Skip to content
Compliance & mandatesNIST IR 8547

NIST PQC migration timeline (IR 8547)

Transition to Post-Quantum Cryptography Standards · Initial Public Draft, November 2024

Updated

The term on this page

NISTNational Institute of Standards and Technology
the US agency that ran the competition these algorithms came out of

Also mentioned

RSARSARivest, Shamir and AdlemanA widely used public-key algorithm for encryption and digital signatures whose security relies on the difficulty of factoring large numbers.Read the full entry, ECDSAECDSAElliptic Curve Digital Signature AlgorithmElliptic Curve Digital Signature Algorithm, a widely deployed signature scheme based on elliptic-curve cryptography, offering strong security with compact keys.Read the full entry, ML-KEMML-KEMModule-Lattice-based Key Encapsulation MechanismModule-Lattice-Based Key-Encapsulation Mechanism, the NIST-standardized post-quantum KEM derived from CRYSTALS-Kyber and specified in FIPS 203.Read the full entry, ML-DSAML-DSAModule-Lattice-based Digital Signature AlgorithmModule-Lattice-Based Digital Signature Algorithm, the NIST-standardized post-quantum signature scheme derived from CRYSTALS-Dilithium and specified in FIPS 204.Read the full entry, SLH-DSASLH-DSAStateless Hash-based Digital Signature AlgorithmStateless Hash-Based Digital Signature Algorithm, the NIST-standardized signature scheme derived from SPHINCS+ and specified in FIPS 205.Read the full entry, FIPSFIPSFederal Information Processing StandardFederal Information Processing Standards, publicly announced standards developed by NIST for use in U.S. government computer systems, including cryptographic algorithms and modules.Read the full entry, CNSACNSACommercial National Security Algorithm SuiteThe Commercial National Security Algorithm Suite 2.0, the NSA's mandated algorithm set for US National Security Systems.Read the full entry are defined in the glossary.

NIST IR 8547, *Transition to Post-Quantum Cryptography Standards*, is NIST's own roadmap for retiring the public-key cryptography that a quantum computer will break. Published as an Initial Public Draft in November 2024, it is still a draft at the time of writing, but it is the authoritative signal of NIST's direction, and it puts concrete dates on when RSA, Diffie–Hellman, ECDSA and EdDSA stop being acceptable in U.S. federal systems and the standards that follow them.

Why it matters

The finalized algorithm standards, ML-KEM, ML-DSA and SLH-DSA, tell you what to migrate to. IR 8547 tells you when the classical algorithms you run today become non-compliant, and that timeline is what turns post-quantum migration from an open-ended research project into a dated program of work. It also sharpens the harvest-now-decrypt-later exposure: any data whose confidentiality must survive past 2035 is already at risk, because it can be recorded today and decrypted once the algorithms protecting it are broken.

The transition timeline IR 8547 sets out

IR 8547 treats the quantum-vulnerable public-key families together with the 112-bit classical security-strength tier, and defines two milestones for each. *Deprecated* means the algorithm is still allowed but its use is discouraged and flagged as a risk; *disallowed* means it is no longer permitted at all. The dates are the same across the board:

  • Quantum-vulnerable public-key algorithms (RSA, finite-field and elliptic-curve Diffie-Hellman, ECDSA and EdDSA) are deprecated after 2030 and disallowed after 2035.
  • The 112-bit classical security-strength tier follows the same deprecate-after-2030, disallow-after-2035 schedule.
  • Key establishment moves to ML-KEM (FIPS 203); general-purpose signatures move to ML-DSA (FIPS 204) and SLH-DSA (FIPS 205).
  • Firmware and code signing can use the stateful hash-based schemes LMS and XMSS (SP 800-208).
  • The dates align with CNSA 2.0's 2033 target for national security systems and with the 2035 federal goal behind the federal inventory mandate (OMB M-23-02 / NSM-10).
Pitfall

2035 is the deadline for what's still running, not when to start

"Disallowed after 2035" applies to whatever is still live then, and cryptographic migration across a real estate of applications, protocols and embedded devices takes years, not months. Working backward from 2035 puts the effective planning deadline now. Treat IR 8547 as a draft to track for its final dates, but plan against the numbers it already states. They are unlikely to get more generous.

Planning backward from 2030 and 2035

We turn IR 8547's dates into a plan you can execute. We build the cryptographic inventory that finds every RSA, Diffie–Hellman and ECDSA dependency in scope (audit), sequence the replacements into a dated migration roadmap that lands ahead of the 2030 deprecation (migration), and bring your engineering and compliance teams up to speed on the standards and the deadlines they now answer to (training).

Frequently asked questions

Is NIST IR 8547 a final standard?

No. It was published as an Initial Public Draft in November 2024 and remains a draft at the time of writing. It is not a binding standard on its own, but it is NIST's authoritative statement of the transition timeline, so the practical guidance is to track it for the final publication while planning against the dates it already states.

What is the difference between 'deprecated' and 'disallowed'?

Deprecated means the algorithm is still allowed but its use is discouraged and treated as a risk to be justified and phased out. Disallowed means it is no longer permitted. In IR 8547 the quantum-vulnerable public-key algorithms and the 112-bit security tier are deprecated after 2030 and disallowed after 2035.

Which algorithms are affected, and what replaces them?

RSA, finite-field and elliptic-curve Diffie–Hellman, ECDSA and EdDSA are all in scope. Key establishment moves to ML-KEM (FIPS 203); general-purpose signatures move to ML-DSA (FIPS 204) and SLH-DSA (FIPS 205); and firmware or code signing can use the stateful hash-based schemes LMS and XMSS from SP 800-208.

How does IR 8547 relate to CNSA 2.0 and NSM-10?

They point in the same direction. CNSA 2.0 sets a 2033 target for national security systems, while OMB M-23-02 and NSM-10 drive the federal cryptographic inventory and a 2035 goal for federal systems. IR 8547 supplies the underlying algorithm-level deprecate/disallow schedule those policies rest on.

Work with us on NIST PQC migration timeline (IR 8547)

Related reading

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.