pqcstatus

Post-quantum regulations and deadlines

Every official requirement and milestone on cryptography and the post-quantum transition, on one timeline.

Consolidated timeline

  1. PCI DSS v4.0.1: Requirement 12.3.3 becomes mandatory (was a best practice before).
  2. NIS2 (Directive (EU) 2022/2555): Commission proposal COM(2026) 13: national strategies must include a policy for the transition to post-quantum cryptography (not yet adopted).
  3. Cyber Resilience Act (Regulation (EU) 2024/2847): Vulnerability and incident reporting obligations (Art. 14) apply.
  4. US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): Agency PQC migration plans due (120 days after OMB M-26-15).
  5. EU Coordinated Implementation Roadmap for the Transition to PQC: First steps implemented (including cryptographic inventory), national PQC roadmaps in place, planning and pilots started for high- and medium-risk use cases.
  6. ANSSI — Post-quantum cryptography doctrine: ANSSI aims to require PQC for products entering qualification from 2027.
  7. Cyber Resilience Act (Regulation (EU) 2024/2847): Full application of the regulation.
  8. UK NCSC — PQC migration timelines: Define migration goals, carry out a full discovery exercise, build an initial migration plan.
  9. EU Coordinated Implementation Roadmap for the Transition to PQC: High-risk use cases migrated; quantum-safe software and firmware upgrades enabled by default; quantum-vulnerable public key no longer used stand-alone for high-risk cases.
  10. ANSSI — Post-quantum cryptography doctrine: After 2030, buying products without PQC will not be reasonable (recommendation).
  11. US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): High-value and high-impact systems on PQC key establishment; federal contractors expected to comply with FIPS including PQC (FAR rule pending).
  12. NSA CNSA 2.0: Exclusive use for software/firmware signing and traditional networking equipment.
  13. BSI TR-02102-1 (2026-01): End of recommendation for classical key agreement used alone (end of 2030 for very high protection needs).
  14. UK NCSC — PQC migration timelines: Carry out the early, highest-priority PQC migration activities.
  15. US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): High-value and high-impact systems on PQC signatures.
  16. NSA CNSA 2.0: Exclusive use for web browsers/servers, cloud services, operating systems and niche equipment.
  17. EU Coordinated Implementation Roadmap for the Transition to PQC: Medium-risk use cases migrated; low-risk as much as feasible.
  18. UK NCSC — PQC migration timelines: Complete migration to PQC of all systems, services and products.
  19. US federal PQC migration (EO 14412, OMB M-26-15, NSM-10): Mitigate as much quantum risk as feasible (NSM-10); full migration.

Frameworks

Industry standard · international

PCI DSS v4.0.1

Requirement 12.3.3 makes a yearly-reviewed inventory of cipher suites and protocols mandatory since 31 March 2025.

EU regulation · EU

Cyber Resilience Act (Regulation (EU) 2024/2847)

Essential cybersecurity requirements for products, including state-of-the-art encryption of data at rest and in transit.

EU regulation · EU

DORA — RTS on ICT risk management (Delegated Regulation (EU) 2024/1774)

Requires an encryption policy that can change cryptographic technology as cryptanalysis evolves, plus full key and certificate lifecycle management.

EU directive · EU

NIS2 (Directive (EU) 2022/2555)

Cybersecurity risk-management measures include policies on cryptography and encryption; a 2026 proposal adds the PQC transition to national strategies.

Official guidance · EU

EU Coordinated Implementation Roadmap for the Transition to PQC

Common EU timeline: first steps and national roadmaps by end of 2026, high-risk systems migrated by end of 2030, medium-risk by end of 2035.

Official guidance · FR

ANSSI — Post-quantum cryptography doctrine

Hybridation mandatory in the regulated scope; start the cryptographic inventory now; PQC expected for product qualification from 2027.

Official guidance · DE

BSI TR-02102-1 (2026-01)

Hybrid PQC recommended; classical key agreement alone only until end of 2031; RSA of at least 3000 bits.

Official guidance · UK

UK NCSC — PQC migration timelines

Discovery and plan by 2028, priority migrations by 2031, full migration by 2035.

Government policy · US

US federal PQC migration (EO 14412, OMB M-26-15, NSM-10)

Automated cryptographic inventory and CBOM, PQC key establishment by end of 2030, PQC signatures by end of 2031, full migration by 2035.

Government policy · US

NSA CNSA 2.0

Mandated algorithms: ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256, SHA-384/512, with category-specific deadlines.

Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.