What Is Executive Order 14413?

Executive Order 14413 is a U.S. executive order signed on June 22, 2026, to accelerate quantum innovation and prepare federal systems for the transition to post-quantum cryptography (PQC). While the order primarily applies to federal agencies, it also signals important changes for private businesses, software providers, and enterprise organizations that manage long-lived sensitive data. Companies should begin evaluating their quantum readiness, reviewing vendor security, and planning for post-quantum encryption.

Key Takeaways

  • What Executive Order 14413 does: The order accelerates the United States’ national quantum strategy while preparing federal systems for the transition to post-quantum cryptography.
  • Why businesses should pay attention: Although the Executive Order primarily applies to federal agencies, it signals the direction of future cybersecurity expectations for private organizations.
  • The biggest cybersecurity risk: Organizations that store long-lived sensitive data should begin preparing now for the transition to quantum-resistant encryption.
  • What procurement leaders should do: Evaluate whether software vendors, suppliers, and third-party partners have a roadmap for post-quantum cryptography and crypto agility.
  • The business opportunity: Organizations that prepare early can reduce long-term cybersecurity, compliance, and supplier risk while building greater trust with customers and partners.

Why Executive Order 14413 Matters

Executive Order 14413 is more than a government initiative. It signals the direction of U.S. cybersecurity policy and reinforces that quantum readiness is becoming a national priority.

While the Executive Order primarily applies to federal agencies, its implications extend far beyond government.

It accelerates the nation’s transition toward post-quantum cryptography while increasing investment in quantum research, workforce development, public-private partnerships, and implementation milestones designed to move quantum readiness from strategy to action. For businesses, it offers an early look at where cybersecurity expectations and technology standards are headed.

Today’s encryption protects everything from supplier records and banking information to contracts, intellectual property, and payment data. Although these encryption standards remain secure against classical computers, sufficiently powerful quantum computers could eventually compromise many of the cryptographic algorithms organizations rely on today.

The challenge is that attackers do not need to wait for quantum computers to mature. Cybersecurity experts have warned about a growing strategy known as Harvest Now, Decrypt Later, where encrypted information is intercepted and stored today with the expectation that it can be decrypted in the future. Any data that must remain confidential for years or decades, including supplier information, financial records, contracts, and intellectual property, should already be part of an organization’s quantum readiness strategy.

As Sumudu Tennakoon, Data Scientist at apexanalytix, explained after attending a national quantum readiness conference featuring representatives from the White House, NIST, IBM, and other industry leaders:

Some data only needs to remain confidential for a few years. Other data needs to remain protected forever. Those are the assets organizations need to safeguard today before we enter the post-quantum era."

He also emphasized that Executive Order 14413 is about more than preparing for future cyber threats.

"One part is about quantum readiness through research funding, national labs, and industry partnerships. The second part is security: how we become post-quantum cryptography ready and safeguard both our current and future data."

For enterprise leaders, the question is no longer whether quantum computing will influence their business. The question is whether they will be prepared before it does.

 

Who Is Affected by Executive Order 14413?

Executive Order 14413 primarily directs federal agencies, but its implications extend far beyond the public sector. As federal cybersecurity standards evolve, technology providers, contractors, and enterprise organizations should expect increasing expectations around quantum readiness and post-quantum cryptography.

Untitled design (46)

Organizations that should be paying close attention include:

  • Federal agencies and government contractors
  • Software providers serving public and private sector organizations
  • Critical infrastructure operators
  • Financial institutions
  • Healthcare organizations
  • Manufacturers
  • Energy and utilities providers
  • Defense and aerospace suppliers
  • Enterprise organizations that store long-lived sensitive data

For procurement and supplier risk leaders, the Executive Order introduces another important consideration: your organization’s security is only as strong as the vendors and technology partners you depend on.

Most enterprises rely on dozens or even hundreds of third-party applications to manage supplier onboarding, procurement, ERP, payments, contracts, and supplier risk. As quantum computing advances, evaluating whether those providers have a roadmap for post-quantum cryptography will become an increasingly important part of enterprise risk management.

Even organizations with no direct relationship to the federal government should pay attention. Federal cybersecurity priorities often become tomorrow’s industry standards, customer expectations, and procurement requirements. Companies that begin preparing now will be better positioned to meet evolving security expectations and build greater trust with customers, partners, and suppliers.

 

What Executive Order 14413 Means for Private Businesses

Executive Order 14413 does not impose immediate compliance requirements on most private businesses. However, it provides one of the clearest signals yet that organizations should begin preparing for the transition to post-quantum cryptography.

For many organizations, the challenge isn’t protecting today’s data. It’s protecting information that will still be valuable five, ten, or even twenty years from now.

Many enterprises retain sensitive information with long lifespans, including supplier master records, vendor banking information, payment instructions, commercial contracts, pricing agreements, financial records, intellectual property, and customer data. If that information is intercepted today, it could potentially be decrypted in the future as quantum computing capabilities mature.

As Sumudu Tennakoon, Data Scientist at apexanalytix, explained:

Encrypted data is already exposed. Anyone can intercept it today. The risk is that attackers may harvest that encrypted data now and wait until quantum computers can decrypt it in the future."

For business leaders, quantum readiness is no longer just a cybersecurity initiative. It is becoming a strategic business planning issue that affects technology investments, vendor relationships, data governance, and long-term risk management.

Organizations should begin asking practical questions, including:

  • What sensitive data do we retain for the long term?
  • Which systems rely on cryptographic algorithms that may eventually become vulnerable?
  • Are our software providers preparing for post-quantum cryptography?
  • Do our supplier risk and procurement programs evaluate vendor quantum readiness?
  • What roadmap do we have for migrating to quantum-resistant encryption?

Organizations that begin answering these questions today will be better positioned to adapt as standards evolve, customer expectations increase, and quantum-resistant technologies become the new baseline for enterprise security.

Rather than waiting for future mandates, Executive Order 14413 gives private businesses an opportunity to assess their readiness, reduce long-term cyber risk, and strengthen trust across their supplier ecosystem.

 

What Procurement and Supplier Risk Leaders Should Do Now

For procurement and supplier risk leaders, Executive Order 14413 is more than a cybersecurity discussion. It is a reminder that protecting enterprise data extends beyond your own systems to every supplier, software provider, and third-party partner you trust with sensitive information.

Modern procurement organizations manage enormous volumes of long-lived data that remain valuable for years or even decades. Supplier master records, vendor banking information, payment instructions, contracts, pricing agreements, invoices, tax documentation, and compliance records all represent information that organizations cannot afford to expose.

Preparing for the quantum era requires organizations to look beyond their own infrastructure. Every supplier portal, ERP platform, payment system, and third-party application that stores or processes sensitive information becomes part of your organization’s security posture.

Procurement and supplier risk leaders should evaluate the systems that support critical business operations, including:

  • Supplier onboarding platforms
  • Supplier master data
  • Vendor banking information
  • Enterprise resource planning (ERP) systems
  • Procurement and sourcing platforms
  • Supplier risk management solutions
  • Contract repositories
  • Invoice archives and payment records
  • Third-party integrations and APIs

These systems often retain information for many years, making them potential targets for Harvest Now, Decrypt Later attacks. Even if that information cannot be decrypted today, organizations should begin evaluating whether the technologies protecting it are prepared for the transition to post-quantum cryptography.

Just as importantly, now is the time to begin asking your technology providers difficult questions.

Do they support NIST-approved post-quantum cryptography?

Have they inventoried their cryptographic assets? What is their roadmap for crypto agility?

How will they continue protecting customer data as standards evolve?

Organizations that begin these conversations today will be better positioned to protect sensitive supplier information, strengthen trust across their supply chain, and reduce long-term cyber risk as quantum-resistant security becomes the new enterprise standard.

 

The Three Pillars of Quantum Readiness

Preparing for quantum computing is not a single technology upgrade. It requires organizations to understand where sensitive data lives, address cryptographic risks, and build the ability to adapt as security standards evolve.

Following discussions with quantum experts and the guidance emerging from Executive Order 14413, organizations should focus on three foundational pillars of quantum readiness.

The Three Pillars of Quantum Readiness

Pillar What It Means
1. Know Your Encryption Inventory where sensitive data lives, which systems use encryption, and which cryptographic algorithms protect your business.
2. Close Security Gaps Identify legacy encryption, unsupported applications, third-party dependencies, and systems that lack a migration plan.
3. Build Crypto Agility Establish governance and processes that allow encryption to evolve as standards, technologies, and threats continue to change.

1. Know Your Encryption

The first step toward quantum readiness is understanding where encryption is used across your organization. Inventory the systems and data that must remain protected over the long term, including supplier master data, vendor banking information, ERP systems, contracts, invoice archives, and third-party integrations.

Without a complete inventory, organizations cannot accurately assess their exposure or prioritize migration efforts.

 

2. Close Security Gaps

Once cryptographic assets have been identified, evaluate where improvements are needed. Review legacy encryption algorithms, unsupported applications, outdated certificates, long-lived sensitive data, and third-party software dependencies. This is also the time to engage technology providers and understand their roadmap for post-quantum cryptography.

The goal isn’t simply identifying risk—it’s building a prioritized plan to reduce it.

 

3. Build Crypto Agility

Quantum readiness is not a one-time migration project. Organizations need the ability to continuously update encryption as standards evolve and new threats emerge. This capability, known as crypto agility, should become part of long-term security governance.

Organizations that invest in crypto agility today will be better positioned to protect sensitive supplier information, customer data, and critical business systems throughout the transition to post-quantum security.

 

Frequently Asked Questions About Executive Order 14413

What is Executive Order 14413?

Executive Order 14413 is a U.S. executive order signed on June 22, 2026, that advances the nation’s quantum computing strategy and accelerates the transition to post-quantum cryptography (PQC). The order directs federal agencies to strengthen quantum research, workforce development, cybersecurity, and public-private collaboration while preparing government systems for the quantum era.

 

Why was Executive Order 14413 issued?

Executive Order 14413 was issued to strengthen U.S. leadership in quantum technology and prepare the country for the cybersecurity challenges posed by quantum computing. It aims to accelerate innovation, support domestic manufacturing, expand the quantum workforce, and improve the federal government’s readiness for post-quantum cryptography.

 

Does Executive Order 14413 apply to private businesses?

Executive Order 14413 primarily applies to federal agencies, but it has important implications for private businesses. Organizations that develop software, manage sensitive data, support government agencies, or operate complex supply chains should begin preparing for post-quantum cryptography and evaluating their long-term cybersecurity strategy.

 

What is post-quantum cryptography?

Post-quantum cryptography (PQC) refers to encryption algorithms designed to resist attacks from both classical and quantum computers. These algorithms are being standardized by the National Institute of Standards and Technology (NIST) and will replace many of the cryptographic methods businesses rely on today as quantum computing continues to advance.

 

What is “Harvest Now, Decrypt Later”?

Harvest Now, Decrypt Later is a cyberattack strategy in which attackers steal encrypted data today and store it until quantum computers become powerful enough to decrypt it in the future. Organizations with long-lived sensitive information, such as contracts, supplier records, banking details, and intellectual property, should consider this risk as part of their cybersecurity planning.

 

Why should procurement and supplier risk leaders care about Executive Order 14413?

Procurement and supplier risk leaders manage systems and data that often remain valuable for many years. Executive Order 14413 highlights the growing importance of quantum readiness, making it increasingly important to understand whether software vendors, suppliers, and third parties are preparing for post-quantum cryptography and long-term data protection.

 

How can organizations prepare for quantum computing?

Organizations can begin preparing by identifying long-lived sensitive data, inventorying cryptographic assets, evaluating technology vendors’ post-quantum roadmaps, following NIST guidance, and developing a phased migration strategy. Starting early reduces future cybersecurity risk and helps organizations adapt as industry standards evolve.

 

Will quantum computers break today’s encryption?

Large-scale quantum computers capable of breaking widely used encryption are not yet available, but experts expect they could eventually compromise many current cryptographic algorithms. Because sensitive data often remains valuable for years or decades, organizations are encouraged to begin planning for quantum-resistant encryption now rather than waiting for the technology to mature.

 

How does Executive Order 14413 affect software vendors?

Software vendors should expect growing customer and government interest in post-quantum cryptography. Organizations purchasing enterprise software are increasingly asking vendors about their quantum readiness, cryptographic roadmap, and plans for adopting NIST-approved post-quantum encryption standards.

 

What should businesses do next after Executive Order 14413?

Businesses should assess where sensitive data is stored, determine how long it needs to remain secure, evaluate whether current technology providers are preparing for post-quantum cryptography, and begin developing a quantum readiness strategy. Taking proactive steps today can reduce long-term cyber risk and improve resilience as quantum technologies continue to evolve.

 

What questions should I ask my software vendors about quantum readiness?

Organizations should ask software vendors whether they have a roadmap for post-quantum cryptography, which NIST-approved algorithms they plan to support, how they are protecting long-lived customer data, whether they have inventoried cryptographic assets, and when customers can expect quantum-resistant capabilities. Understanding a vendor’s preparedness can help reduce future cybersecurity and supplier risk.

TL;DR — Executive Order 14413 at a Glance

Topic Key Point
What it is A U.S. executive order that accelerates quantum innovation while preparing federal systems for the transition to post-quantum cryptography (PQC).
Primary goal Strengthen U.S. leadership in quantum computing through research, workforce development, public-private partnerships, domestic manufacturing, and stronger cybersecurity.
Who it affects Federal agencies first, with growing implications for government contractors, enterprise software providers, procurement teams, and organizations managing long-lived sensitive data.
Biggest cybersecurity risk Attackers can harvest encrypted data today and decrypt it in the future using quantum computers, making long-lived sensitive information especially vulnerable.
What businesses should do Inventory sensitive data, identify cryptographic assets, evaluate technology vendors, adopt NIST-approved post-quantum cryptography where appropriate, and develop a quantum readiness roadmap.
Procurement takeaway Assess whether suppliers and technology providers are prepared for post-quantum cryptography and incorporate quantum readiness into supplier risk and vendor governance programs.
Critical capability Build crypto agility so your organization can continuously adapt encryption as standards, threats, and technologies evolve.
Bottom line Executive Order 14413 signals that quantum readiness is becoming a business imperative. Organizations that begin preparing today will be better positioned to protect sensitive data, strengthen supplier trust, and reduce long-term cybersecurity risk.

How apexanalytix Supports Quantum Readiness

Preparing for the quantum era requires more than awareness. Organizations need trusted technology partners that are actively investing in secure infrastructure, evolving cryptographic standards, and continuous innovation.

At apexanalytix, quantum readiness is already part of our technology strategy. We have implemented NIST-approved post-quantum cryptography to help safeguard customer data today while preparing for the cybersecurity challenges of tomorrow. As standards evolve, our focus extends beyond a one-time migration to maintaining the crypto agility needed to continuously strengthen our security posture.

Our approach to quantum readiness includes:

  • Private AI infrastructure that keeps sensitive enterprise data within a secure, controlled environment.
  • Post-quantum encryption using NIST-approved cryptographic algorithms to protect data both today and into the future.
  • Continuous monitoring and crypto agility to help ensure security evolves alongside emerging threats and industry standards.
  • Supplier Risk Management that helps organizations gain greater visibility into the third-party relationships and supplier ecosystems that increasingly influence enterprise risk.
  • The Quantum Readiness Assessment, a practical tool designed to help organizations evaluate their preparedness and identify opportunities to strengthen their long-term cybersecurity strategy.

As Executive Order 14413 accelerates the transition toward post-quantum security, organizations should not only evaluate their own readiness but also understand how their technology providers are preparing for the future. Asking these questions today can help reduce long-term risk, strengthen trust, and improve resilience across the enterprise.

Ready to assess your organization’s quantum readiness?

Take our Quantum Readiness Assessment to identify potential gaps and better understand how prepared your organization is for the transition to post-quantum security.

Your potential ROI, backed by Forrester.

Explore our ROI calculator, developed in partnership with Forrester, by navigating to the link below and selecting “configure data” on the right-hand side.

Click here to calculate your ROI.

Complete this quick form and we will get back to you within 24 hours.