pqcstatus
Algorithm

RSA: quantum risk, deadlines and replacements

Quantum-vulnerable

Public-key algorithm for signatures and key transport. Broken by Shor's algorithm on a large quantum computer, whatever the key size.

At a glance

Quantum riskQuantum-vulnerable
Used forDigital signature, Key establishment
Post-quantum algorithmNo

Variants and security strength

VariantClassical security (bits)
RSA-102480
RSA-2048112
RSA-3072128
RSA-4096128
RSA-7680192

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
NISTDisallowedin forcestrength ≤ 80 bitsKeys below 112-bit strength (RSA < 2048) are already disallowed.
BSIDeprecatedin forceRSA-1024, RSA-2048BSI requires at least 3000-bit RSA moduli.
European UnionDeprecatedfrom January 1, 2031all variantsEU roadmap: must not be used stand-alone after 2030 for high-risk use cases.
ANSSIDeprecatedfrom January 1, 2031all variantsANSSI: buying products without PQC after 2030 is not reasonable (recommendation). Hybridation is already mandatory in the regulated scope (DR, SAIV/SIIV, product qualification).
NISTDeprecatedfrom January 1, 2031strength ≤ 112 bitsNIST IR 8547 (draft): 112-bit security strength deprecated after 2030.
US Federal Government (EO / OMB)Deprecatedfrom January 1, 2031all variantsEO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC key establishment by 2030-12-31; federal contractors expected to comply by the same date (FAR rule pending).
BSIDeprecatedfrom January 1, 2032all variantsBSI TR-02102-1: classical key agreement alone recommended only until end of 2031 (end of 2030 for very high protection needs); hybrid use is recommended.
US Federal Government (EO / OMB)Deprecatedfrom January 1, 2032all variantsEO 14412 / OMB M-26-15: federal high-value and high-impact systems on PQC signatures by 2031-12-31.
NSA (CNSA 2.0)Disallowedfrom January 1, 2034all variantsCNSA 2.0 (US national security systems): exclusive use of PQC by 2030–2033 depending on the product category.
NISTDisallowedfrom January 1, 2036all variantsNIST IR 8547 (draft): disallowed after 2035 at every security strength.
European UnionDeprecatedfrom January 1, 2036all variantsEU roadmap: must not be used stand-alone after 2035 for medium-risk use cases.
UK NCSCDeprecatedfrom January 1, 2036all variantsUK NCSC: complete migration of all systems to PQC by 2035.
BSIDeprecatedfrom January 1, 2036all variantsBSI TR-02102-1: classical signatures expected to remain recommended until end of 2035.

Recommended replacements

Sources

  1. NIST IR 8547 (Initial Public Draft) — Transition to Post-Quantum Cryptography Standards · NIST (draft)
  2. SP 800-57 Part 1 Rev. 5 — Recommendation for Key Management (security strength tables) · NIST
  3. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
  4. FAQ — Cryptographie post-quantique · ANSSI (guidance)
  5. Timelines for migration to post-quantum cryptography (v1.0) · UK NCSC (guidance)
  6. CNSA 2.0 FAQ (Ver. 2.1) · NSA (guidance)
  7. BSI TR-02102-1 — Cryptographic Mechanisms: Recommendations and Key Lengths (Version 2026-01) · BSI
  8. Executive Order 14412 — Securing the Nation Against Advanced Cryptographic Attacks · The White House
  9. OMB M-26-15 — Execution of the Migration to Post-Quantum Cryptography · The White House (OMB)
  10. SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is RSA quantum-safe?

No. RSA is broken by Shor’s algorithm on a sufficiently large quantum computer, whatever the key size. Data protected today can be recorded now and decrypted later.

When will RSA be deprecated or disallowed?

European Union: Deprecated from January 1, 2031 (all variants). ANSSI: Deprecated from January 1, 2031 (all variants). NIST: Deprecated from January 1, 2031 (strength ≤ 112 bits). US Federal Government (EO / OMB): Deprecated from January 1, 2031 (all variants). BSI: Deprecated from January 1, 2032 (all variants). US Federal Government (EO / OMB): Deprecated from January 1, 2032 (all variants).

What should replace RSA?

X25519MLKEM768, ML-KEM, ML-DSA.