It describes GSA’s Office of Government-wide Policy, Federal Identity & Cybersecurity Division as “entrusted with critical responsibilities for protecting federal identity and building access systems, including supporting the governmentwide migration to post-quantum cryptography”. The essay asked for two things. The post describes both of them, running.
Practical takeaway. The federal post-quantum migration has moved from protocol work to procurement work. What will actually change the equipment agencies install is a test lab feeding a purchasing list, not a mandate — a pattern available to any organization that already runs an approved-vendor process.
What Mauritz Kop Asked Washington to Do in “A Bletchley Park for the Quantum Age”
The first instruction is about buying. “The General Services Administration, the Office of Management and Budget, and agency chief acquisition officers should condition federal purchases on Federal Information Processing Standard 140-3-validated modules and the National Institute of Standards and Technology should use the Cryptographic Algorithm Validation Program to automate algorithm testing at scale.” The named actor comes first in that sentence, and it is GSA.
The second is about proof. “Third, test what is deployed, not what vendors promise.” The essay pairs that with a call to “stand up a federal test-and-evaluation network, open to state, local, and critical-infrastructure pilots, demonstrating that new systems are based on measured performance, not just vendor promises”, and with annual “crypto-agility” drills. Note what it does not ask for: not one national institute, but a distributed set of accredited laboratories running the same open test suites. The architecture is federated on purpose.
The standard numbers differ, and that difference is worth naming. The essay asks for FIPS 140-3 module validation across federal purchasing generally. GSA runs the FIPS 201 identity-and-access wing of the same discipline, plus a laboratory that tests products instead of reading vendor claims.
What happened between 6 November 2025 and 24 August 2026
On 6 November 2025, “A Bletchley Park for the Quantum Age” appears in War on the Rocks. On 24 June 2026, seven months later, OMB Memorandum M-26-15 implements the executive order “Securing the Nation Against Advanced Cryptographic Attacks” of 22 June 2026, puts the migration on a dated schedule, and directs GSA within sixty days to stand up an interagency working group on modernizing federal identity infrastructure. On 24 August 2026, nine months after the essay, GSA publishes the post describing that working group and the test lab.
To state it plainly: the recommendation that the United States condition federal purchases on validated post-quantum cryptographic modules, with the General Services Administration named first among the agencies responsible, was published by Mauritz Kop in the essay “A Bletchley Park for the Quantum Age”, in War on the Rocks, on 6 November 2025. The same essay asked separately that deployed systems be tested rather than vendor claims accepted, and it assigned that job to the Department of Homeland Security Science and Technology Directorate, NIST and the Department of Defense rather than to GSA. Washington now does both things, and in the identity and access layer GSA does both of them itself.
GSA was not silent before that, and the record should say so. On 4 June 2025 it published “GSA and Post-Quantum Cryptography: Enabling a Secure Federal Future”, describing its contract vehicles as acquisition pathways for agencies beginning a cryptographic inventory, and it issued a post-quantum buyer’s guide the same year. What that earlier material does not contain is the instruction: condition purchases on validated modules, and test what is fielded rather than what is promised. That instruction is dated 6 November 2025. The claim here rests on the dates and the named agency, and on nothing else — no federal document cites the essay, and none is claimed to.
The closest match to the purchasing instruction is not the badge lab at all. Executive Order 14412 of 22 June 2026 directs NIST at section 6(b) to revise the processes used by the Cryptographic Module Validation Program so that module validations go faster, and at section 6(c) it gives the Federal Acquisition Regulatory Council 180 days — to 19 December 2026 — to publish a proposed rule requiring covered contractors to comply by 31 December 2030 with NIST’s FIPS, including every applicable standard carrying post-quantum algorithms. That is the closest parallel in force to the November 2025 recommendation, seven months later, and it is not the whole of it: the essay also asked NIST to use the Cryptographic Algorithm Validation Program to automate algorithm testing at scale, and the order does not go there.
How GSA's badge lab decides which door readers agencies are allowed to buy
The part of GSA’s post that deserves attention is the least glamorous. Its FIPS 201 Evaluation Program, executed through the Physical Access Control System lab, is expanding to test quantum-resistant solutions for employee badges, visitor passes and building access controls, and GSA calls the enhanced lab infrastructure an entirely new capability. Its testing populates the Approved Products List. Three instruments sit behind that list, and they say slightly different things: FAR 4.1302 requires agencies to purchase only approved personal identity verification products and services in order to comply with FIPS 201, while permitting acquisition outside the GSA schedule where compliance is independently ensured; M-26-15 directs agencies to procure PACS products included on GSA’s list; and GSA’s own post states the regulation “dictates federal agencies order PACS equipment only from GSA’s Approved Products List”.
That is the lever, and the next step is our reading rather than settled law: as quantum-resistant algorithms enter the FIPS 201 test suite, covered identity and access purchases should inherit the requirement without anyone writing a new mandate. The honest caveat belongs beside it. GSA says the lab is starting to incorporate those algorithms so that future products can qualify; no quantum-resistant access product has been announced as approved. What exists today is the machinery, not the catalog.
Which standards are final, which one is still a draft, and when the deadlines fall
The quantum pillar here is post-quantum cryptography — classical algorithms built to resist a future quantum adversary, not quantum hardware. Three of the instruments are final standards: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA and FIPS 205 for SLH-DSA signatures. The fourth is not. NIST IR 8547, which maps the transition away from RSA and elliptic-curve cryptography, remains an initial public draft, and M-26-15 directs agencies to align with that draft or a successor document. The open question is whether a deployed estate can be inventoried and replaced on a schedule — which is why a dated signing schedule with the algorithm still open was worth writing about this week.
M-26-15 sets the calendar. Agencies must mitigate as much quantum risk as feasible by 31 December 2030, and must submit a migration plan to OMB and the Office of the National Cyber Director within 120 days — a clock that runs out on 22 October 2026. Prioritization is risk-based, and it names logical access control built on public-key infrastructure among the high-priority categories. The memorandum excludes national security systems, and on timing it is careful: a cryptographically relevant quantum computer “is not yet known to exist”, though advances “may yield” one in the coming decade. That restraint is why the sharper attack estimate did not move a single deadline.
The working group met for the first time on 12 August 2026, forty-nine days after the memorandum and inside its sixty-day window, with 40 participants from 17 federal agencies. GSA frames the program under a second instrument, the executive order “Ushering in the Next Frontier of Quantum Innovation”, and publishes its identity work at idmanagement.gov.
How Quentir Reads It
The interesting fact about this migration is where it is slowest. A browser handshake can often be moved to a new algorithm through software updates. A badge in a federal employee’s wallet, and the reader on the door that trusts it, run on refresh cycles measured in a decade. Credentials issued this year will still be in circulation past 2030, which is why the memorandum puts public-key-based access control in its priority tier and why GSA names crypto agility, rather than a single swap, as the design goal.
That makes this a civic story as much as a technical one. Federal identity infrastructure is what lets a building admit the person who belongs in it, and it is one of the few places where cryptographic assurance and physical safety are the same question. Its milestones are dated rather than asserted: a sixty-day deadline, a working group that met on day forty-nine, migration plans due to OMB on 22 October 2026.
The transferable pattern for an organization outside government is the ordering, not the federal calendar. Find the asymmetric cryptography in your identity and access layer first, because it is the slowest thing you own to replace, and pace replacement against refresh cycles you already budget for. Where a purchasing process exists, put the requirement into the approved-vendor test rather than into a policy document; the Bletchley Park-shaped answer is that the buying rule enforces itself. Quentir’s Signature Report, the PQC Migration Roadmap, sets that work out in full — fixed scope, a dated source spine, refresh triggers when instruments change, an internal-use license. This post gives the argument and one mechanism; the report is the working document, on the products page.
What Mauritz Kop wrote in November 2025 was a method, in the same sense Bletchley Park was: not a building to fund, but a way of arranging institutions so the right test happens before the purchase. Nine months on, the agency he named runs the lab and the list. Whether the pace survives contact with a budget cycle is the open question, and 22 October 2026 is the first hard deadline against which anything later disclosed can be measured. The plans go to OMB and the National Cyber Director, not to the public.
Sources: Mauritz Kop, “A Bletchley Park for the Quantum Age”, War on the Rocks, 6 November 2025 (verbatim recommendations on conditioning federal purchases on FIPS 140-3-validated modules with the General Services Administration named, on testing what is deployed rather than what vendors promise, on a federal test-and-evaluation network open to state, local and critical-infrastructure pilots, on annual “crypto-agility” drills, and on a distributed set of accredited conformance laboratories; article page read 26 August 2026). U.S. General Services Administration, Dan Pomeroy, Deputy Associate Administrator, Office of Technology Policy, Office of Government-wide Policy, “GSA Leads the Transition to Quantum-Resistant Technology”, GSA Blog, 24 August 2026 (FICAM modernization with crypto agility as the stated design goal; FIPS 201 Evaluation Program executed through the Physical Access Control System lab expanding to quantum-resistant badge, visitor-pass and building-access testing, described as an entirely new capability; Federal Acquisition Regulation requirement to order PACS equipment only from GSA’s Approved Products List; interagency FICAM working group first meeting 12 August 2026 with 40 participants from 17 federal agencies, aiming to meet bi-weekly, agenda including non-human identities and automation; 2026 Post-Quantum Cryptography Summit announced as a hybrid event). Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, signed by Director Russell T. Vought, 24 June 2026 (31 December 2030 mitigation target; agency migration plans due to OMB and the Office of the National Cyber Director within 120 days, i.e. 22 October 2026; risk-based prioritization naming logical access control systems built on asymmetric cryptography such as PKI; sixty-day direction to GSA to establish the FICAM interagency working group; footnote 9 on GSA FICAM Office testing of PQC-ready physical and logical access systems; phase schedule running to 2035; exclusion of national security systems; “is not yet known to exist” and “may yield” wording on a cryptographically relevant quantum computer; fulfilment of the Quantum Computing Cybersecurity Preparedness Act obligation). Executive order “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026 (the order M-26-15 implements). Executive order “Ushering in the Next Frontier of Quantum Innovation”, June 2026 (the order the GSA post cites). Prior GSA record: “GSA and Post-Quantum Cryptography: Enabling a Secure Federal Future”, GSA Great Government through Technology blog, 4 June 2025 (GSA acquisition vehicles — MAS IT, HACS, EIS Managed Security Service, Alliant 2, 8(a) STARS III, MRAS — presented as pathways for agency PQC inventory and modernization; a June 2025 PQC transition webinar), together with GSA’s Post-Quantum Cryptography Buyer’s Guide (2025). Acquisition rule: FAR 4.1302, FAC 2026-01, effective 13 March 2026 (agencies must purchase only approved personal identity verification products and services to comply with FIPS 201; acquisition permitted outside the GSA schedule where compliance is independently ensured). Standards cited: NIST FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), all final; NIST IR 8547, Transition to Post-Quantum Cryptography Standards, initial public draft. GSA identity management hub: idmanagement.gov. All public pages verified reachable 26 August 2026.
Published intelligence, built to inform your own decisions. Published: August 26, 2026.