| NIST | Disallowed | in force | strength ≤ 80 bits | Groups below 112-bit strength are already disallowed. |
| European Union | Deprecated | from January 1, 2031 | all variants | EU roadmap: must not be used stand-alone after 2030 for high-risk use cases. |
| ANSSI | Deprecated | from January 1, 2031 | all variants | ANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification). |
| NIST | Deprecated | from January 1, 2031 | strength ≤ 112 bits | NIST IR 8547 (draft): 112-bit security strength deprecated after 2030. |
| US Federal Government (EO / OMB) | Deprecated | from January 1, 2031 | all variants | EO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC key establishment by 2030-12-31; federal contractors expected to comply by the same date (FAR rule pending). |
| BSI | Deprecated | from January 1, 2032 | all variants | BSI TR-02102-1: classical key agreement alone recommended only until end of 2031 (end of 2030 for very high protection needs); hybrid use is recommended. |
| NSA (CNSA 2.0) | Disallowed | from January 1, 2034 | all variants | CNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category. |
| NIST | Disallowed | from January 1, 2036 | all variants | NIST IR 8547 (draft): disallowed after 2035 at every security strength. |
| European Union | Deprecated | from January 1, 2036 | all variants | EU roadmap: must not be used stand-alone after 2035 for medium-risk use cases. |
| UK NCSC | Deprecated | from January 1, 2036 | all variants | UK NCSC: complete migration of all systems to PQC by 2035. |