October 10, 2026
Bonus Content: The CBOM Is the Real PQC Bottleneck. These Stocks Feel It First.
The download link for my Simple Options Trading For Beginners book is about to expire.
Once it goes, the book goes back to $29.97 on the website – same book, same content, just no longer free.
This is one of those things where the people who grab it in the next sixty seconds will have it on their computer forever. The people who don’t will be staring at an order page tomorrow, wishing they’d taken the twenty seconds.
It’s a quick read that finally explains options in plain English. No Greeks. No textbook charts. Just the actual mechanics with step-by-step trade examples.
Grab the free copy before the link expires.
Good Trading,
Bill Poulos
p.s. This link will expire without warning.
The CBOM Is the Real PQC Bottleneck. These Stocks Feel It First.
October is not a soft deadline. Federal agencies must submit PQC migration plans to the Office of Management and Budget and the Office of the National Cyber Director around October 22, 2026. Traders watching the post-quantum cryptography space have focused on the December FAR rule and the 2030 compliance finish line. The more immediate pressure point is something far less discussed: the Cryptographic Bill of Materials.
- October 2026: Agency PQC migration plans due to OMB and ONCD (around October 22, 2026)
- December 19, 2026: FAR Council must publish a proposed rule requiring covered contractors to comply with NIST’s FIPS, including applicable FIPS incorporating PQC-compliant algorithms, by December 31, 2030
- March 19, 2027 (approx.): FAR Council must publish a proposed rule that also tees up CBOM-related contractor obligations via FAR changes focused on cryptographic vulnerabilities, including testing for lack of encryption and the use of non-FIPS-approved algorithms
- January 2027: The NSA’s CNSA 2.0 expects new deployments to be compliant starting January 1, 2027 (unless otherwise explicitly noted)
- HNDL threat is active now: “Harvest now, decrypt later” collection risk is widely cited by U.S. and allied cybersecurity authorities as a live driver of PQC urgency
Why the CBOM Is the Choke Point
OMB Memorandum M-26-15 operationalizes EO 14412 and makes cryptographic inventory management a required input to agency PQC migration plans. In practice, that pushes agencies and their vendors toward producing a Cryptographic Bill of Materials that catalogs the cryptographic mechanisms running inside the systems and software delivered to the government. Think of it as a SBOM for cryptography. A CBOM is meant to inventory cryptographic assets like algorithms, key sizes, certificates, and implementations. An SBOM tells you which library you use. A CBOM tells you whether that library is using RSA-2048 or ML-KEM, and whether it is quantum-vulnerable.
Discovery is the slowest step. The 2030 and 2031 dates in EO 14412 are finish lines, not starting pistols. EO 14412 also attaches two nearer-term execution clocks: a proposed FAR rule due in December 2026 and a second proposed FAR rule due around March 2027. Separately, the White House fact sheet accompanying EO 14412 says the Department of Commerce is to run a PQC migration pilot to be completed by December 31, 2027. The organizations that meet the 2030 deadline will have started their CBOM-grade inventory work in 2026. That urgency is directly monetizable.
Who Captures the Discovery Revenue
Leading tools in 2026 include IBM Quantum Safe Explorer for enterprise codebases and mainframe environments, SandboxAQ AQtive Guard for large-scale discovery and cryptography management, and Keyfactor’s Command Risk Intelligence after its 2025 acquisition of InfoSec Global and CipherInsights for cryptographic posture management and discovery. SandboxAQ is private but material to the capital flow picture: the company disclosed it raised over $450 million in a Series E round that closed in April 2025, with new investors including Ray Dalio, Google, NVIDIA, BNP Paribas, and Horizon Kinetics. It also publicized a five-year U.S. defense-related agreement tied to deploying AQtive Guard for cryptographic discovery and inventory at scale.
The publicly traded hardware angle runs through Lattice Semiconductor (LSCC). Lattice introduced the MachXO5-NX TDQ family as secure control FPGAs with CNSA 2.0-compliant PQC support, crypto-agility, and a hardware root of trust. The numbers are accelerating: Lattice reported record Q2 2026 revenue of $201 million, up 62% year over year. On the M&A front, Lattice completed its $1.65 billion acquisition of AMI in 2026. Lattice said AMI’s calendar 2026 revenue is expected to be more than $200 million, with a non-GAAP gross margin expected to exceed 75% by the end of 2026 and adjusted EBITDA margins of approximately 40%.
For consulting exposure, Booz Allen Hamilton (BAH) reported total backlog of about $39.5 billion as of June 30, 2026. The firm has also disclosed quantum-adjacent contract activity, including a potential five-year Air Force award reported around $25.3 million tied to quantum-accelerated technology advancement. The firm’s full-year FY26 revenue was $11.2 billion. In its reporting, Booz Allen groups defense and intelligence under “National Security,” and that segment’s quarterly revenue has been running around $2.0 billion.
Technical Framework
LSCC has rebuilt its trend since mid-2025. Q3 FPGA revenue guidance of $210 million to $230 million implies approximately 65% year-over-year growth at the midpoint, with total Q3 revenue guided at $245 million to $265 million. Watch the $17.8 billion market cap against that forward revenue trajectory. A compression in the current multiple would put the stock near 50-day support around $130; a re-rate on PQC procurement acceleration would challenge the $160 area.
Three Scenarios
Bull case: October agency submissions reveal cryptographic inventories far behind schedule, triggering emergency CBOM procurement. LSCC’s secure FPGA pipeline accelerates into Q4 guidance beat territory. SandboxAQ files for a 2027 IPO, pulling forward institutional interest in the entire sector.
Base case: The December FAR proposed rule lands on schedule. Agencies begin mandatory cryptographic inventory work in Q1 2027 after the next FAR step due around March 2027 clarifies contractor-side expectations for cryptographic vulnerability reporting and related controls. LSCC’s Q3 revenue prints near the midpoint of $255 million guidance. Discovery-tool vendors see steady, not explosive, revenue ramps through mid-2027.
Bear case: The FAR rule slips past December, reducing urgency for contractor spend. Budget friction in the continuing resolution environment delays agency CBOM obligations. LSCC multiple compresses as the broader semiconductor cycle softens, erasing PQC premium.
Positioning Considerations
The CBOM requirement is the least-priced catalyst in the PQC complex because it is procedural rather than headline-generating. That mispricing corrects when agencies publish their October migration plans and the gap between required inventory and actual readiness becomes visible. Traders should monitor the December FAR publication date as the first hard binary event, size positions to account for regulatory slip risk, and treat LSCC’s Q3 earnings report as a near-term read on whether CNSA 2.0 hardware demand is accelerating into year-end. Preparation over speculation. The structural demand is real. The timing is still subject to Washington’s execution pace.
