← Back to News Policy

GSA Modernizes FICAM and Physical Access Systems for Post-Quantum Cryptography

On August 24, 2026, the General Services Administration (GSA) announced concrete steps to modernize federal identity, credential, and physical access infrastructure for the post-quantum era—parallel to the Treasury Department’s financial-sector task force launch the same day.

GSA’s initiatives implement Executive Order 14412 and OMB M-26-15, translating government-wide PQC mandates into the systems that authenticate federal employees and control access to government facilities.

FICAM modernization

GSA is updating the Federal Identity, Credential, and Access Management (FICAM) architecture to support quantum-resistant algorithms while maintaining compatibility with existing systems. Key themes:

  • Crypto-agility — the ability to switch encryption methods as threats evolve or NIST guidance updates, without rebuilding entire identity stacks from scratch.
  • Interagency coordination — GSA convened the first meeting of a FICAM PQC working group on August 12, 2026, with representatives from 17 agencies (~40 participants). The group plans bi-weekly sessions on non-human identities, automation, and modern identity features in a PQC environment.
  • Smooth transition — emphasis on avoiding disruption to daily operations during algorithm migration.

Identity and PKI infrastructure are among the hardest PQC migration surfaces: certificate hierarchies, smart cards, HSMs, and cross-agency trust fabrics all require coordinated cutover planning.

Physical access control (PACS)

GSA is also expanding the FIPS 201 Evaluation Program under its Physical Access Control System (PACS) laboratory to evaluate quantum-resistant technologies for:

  • Employee badges and PIV credentials
  • Visitor passes
  • Building access control systems

The enhanced lab capability requires new research and development to test PQC algorithms in physical security contexts—a domain often overlooked in TLS-centric migration discussions. Future products on GSA’s approved products list for physical access will incorporate quantum-resistant protections.

2026 PQC Summit — September 16

GSA will host the 2026 Post-Quantum Cryptography Summit on September 16, 2026 (hybrid format), bringing together federal leaders, industry partners, and subject-matter experts. The summit will cover FICAM, PACS, procurement, and cross-agency migration coordination.

Implications for vendors and integrators

  1. Identity and access management vendors face near-term PQC requirements. Federal IAM, PKI, and PIV products must align with FICAM modernization and NIST standards.
  2. Physical security is in scope. Badge systems and PACS vendors should expect quantum-resistant testing requirements in federal procurement.
  3. Agencies must inventory identity and physical-access cryptography separately from application-layer TLS. OMB migration plans must address both.

QTL perspective

Quantum Transition Labs frequently finds that organizations underestimate identity, PKI, and IoT/physical-access dependencies in PQC inventories. GSA’s early action on FICAM and PACS validates a whole-of-enterprise approach—exactly the scope QTL applies in cryptographic discovery and migration roadmapping engagements.

Need help aligning your cryptographic roadmap with evolving federal quantum policy?

Contact QTL