pqcstatus
Algorithm

3DES (TDEA): quantum risk, deadlines and replacements

Weakened by quantum

Legacy 64-bit block cipher (Sweet32). Disallowed for encryption.

At a glance

Quantum riskWeakened by quantum
Used forSymmetric encryption
Post-quantum algorithmNo

Positions and deadlines by authority

AuthorityPositionEffectiveScopeDetails
NISTDisallowedin forceall variantsEncryption disallowed since 2024; decryption for legacy use only.

Recommended replacements

Sources

  1. SP 800-131A Rev. 3 (Initial Public Draft) — Transitioning the Use of Cryptographic Algorithms and Key Lengths · NIST (draft)

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.

Frequently Asked Questions

Is 3DES (TDEA) quantum-safe?

Partially. Grover’s algorithm reduces its effective security; larger variants remain adequate, while broken legacy variants must be retired now.

What should replace 3DES (TDEA)?

AES.