PQC deadlines Β· global

How Exposed Are You Today and Will You Make the Deadline?

Global PQC deadlines are set β€” but the algorithms aren't converging. CNSA 2.0 compliance starts in 2027. Most nations target 2035 for full migration. China has announced independent standards on different mathematics, targeting 2029. Organizations with cross-jurisdictional exposure face migration tracks with varied algorithm requirements. The timeline below helps show you who expects what and when. [PQ]probe tells you if you're getting closer or further away.

In effect Ahead 27 of 27 deadlines
2025
PCI PCI DSS 4.0 March IN EFFECT
Crypto inventory mandatory
πŸ‡ΊπŸ‡Έ United States December IN EFFECT
CNSA 1.0 baseline cutoff; CNSSP-15 update incorporates CNSA 2.0
πŸ‡°πŸ‡· South Korea IN EFFECT
Pilot transition begins, 2025–2028 (energy, healthcare, administration)
2026
Today Β· Sep 2026
πŸ‡ΊπŸ‡Έ United States September IN EFFECT
FIPS 140-2 certificates moved to Historical; new federal procurement requires FIPS 140-3 validated modules
πŸ‡ͺπŸ‡Ί European Union December
PQC roadmap defined; planning for high/medium-risk use cases underway
2027
πŸ‡ΊπŸ‡Έ United States January
All new NSS acquisitions must be CNSA 2.0 compliant
2029
πŸ‡¨πŸ‡³ China
National PQC standards expected (structureless lattice; finance & energy priority)
🏒 Google VENDOR
Internal PQC migration complete (vendor commitment, not regulatory deadline)
🏒 Cloudflare VENDOR
Full post-quantum security including authentication (vendor commitment, matching Google)
2030
πŸ‡ΊπŸ‡Έ United States
NIST IR 8547 (draft): RSA, ECDSA, ECDH and DH at 112-bit strength deprecated
πŸ‡ΊπŸ‡Έ United States
All NSS software/firmware using PQC signatures
πŸ‡ΊπŸ‡Έ United States December
Federal HVAs & high-impact systems: PQC for key establishment (EO 14412)
πŸ‡¦πŸ‡Ί Australia
Classical public-key crypto eliminated
πŸ‡ͺπŸ‡Ί European Union December
Critical infrastructure fully PQC compliant
πŸ‡©πŸ‡ͺ Germany December
Classical encryption deprecated for high-sensitivity (standalone)
2031
πŸ‡ΊπŸ‡Έ United States December
Federal HVAs & high-impact systems: PQC for digital signatures (EO 14412)
πŸ‡©πŸ‡ͺ Germany December
Classical encryption deprecated for general use (standalone)
2033
🏒 Microsoft VENDOR
Quantum Safe Program: full transition complete (vendor commitment)
2034
G7 G7 Financial
Financial sector fully PQC compliant
2035
πŸ‡ΊπŸ‡Έ United States
Pure PQC (no hybrid) for National Security Systems
πŸ‡ΊπŸ‡Έ United States
NIST IR 8547 (draft): all quantum-vulnerable public-key algorithms disallowed
πŸ‡¬πŸ‡§ United Kingdom
Full PQC migration complete
πŸ‡©πŸ‡ͺ Germany
Classical signatures deprecated (standalone)
πŸ‡ͺπŸ‡Ί European Union
All remaining systems migrated
πŸ‡¨πŸ‡¦ Canada
Non-classified IT complete
πŸ‡―πŸ‡΅ Japan
Full PQC transition
πŸ‡°πŸ‡· South Korea
Full PQC transition

The deadlines above are fixed. The frameworks below spell out the details. [PQ]probe tracks whether you're improving, degrading, or stable over timeβ€”so you know if you're closing the gap or falling behind.

United States (NSA CNSA 2.0)

DeadlineRequirement
Aug 2024NIST releases final PQC standards (ML-KEM, ML-DSA, SLH-DSA)
Dec 2025CNSA 1.0 baseline cutoff; CNSSP-15 update incorporates CNSA 2.0
Jan 2027All new NSS acquisitions must be CNSA 2.0 compliant
Jan 2030All NSS software/firmware using PQC signatures; TLS 1.3 required
2033Final mandatory compliance for most system types
2035Pure PQC (no hybrid) required for National Security Systems
Targeting CNSA 2.0 compliance? Track your trajectory β†’

United States Civilian (Executive Order 14412)

DeadlineRequirement
Jun 2026EO 14412 "Securing the Nation Against Advanced Cryptographic Attacks" signed; NSS carved out and remain on CNSA 2.0
Dec 2030Federal high value assets & high impact systems using PQC for key establishment
Dec 2030Covered federal contractors must meet NIST PQC FIPS (proposed FAR rule)
Dec 2031Federal high value assets & high impact systems using PQC for digital signatures
Measuring against the federal deadline? Track your trajectory β†’

United States Civilian (NIST IR 8547, draft)

DeadlineRequirement
Nov 2024Initial public draft published; comment period closed Feb 2025. Not yet final as of 2026 β€” treat dates as the working baseline
2030Quantum-vulnerable public-key algorithms at 112-bit security (RSA-2048, ECDSA/ECDH P-256, DH-2048) deprecated
2035All quantum-vulnerable public-key algorithms disallowed, including RSA-3072 and P-384. Hybrid PQC + classical modes remain allowed
Still on RSA-2048 or P-256? See where it lives β†’

European Union

DeadlineRequirement
Dec 2026PQC roadmap defined; planning for high/medium-risk use cases underway
Dec 2030Critical infrastructure fully PQC compliant
2035All remaining systems migrated
Need to demonstrate progress to regulators? See your trend data β†’

G7 Financial Sector

PhaseTimelineActivity
Awareness2025-2027Quantum threat awareness, critical system mapping
Inventory2025-2028Full systems inventory with third-party dependencies
Migration Start2026-2029Begin migration for all systems
Critical Systems2030-2032Complete critical system migration
Full Compliance2034All financial sector PQC compliant
Board asking about quantum preparedness? Get trajectory reports β†’

National Timelines

CountryAgencyKey deadlineRequirement
πŸ‡¬πŸ‡§ United KingdomNCSC2028Define migration goals, full discovery, initial plan
πŸ‡¬πŸ‡§ United KingdomNCSC2031Carry out highest-priority migration activities
πŸ‡¬πŸ‡§ United KingdomNCSC2035Full migration complete
πŸ‡©πŸ‡ͺ GermanyBSI2030Classical encryption deprecated for high-sensitivity (standalone)
πŸ‡©πŸ‡ͺ GermanyBSI2031Classical encryption deprecated for general use (standalone)
πŸ‡©πŸ‡ͺ GermanyBSI2035Classical signatures deprecated (standalone)
πŸ‡¦πŸ‡Ί AustraliaASD2030Eliminate classical public-key crypto
πŸ‡¨πŸ‡¦ CanadaCCCS2031High-priority systems migrated
πŸ‡¨πŸ‡¦ CanadaCCCS2035Complete PQC transition for non-classified IT
πŸ‡―πŸ‡΅ JapanCRYPTREC2035Full PQC transition (aligning with US/EU)
πŸ‡°πŸ‡· South KoreaKISA/NIS2035Complete PQC transition (includes KpqC domestic algorithms)
πŸ‡¨πŸ‡³ ChinaTC2602029National PQC standards expected (structureless lattice algorithms; finance & energy priority sectors)
πŸ‡¨πŸ‡³ ChinaTC260TBDFull migration timeline not yet announced

Regulatory Mandates (Already In Effect)

RegulationEffectivePQC-relevant requirement
PCI DSS 4.0Mar 2025Annual crypto inventory + cipher review (Req 12.3.3)
NIS2 Directive (EU)Oct 2024Cybersecurity risk management across 18 critical sectors
DORA (EU)Jan 2025"Robust cryptographic controls" for financial entities
OMB M-23-02 (US)2023Federal agencies must inventory crypto systems
FIPS 140-2 sunset (US)Sep 2026CMVP moves remaining FIPS 140-2 certificates to Historical; only FIPS 140-3 modules for new federal procurement

National Agency Algorithm Recommendations

AgencyDigital signaturesKey encapsulation
NIST (US)ML-DSA, SLH-DSAML-KEM (HQC coming)
NSA (US)ML-DSA, SLH-DSA, LMSML-KEM
BSI (DE)SLH-DSA, ML-DSA L3/L5, LMS/XMSSML-KEM
ANSSI (FR)ML-DSA, FN-DSA L3/L5, SLH-DSAML-KEM
NCSC (UK)ML-DSA-65, SLH-DSA, LMS/XMSSML-KEM
CRYPTREC (JP)ML-DSA, SLH-DSAML-KEM
KISA (KR)ML-DSA, SLH-DSA + KpqC (domestic)ML-KEM + KpqC (domestic)
TC260 (CN)TBD (structureless lattice candidates)TBD (S-Cloud+ candidate)

Official sources

NIST IR 8547: Transition to Post-Quantum Cryptography Standards NSA CNSA 2.0 Post-Quantum Cybersecurity Resources White House: EO 14412 "Securing the Nation Against Advanced Cryptographic Attacks" (Cloudflare summary) EU Coordinated Implementation Roadmap for PQC Germany BSI: TR-02102 Cryptographic Mechanisms G7 Cyber Expert Group: Quantum Readiness Roadmap (PDF) UK NCSC: Timelines for Migration to Post-Quantum Cryptography Australia ASD: Planning for Post-Quantum Cryptography Canada CCCS: Roadmap for PQC Migration (ITSM.40.001) PCI Security Standards Council: PCI DSS Europol: Post-Quantum Cryptography Report (PDF) Japan CRYPTREC: Cryptography Research and Evaluation Committees Korea KISA: Korea Internet & Security Agency China ICCSC: Global Call for Post-Quantum Algorithm Proposals

Will you hit these dates at your current pace?

Every probe adds to your history. [PQ]probe projects your rate of change onto the deadlines above.