Guidance
Migration timelines.
Every entry on this page was checked against its source on or after 2026-08-09
Every authority we have checked, in date order. The badge on each milestone is the part most published timelines lose: whether anyone is actually obliged to meet it — and, for the entries that do not speak for a whole country, how far it reaches.
What the badges mean
- Binding In force, with legal or contractual effect on someone.
- Recommendation Published by an authority. Compels no one.
- Draft Not yet issued in final form.
- Proposed Announced or trailed, not published.
| Jurisdiction | 2026 | 2027 | 2028 | 2029 | 2030 | 2031 | 2032 | 2033 | 2034 | 2035 |
|---|---|---|---|---|---|---|---|---|---|---|
| European Union | European Union, 2030: Transition of high-risk use cases completed | European Union, 2035: Transition of medium-risk use cases completed | ||||||||
| Germany | Germany, 2031: Sole use of classical key agreement no longer recommended after this point | Germany, 2035: Transition to quantum-safe signatures, at the latest | ||||||||
| Switzerland | Switzerland, 2027: Draw up a post-quantum roadmap | |||||||||
| Canton of Bern | ||||||||||
| United States | United States, 2030: Transition to post-quantum key establishment | United States, 2031: Transition to post-quantum signatures | ||||||||
| United Kingdom | United Kingdom, 2028: Define migration goals, complete a full discovery exercise, build an initial plan | United Kingdom, 2031: Carry out the earliest, highest-priority migration activities; refine into a full roadmap | United Kingdom, 2035: Complete migration of all systems, services and products | |||||||
| France | France, 2030: Standalone post-quantum cryptography becomes optional | |||||||||
| Netherlands | ||||||||||
| Canada | Canada, 2031: Migration of high-priority systems completed | Canada, 2035: Migration of remaining systems completed | ||||||||
| Australia | Australia, 2030: RSA, DH, ECDH and ECDSA no longer approved. New equipment must support ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by this point (ISM-1917) |
Almost everything lands on 2030, 2031 or 2035. Australia is the outlier: its approval for RSA, Diffie-Hellman, ECDH and ECDSA ends after 2030, five years before the date most other authorities work towards. A product built to the 2035 consensus is already non-compliant there.
European Union
- Authority
- NIS Cooperation Group
- Document
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1
A coordinated recommendation to Member States, not law. It sets the dates most European sector regulators are now aligning to, which is why it matters more than its legal weight suggests.
- 2030 Recommendation
Transition of high-risk use cases completed
Applies to Member States, for critical infrastructure
Source NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025 Checked 2026-08-09
- 2035 Recommendation
Transition of medium-risk use cases completed
Applies to Member States
Source NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025 Checked 2026-08-09
Germany
- Authority
- BSI
- Document
- Technical Guideline TR-02102-1
Revised each January, which makes it the fastest-moving document on this page. BSI approves a wider algorithm set than NIST does, including FrodoKEM and Classic McEliece.
- 2031 Recommendation
Sole use of classical key agreement no longer recommended after this point
Applies to Systems following TR-02102-1
Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09
- 2035 Recommendation
Transition to quantum-safe signatures, at the latest
Applies to Systems following TR-02102-1
Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09
Switzerland
- Authority
- FINMA
- Document
- FINMA Guidance 05/2026
FINMA supervises the financial market, so this reaches the institutions it supervises and nobody else. The roadmap date is a recommendation — though FINMA also states that the principles-based governance and risk-management rules already binding those institutions cover quantum risk, and that it expects them to engage with it in good time. It sets no algorithm position of its own, citing the NIST standards instead.
- mid-2027 Recommendation
Draw up a post-quantum roadmap
Applies to FINMA-supervised institutions
Source FINMA Guidance 05/2026, Quantum computing , 9 July 2026 Checked 2026-08-13
Canton of Bern
Binds one administration- Document
- ICSGW, Anhang 6 (Kryptographische Verfahren)
A cantonal directive, binding on that canton’s own administration and on no one else. It is here because it permits an algorithm set no other authority on these pages permits, not because it carries national weight.
- 1 January 2025 Binding
Directive in force: only FrodoKEM and Classic McEliece permitted, hybrid operation required
Applies to Canton of Bern administration systems
Source Canton Bern ICSGW, Anhang 6 (Kryptographische Verfahren) , in force 1 January 2025 Checked 2026-08-09
United States
- Authority
- NIST, OMB and NSA
- Document
- FIPS 203/204/205; IR 8547 (draft); EO 14412; OMB M-26-15; CNSA 2.0
The only jurisdiction here with dates that carry legal force, via executive order and OMB memorandum. The widely-cited IR 8547 deprecation dates are still a draft — the binding dates come from EO 14412 and M-26-15.
- 31 December 2030 Binding
Transition to post-quantum key establishment
Applies to Federal high-impact systems
Source Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (91 FR 38483); OMB M-26-15 , 22 and 24 June 2026 Checked 2026-08-09
- 31 December 2031 Binding
Transition to post-quantum signatures
Applies to Federal high-impact systems
Source Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (91 FR 38483); OMB M-26-15 , 22 and 24 June 2026 Checked 2026-08-09
- after 2030 Draft
Quantum-vulnerable public-key algorithms deprecated; disallowed after 2035
Applies to Federal information systems, once final
Source NIST, IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards , November 2024 — still a draft, comments closed 10 January 2025 Checked 2026-08-09
United Kingdom
- Authority
- NCSC
- Document
- Timelines for migration to post-quantum cryptography
The clearest three-step framing published by any authority, and explicitly indicative. NCSC aims it at large organisations, operators of critical national infrastructure, and anyone running bespoke systems.
- 2028 Recommendation
Define migration goals, complete a full discovery exercise, build an initial plan
Applies to Large organisations and CNI operators
Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09
- 2031 Recommendation
Carry out the earliest, highest-priority migration activities; refine into a full roadmap
Applies to Large organisations and CNI operators
Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09
- 2035 Recommendation
Complete migration of all systems, services and products
Applies to Large organisations and CNI operators
Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09
France
- Authority
- ANSSI
- Document
- Views on the Post-Quantum Cryptography transition
Structured as phases rather than deadlines, and the strongest position on hybridisation of any authority here: hybrid operation is mandatory through phases 1 and 2, not merely advised.
- phase 1, now Recommendation
Classical security mandatory, post-quantum optional and claimed as defence in depth only
Applies to Security products seeking ANSSI approval
Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09
- phase 2, not before 2025 Recommendation
Post-quantum mechanisms must be hybrid, except hash-based signatures; quantum resistance may be claimed
Applies to Security products seeking ANSSI approval
Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09
- phase 3, probably not before 2030 Recommendation
Standalone post-quantum cryptography becomes optional
Applies to Security products seeking ANSSI approval
Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09
Netherlands
- Authority
- AIVD, TNO and CWI
- Document
- The PQC Migration Handbook, 2nd edition
Sets no deadline at all, and is included for exactly that reason. The Dutch contribution is the migration method — how to inventory, how to choose an algorithm, how to sequence the work — which is the part a date does not tell you.
- 3 December 2024 Recommendation
Second edition published, with the PQChoiceAssistant algorithm-selection tool
Applies to Any organisation planning a migration
Source AIVD, TNO and CWI, The PQC Migration Handbook, 2nd edition , 3 December 2024 Checked 2026-08-09
Canada
- Authority
- Canadian Centre for Cyber Security
- Document
- ITSM.40.001
Frequently described as a mandate. It is not yet: the roadmap states that Treasury Board Secretariat will issue the policy instruments needed to require what it currently recommends.
- April 2026 Recommendation
Develop an initial departmental migration plan; report progress annually thereafter
Applies to Federal departments and agencies
Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09
- 2031 Recommendation
Migration of high-priority systems completed
Applies to Federal departments and agencies
Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09
- 2035 Recommendation
Migration of remaining systems completed
Applies to Federal departments and agencies
Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09
Australia
- Authority
- ASD
- Document
- Information Security Manual — Guidelines for cryptography
The most aggressive position of any authority here. ASD approval for classical asymmetric cryptography ends after 2030 — five years ahead of the 2035 most other authorities work to — and it withdraws approval from ML-KEM-768 and ML-DSA-65 at the same time.
- 2030 Recommendation
RSA, DH, ECDH and ECDSA no longer approved. New equipment must support ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by this point (ISM-1917)
Applies to Systems assessed against the ISM
Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09
- now Recommendation
A post-quantum transition plan is developed, implemented and maintained (ISM-2073)
Applies to Systems assessed against the ISM
Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09