Guidance

Commonly repeated, and wrong.

Every entry on this page was checked against its source on or after 2026-08-09

Each of these circulates widely, including in vendor material and in summaries of the very documents they misdescribe. None survives a check against the source. They are listed here for the same reason we keep them in the codebase: they are easy to reintroduce by accident.

This page argues with documents, not with companies, and names none.

  1. Commonly stated

    ECC-256 / P-256 is deprecated after 2030.

    What the source says

    P-256 is 128-bit strength, so the IR 8547 draft disallows it only after 2035. The 2030 deprecation applies to 112-bit parameters — RSA-2048 and P-224.

    Source NIST, IR 8547 (Initial Public Draft), Tables 1 and 2 Checked 2026-08-09

  2. Commonly stated

    NIST IR 8547 is a final standard that requires migration by 2035.

    What the source says

    IR 8547 and SP 800-131A Rev. 3 are both still initial public drafts. The IR 8547 comment period closed on 10 January 2025 and no final version has been published. A draft is not a requirement.

    Source NIST, IR 8547 (Initial Public Draft) Checked 2026-08-09

  3. Commonly stated

    There are five final NIST post-quantum standards.

    What the source says

    Three: FIPS 203, 204 and 205. HQC was selected for standardisation in March 2025 but no FIPS has been published for it, and FN-DSA (FIPS 206) has not been published even as a draft.

    Source NIST, NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption , 11 March 2025 Checked 2026-08-09

  4. Commonly stated

    The EU requires Member States to begin post-quantum migration by the end of 2026.

    What the source says

    The NIS Cooperation Group roadmap is a coordinated recommendation, not law. No post-quantum deadline is written into the NIS2 Directive itself.

    Source NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025 Checked 2026-08-09

  5. Commonly stated

    The UK NCSC requires critical organisations to complete migration by 2035.

    What the source says

    NCSC publishes guidance and calls its dates indicative timelines that organisations "should work towards". It requires nothing.

    Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09

  6. Commonly stated

    Canada requires federal departments to have a migration plan by April 2026.

    What the source says

    ITSM.40.001 recommends those milestones. It states that Treasury Board Secretariat will issue the policy instruments needed to require them — so at the time of writing they are not yet mandatory.

    Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09

  7. Commonly stated

    FINMA requires Swiss institutions to have a post-quantum roadmap by 2027.

    What the source says

    The German original reads "legt … nahe" — suggests — in a chapter headed Empfehlungen, and concerns producing a roadmap, not completing a migration.

    Source FINMA Guidance 05/2026, Quantum computing , 9 July 2026 Checked 2026-08-13

  8. Commonly stated

    Switzerland has a binding post-quantum mandate.

    What the source says

    It does not. The Federal Council has stated twice on the record that binding timetables cannot yet be defined, and nothing from the SNB, SIX/SIC, the EPD framework, the EDÖB or BAKOM imposes one. The EU roadmap does not bind Switzerland either.

    Source FINMA Guidance 05/2026, Quantum computing , 9 July 2026 Checked 2026-08-13

  9. Commonly stated

    SIX requires Swiss banks to migrate.

    What the source says

    Its published activity concerns its own HSM and infrastructure refresh, not an obligation on participants.

    Source SIX Group, published infrastructure communications Checked 2026-08-09

  10. Commonly stated

    The CA/Browser Forum has adopted post-quantum algorithms for TLS certificates.

    What the source says

    For S/MIME only — Ballot SMC013, effective 22 August 2025. There is no publicly-trusted TLS certificate ballot.

    Source CA/Browser Forum, Ballot SMC013 Checked 2026-08-09

← Back to guidance