No law says that every company must use post-quantum cryptography by a given date. What exists is a set of converging timelines from standards bodies, national agencies and governments, some binding for specific sectors, most of them guidance. Read together, they draw a clear plan: inventory now, migrate the most sensitive systems by 2030, finish by 2035. Every date below links to our sourced timeline.
The anchor dates
NIST: 2030 and 2035
NIST's transition plan, published as the draft IR 8547, deprecates RSA and elliptic-curve algorithms at the 112-bit security level after 2030 and disallows quantum-vulnerable public-key algorithms such as RSA and ECDSA after 2035, whatever their size. The document is still a draft, but vendors and agencies worldwide already plan around these dates.
European Union: 2026, 2030, 2035
The coordinated EU roadmap of June 2025 asks Member States to start the transition and have national roadmaps by the end of 2026, to migrate high-risk use cases by the end of 2030, and medium-risk use cases by the end of 2035. After those dates, quantum-vulnerable public-key cryptography should no longer be used alone in the corresponding use cases. It is guidance addressed to Member States, but it is becoming the reference for the private sector.
France: 2027 and 2030
ANSSI makes hybridation mandatory in its regulated scope (restricted and classified information, operators of vital importance, qualified products). It aims to require post-quantum cryptography for products entering qualification from 2027, and considers that buying products without it after 2030 will not be reasonable. Outside the regulated scope, these are recommendations, not legal obligations.
Germany and the UK
The BSI recommends classical key agreement alone only until the end of 2031, and hybrid use from now on. The UK NCSC asks organizations to complete discovery and a migration plan by 2028, priority migrations by 2031, and full migration by 2035.
United States
Executive Order 14412 and OMB memorandum M-26-15 (June 2026) require federal agencies to keep an automated cryptographic inventory, to use post-quantum key establishment on high-value systems by the end of 2030 and post-quantum signatures by the end of 2031. A proposed procurement rule should extend requirements to federal contractors.
The rules that already bind many companies
- PCI DSS 12.3.3: a yearly-reviewed inventory of cipher suites and protocols, mandatory since March 2025 for anyone handling card payments.
- DORA: EU financial entities need an encryption policy able to change cryptographic technology as cryptanalysis evolves, plus a certificate register.
- NIS2: essential and important entities need policies on cryptography and encryption.
- Cyber Resilience Act: products sold in the EU must encrypt data with state-of-the-art mechanisms, with full application in December 2027.
None of these texts names ML-KEM, but all of them require you to know your cryptography and to be able to change it. That is exactly what the post-quantum transition needs.
What to do, date by date
Now to end of 2026
- Build the cryptographic inventory: external endpoints, internal links, certificates, libraries and keys.
- Enable hybrid post-quantum key exchange where it is a configuration change, starting with internet-facing services.
- Remove what is already obsolete: TLS 1.0 and 1.1, 3DES, RC4, SHA-1 signatures, RSA keys below 2048 bits.
- Ask your vendors for their post-quantum roadmap.
2027 to 2030
- Migrate high-risk systems: data with long confidentiality needs, critical infrastructure, identity and signing systems.
- Prefer products with post-quantum support in every new purchase.
- Test post-quantum signatures and certificates where your ecosystem supports them.
2031 to 2035
- Complete the migration of remaining systems, including signatures.
- Retire quantum-vulnerable algorithms used alone before NIST disallows them after 2035.