Skip to content
All news
News

NIST's 2030 and 2035 deadlines for legacy cryptography

By quantakrypto Research3 min read

The term on this page

NISTNational Institute of Standards and Technology
the US agency that ran the competition these algorithms came out of

Also mentioned

RSARSARivest, Shamir and AdlemanA widely used public-key algorithm for encryption and digital signatures whose security relies on the difficulty of factoring large numbers.Read the full entry (new tab), ECDSAECDSAElliptic Curve Digital Signature AlgorithmElliptic Curve Digital Signature Algorithm, a widely deployed signature scheme based on elliptic-curve cryptography, offering strong security with compact keys.Read the full entry (new tab), ML-KEMML-KEMModule-Lattice-based Key Encapsulation MechanismModule-Lattice-Based Key-Encapsulation Mechanism, the NIST-standardized post-quantum KEM derived from CRYSTALS-Kyber and specified in FIPS 203.Read the full entry (new tab), ML-DSAML-DSAModule-Lattice-based Digital Signature AlgorithmModule-Lattice-Based Digital Signature Algorithm, the NIST-standardized post-quantum signature scheme derived from CRYSTALS-Dilithium and specified in FIPS 204.Read the full entry (new tab), SLH-DSASLH-DSAStateless Hash-based Digital Signature AlgorithmStateless Hash-Based Digital Signature Algorithm, the NIST-standardized signature scheme derived from SPHINCS+ and specified in FIPS 205.Read the full entry (new tab), FIPSFIPSFederal Information Processing StandardFederal Information Processing Standards, publicly announced standards developed by NIST for use in U.S. government computer systems, including cryptographic algorithms and modules.Read the full entry (new tab), CBOMCBOMcryptographic bill of materialsA Cryptographic Bill of Materials, a structured, machine-readable inventory of the cryptographic assets used by a system or application, often expressed as an extension of a software bill of materials (SBOM).Read the full entry (new tab) are defined in the glossary.

TL;DR

Read this first

NIST's IR 8547, Transition to Post-Quantum Cryptography Standards, sets out the timeline for retiring quantum-vulnerable public-key cryptography. The algorithms in near-universal use today, RSA, finite-field and elliptic-curve Diffie-Hellman, ECDSA, and EdDSA, are slated to be deprecated after 2030 and disallowed after 2035. The replacements are the finalized standards: ML-KEM (FIPS 203) for key establishment, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures, alongside the stateful hash-based schemes LMS and XMSS. The point of the dates is to make the migration a schedule, not a someday.

Most post-quantum urgency is argued from the threat: a large enough quantum computer, someday, breaks RSA and elliptic curves. That is true, and the date is unknown, which makes it easy to defer. The more useful pressure is not the threat date. It is the compliance date, and NIST has now written it down. IR 8547 turns an open-ended risk into a calendar.

What the deadlines actually say

The report draws a line at two years. After 2030, the classical public-key algorithms are deprecated, meaning their use is discouraged and carries risk that has to be accepted deliberately. After 2035, they are disallowed, meaning they should not be used at all in the systems the guidance covers. That applies to the primitives that carry essentially all of today's public-key security: RSA, Diffie-Hellman in both its finite-field and elliptic-curve forms, ECDSA, and EdDSA. The named successors are the algorithms NIST finalized in 2024: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures, with LMS and XMSS for the narrower stateful-signature cases.

It is worth being precise that IR 8547 is guidance describing NIST's expected approach, not a self-executing law, and the current document is a public draft. But it is the reference every downstream mandate, procurement rule, and auditor will point at, which makes the 2030 and 2035 dates the planning horizon in practice whether or not they bind you directly. The mandates that do bind, and their own dates, are collected on one deadlines page.

Why a 2035 deadline is a today problem

Ten years sounds like room to wait. It is not, for two reasons. The first is harvest-now-decrypt-later: data with a confidentiality lifetime that runs past the moment a quantum computer arrives is effectively exposed the day it is captured, not the day it is decrypted, so anything you need secret into the 2030s is already on the clock. The second is that migrations of this size are measured in years, not sprints. You have to discover every place the doomed algorithms live, across code, dependencies, protocols, certificates, and hardware, prioritize by risk, replace, and validate, often in systems you cannot take offline. Working backwards from disallow-after-2035, with multi-year programs and long-lived data, the honest start date is now.

TL;DR

The point

The value of IR 8547 is not that it reveals a new threat. It is that it converts an unknowable threat date into a fixed pair of compliance dates, deprecate after 2030, disallow after 2035, that you can actually plan against. A deadline you can schedule beats a risk you can defer.

So treat the dates as a backward-planning anchor, not a countdown to watch. The first move is not to buy an algorithm; it is to find out where RSA, ECDSA, and Diffie-Hellman actually run in your systems, because nothing gets retired until it is on a list. That inventory is a cryptographic bill of materials, and it is the step every framework, NIST's included, puts first. We build one at the start of every audit for exactly that reason.

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.