Skip to content
All standards
Compliance & mandatesNIST IR 8547

NIST PQC migration timeline (IR 8547)

Transition to Post-Quantum Cryptography Standards · Initial Public Draft, November 2024

Updated

NIST IR 8547, *Transition to Post-Quantum Cryptography Standards*, is NIST's own roadmap for retiring the public-key cryptography that a quantum computer will break. Published as an Initial Public Draft in November 2024, it is still a draft at the time of writing — but it is the authoritative signal of NIST's direction, and it puts concrete dates on when RSA, Diffie–Hellman, ECDSA and EdDSA stop being acceptable in U.S. federal systems and the standards that follow them.

Why it matters

The finalized algorithm standards — ML-KEM, ML-DSA and SLH-DSA — tell you what to migrate to. IR 8547 tells you when the classical algorithms you run today become non-compliant, and that timeline is what turns post-quantum migration from an open-ended research project into a dated program of work. It also sharpens the harvest-now-decrypt-later exposure: any data whose confidentiality must survive past 2035 is already at risk, because it can be recorded today and decrypted once the algorithms protecting it are broken.

The transition timeline IR 8547 sets out

IR 8547 treats the quantum-vulnerable public-key families together with the 112-bit classical security-strength tier, and defines two milestones for each. *Deprecated* means the algorithm is still allowed but its use is discouraged and flagged as a risk; *disallowed* means it is no longer permitted at all. The dates are the same across the board:

  • Quantum-vulnerable public-key algorithms — RSA, finite-field and elliptic-curve Diffie–Hellman, ECDSA and EdDSA — are deprecated after 2030 and disallowed after 2035.
  • The 112-bit classical security-strength tier follows the same deprecate-after-2030, disallow-after-2035 schedule.
  • Key establishment moves to ML-KEM (FIPS 203); general-purpose signatures move to ML-DSA (FIPS 204) and SLH-DSA (FIPS 205).
  • Firmware and code signing can use the stateful hash-based schemes LMS and XMSS (SP 800-208).
  • The dates align with CNSA 2.0's 2033 target for national security systems and with the 2035 federal goal behind the federal inventory mandate (OMB M-23-02 / NSM-10).
Pitfall

2035 is the deadline for what's still running — not when to start

"Disallowed after 2035" applies to whatever is still live then, and cryptographic migration across a real estate of applications, protocols and embedded devices takes years, not months. Working backward from 2035 puts the effective planning deadline now. Treat IR 8547 as a draft to track for its final dates, but plan against the numbers it already states — they are unlikely to get more generous.

How quantakrypto helps

We turn IR 8547's dates into a plan you can execute. We build the cryptographic inventory that finds every RSA, Diffie–Hellman and ECDSA dependency in scope (audit), sequence the replacements into a dated migration roadmap that lands ahead of the 2030 deprecation (migration), and bring your engineering and compliance teams up to speed on the standards and the deadlines they now answer to (training).

Frequently asked questions

Is NIST IR 8547 a final standard?

No. It was published as an Initial Public Draft in November 2024 and remains a draft at the time of writing. It is not a binding standard on its own, but it is NIST's authoritative statement of the transition timeline, so the practical guidance is to track it for the final publication while planning against the dates it already states.

What is the difference between 'deprecated' and 'disallowed'?

Deprecated means the algorithm is still allowed but its use is discouraged and treated as a risk to be justified and phased out. Disallowed means it is no longer permitted. In IR 8547 the quantum-vulnerable public-key algorithms and the 112-bit security tier are deprecated after 2030 and disallowed after 2035.

Which algorithms are affected, and what replaces them?

RSA, finite-field and elliptic-curve Diffie–Hellman, ECDSA and EdDSA are all in scope. Key establishment moves to ML-KEM (FIPS 203); general-purpose signatures move to ML-DSA (FIPS 204) and SLH-DSA (FIPS 205); and firmware or code signing can use the stateful hash-based schemes LMS and XMSS from SP 800-208.

How does IR 8547 relate to CNSA 2.0 and NSM-10?

They point in the same direction. CNSA 2.0 sets a 2033 target for national security systems, while OMB M-23-02 and NSM-10 drive the federal cryptographic inventory and a 2035 goal for federal systems. IR 8547 supplies the underlying algorithm-level deprecate/disallow schedule those policies rest on.

Work with us on NIST PQC migration timeline (IR 8547)

Related reading

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.