pqcstatus
Algorithm

ECDSA: quantum risk, deadlines and replacements

Quantum-vulnerable

Elliptic-curve signature algorithm (TLS certificates, code signing, JWT ES256). Broken by Shor's algorithm.

At a glance

Quantum riskQuantum-vulnerable
Used forDigital signature
Post-quantum algorithmNo

Variants and security strength

VariantClassical security (bits)
P-224 (secp224r1)112
P-256 (secp256r1)128
P-384 (secp384r1)192
P-521 (secp521r1)256
secp256k1128
brainpoolP256r1128
brainpoolP384r1192

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
European UnionDeprecatedfrom January 1, 2031all variantsEU roadmap: must not be used stand-alone after 2030 for high-risk use cases.
ANSSIDeprecatedfrom January 1, 2031all variantsANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification).
NISTDeprecatedfrom January 1, 2031strength ≤ 112 bitsNIST IR 8547 (draft): 112-bit security strength deprecated after 2030.
US Federal Government (EO / OMB)Deprecatedfrom January 1, 2032all variantsEO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC signatures by 2031-12-31.
NSA (CNSA 2.0)Disallowedfrom January 1, 2034all variantsCNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category.
NISTDisallowedfrom January 1, 2036all variantsNIST IR 8547 (draft): disallowed after 2035 at every security strength.
European UnionDeprecatedfrom January 1, 2036all variantsEU roadmap: must not be used stand-alone after 2035 for medium-risk use cases.
UK NCSCDeprecatedfrom January 1, 2036all variantsUK NCSC: complete migration of all systems to PQC by 2035.
BSIDeprecatedfrom January 1, 2036all variantsBSI TR-02102-1: classical signatures expected to remain recommended until end of 2035.

Recommended replacements

Sources

  1. FIPS 186-5 — Digital Signature Standard (DSS) · NIST
  2. NIST IR 8547 (Initial Public Draft) — Transition to Post-Quantum Cryptography Standards · NIST (draft)
  3. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
  4. FAQ — Cryptographie post-quantique · ANSSI (guidance)
  5. Timelines for migration to post-quantum cryptography (v1.0) · UK NCSC (guidance)
  6. CNSA 2.0 FAQ (Ver. 2.1) · NSA (guidance)
  7. BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
  8. Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
  9. OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is ECDSA quantum-safe?

No. ECDSA is broken by Shor’s algorithm on a sufficiently large quantum computer, whatever the key size. Data protected today can be recorded now and decrypted later.

When will ECDSA be deprecated or disallowed?

European Union: Deprecated from January 1, 2031 (all variants). ANSSI: Deprecated from January 1, 2031 (all variants). NIST: Deprecated from January 1, 2031 (strength ≤ 112 bits). US Federal Government (EO / OMB): Deprecated from January 1, 2032 (all variants). NSA (CNSA 2.0): Disallowed from January 1, 2034 (all variants). NIST: Disallowed from January 1, 2036 (all variants).

What should replace ECDSA?

ML-DSA, SLH-DSA.