Post-quantum regulations and deadlines
Every official requirement and milestone on cryptography and the post-quantum transition, on one timeline.
Consolidated timeline
- PCI DSS v4.0.1: Requirement 12.3.3 becomes mandatory (was a best practice before).
- NIS2 (Directive (EU) 2022/2555): Commission proposal COM(2026) 13: national strategies must include a policy for the transition to post-quantum cryptography (not yet adopted).
- Cyber Resilience Act (Regulation (EU) 2024/2847): Vulnerability and incident reporting obligations (Art. 14) apply.
- US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): Agency PQC migration plans due (120 days after OMB M-26-15).
- EU Coordinated Implementation Roadmap for the Transition to PQC: First steps implemented (including cryptographic inventory), national PQC roadmaps in place, planning and pilots started for high- and medium-risk use cases.
- ANSSI — Post-quantum cryptography doctrine: ANSSI aims to require PQC for products entering qualification from 2027.
- Cyber Resilience Act (Regulation (EU) 2024/2847): Full application of the regulation.
- UK NCSC — PQC migration timelines: Define migration goals, carry out a full discovery exercise, build an initial migration plan.
- EU Coordinated Implementation Roadmap for the Transition to PQC: High-risk use cases migrated; quantum-safe software and firmware upgrades enabled by default; quantum-vulnerable public key no longer used stand-alone for high-risk cases.
- ANSSI — Post-quantum cryptography doctrine: After 2030, buying products without PQC will not be reasonable (recommendation).
- US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): High-value and high-impact systems on PQC key establishment; federal contractors expected to comply with FIPS including PQC (FAR rule pending).
- NSA CNSA 2.0: Exclusive use for software/firmware signing and traditional networking equipment.
- BSI TR-02102-1 (2026-01): End of recommendation for classical key agreement used alone (end of 2030 for very high protection needs).
- UK NCSC — PQC migration timelines: Carry out the early, highest-priority PQC migration activities.
- US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): High-value and high-impact systems on PQC signatures.
- NSA CNSA 2.0: Exclusive use for web browsers/servers, cloud services, operating systems and niche equipment.
- EU Coordinated Implementation Roadmap for the Transition to PQC: Medium-risk use cases migrated; low-risk as much as feasible.
- UK NCSC — PQC migration timelines: Complete migration to PQC of all systems, services and products.
- US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): Mitigate as much quantum risk as feasible (NSM-10); full migration.
Frameworks
PCI DSS v4.0.1
Requirement 12.3.3 makes a yearly-reviewed inventory of cipher suites and protocols mandatory since 31 March 2025.
EU regulation · EUCyber Resilience Act (Regulation (EU) 2024/2847)
Essential cybersecurity requirements for products, including state-of-the-art encryption of data at rest and in transit.
EU regulation · EUDORA — RTS on ICT risk management (Delegated Regulation (EU) 2024/1774)
Requires an encryption policy that can change cryptographic technology as cryptanalysis evolves, plus full key and certificate lifecycle management.
EU directive · EUNIS2 (Directive (EU) 2022/2555)
Cybersecurity risk-management measures include policies on cryptography and encryption; a 2026 proposal adds the PQC transition to national strategies.
Official guidance · EUEU Coordinated Implementation Roadmap for the Transition to PQC
Common EU timeline: first steps and national roadmaps by end of 2026, high-risk systems migrated by end of 2030, medium-risk by end of 2035.
Official guidance · FRANSSI — Post-quantum cryptography doctrine
Hybridation mandatory in the regulated scope; start the cryptographic inventory now; PQC expected for product qualification from 2027.
Official guidance · DEBSI TR-02102-1 (2026-01)
Hybrid PQC recommended; classical key agreement alone only until end of 2031; RSA of at least 3000 bits.
Official guidance · UKUK NCSC — PQC migration timelines
Discovery and plan by 2028, priority migrations by 2031, full migration by 2035.
Government policy · USUS federal PQC migration (EO 14412, OMB M-26-15, NSM-10)
Automated cryptographic inventory and CBOM, PQC key establishment by end of 2030, PQC signatures by end of 2031, full migration by 2035.
Government policy · USNSA CNSA 2.0
Mandated algorithms: ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256, SHA-384/512, with category-specific deadlines.
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.