← Q-Day

Policy & Standards

Post-Quantum Deadlines 2026–2035: Who Has to Act, and When

qdayiscoming.com · October 2026

Timeline from 2026 to 2035 with one row each for US federal agencies, US contractors, US national security systems, EU member states, the UK NCSC and NIST. Most hard dates cluster at the end of 2030, the end of 2031 and 2035.

Who is bound by which date. Filled dots are dates that are set; open diamonds are proposals or drafts.

Post-quantum deadlines depend on who you are. US federal agencies must move their most important systems to quantum-safe key exchange by 31 December 2030 and to quantum-safe signatures by 31 December 2031, new purchases for US national security systems must comply from 1 January 2027, the EU wants critical infrastructure protected by the end of 2030, and US and UK guidance points to 2035 for everything else.

Post-quantum cryptography (PQC) means encryption methods designed to withstand a future quantum computer. This page lists the dates that are actually written down, who they bind, and which ones are still a draft.

A deadline is not a prediction

A deadline says when someone must be ready. It says nothing about when a quantum computer that can break today's encryption will exist. Think of a building code. A city can require sprinklers by a certain year without predicting a fire in that year.

The governments behind these dates say so themselves. The White House budget office writes: "A CRQC is not yet known to exist, but steady advancements in the quantum computing field may yield a CRQC in the coming decade." A CRQC is a cryptographically relevant quantum computer: one strong enough to break real-world encryption. The NSA is blunter: "NSA does not know when there will be a CRQC." For expert estimates of when that could happen, see our Q-Day countdown and the Q-Day timeline.

US federal agencies: a plan first, then 2030 and 2031

On 22 June 2026 the US president signed Executive Order 14412. Two days later the Office of Management and Budget (OMB) turned it into instructions in memorandum M-26-15.

Step one is paperwork. Every agency must send OMB and the National Cyber Director a PQC migration plan "no later than 120 days" after the memo. That is 22 October 2026.

Step two is the real work. Two groups of systems go first. "High value assets" are systems formally designated as such. "High impact" systems are rated "high" on confidentiality, integrity or availability. Both must use PQC for key establishment by 31 December 2030. Key establishment is how two computers agree on a secret key. They must use PQC for digital signatures by 31 December 2031. Signatures prove who sent a message or a software update. The memo places all remaining systems in a final phase that ends in 2035.

Two smaller items sit along the way. Agencies must support TLS 1.3, the modern version of the protocol behind the padlock in your browser, no later than 2 January 2030. And systems holding data "expected to remain mission-sensitive in 2030" belong on the priority list. That is the harvest now, decrypt later logic: data copied today can be read once the machine exists.

None of this applies to national security systems. Those follow the NSA.

Companies that sell to the US government: 2030, rule not yet final

The order also reaches suppliers. Within 180 days, so by 19 December 2026, the Federal Acquisition Regulatory Council must publish a proposed rule. It must require "covered contractors to comply by December 31, 2030, with NIST's FIPS, including all applicable FIPS incorporating PQC compliant algorithms." FIPS are the US government's official security standards.

Note the word "proposed". Until the rule is final, nobody knows exactly which contractors count as "covered". Suppliers will feel it earlier through purchasing, though. M-26-15 tells agencies to make sure their requirements for products in the categories listed by CISA, the US cybersecurity agency, "include PQC integration".

Defence and national security suppliers: 1 January 2027

National security systems (NSS) are US government systems that protect national security information. Their rules come from the NSA, through a set of approved algorithms called CNSA 2.0. The NSA's CNSA 2.0 FAQ (version 2.1, December 2024) gives four dates:

1 January 2027: "all new acquisitions for NSS will be required to be CNSA 2.0 compliant unless otherwise noted."
31 December 2030: equipment and services that cannot support CNSA 2.0 must be phased out.
31 December 2031: CNSA 2.0 algorithms become mandatory.
2035: all national security systems quantum-resistant, the goal of National Security Memorandum 10.

The NSA aims this at system owners and their vendors. It writes that it is not using these requirements "to dictate to any other entity outside of NSS" which algorithms to use. More background: NSA's CNSA 2.0.

The EU: start by end 2026, critical infrastructure by end 2030

In June 2025 the EU member states, supported by the European Commission, published a coordinated roadmap. The Commission's announcement gives two dates: "All Member States should start transitioning to post-quantum cryptography by the end of 2026." And: "the protection of critical infrastructures should be transitioned to PQC as soon as possible, no later than by the end of 2030."

Two things stand out. The verb is "should", not "must". And the announcement does not say which organisations count as critical infrastructure in each country.

The UK: 2028, 2031, 2035 as advice

The UK's National Cyber Security Centre (NCSC) set out three target dates in March 2025. It calls them "indicative timelines". By 2028: finish discovery, meaning find out where you use vulnerable cryptography, and draw up a first plan. By 2031: complete the highest-priority migrations. By 2035: complete the migration of "all your systems, services and products".

The NCSC writes mainly for large organisations, operators of critical national infrastructure and companies with bespoke IT.

The algorithms themselves: NIST's 2030 and 2035, still a draft

Behind the US dates sits a NIST report, IR 8547. In it, NIST proposes that RSA, elliptic-curve and similar algorithms at 112-bit security strength become "deprecated" after 2030. All of them, at every strength, become "disallowed" after 2035. Deprecated means you may still use them, but you carry the risk. Disallowed means they are no longer allowed.

IR 8547 is still the initial public draft from November 2024. NIST's publication list shows it as "Draft". Yet M-26-15 already tells agencies to align their plans with it.

All dates in one table

DateWhoWhat
22 Oct 2026US federal agenciesSubmit PQC migration plan
19 Dec 2026US FAR CouncilPublish proposed rule for contractors
End 2026EU member statesStart the transition ("should")
1 Jan 2027US national security systemsNew acquisitions CNSA 2.0 compliant
2028UK organisations (advice)Discovery done, first plan
2 Jan 2030US federal agenciesSupport TLS 1.3
31 Dec 2030US agencies, priority systemsPQC for key establishment
31 Dec 2030US contractors (proposed)Comply with FIPS, including PQC
31 Dec 2030US national security systemsPhase out equipment without CNSA 2.0
End 2030EU critical infrastructureTransitioned to PQC ("should")
After 2030NIST (draft)112-bit RSA and elliptic curves deprecated
31 Dec 2031US agencies, priority systemsPQC for digital signatures
31 Dec 2031US national security systemsCNSA 2.0 mandatory
2031UK organisations (advice)Highest-priority migrations done
2035US agencies, US national security, UKEverything else migrated
After 2035NIST (draft)Quantum-vulnerable algorithms disallowed

What this means if you are not a government

No date on this page binds an ordinary person. There is nothing to file. For small businesses that use standard browsers, operating systems and phones, the NCSC expects the switch "should happen seamlessly, as services are updated by their vendors." Keeping your software up to date covers that part.

For organisations it is different. If you sell to the US government or to defence, or run critical infrastructure in the EU, these dates reach you through contracts and regulators. The first step is the same everywhere: find out where you use RSA and elliptic-curve cryptography. Our Y2Q migration guide walks through it.

What we don't know

Four things are open. Which contractors the final US rule will cover. Whether NIST keeps 2030 and 2035 when it finalises IR 8547. How EU countries will define critical infrastructure for this roadmap. And the biggest one: when a quantum computer that can break RSA will actually exist. Nobody who set these deadlines claims to know.

Sources