Eclypses and Sterling are deploying a FIPS 140-3 validated, quantum-resistant cryptographic platform for US federal agencies, aiming to address harvest-now-decrypt-later threats and meet upcoming post-quantum migration deadlines
US federal agencies are preparing for a transition to post-quantum cryptography as the risk of quantum-enabled attacks on classical encryption becomes more immediate. Eclypses, a developer of cryptographic software, has partnered with IT integrator Sterling to deploy the MicroToken Exchange(R) (MTE) platform across federal systems. The collaboration is designed to help agencies comply with new federal requirements for quantum-resistant data protection, particularly in light of the October 2026 deadline for post-quantum cryptography (PQC) migration plans set by the White House and the Office of Management and Budget (OMB).
Payload-Level Cryptographic Enforcement
The MTE platform distinguishes itself by applying cryptographic protection directly at the data payload level, rather than relying solely on network transport protocols such as TLS or IPsec. Instead of encrypting data streams with reusable keys or certificates, MTE replaces sensitive payloads with single-use, self-verifying tokens at the application layer. This approach is intended to prevent adversaries from capturing and later decrypting traffic, even if future quantum computers become capable of breaking current public-key cryptography. The tokens are non-mathematical and self-validating, meaning intercepted packets contain no persistent secrets that could be exploited by attackers using cryptanalytically relevant quantum computers.
Technical Standards and Deployment
The cryptographic core of the MTE platform is the Eclypses Cryptographic Library (ECL), which has achieved FIPS 140-3 validation (Certificate #4690). The platform incorporates NIST post-quantum standards, including the ML-KEM (FIPS 203) key encapsulation mechanism, aligning with the latest federal guidance on quantum-resistant algorithms. MTE is distributed as a containerized software package compatible with major cloud providers such as AWS, Azure, Google Cloud, and Oracle. According to the developers, the system can be integrated into existing legacy environments and API endpoints within hours, without requiring major changes to network architecture or application code.
Federal Migration Requirements
Federal agencies face a strict timeline for PQC migration. Under OMB Memorandum M-26-15, issued in June 2026, all civilian executive departments must submit comprehensive migration plans for high-value assets by October 22, 2026. Sterling's integration strategy includes automated cryptographic inventory, gap analysis, and zero-trust modernization, leveraging asset discovery and network visibility tools alongside the MTE platform. The goal is to provide agencies with a practical path to compliance while minimizing operational disruption. This approach reflects a broader trend in the quantum technology sector, where organizations are moving from theoretical risk assessment to concrete implementation of quantum-resistant protocols. For context, recent efforts to benchmark quantum hardware for practical applications, such as the collaboration between Quantinuum and Quanta Computer on scalable trapped-ion systems, highlight the growing intersection between quantum research and real-world security requirements.
Limitations and Open Questions
While the MTE platform's FIPS 140-3 validation and NIST-aligned algorithms represent a step toward standardized post-quantum security, several challenges remain. The effectiveness of payload-level tokenization depends on correct implementation and integration with existing systems, and the transition to PQC across large federal infrastructures is likely to encounter legacy compatibility issues, performance trade-offs, and operational complexity. Additionally, while post-quantum algorithms are designed to resist attacks from large-scale quantum computers, the long-term security of these standards will depend on ongoing cryptanalysis and the evolution of both quantum and classical attack methods. Independent evaluation of the platform's deployment at scale, as well as transparent reporting of integration outcomes, will be essential for assessing its practical impact on federal cybersecurity.
Understanding the distinction between quantum cryptography and post-quantum cryptography is central to this story. Quantum cryptography typically refers to protocols such as quantum key distribution, which use quantum states to secure communication channels. In contrast, post-quantum cryptography involves new mathematical algorithms designed to run on conventional computers but remain secure even if large-scale quantum computers become available. These algorithms are being standardized by organizations such as NIST and are intended to replace or supplement existing public-key systems that are vulnerable to quantum attacks. The transition to post-quantum cryptography is a complex engineering and policy challenge, requiring careful integration, ongoing validation, and adaptation as both quantum and classical threats evolve.