pqcstatus
Algorithm

Finite-field Diffie-Hellman (DH / DHE): quantum risk, deadlines and replacements

Quantum-vulnerable

Classic Diffie-Hellman key exchange over finite fields (DHE cipher suites, IPsec). Broken by Shor's algorithm.

At a glance

Quantum riskQuantum-vulnerable
Used forKey establishment
Post-quantum algorithmNo

Variants and security strength

VariantClassical security (bits)
DH-102480
ffdhe2048112
ffdhe3072128
ffdhe4096128

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
NISTDisallowedin forcestrength ≤ 80 bitsGroups below 112-bit strength are already disallowed.
European UnionDeprecatedfrom January 1, 2031all variantsEU roadmap: must not be used stand-alone after 2030 for high-risk use cases.
ANSSIDeprecatedfrom January 1, 2031all variantsANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification).
NISTDeprecatedfrom January 1, 2031strength ≤ 112 bitsNIST IR 8547 (draft): 112-bit security strength deprecated after 2030.
US Federal Government (EO / OMB)Deprecatedfrom January 1, 2031all variantsEO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC key establishment by 2030-12-31; federal contractors expected to comply by the same date (FAR rule pending).
BSIDeprecatedfrom January 1, 2032all variantsBSI TR-02102-1: classical key agreement alone recommended only until end of 2031 (end of 2030 for very high protection needs); hybrid use is recommended.
NSA (CNSA 2.0)Disallowedfrom January 1, 2034all variantsCNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category.
NISTDisallowedfrom January 1, 2036all variantsNIST IR 8547 (draft): disallowed after 2035 at every security strength.
European UnionDeprecatedfrom January 1, 2036all variantsEU roadmap: must not be used stand-alone after 2035 for medium-risk use cases.
UK NCSCDeprecatedfrom January 1, 2036all variantsUK NCSC: complete migration of all systems to PQC by 2035.

Recommended replacements

Sources

  1. NIST IR 8547 (Initial Public Draft) — Transition to Post-Quantum Cryptography Standards · NIST (draft)
  2. SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management (security strength tables) · NIST
  3. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
  4. FAQ — Cryptographie post-quantique · ANSSI (guidance)
  5. Timelines for migration to post-quantum cryptography (v1.0) · UK NCSC (guidance)
  6. CNSA 2.0 FAQ (Ver. 2.1) · NSA (guidance)
  7. BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
  8. Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
  9. OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)
  10. SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is Finite-field Diffie-Hellman (DH / DHE) quantum-safe?

No. Finite-field Diffie-Hellman (DH / DHE) is broken by Shor’s algorithm on a sufficiently large quantum computer, whatever the key size. Data protected today can be recorded now and decrypted later.

When will Finite-field Diffie-Hellman (DH / DHE) be deprecated or disallowed?

European Union: Deprecated from January 1, 2031 (all variants). ANSSI: Deprecated from January 1, 2031 (all variants). NIST: Deprecated from January 1, 2031 (strength ≤ 112 bits). US Federal Government (EO / OMB): Deprecated from January 1, 2031 (all variants). BSI: Deprecated from January 1, 2032 (all variants). NSA (CNSA 2.0): Disallowed from January 1, 2034 (all variants).

What should replace Finite-field Diffie-Hellman (DH / DHE)?

X25519MLKEM768, ML-KEM.