Read this first
Nothing on this page depends on when a quantum computer arrives. These are calendar dates already written into standards and regulation, and the earliest of them is 2030. Two of them, NIS2 and DORA, are in force now and ask for governance rather than algorithms. If you only take one thing: the first obligation in almost every column is an inventory, and that is work you can start this quarter.
| Mandate | Applies to | Key dates | What it obliges |
|---|---|---|---|
| NIST IR 8547 | US federal baseline, cited far beyond it | Deprecated after 2030, disallowed after 2035 | Retire quantum-vulnerable public-key cryptography and the 112-bit security tier, which includes RSA-2048 and ECDSA P-256 as commonly deployed. Still an initial public draft. |
| CNSA 2.0 | US national-security systems and their vendors | Firmware and software signing exclusive by 2030; everything else by 2033 | Exclusive use of ML-KEM-1024 and ML-DSA-87. Staged by system class, so the 2030 wave is narrower than it looks, and there is no hybrid requirement. |
| NSM-10 and OMB M-23-02 | US federal agencies | Inventory annually; mitigate by 2035 | A prioritised cryptographic inventory of high-impact systems, submitted and kept current. The inventory is the obligation, and it recurs. |
| NIS2 | EU essential and important entities, 18 sectors | In force; transposition was due 17 October 2024 | Risk-appropriate cryptography as a governance duty, enforced through national law. Names no algorithm and sets no PQC date of its own. |
| DORA | EU financial entities and their critical ICT providers | Applies from 17 January 2025 | Directly applicable, no transposition. The RTS make cryptographic controls and key management examinable, and crypto-agility is the expectation behind them. |
| ISO 27001 A.8.24 | Anyone holding or seeking certification | Continuous, at every audit | A cryptographic-controls policy and key-lifecycle management. Standard-agnostic, which is exactly why auditors use it as the hook to ask about quantum risk. |
Which one binds you first
The dates in the table are not equally urgent, because they oblige different things. Two of the six are live today and ask for governance you can be audited on this year; the rest are calendar deadlines for engineering work that takes years.
- If you are an EU financial entity, DORA is already applying to you and is the one with a supervisor attached. Start there, not with 2035.
- If you are EU critical infrastructure, NIS2 is in force through your national transposition, and the cryptography duty is written as risk management rather than as an algorithm list.
- If you hold ISO 27001, A.8.24 is where the question arrives, at your next audit, whether or not you have a post-quantum programme.
- If you sell to US national-security systems, CNSA 2.0's 2030 firmware and software signing wave is the earliest hard technical date on this page, and signing keys have long lead times.
- Everyone else is working to IR 8547's 2030 and 2035, which is the pair most other guidance now cites.
The deadline that is not on this page
None of these dates is when the risk starts. Data captured today under RSA or ECDH can be decrypted the day a cryptographically-relevant quantum computer exists, so for anything with a long confidentiality requirement the exposure began whenever you first sent it. That is the harvest-now-decrypt-later problem, and Mosca's theorem is the arithmetic for deciding whether it already applies to you. A mandate deadline tells you when someone will ask; it does not tell you when you needed to have started.
What to do with this
In every column above, the first real obligation is knowing what cryptography you run. Not one of these mandates can be answered from a spreadsheet of applications; they need an inventory at the level of algorithms, key sizes and where the keys live. That is the work to start now, because it is the input to all six and the longest pole in any of them. Our cryptographic inventory guide covers the method, and qScan produces the machine-readable version.
Do not plan to the last date
2035 is when quantum-vulnerable cryptography is disallowed, not when a sensible migration finishes. A serious enterprise migration is rarely under five years, and every one of these mandates expects evidence of progress well before its own deadline rather than a single cutover at the end.
Frequently asked questions
Which post-quantum deadline is the earliest?
2030, and it appears twice for different reasons. NIST IR 8547 deprecates quantum-vulnerable public-key cryptography after 2030, and CNSA 2.0 requires exclusive post-quantum use for software and firmware signing by 2030. NIS2, DORA and ISO 27001 A.8.24 are already in force, but they impose governance duties rather than a dated algorithm change.
Is the CNSA 2.0 deadline 2030 or 2033?
Both, for different system classes. CNSA 2.0 is staged: software and firmware signing must be exclusively post-quantum by 2030, while web browsers and servers, cloud services, operating systems and networking equipment reach exclusive use by 2033. Quoting a single CNSA 2.0 date without saying which wave it refers to is the most common error made about it.
Do NIS2 and DORA set a post-quantum deadline?
Neither sets a dated post-quantum requirement of its own. Both make cryptographic risk management and key management examinable obligations that are in force now, which in practice means a supervisor can ask what your plan is before any NIST date arrives.
What does 'deprecated' mean in IR 8547, as opposed to 'disallowed'?
Deprecated after 2030 means the algorithm may still be used but is no longer recommended and carries documented risk. Disallowed after 2035 means it must not be used at all. The gap between the two is the migration window the document is describing.
These are US and EU mandates. What if I am elsewhere?
Most national programmes cite or track these. Australia's ASD is more aggressive, recommending an end to traditional asymmetric cryptography by the end of 2030. In practice, if you sell into regulated US or EU markets, the strictest applicable mandate sets your timeline regardless of where you are incorporated.