Government and defense is the one sector where the deadlines are already written down. CNSA 2.0 sets dated milestones, NSM-10 directs inventory and planning, and the acquisition gate in January 2027 reaches suppliers to national security systems through contract flow-down, scoped by the systems and clauses in each acquisition.
This is a working day, delivered privately. You bring your own systems inventory and your own contract obligations, and you leave with a plan mapped against dates that already exist.
Who this intensive is for
Agency security architects and CIO staff, defense industrial base security leads, contracting and acquisition officers, and the system owners who will have to deliver against the milestones. Delivered privately, so the day works from your actual environment.
Contracting staff belong in the room. A large share of what this workshop produces is procurement language.
What you’ll be able to do afterward
- Map CNSA 2.0 requirements and dates onto specific systems you own
- Apply NSM-10 inventory and planning obligations without producing an inventory nobody uses
- Read the CISA product category guidance for what it means for your next acquisition
- Plan across classified and unclassified environments where the constraints differ
- Trace contractual flow-down to the suppliers it actually binds, and write the language that imposes it
- Assess cloud service provider readiness against the obligations you cannot delegate
What you leave with
Every participant receives the course handbook, a PDF of the full material with the instructor notes written out, and a PDF copy of Quantum Ready. The day itself produces a system inventory mapped to CNSA 2.0 milestone dates, a flow-down obligation register covering your supplier base, acquisition and contract language for post-quantum requirements, and a milestone-dated roadmap with named system owners. All are editable and yours to keep.
The day
Morning, first block. The mandate. CNSA 2.0, NSM-10, and the acquisition gates, read precisely and mapped to your systems.
Morning, second block. The estate. Inventory across classified and unclassified environments. Where the constraints diverge and why.
Afternoon, first block. Flow-down and acquisition. Which obligations bind which suppliers, and the contract language that imposes them.
Afternoon, second block. The plan. Assemble the milestone-dated roadmap with owners against each date.
Where this course fits
Quantum-Safe Government and Defense is the prerequisite in substance rather than in rule. It covers the same ground at overview depth, and participants who arrive having taken it start the day with the vocabulary already shared. Afterward, PQC Vendor Governance for the supplier programs, and Cryptographic Discovery, Inventory, and CBOM for the inventory work the mandates require.
Why we teach this
The day is built on the Government/Defense Extension of the Applied Quantum PQC Migration Framework, published openly under Creative Commons at pqcframework.org. The instructors run migration programs in this sector, and that is where the constraints in this material come from.
Certificate of Completion
Upon completion, you will receive a Quantum Academy certificate of completion. This is not a professional certification.
Enrollment includes 180 days of access to the corresponding online on-demand course. Where that course is not yet published, the 180 days start on the day it is.
About this program
Quantum Academy credentials are private professional credentials issued by Quantum Academy, a trade name of Post-Quantum Institute. They are not government-issued licenses, accredited degrees, or academic credit, and earning one does not guarantee employment, promotion, regulatory approval, or any other specific outcome.
Quantum Academy programs are educational and informational only, and are not legal, compliance, or engineering advice.