# What the RFI asks for
War (DOW) issued a request for information seeking commercially available, software-only cryptographic capabilities to protect data packets as programs of record transition to post-quantum cryptography (PQC). The core requirement: the technology must deploy without replacing, modifying, or adding hardware such as radios, cryptographic cards, or hardware security modules.
# Specific technical requirements
- Key transport: ML-KEM-1024 encapsulation is required for encryption key transport.
- Authentication: integration must be possible via authorized digital signatures or message authentication codes.
- Integration: solutions must work with public key infrastructure (PKI) and avoid reliance on pre-shared secret keys.
- Authorization: tools must be able to receive authorization through the ATLAS process.
- Security level: encryption must meet or exceed the security of AES with a 512-bit key.
- Key control: implementations must preserve full key sovereignty for DOW.
# Timeline and administrative details
Dec. 31, 2029. Responses to the notice will be accepted through Sept. 27. The notice builds on prior DOW guidance that required components to inventory cryptographic technologies and begin transition planning.
# Why DOW wants software-only solutions
DOW's specification to avoid hardware changes aims to limit operational disruption and speed adoption across diverse platforms. Replacing radios or installing new cryptographic modules can be logistically difficult, costly, and time-consuming for deployed and edge systems. A software-first approach lets programs of record adapt cryptography while retaining existing hardware baselines.
# How this fits into broader DOW quantum planning
The RFI is one element of a wider DOW effort to prepare military systems for quantum-era threats. The department is pursuing PQC transition plans and parallel investments in quantum sensing and timing capabilities, including initiatives such as Farseer pursued by the Defense Innovation Unit. The RFI complements other federal and defense actions to manage "harvest now, decrypt later" risk and phase legacy systems toward quantum-resistant algorithms.
# Practical implications for industry
Vendors should assess whether their products can meet the ML-KEM-1024 key transport requirement, integrate with PKI workflows, and operate without hardware dependencies. Responding companies will need to document how their software preserves key sovereignty, provides the stated security equivalence, and can integrate with ATLAS authorization processes.
# Immediate next steps for interested vendors
- Review the SAM.gov RFI text and submission instructions.
- Confirm ML-KEM-1024 support or provide a development plan to implement it.
- Prepare technical demonstrations showing software-only deployment on representative platforms.
- Detail PKI integration, authentication mechanisms, and key-sovereignty protections.
- Submit responses by the RFI deadline: Sept. 27.
# Bottom line
DOW is prioritizing a transition path to PQC that minimizes hardware work and emphasizes software solutions compatible with existing systems. Vendors that can meet ML-KEM-1024 key transport, PKI integration, ATLAS authorization, and AES-512-equivalent security while preserving DOW key control are positioned to respond to the RFI before the Sept. 27 closing date.