Elliptic-curve Diffie-Hellman key exchange (ECDHE in TLS, X25519). Exposed to 'harvest now, decrypt later' attacks.
At a glance
| Quantum risk | Quantum-vulnerable |
|---|---|
| Used for | Key establishment |
| Post-quantum algorithm | No |
Variants and security strength
| Variant | Classical security (bits) |
|---|---|
| X25519 | 128 |
| X448 | 224 |
| P-224 (secp224r1) | 112 |
| P-256 (secp256r1) | 128 |
| P-384 (secp384r1) | 192 |
| P-521 (secp521r1) | 256 |
Positions and deadlines by authority
| Authority | Position | Effective | Scope | Details |
|---|---|---|---|---|
| European Union | Deprecated | from January 1, 2031 | all variants | EU roadmap: must not be used stand-alone after 2030 for high-risk use cases. |
| ANSSI | Deprecated | from January 1, 2031 | all variants | ANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification). |
| NIST | Deprecated | from January 1, 2031 | strength ≤ 112 bits | NIST IR 8547 (draft): 112-bit security strength deprecated after 2030. |
| US Federal Government (EO / OMB) | Deprecated | from January 1, 2031 | all variants | EO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC key establishment by 2030-12-31; federal contractors expected to comply by the same date (FAR rule pending). |
| BSI | Deprecated | from January 1, 2032 | all variants | BSI TR-02102-1: classical key agreement alone recommended only until end of 2031 (end of 2030 for very high protection needs); hybrid use is recommended. |
| NSA (CNSA 2.0) | Disallowed | from January 1, 2034 | all variants | CNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category. |
| NIST | Disallowed | from January 1, 2036 | all variants | NIST IR 8547 (draft): disallowed after 2035 at every security strength. |
| European Union | Deprecated | from January 1, 2036 | all variants | EU roadmap: must not be used stand-alone after 2035 for medium-risk use cases. |
| UK NCSC | Deprecated | from January 1, 2036 | all variants | UK NCSC: complete migration of all systems to PQC by 2035. |
Recommended replacements
Sources
- NIST IR 8547 (Initial Public Draft) — Transition to Post-Quantum Cryptography Standards · NIST (draft)
- SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management (security strength tables) · NIST
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
- FAQ — Cryptographie post-quantique · ANSSI (guidance)
- Timelines for migration to post-quantum cryptography (v1.0) · UK NCSC (guidance)
- CNSA 2.0 FAQ (Ver. 2.1) · NSA (guidance)
- BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
- Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
- OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.