Post-Quantum Cryptography Now Has Deadlines
For most of the past decade, post-quantum cryptography lived in planning documents. The United States set a 2035 federal migration target in National Security Memorandum 10 in May 2022 and reinforced it with the Quantum Computing Cybersecurity Preparedness Act that December. NIST finalized the first three post-quantum standards in August 2024. All of it was direction without enforcement.
That changed in the last week of June 2026, when three US documents landed in three days and converted the transition from guidance into obligations with dates attached and procurement consequences behind them. The EU, the UK, Australia, Canada, and Japan set their dates earlier, and much of Asia is moving on the same schedule. This post lays out the full map: what each jurisdiction now requires and by when, with a reference table collecting the dates. It also covers what the research says about why the dates keep moving, and why the practical deadlines arrive years before the ones printed in the documents. It stays at survey level by design; later posts will take individual jurisdictions and the migration mechanics in more depth.
The US mandate: three documents in three days
On June 22, 2026, the President signed Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks.” It replaces the leisurely part of the 2035 posture. Federal agencies must transition their High Value Assets and high-impact systems to NIST-approved post-quantum algorithms for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. A companion order signed the same day, Executive Order 14413, covers quantum research and commercialization policy rather than migration, and sits outside this post’s scope.
Two provisions matter beyond the headline deadlines. Within 180 days, NIST must revise the Cryptographic Module Validation Program’s processes to accelerate validations of cryptographic modules, a direct acknowledgment that FIPS validation throughput is a bottleneck for the whole transition. And within 270 days, CISA and NIST must publish the minimum elements of a cryptographic bill of materials (CBOM), the machine-readable inventory format positioned to do for cryptographic dependencies what SBOMs did for software components.
Two days later, OMB issued the implementing memorandum, M-26-15, “Execution of the Migration to Post-Quantum Cryptography.” Every agency was required to name a PQC migration lead by late July 2026 and owes OMB a full migration plan by late October. The memo sets the phased schedule: inventories and planning through 2027, pilots and early migration through 2028, key establishment migrated through 2030, digital signatures in 2031, and remaining systems by 2035. It directs agencies to fold PQC into cloud migrations, hardware refresh cycles, and software development rather than run it as a standalone program, and it requires systems that cannot support PQC or hybrid cryptography to be identified and prioritized for replacement. National security systems are excluded; they follow NSA’s CNSA 2.0 track, whose category-by-category requirements phase in now and complete by 2033.
The third document is the Department of War Post-Quantum Cryptography Strategy, released June 23 (the administration’s name for the Department of Defense; Congress has not acted on the renaming). It requires every DoW system to support PQC or be phased out by the end of 2030, and to use PQC by the end of 2031. The strategy notes that “nearly every deployed military asset will be affected in some way,” and it commits to extending cryptographic requirements across the defense industrial base, including updates to CMMC. The rulemaking that moves CMMC from NIST SP 800-171 Revision 2 to Revision 3 (RIN 0790-AM01) entered the regulatory agenda in July 2026, and Revision 3’s organization-defined parameters give the department a mechanism that could carry requirements such as PQC into contract clauses ahead of finished rulemaking.
For contractors, the provision with the longest reach sits in the EO’s procurement section. The FAR Council must publish a proposed rule by December 2026 requiring covered contractors to comply with NIST FIPS, including the post-quantum standards, by December 31, 2030. A second proposed rule, due by March 2027, will require vulnerability disclosure policies that cover cryptographic weaknesses, including testing for unencrypted channels and non-FIPS algorithms. FAR clauses flow down from prime contractors to subcontractors and suppliers, so the requirement will reach well beyond direct contract holders. If you sell to anyone who sells to the government, the 2030 date is functionally yours.
If you sell to anyone who sells to the government, the 2030 date is functionally yours.
The standards underneath
Every mandate above points at the same algorithm set. NIST published FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, lattice-based signatures), and FIPS 205 (SLH-DSA, hash-based signatures) in August 2024. NIST’s transition guidance, IR 8547, issued in draft in November 2024 and still in draft as of this writing, schedules the classical algorithms for removal: RSA and elliptic curve cryptography deprecated by 2030 and disallowed by 2035. For any given system the open questions are sequencing and timing. The algorithm set is settled.
The European Union: 2026, 2030, 2035
The European Commission recommended a coordinated transition in April 2024, and in June 2025 the member states, working through the NIS Cooperation Group, published the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. It sets three dates. By the end of 2026, member states start: national strategies, cryptographic inventories, and pilots for high- and medium-risk use cases. By the end of 2030, high-risk use cases and critical infrastructure must be transitioned. By the end of 2035, the migration completes for as many remaining systems as practically feasible.
European guidance leans harder on hybrid deployment than the US documents do: the roadmap recommends standardized, hybrid solutions during the transition, and the ECCG’s Agreed Cryptographic Mechanisms version 2 (May 2025), the cryptographic reference for European Common Criteria certification, does not accept classical primitives such as RSA in quantum-resistant contexts unless combined with a post-quantum mechanism.
The largest member states are more prescriptive than the roadmap. Germany’s BSI recommends hybrid post-quantum deployments in its technical guideline TR-02102-1, and a joint statement from BSI, ANSSI, and other European security agencies sets the end of 2030 as the latest acceptable date for the transitions it prioritizes, with detailed public key infrastructure plans due in the same window. France’s ANSSI has run a three-phase position since 2022: hybrid post-quantum mechanisms as defense in depth now, hybrid mechanisms carrying the post-quantum security claim from the mid-2020s, and standalone post-quantum cryptography probably not before 2030, with hybrid expected for any product protecting information beyond that date. The roadmap also lands in a regulatory environment, alongside NIS2, DORA, and the Cyber Resilience Act, where cryptographic posture is becoming something supervisors examine rather than something engineering teams choose privately.
The United Kingdom: 2028, 2031, 2035
The NCSC published Timelines for Migration to Post-Quantum Cryptography in March 2025, structured as three phases. Through 2028: complete a full discovery of where cryptography is used across the organization and produce a written migration plan. From 2028 to 2031: execute the highest-priority migrations. From 2031 to 2035: complete the transition across systems, services, and products. The detail worth noticing is the discovery deadline. An organization that cannot produce a cryptographic inventory by 2028 is behind the UK schedule regardless of what it has deployed.
Australia and Canada
Australia holds the most aggressive general-purpose date anywhere. The Australian Signals Directorate’s Information Security Manual does not approve RSA, Diffie-Hellman, ECDH, or ECDSA beyond the end of 2030, and it expects any cryptographic equipment, application, or library procured now with a service life past 2030 to support ASD-approved post-quantum algorithms. That is five years ahead of the US and EU disallowance dates, on a deadline that applies to key exchange and signatures alike.
Canada’s Cyber Centre published its roadmap, ITSM.40.001, in June 2025: federal departments owed initial migration plans by April 2026 with annual progress reporting after that, high-priority systems must be migrated by the end of 2031, and everything else by the end of 2035.
Asia
Japan converged on the Western end date in November 2025, when the National Cybersecurity Office (formerly NISC) concluded in an interim report that government agencies must complete their transition to post-quantum cryptography by 2035. The technical groundwork is further along: CRYPTREC, the body that maintains Japan’s approved cipher lists, published its post-quantum cryptography guideline in April 2025, and the Financial Services Agency’s 2024 study group told deposit-taking institutions to begin the transition immediately.
South Korea is running the most sovereign version of the migration. The National Intelligence Service and the Ministry of Science and ICT published a PQC master plan in 2023, ran the KpqC competition to standardize domestic algorithms alongside the NIST set, selected the final four in early 2025, and target a national transition by 2035. MSIT has been converting critical infrastructure sector by sector since 2025, expanding the pilot program to telecommunications, finance, transportation, defense, and space in 2026.
China is the significant outlier: it has published no migration deadline, because it declined to adopt the NIST algorithms and is standardizing its own. In February 2025 the Institute of Commercial Cryptography Standards, under the state cryptography administration, opened a call for next-generation quantum-resistant commercial cryptographic algorithms covering public key schemes, hash functions, and block ciphers. In March 2026, remarks reported by Reuters from the National People’s Congress put national standards roughly three years out, with finance and energy expected to migrate first. Once those standards land, adoption inside China can be expected to run through the commercial cryptography certification regime that already makes the SM algorithm suite effectively mandatory for regulated uses, which would create a second standards track that vendors selling into China would need to support alongside the NIST set.
India published its first national migration document in July 2025, a whitepaper from MeitY and CERT-In titled Transitioning to Quantum Cyber Readiness, which lays out a phased roadmap and directs finance, defense, and healthcare to move first. A national task force followed in early 2026 with recommendations for accelerated critical infrastructure timelines, mandatory cryptographic inventories, and a tiered testing and certification framework. There is no single national deadline yet, but the direction and the procurement implications are set.
Singapore regulates through supervisory expectation rather than a date. MAS circular MAS/TCRS/2024/01, sent to the chief executives of every financial institution in February 2024, directs them to maintain cryptographic inventories, identify priority assets for migration, build crypto-agility, and press vendors for quantum-resistant products. MAS has since run post-quantum and quantum key distribution trials with major banks and with Banque de France.
The UAE stood up one of the first coordinated national migration programs. The Cyber Security Council and the National Cryptography Center run a National Post-Quantum Migration Program, and in May 2026 signed agreements to deploy national cryptographic discovery tooling and a country-level post-quantum readiness index across critical sectors. No deadline has been published; the program itself is the signal.
Outside China, the pattern is consistent: inventory and procurement expectations arrive between now and 2028, and completion dates cluster between 2030 and 2035. China is moving on standards first, dates later.
The deadlines at a glance
| Jurisdiction and scope | Instrument | Dates that matter |
|---|---|---|
| US federal civilian (HVAs, high-impact systems) | EO 14412 and OMB M-26-15 (June 2026) | Key establishment by Dec 31, 2030; signatures by Dec 31, 2031; remaining systems by 2035 |
| US federal contractors | FAR proposed rule (due Dec 2026) | NIST FIPS compliance, including PQC, by Dec 31, 2030 |
| US defense and industrial base | DoW PQC Strategy (June 2026); CMMC updates | Systems support PQC by end of 2030; use PQC by end of 2031 |
| US national security systems | NSA CNSA 2.0 (2022) | Category-by-category requirements completing by 2033 |
| Algorithm lifecycle (US) | NIST IR 8547 | RSA and ECC deprecated by 2030, disallowed by 2035 |
| European Union | NIS Cooperation Group roadmap (June 2025) | Start by end of 2026; high-risk and critical infrastructure by end of 2030; rest by end of 2035 |
| Germany | BSI TR-02102-1; joint European agency statement | Hybrid PQC recommended now; end of 2030 as the latest date for prioritized transitions |
| France | ANSSI position papers (2022, 2023) | Hybrid required for post-quantum claims now; standalone PQC probably not before 2030 |
| United Kingdom | NCSC migration timelines (March 2025) | Discovery and plan by 2028; high-priority migrations by 2031; complete by 2035 |
| Australia | ASD Information Security Manual | RSA, DH, ECDH, ECDSA not approved beyond end of 2030 |
| Canada | Cyber Centre ITSM.40.001 (June 2025) | Plans by April 2026; high-priority systems by end of 2031; complete by end of 2035 |
| Japan | NCO interim report (Nov 2025); CRYPTREC guideline (April 2025) | Government agencies complete transition by 2035 |
| South Korea | NIS and MSIT PQC Master Plan (2023); KpqC standards (2025) | National transition by 2035; sector pilots under way |
| China | ICCS call for next-generation commercial cryptographic algorithms (Feb 2025) | National PQC standards expected within roughly three years; no published migration deadline |
| India | MeitY and CERT-In whitepaper (July 2025); task force recommendations (2026) | Roadmaps and inventories now; no fixed national deadline yet |
| Singapore | MAS advisory MAS/TCRS/2024/01 (Feb 2024) | Cryptographic inventory, prioritization, and crypto-agility expected of financial institutions now |
| UAE | National Post-Quantum Migration Program | Coordinated national migration under way; no published deadline |
The research that moved the dates
The June acceleration in Washington followed a spring in which published estimates of what a cryptographically relevant quantum computer requires fell sharply. On March 25, 2026, Google set 2029 as the target for migrating its own infrastructure to post-quantum cryptography, citing progress in quantum hardware, error correction, and factoring resource estimates. Days later, Google researchers published an analysis indicating that elliptic curve cryptography could be broken with roughly twenty times fewer physical qubits than earlier estimates, with the resource figures detailed in an accompanying whitepaper. The same week, Oratomic, a startup founded by Caltech and Harvard researchers in fault tolerance and neutral-atom hardware, launched with a paper arguing that a cryptographically relevant machine could be built with about ten thousand reconfigurable atomic qubits, against prior estimates near one million.
Hardware roadmaps point the same direction. IBM’s June 2025 roadmap targets Starling, a fault-tolerant system running 100 million quantum operations on roughly 200 logical qubits, for delivery in 2029. Starling is the foundation for Blue Jay, a follow-on system an order of magnitude larger targeted for 2033 and beyond, and IBM publishes the full development roadmap charting each system on that path.
None of this means a cryptographically relevant quantum computer exists, and resource estimates are estimates. But the revisions of the past eighteen months have moved in one direction: fewer qubits required, earlier dates targeted. Practitioners have registered the shift; the cryptography engineer Filippo Valsorda noted in April that the timelines presented at this year’s Real World PQC were materially tighter than those of two years ago. The mandates price that shift in.
Why the dates are closer than they look
A 2030 deadline reads like breathing room. Four things compress it.
First, harvest now, decrypt later is the threat model written into the mandates themselves. EO 14412 opens with it: adversaries can collect encrypted traffic today and decrypt it once a cryptographically relevant quantum computer exists. Any data that must remain confidential into the 2030s and crosses a network today under classical key exchange is already inside the exposure window.
Unlike stolen credentials, harvested ciphertext cannot be rotated, revoked, or recovered. The copies are already out, and the only variable still in play is whether the data loses its value before the capability to read it arrives.
For that class of data, the meaningful deadline passed some time ago.
Second, cryptographic migrations run on decade timescales. AWS’s retrospective on prior transitions notes that retiring SHA-1 took close to twenty years from the first published weakness to browsers rejecting it, and MD5, 3DES, and RC4 followed the same slow arc. Certificate hierarchies renew on multi-year cycles, embedded devices ship with algorithms burned into firmware, and every protocol change drags an interoperability tail. The 2031 signature deadlines are the harder half of the problem: post-quantum key exchange is already deployed at scale on the public internet, while the certificate and code-signing migration has barely started. A peer-reviewed analysis published in December 2025 puts numbers on those timescales:
| Enterprise size | Optimistic | Baseline | Pessimistic | Key assumptions |
|---|---|---|---|---|
| Small | 3-4 years | 5-7 years | 8-10 years | Vendor readiness, SaaS reliance, budget |
| Medium | 6-8 years | 8-12 years | 12-15 years | Hybrid cloud, legacy systems, partners |
| Large | 9-12 years | 12-15 years | 15-20+ years | Global ops, IoT/OT, regulation, supply chain |
Third, private-sector deadlines are moving ahead of public ones. Google and Cloudflare have both set 2029 for their own infrastructure, a year ahead of the federal deadline, and Cloudflare reports that more than two thirds of browser traffic to its network already negotiates post-quantum key exchange, tracked live on Cloudflare Radar. When the companies that terminate a large share of the internet’s TLS run ahead of governments, their customers inherit the earlier dates through defaults and deprecations, not through regulation.
Fourth, procurement arrives before compliance dates. The FAR requirement will surface as contract language in 2027, not in 2030. CMMC’s coming move to a standard built on organization-defined parameters could put PQC requirements into defense contracts ahead of finished rulemaking. AWS reports post-quantum readiness questions already appearing in RFPs and vendor security questionnaires. For anyone selling into government or regulated industries, the operative deadline is the next contract renewal.
What actually has to change
This is worth stating precisely, because over-scoping kills migration programs. The quantum threat applies to asymmetric cryptography: key establishment (RSA, Diffie-Hellman, ECDH) and digital signatures (RSA, ECDSA). Symmetric encryption at adequate key lengths is not the driver, and data at rest under AES-256 does not need re-encryption on quantum grounds. The margin is wider than most guidance implies: Filippo Valsorda makes the detailed case that Grover’s algorithm does not parallelize well enough to threaten even 128-bit symmetric keys, a view most authorities including NIST share, though the settled convention remains 256-bit keys for new systems. The work concentrates where asymmetric cryptography lives: TLS and other protocol handshakes, PKI and certificate infrastructure, code and firmware signing, and key management. Those are also the layers a cryptographic bill of materials will be expected to make visible to auditors once the CISA and NIST guidance lands in 2027.
Some of this comes free. The algorithms are published, and current OpenSSL releases already enable hybrid key exchange by default; what the deadlines actually test is whether an organization knows where its cryptography lives. Nearly every jurisdiction in the table asks for the inventory first, because everything downstream is gated on it: prioritization, procurement answers, and the migration plan itself. An organization with a complete inventory and no migrated systems is in better shape than one with post-quantum TLS at the edge and no idea what sits behind it.
A note on claims, because the market is filling with them. “Quantum-safe” asserted without particulars is not a migration story. Three questions separate substance from labels: which of the NIST algorithms the product implements (FIPS 203, 204, or 205); in which cryptographic module, on what validation path; and in which protocols it actually negotiates them. A real answer names all three. Two patterns deserve particular skepticism. Quantum key distribution offered as a migration is one: it is point-to-point hardware, it does nothing for signatures, and both the NSA and the major European security agencies advise against relying on it for this transition. Proprietary algorithms outside any standardization process are the other. The sovereign tracks are a different matter entirely: South Korea’s KpqC and China’s forthcoming standards are national standards processes, not marketing.
Where the OpenSSL Library stands
The infrastructure half of this transition is further along than the policy coverage suggests. OpenSSL 3.5, a long-term support release shipped in April 2025, includes ML-KEM, ML-DSA, and SLH-DSA, and enables a hybrid X25519MLKEM768 key share by default in TLS 1.3, so current clients and servers negotiate post-quantum key exchange without configuration changes. The FIPS provider based on 3.5, which brings the NIST post-quantum algorithms into the validation pipeline, was submitted to CMVP in October 2025 and is in the review queue. EO 14412’s directive to accelerate CMVP validations is relevant to everyone whose compliance path runs through that queue. Post-quantum work continues in the 4.0 series, including hybrid key exchange groups and signature extensions.
The library is the starting point, not the whole of it. OpenSSL Corporation works directly with customers on the migration itself: planning and executing the move of systems to post-quantum key exchange and, when they are ready, post-quantum signatures; meeting the certificate, validation, and compliance criteria that a given deadline in the table above imposes; and auditing cryptographic estates so the inventory regulators keep asking for actually exists. Where a product ships an OpenSSL-based FIPS module, that work covers the FIPS dimension across the full validation lifecycle.
The roadmap is also wider than FIPS. We are actively researching and working to expand both the post-quantum algorithm coverage in OpenSSL itself and support for government certification regimes beyond FIPS 140-3, including schemes run by authorities such as Germany’s BSI. What gets prioritized is shaped by conversations. OpenSSL is open source: there is no telemetry and no deployment dashboard, and the only way to see where the migration is hurting is to talk to the people running it. Those conversations tell us where to help first and what to build next. If your product terminates TLS in OpenSSL, ships an OpenSSL-based FIPS module, or has a date in the table above attached to it, contact us to see how we can help.
Sources
Government and standards documents
- Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, Federal Register, June 25, 2026
- OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 24, 2026
- Department of War Post-Quantum Cryptography Strategy, June 2026
- RIN 0790-AM01, Cybersecurity Maturity Model Certification Program transition to NIST SP 800-171 Revision 3, Unified Agenda entry, reginfo.gov
- NSA, CNSA 2.0 Algorithms Advisory
- NIST Post-Quantum Cryptography program
- NIST IR 8547, Transition to Post-Quantum Cryptography Standards, initial public draft, November 2024
- European Commission Recommendation (EU) 2024/1101, April 11, 2024
- NIS Cooperation Group, Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, June 23, 2025
- ECCG, Agreed Cryptographic Mechanisms version 2, EUCC Guidelines on Cryptography, May 2025
- BSI, ANSSI, and partner agencies, Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography, joint statement
- ANSSI, Views on the Post-Quantum Cryptography Transition, 2022 position paper and 2023 follow-up
- NCSC, Timelines for Migration to Post-Quantum Cryptography, March 2025
- ASD, Planning for Post-Quantum Cryptography
- Canadian Centre for Cyber Security, ITSM.40.001, Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada, June 2025
- Japan Cabinet Secretariat, interim summary on the government transition to post-quantum cryptography, November 2025 (Japanese only)
- CRYPTREC, Cryptographic Technology Guideline, Post-Quantum Cryptography, 2024 Edition, published April 2025
- South Korea National Intelligence Service and Ministry of Science and ICT, pan-national Post-Quantum Cryptography Transition Master Plan, announced July 2023; the plan document was not publicly released (Korean-language press record)
- China Institute of Commercial Cryptography Standards, announcement of the next-generation commercial cryptographic algorithm call, February 5, 2025 (Chinese only)
- Reuters, China likely to have standards for post-quantum cryptography in 3 years, expert says, March 19, 2026
- MeitY and CERT-In, Transitioning to Quantum Cyber Readiness, whitepaper launch, July 2025
- MAS, Advisory on Addressing the Cybersecurity Risks Associated with Quantum, MAS/TCRS/2024/01, February 2024
- UAE Cyber Security Council and ATRC, national post-quantum security transition agreements, May 2026
Research and first-party industry statements
- Google, Quantum Frontiers May Be Closer Than They Appear, March 25, 2026 (first-party source for Google’s 2029 target)
- Google Research, Safeguarding Cryptocurrency by Disclosing Quantum Vulnerabilities Responsibly, March 2026
- Oratomic, launch announcement, March 2026 and the underlying paper
- IBM, roadmap to IBM Quantum Starling, June 10, 2025
- IBM Quantum Development Roadmap, through 2033 and beyond
- Google Quantum AI, Securing Elliptic Curve Cryptocurrencies against Quantum Vulnerabilities, whitepaper, March 2026
- Cloudflare, post-quantum roadmap update, April 2026 (first-party source for Cloudflare’s 2029 target)
- Cloudflare, The post-quantum EO is an important milestone, June 23, 2026 (first-party source for Cloudflare’s deployment figures)
- AWS Security Blog, The CISO’s guide to post-quantum mandates and migrations, July 8, 2026 (first-party source for the statements attributed to AWS)
- Filippo Valsorda, A Cryptography Engineer’s Perspective on Quantum Computing Timelines, April 2026
- Filippo Valsorda, Quantum Computers Are Not a Threat to 128-bit Symmetric Keys, April 20, 2026
- Cloudflare Radar, Post-Quantum Encryption, live adoption charts
- Institutional Approaches to Post-Quantum Cryptography: A Comparative Analysis of Migration Frameworks, IEEE Access, DOI 10.1109/ACCESS.2025.3650465 (CC BY 4.0)
- Robert Campbell, Enterprise Migration to Post-Quantum Cryptography: Timeline Analysis and Strategic Frameworks, Computers 15(1):9, MDPI, December 2025 (CC BY open access)