pqcstatus
Algorithm

SHA-2: quantum risk, deadlines and replacements

Quantum-resistant

Standard hash family. SHA-256 and above remain secure against known quantum attacks.

At a glance

Quantum riskQuantum-resistant
Used forHash function
Post-quantum algorithmNo

Variants and security strength

VariantClassical security (bits)
SHA-224112
SHA-256128
SHA-384192
SHA-512256

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
NISTAcceptablein forceall variants
NSA (CNSA 2.0)Recommendedin forceSHA-384, SHA-512CNSA 2.0 requires SHA-384 or SHA-512.
NISTDisallowedfrom January 1, 2031SHA-224224-bit hashes disallowed for applying protection after 2030 (SP 800-131A Rev. 3 draft).

Sources

  1. FIPS 180-4 — Secure Hash Standard (SHS) · NIST
  2. SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)
  3. CNSA 2.0 Algorithms (Cybersecurity Advisory) · NSA (guidance)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is SHA-2 quantum-safe?

Yes. No known quantum attack breaks SHA-2 at the recommended parameter sizes.

When will SHA-2 be deprecated or disallowed?

NIST: Disallowed from January 1, 2031 (SHA-224).