Guidance

Migration timelines.

Every entry on this page was checked against its source on or after 2026-08-09

Every authority we have checked, in date order. The badge on each milestone is the part most published timelines lose: whether anyone is actually obliged to meet it — and, for the entries that do not speak for a whole country, how far it reaches.

What the badges mean

  • Binding In force, with legal or contractual effect on someone.
  • Recommendation Published by an authority. Compels no one.
  • Draft Not yet issued in final form.
  • Proposed Announced or trailed, not published.
Post-quantum migration milestones by jurisdiction and year, 2026 to 2035.
Jurisdiction 2026202720282029203020312032203320342035
European Union European Union, 2030: Transition of high-risk use cases completed European Union, 2035: Transition of medium-risk use cases completed
Germany Germany, 2031: Sole use of classical key agreement no longer recommended after this point Germany, 2035: Transition to quantum-safe signatures, at the latest
Switzerland Switzerland, 2027: Draw up a post-quantum roadmap
Canton of Bern
United States United States, 2030: Transition to post-quantum key establishment United States, 2031: Transition to post-quantum signatures
United Kingdom United Kingdom, 2028: Define migration goals, complete a full discovery exercise, build an initial plan United Kingdom, 2031: Carry out the earliest, highest-priority migration activities; refine into a full roadmap United Kingdom, 2035: Complete migration of all systems, services and products
France France, 2030: Standalone post-quantum cryptography becomes optional
Netherlands
Canada Canada, 2031: Migration of high-priority systems completed Canada, 2035: Migration of remaining systems completed
Australia Australia, 2030: RSA, DH, ECDH and ECDSA no longer approved. New equipment must support ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by this point (ISM-1917)

Almost everything lands on 2030, 2031 or 2035. Australia is the outlier: its approval for RSA, Diffie-Hellman, ECDH and ECDSA ends after 2030, five years before the date most other authorities work towards. A product built to the 2035 consensus is already non-compliant there.

European Union

Authority
NIS Cooperation Group
Document
A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1

A coordinated recommendation to Member States, not law. It sets the dates most European sector regulators are now aligning to, which is why it matters more than its legal weight suggests.

  1. 2030 Recommendation

    Transition of high-risk use cases completed

    Applies to Member States, for critical infrastructure

    Source NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025 Checked 2026-08-09

  2. 2035 Recommendation

    Transition of medium-risk use cases completed

    Applies to Member States

    Source NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1 , 11 June 2025 Checked 2026-08-09

Germany

Authority
BSI
Document
Technical Guideline TR-02102-1

Revised each January, which makes it the fastest-moving document on this page. BSI approves a wider algorithm set than NIST does, including FrodoKEM and Classic McEliece.

  1. 2031 Recommendation

    Sole use of classical key agreement no longer recommended after this point

    Applies to Systems following TR-02102-1

    Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09

  2. 2035 Recommendation

    Transition to quantum-safe signatures, at the latest

    Applies to Systems following TR-02102-1

    Source BSI Technical Guideline TR-02102-1, version 2026-01 , 23 January 2026 Checked 2026-08-09

Switzerland

Authority
FINMA
Document
FINMA Guidance 05/2026

FINMA supervises the financial market, so this reaches the institutions it supervises and nobody else. The roadmap date is a recommendation — though FINMA also states that the principles-based governance and risk-management rules already binding those institutions cover quantum risk, and that it expects them to engage with it in good time. It sets no algorithm position of its own, citing the NIST standards instead.

  1. mid-2027 Recommendation

    Draw up a post-quantum roadmap

    Applies to FINMA-supervised institutions

    Source FINMA Guidance 05/2026, Quantum computing , 9 July 2026 Checked 2026-08-13

Canton of Bern

Binds one administration
Document
ICSGW, Anhang 6 (Kryptographische Verfahren)

A cantonal directive, binding on that canton’s own administration and on no one else. It is here because it permits an algorithm set no other authority on these pages permits, not because it carries national weight.

  1. 1 January 2025 Binding

    Directive in force: only FrodoKEM and Classic McEliece permitted, hybrid operation required

    Applies to Canton of Bern administration systems

    Source Canton Bern ICSGW, Anhang 6 (Kryptographische Verfahren) , in force 1 January 2025 Checked 2026-08-09

United States

Authority
NIST, OMB and NSA
Document
FIPS 203/204/205; IR 8547 (draft); EO 14412; OMB M-26-15; CNSA 2.0

The only jurisdiction here with dates that carry legal force, via executive order and OMB memorandum. The widely-cited IR 8547 deprecation dates are still a draft — the binding dates come from EO 14412 and M-26-15.

  1. 31 December 2030 Binding

    Transition to post-quantum key establishment

    Applies to Federal high-impact systems

    Source Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (91 FR 38483); OMB M-26-15 , 22 and 24 June 2026 Checked 2026-08-09

  2. 31 December 2031 Binding

    Transition to post-quantum signatures

    Applies to Federal high-impact systems

    Source Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (91 FR 38483); OMB M-26-15 , 22 and 24 June 2026 Checked 2026-08-09

  3. after 2030 Draft

    Quantum-vulnerable public-key algorithms deprecated; disallowed after 2035

    Applies to Federal information systems, once final

    Source NIST, IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards , November 2024 — still a draft, comments closed 10 January 2025 Checked 2026-08-09

United Kingdom

Authority
NCSC
Document
Timelines for migration to post-quantum cryptography

The clearest three-step framing published by any authority, and explicitly indicative. NCSC aims it at large organisations, operators of critical national infrastructure, and anyone running bespoke systems.

  1. 2028 Recommendation

    Define migration goals, complete a full discovery exercise, build an initial plan

    Applies to Large organisations and CNI operators

    Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09

  2. 2031 Recommendation

    Carry out the earliest, highest-priority migration activities; refine into a full roadmap

    Applies to Large organisations and CNI operators

    Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09

  3. 2035 Recommendation

    Complete migration of all systems, services and products

    Applies to Large organisations and CNI operators

    Source NCSC, Timelines for migration to post-quantum cryptography , 20 March 2025 Checked 2026-08-09

France

Authority
ANSSI
Document
Views on the Post-Quantum Cryptography transition

Structured as phases rather than deadlines, and the strongest position on hybridisation of any authority here: hybrid operation is mandatory through phases 1 and 2, not merely advised.

  1. phase 1, now Recommendation

    Classical security mandatory, post-quantum optional and claimed as defence in depth only

    Applies to Security products seeking ANSSI approval

    Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09

  2. phase 2, not before 2025 Recommendation

    Post-quantum mechanisms must be hybrid, except hash-based signatures; quantum resistance may be claimed

    Applies to Security products seeking ANSSI approval

    Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09

  3. phase 3, probably not before 2030 Recommendation

    Standalone post-quantum cryptography becomes optional

    Applies to Security products seeking ANSSI approval

    Source ANSSI, Views on the Post-Quantum Cryptography transition , 4 January 2022 Checked 2026-08-09

Netherlands

Authority
AIVD, TNO and CWI
Document
The PQC Migration Handbook, 2nd edition

Sets no deadline at all, and is included for exactly that reason. The Dutch contribution is the migration method — how to inventory, how to choose an algorithm, how to sequence the work — which is the part a date does not tell you.

  1. 3 December 2024 Recommendation

    Second edition published, with the PQChoiceAssistant algorithm-selection tool

    Applies to Any organisation planning a migration

    Source AIVD, TNO and CWI, The PQC Migration Handbook, 2nd edition , 3 December 2024 Checked 2026-08-09

Canada

Authority
Canadian Centre for Cyber Security
Document
ITSM.40.001

Frequently described as a mandate. It is not yet: the roadmap states that Treasury Board Secretariat will issue the policy instruments needed to require what it currently recommends.

  1. April 2026 Recommendation

    Develop an initial departmental migration plan; report progress annually thereafter

    Applies to Federal departments and agencies

    Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09

  2. 2031 Recommendation

    Migration of high-priority systems completed

    Applies to Federal departments and agencies

    Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09

  3. 2035 Recommendation

    Migration of remaining systems completed

    Applies to Federal departments and agencies

    Source Canadian Centre for Cyber Security, ITSM.40.001 , 23 June 2025 Checked 2026-08-09

Australia

Authority
ASD
Document
Information Security Manual — Guidelines for cryptography

The most aggressive position of any authority here. ASD approval for classical asymmetric cryptography ends after 2030 — five years ahead of the 2035 most other authorities work to — and it withdraws approval from ML-KEM-768 and ML-DSA-65 at the same time.

  1. 2030 Recommendation

    RSA, DH, ECDH and ECDSA no longer approved. New equipment must support ML-DSA-87, ML-KEM-1024, SHA-384, SHA-512 and AES-256 by this point (ISM-1917)

    Applies to Systems assessed against the ISM

    Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09

  2. now Recommendation

    A post-quantum transition plan is developed, implemented and maintained (ISM-2073)

    Applies to Systems assessed against the ISM

    Source ASD, Information Security Manual — Guidelines for cryptography , controls ISM-1917 and ISM-2073, revised September 2025 Checked 2026-08-09

← Back to guidance