High-value and high-impact federal systems have a 2030 migration target. This asks whether a later public assessment finds a majority miss, driven mainly by incomplete inventories or legacy cryptography.
38%likely
Well sourcedNext check
Watching
Why it is different
The new cryptographic standards exist; the unresolved work is discovering and replacing every in-scope legacy path.
Why it matters
Migration reduces harvest-now-decrypt-later exposure, while incomplete inventories can leave old cryptographic paths open.
Next check · 30 Sep 2026
Does the White House budget office issue the required post-quantum guidance on or before 30 Sep 2026, as the executive order’s 90-day clock demands?
How we scored it ·
from how often this kind of thing happens
If right, how big4/5How overlooked4/5Upside vs downside2/5Source trust4/5Independent sources4/5
The exact wording we score
By 31 Dec 2031, a public GAO or OMB assessment reports both that more than 50% of the high-value assets and high-impact federal systems in its stated reporting denominator failed to complete ML-KEM key-establishment migration by 31 Dec 2030, and that incomplete cryptographic inventory/discovery or un-updatable legacy/embedded cryptography was the primary cause across the non-compliant set. Resolves YES only if both legs appear in a public assessment; NO if either leg fails or no qualifying assessment is published by the deadline. Systems outside EO 14412's HVA/high-impact scope and contractors are excluded unless the assessment explicitly includes them in a separately reported denominator.
PROOF
Evidence and provenance
The links below are the evidence recorded when this forecast was scored. Each note states source quality or bias; a citation is not an endorsement.
Recorded sources · 4 citations / 4 independent origins
2026-07-28 | sell-side: no direct note in the evidence set; mainstream press: deadline compliance is the dominant frame; priced market: no relevant contract identified; specialist: cyber practitioners discuss inventory and legacy crypto but the compliance-versus-confidentiality split remains underdeveloped | E4
Revision history4 entries
Probabilities and interpretations are never silently overwritten. This is the append-only record of what changed and why.
Domain review revision: P 50→38 and scope repaired. EO 14412 applies the 2030 key-establishment deadline to high-value assets and high-impact systems, not an undefined majority of all federal systems or contractors. The new claim uses only the denominator a public GAO/OMB assessment actually reports, excludes contractors unless separately enumerated, and resolves NO if no qualifying public assessment exists. The evidence-publication leg and causal-attribution leg are now priced explicitly as 0.70 × 0.55.
(2nd pass) — P 72→50, edge 3→4. This is a conjunction in which the probability and the edge sit in different conjuncts. (A) 'a majority of covered federal systems miss the 2030 deadline' — P≈0.93, and close to zero edge; everyone expects federal deadline slippage. (B) 'GAO/OMB post-mortems identify cryptographic asset discovery, not algorithm readiness, as the binding constraint' — P≈0.50, and this carries the entire insight. P=72 was pricing A while the edge argument located the claim in B. The conjunction is ≈0.47; edge raised to 4 because B is genuinely non-consensus. Falsifier corrected: it previously listed 'the deadline is formally relaxed/rescinded' as a kill — but a relaxation because agencies cannot inventory their own cryptography is the mechanism vindicated, not refuted. A formal relaxation now resolves this signal CONFIRMED-with-caveat. The 'cryptographically-relevant quantum computer arrives first' clause was also removed from the bear case: a CRQC does not make the migration succeed, it makes the miss catastrophic.
v2 rescore. P 70→72. The open sourcing question is resolved: the June-2026 executive order is EO 14412 ('Securing the Nation Against Advanced Cryptographic Attacks'), signed 2026-06-22, published in the Federal Register 2026-06-25 as FR doc 2026-12909 — not 14409. Primary cite added to the registry. H.R.9516 (119th Congress) has been introduced to codify the EO into statute, modestly reducing the 'deadline formally relaxed or rescinded' falsifier.
created from fresh (non-power) research sweep. EO existence verified across 4 sources; exact EO number left unresolved pending a primary Federal Register cite.
Method challenge
Adversarial review record
Admitted after revision
Structured internal role review tied to this frozen claim. It is not independent human peer review. Independent specialist review not yet performed
technical-domain specialist
delivery and operations reviewer
policy or standards reviewer
forecasting-method reviewer
Strongest specialist challenge
The original question incorrectly generalized EO 14412 from high-value assets and high-impact systems to a majority of federal systems and contractors. It also assumed that a public denominator and causal post-mortem would necessarily exist.
Outside view
Multi-agency federal technology mandates often miss initial deadlines, but the probability of a public assessment with a countable denominator is separate from the probability of operational non-compliance. Both evidence availability and causal attribution must be priced.
Causal rival
Funding, procurement, workforce, vendor readiness, key management, and mission-specific downtime can dominate even when asset discovery is incomplete. Algorithm readiness is a weak rival, but inventory is not automatically the single binding constraint.
Measurement risk
Security-sensitive system inventories may be aggregated or withheld. The revised question resolves NO if GAO or OMB publishes no qualifying assessment, preventing the reviewer from inferring a majority miss from anecdotes or from expanding the covered population after the fact.
Residual risk
A public report may use agency-weighted rather than system-weighted compliance, or combine discovery with legacy replacement. Adjudication will still require a documented rule for what language counts as primary causal attribution.