The term on this page
- PQCpost-quantum cryptography
- algorithms that run on ordinary computers and are believed to resist quantum attack
Also mentioned
RSARSARivest, Shamir and AdlemanA widely used public-key algorithm for encryption and digital signatures whose security relies on the difficulty of factoring large numbers.Read the full entry (new tab), ECDHECDHElliptic Curve Diffie-HellmanElliptic Curve Diffie-Hellman, a key-exchange method using elliptic-curve mathematics to establish a shared secret with smaller keys than classical Diffie-Hellman.Read the full entry (new tab), ECDSAECDSAElliptic Curve Digital Signature AlgorithmElliptic Curve Digital Signature Algorithm, a widely deployed signature scheme based on elliptic-curve cryptography, offering strong security with compact keys.Read the full entry (new tab), NISTNISTNational Institute of Standards and TechnologyThe U.S. National Institute of Standards and Technology, the agency that develops and publishes cryptographic standards, including the FIPS series and post-quantum algorithms.Read the full entry (new tab), CNSACNSACommercial National Security Algorithm SuiteThe Commercial National Security Algorithm Suite 2.0, the NSA's mandated algorithm set for US National Security Systems.Read the full entry (new tab) are defined in the glossary.
Read this first
Nothing on this page depends on when a quantum computer arrives. These are calendar dates already written into standards and regulation, and the earliest of them is 2030. Two of them, NIS2 and DORA, are in force now and ask for governance rather than algorithms. If you only take one thing: the first obligation in almost every column is an inventory, and that is work you can start this quarter.
| Mandate | Applies to | Key dates | What it obliges |
|---|---|---|---|
| NIST IR 8547 | US federal baseline, cited far beyond it | Deprecated after 2030, disallowed after 2035 | Retire quantum-vulnerable public-key cryptography and the 112-bit security tier, which includes RSA-2048 and ECDSA P-256 as commonly deployed. Still an initial public draft. |
| CNSA 2.0 | US national-security systems and their vendors | Firmware and software signing exclusive by 2030; everything else by 2033 | Exclusive use of ML-KEM-1024 and ML-DSA-87. Staged by system class, so the 2030 wave is narrower than it looks, and there is no hybrid requirement. |
| NSM-10 and OMB M-23-02 | US federal agencies | Inventory annually; mitigate by 2035 | A prioritised cryptographic inventory of high-impact systems, submitted and kept current. The inventory is the obligation, and it recurs. |
| NIS2 | EU essential and important entities, 18 sectors | In force; transposition was due 17 October 2024 | Risk-appropriate cryptography as a governance duty, enforced through national law. Names no algorithm and sets no PQC date of its own. |
| DORA | EU financial entities and their critical ICT providers | Applies from 17 January 2025 | Directly applicable, no transposition. The RTS make cryptographic controls and key management examinable, and crypto-agility is the expectation behind them. |
| ISO 27001 A.8.24 | Anyone holding or seeking certification | Continuous, at every audit | A cryptographic-controls policy and key-lifecycle management. Standard-agnostic, which is exactly why auditors use it as the hook to ask about quantum risk. |
None of these dates moved on September 3, 2026, when CISA and the G7 Cyber Security Working Group (joined by the UK, France, Germany, Canada, Japan and Italy's national cyber agencies) published a joint call to action on post-quantum migration. It sets no new deadline of its own. What it does is put seven governments' names on the same page saying the transition can no longer be postponed, which matters most for anyone still treating one of the columns below as a single jurisdiction's problem.
Which one binds you first
The dates in the table are not equally urgent, because they oblige different things. Two of the six are live today and ask for governance you can be audited on this year; the rest are calendar deadlines for engineering work that takes years.
- If you are an EU financial entity, DORA is already applying to you and is the one with a supervisor attached. Start there, not with 2035.
- If you are EU critical infrastructure, NIS2 is in force through your national transposition, and the cryptography duty is written as risk management rather than as an algorithm list.
- If you hold ISO 27001, A.8.24 is where the question arrives, at your next audit, whether or not you have a post-quantum programme.
- If you sell to US national-security systems, CNSA 2.0's 2030 firmware and software signing wave is the earliest hard technical date on this page, and signing keys have long lead times.
- Everyone else is working to IR 8547's 2030 and 2035, which is the pair most other guidance now cites.
The deadline that is not on this page
None of these dates is when the risk starts. Data captured today under RSA or ECDH can be decrypted the day a cryptographically-relevant quantum computer exists, so for anything with a long confidentiality requirement the exposure began whenever you first sent it. That is the harvest-now-decrypt-later problem, and Mosca's theorem is the arithmetic for deciding whether it already applies to you. A mandate deadline tells you when someone will ask; it does not tell you when you needed to have started.
What to do with this
In every column above, the first real obligation is knowing what cryptography you run. Not one of these mandates can be answered from a spreadsheet of applications; they need an inventory at the level of algorithms, key sizes and where the keys live. That is the work to start now, because it is the input to all six and the longest pole in any of them. Our cryptographic inventory guide covers the method, and qScan produces the machine-readable version.
Do not plan to the last date
2035 is when quantum-vulnerable cryptography is disallowed, not when a sensible migration finishes. A serious enterprise migration is rarely under five years, and every one of these mandates expects evidence of progress well before its own deadline rather than a single cutover at the end.
Frequently asked questions
Which post-quantum deadline is the earliest?
2030, and it appears twice for different reasons. NIST IR 8547 deprecates quantum-vulnerable public-key cryptography after 2030, and CNSA 2.0 requires exclusive post-quantum use for software and firmware signing by 2030. NIS2, DORA and ISO 27001 A.8.24 are already in force, but they impose governance duties rather than a dated algorithm change.
Is the CNSA 2.0 deadline 2030 or 2033?
Both, for different system classes. CNSA 2.0 is staged: software and firmware signing must be exclusively post-quantum by 2030, while web browsers and servers, cloud services, operating systems and networking equipment reach exclusive use by 2033. Quoting a single CNSA 2.0 date without saying which wave it refers to is the most common error made about it.
Do NIS2 and DORA set a post-quantum deadline?
Neither sets a dated post-quantum requirement of its own. Both make cryptographic risk management and key management examinable obligations that are in force now, which in practice means a supervisor can ask what your plan is before any NIST date arrives.
What does 'deprecated' mean in IR 8547, as opposed to 'disallowed'?
Deprecated after 2030 means the algorithm may still be used but is no longer recommended and carries documented risk. Disallowed after 2035 means it must not be used at all. The gap between the two is the migration window the document is describing.
These are US and EU mandates. What if I am elsewhere?
Most national programmes cite or track these. Australia's ASD is more aggressive, recommending an end to traditional asymmetric cryptography by the end of 2030. In practice, if you sell into regulated US or EU markets, the strictest applicable mandate sets your timeline regardless of where you are incorporated.