pqcstatus
Algorithm

ECDH: quantum risk, deadlines and replacements

Quantum-vulnerable

Elliptic-curve Diffie-Hellman key exchange (ECDHE in TLS, X25519). Exposed to 'harvest now, decrypt later' attacks.

At a glance

Quantum riskQuantum-vulnerable
Used forKey establishment
Post-quantum algorithmNo

Variants and security strength

VariantClassical security (bits)
X25519128
X448224
P-224 (secp224r1)112
P-256 (secp256r1)128
P-384 (secp384r1)192
P-521 (secp521r1)256

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
European UnionDeprecatedfrom January 1, 2031all variantsEU roadmap: must not be used stand-alone after 2030 for high-risk use cases.
ANSSIDeprecatedfrom January 1, 2031all variantsANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification).
NISTDeprecatedfrom January 1, 2031strength ≤ 112 bitsNIST IR 8547 (draft): 112-bit security strength deprecated after 2030.
US Federal Government (EO / OMB)Deprecatedfrom January 1, 2031all variantsEO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC key establishment by 2030-12-31; federal contractors expected to comply by the same date (FAR rule pending).
BSIDeprecatedfrom January 1, 2032all variantsBSI TR-02102-1: classical key agreement alone recommended only until end of 2031 (end of 2030 for very high protection needs); hybrid use is recommended.
NSA (CNSA 2.0)Disallowedfrom January 1, 2034all variantsCNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category.
NISTDisallowedfrom January 1, 2036all variantsNIST IR 8547 (draft): disallowed after 2035 at every security strength.
European UnionDeprecatedfrom January 1, 2036all variantsEU roadmap: must not be used stand-alone after 2035 for medium-risk use cases.
UK NCSCDeprecatedfrom January 1, 2036all variantsUK NCSC: complete migration of all systems to PQC by 2035.

Recommended replacements

Sources

  1. NIST IR 8547 (Initial Public Draft) — Transition to Post-Quantum Cryptography Standards · NIST (draft)
  2. SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management (security strength tables) · NIST
  3. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
  4. FAQ — Cryptographie post-quantique · ANSSI (guidance)
  5. Timelines for migration to post-quantum cryptography (v1.0) · UK NCSC (guidance)
  6. CNSA 2.0 FAQ (Ver. 2.1) · NSA (guidance)
  7. BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
  8. Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
  9. OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is ECDH quantum-safe?

No. ECDH is broken by Shor’s algorithm on a sufficiently large quantum computer, whatever the key size. Data protected today can be recorded now and decrypted later.

When will ECDH be deprecated or disallowed?

European Union: Deprecated from January 1, 2031 (all variants). ANSSI: Deprecated from January 1, 2031 (all variants). NIST: Deprecated from January 1, 2031 (strength ≤ 112 bits). US Federal Government (EO / OMB): Deprecated from January 1, 2031 (all variants). BSI: Deprecated from January 1, 2032 (all variants). NSA (CNSA 2.0): Disallowed from January 1, 2034 (all variants).

What should replace ECDH?

X25519MLKEM768, ML-KEM.