pqcstatus
Algorithm

SHA-1: quantum risk, deadlines and replacements

Weakened by quantum

Hash function with practical collisions. Must not be used for signatures.

At a glance

Quantum riskWeakened by quantum
Used forHash function
Post-quantum algorithmNo

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
NISTDeprecatedin forceall variantsSP 800-131A Rev. 3 (draft): deprecated through 2030.
NISTDisallowedfrom January 1, 2031all variantsDisallowed for applying cryptographic protection after 2030-12-31.

Recommended replacements

Sources

  1. SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is SHA-1 quantum-safe?

Partially. Grover’s algorithm reduces its effective security; larger variants remain adequate, while broken legacy variants must be retired now.

When will SHA-1 be deprecated or disallowed?

NIST: Disallowed from January 1, 2031 (all variants).

What should replace SHA-1?

SHA-2, SHA-3.