QuSecure post-quantum tools join Carahsoft GSA schedule
Wed, 12th Aug 2026 (Yesterday)
QuSecure's post-quantum cryptography products have been added to Carahsoft's GSA Schedule contract, expanding US government access to the QuProtect R3 platform.
The addition gives federal buyers a new procurement route for QuSecure's software as agencies face deadlines to upgrade cryptographic systems used in high-value environments. Federal guidance sets the end of 2030 for key-establishment upgrades and the end of 2031 for digital-signature upgrades.
The listing is aimed at public sector teams managing the shift to post-quantum cryptography without disrupting existing operations. Carahsoft, which sells technology to government customers through a range of contract vehicles, will now offer QuSecure's tools through its GSA Schedule contract.
Post-quantum cryptography refers to encryption methods designed to resist attacks from quantum computers, which are expected to undermine some widely used cryptographic standards. For government departments, the issue has grown more urgent as agencies assess where vulnerable cryptography sits across networks, applications and legacy systems.
QuProtect R3 is positioned as a platform for discovering and managing cryptographic assets across cloud, on-premise and legacy environments. QuSecure says it combines continuous discovery, remediation and reporting in one system, with tools that can produce compliance records such as Cryptographic Bill of Materials documents.
The platform is also intended to let agencies introduce quantum-resistant algorithms and update encryption policies without rewriting application code or replacing core infrastructure. That is likely to appeal to departments running large estates with a mix of modern and legacy technology.
Procurement route
The GSA Schedule is widely used by US public sector buyers as a pre-approved contracting framework for technology purchases. Placement on the schedule can shorten procurement cycles and widen a vendor's reach across federal agencies.
Garfield Jones, Senior Vice President of Research and Technology Strategy at QuSecure, said the addition reflects a shift in how agencies are approaching the transition.
"Adding QuProtect R3 to Carahsoft's GSA Schedule contract is an important step in helping Government agencies move from planning to execution on post-quantum security," Jones said.
He linked that shift to the federal timetable for moving away from older cryptographic approaches.
"The timelines are no longer theoretical. Key establishment must be upgraded by the end of 2030, and digital signatures by the end of 2031. Agencies are being asked to address cryptographic vulnerabilities, build crypto-agility and prepare production systems for new standards without disrupting critical operations - which is why we're seeing rising demand for solutions like QuProtect R3 that can fast-track these upgrades without changing underlying code or infrastructure," Jones said.
His remarks reflect a broader challenge for public sector technology teams. Many agencies must first identify where cryptography is used before they can replace or update it, especially in systems built over years through separate suppliers, internal development and legacy applications.
QuSecure describes crypto-agility as the ability to change cryptographic methods through policy controls rather than major system rebuilds. In practice, that approach is meant to reduce the operational burden of migrating to new standards as threats and compliance requirements change.
Agency pressure
The pressure on departments is not limited to technical risk. Compliance and audit demands are also rising as agencies are asked to document their use of cryptography and show how they are preparing for newer standards.
QuProtect R3 includes reporting features intended to support those efforts, including automated outputs aligned with federal requirements. QuSecure says this is meant to help teams maintain visibility over cryptographic assets while creating records for internal governance and external review.
Carahsoft says the agreement broadens the range of cyber and security products it can supply to public sector customers. The distributor works with resellers and systems integrators serving federal, state and local government buyers, as well as education and healthcare organizations.
Natalie Gregory, Vice President overseeing the QuSecure Team at Carahsoft, said the contract listing is intended to simplify access for agencies preparing for the transition.
"We are pleased to add QuSecure's post-quantum cryptography solutions to Carahsoft's GSA Schedule contract, further strengthening our portfolio of advanced technologies available to the Public Sector," Gregory said.
"As our customers prepare for the transition to post-quantum security, access to proven, scalable solutions that address evolving cryptographic risk is critical. Together with our reseller partners, we are committed to helping accelerate quantum readiness and enhance security resilience with the QuProtect R3 platform," she added.