The Post-Quantum Standards Timeline: 2030, 2035 And What Is Still A Draft
NIST proposes deprecating 112-bit RSA and elliptic curve parameter sets after 2030 and disallowing all quantum-vulnerable public-key algorithms after 2035. Here is what is final, proposed and pending.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Two years appear in almost every conversation about post-quantum migration: 2030 and 2035. Both trace back to US federal policy, mainly a NIST draft and the NSA’s plans for national security systems. Many other governments and regulators have since set their own dates, often aligned with these.
This article covers the standards side of the timeline: what NIST has published, what it proposes, and the dates the NSA has set. For sector rules and national deadlines, see Cryptography Compliance and the Regulatory Deadline Tracker.
What NIST Proposes For 2030 And 2035
NIST’s transition plan is set out in NIST IR 8547, “Transition to Post-Quantum Cryptography Standards”. It was released as an initial public draft on 12 November 2024, comments closed on 10 January 2025, and as of 7 October 2026 NIST has not published a final version.1
In the draft, NIST proposes two steps for quantum-vulnerable public-key algorithms such as RSA, ECDSA, EdDSA and finite field and elliptic curve Diffie-Hellman.2
- Parameter sets offering 112 bits of security strength would be deprecated after 2030. Deprecated means they may still be used, but the data owner must weigh the added risk.
- All quantum-vulnerable parameter sets, including those at 128 bits of security strength and above, would be disallowed after 2035, meaning they would no longer be allowed for that purpose.
The draft notes that NIST’s earlier guidance had projected disallowing 112-bit public-key schemes from 1 January 2031, and that NIST instead intends to deprecate them so that organisations can keep using them while they migrate.2 NIST’s project page summarises the goal as removing quantum-vulnerable algorithms from its standards by 2035, with high-risk systems moving much earlier.3
The same draft lists the replacements. For signatures it names ML-DSA, SLH-DSA and the stateful schemes LMS and XMSS, and for key establishment it names ML-KEM, which was then the only approved post-quantum scheme. It also points out that NIST’s few symmetric algorithms at the 112-bit level face their own cut-off and will be disallowed in 2030.2
What NIST Has Already Finalised
Three post-quantum standards have been final since 13 August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).4 SP 800-208, approving the stateful hash-based signatures LMS and XMSS, has been final since October 2020.5 SP 800-227, NIST’s recommendations for key encapsulation mechanisms, was finalised in September 2025.6
Two standards are pending. FIPS 206 (FN-DSA, from Falcon) was described by NIST in August 2025 as essentially complete and awaiting approval.7 In September 2026 NIST proposed reworking it to use fixed-point arithmetic, which means the draft is still to come.8 For FIPS 207 (HQC), NIST said in March 2025 that it planned a draft in about a year and a final standard in 2027,9 and in August 2026 it said the draft would be released soon.10 Neither draft appears on NIST’s FIPS list as of 7 October 2026.11
The NSA Dates For National Security Systems
The NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) applies to US national security systems, not to the private sector in general. Its dates are firmer than NIST’s because they are tied to a national security policy, CNSSP 15, which was updated in 2024.12
According to the NSA’s CNSA 2.0 FAQ, version 2.1:12
- From 1 January 2027, new acquisitions for national security systems must be CNSA 2.0 compliant unless noted otherwise.
- By 31 December 2030, equipment and services that cannot support CNSA 2.0 must be phased out unless noted otherwise.
- By 31 December 2031, CNSA 2.0 algorithms are mandated for use unless noted otherwise.
- By 2035, all national security systems should be quantum-resistant, in line with National Security Memorandum 10.
The NSA also asks for software and firmware signing to move early, using LMS or XMSS, because firmware roots of trust are hard to change later.12
- SP 800-208 Final
LMS and XMSS approved.
- FIPS 203, 204 And 205 Final
ML-KEM, ML-DSA and SLH-DSA.
- NIST IR 8547 Draft Released
Proposes the 2030 and 2035 milestones.
- SP 800-227 Final
Recommendations for key encapsulation mechanisms.
- FIPS 206 (FN-DSA) And FIPS 207 (HQC)Upcoming
No public drafts as of 7 October 2026; NIST planned a final HQC standard for 2027.
- CNSA 2.0 For New National Security AcquisitionsUpcoming
- 112-Bit RSA, Diffie-Hellman And Elliptic Curve DeprecatedProposed
NIST proposal.
- Non-CNSA 2.0 Equipment Phased Out In National Security SystemsUpcoming
- CNSA 2.0 Algorithms Mandated In National Security SystemsUpcoming
- All Quantum-Vulnerable Public-Key Algorithms DisallowedProposed
NIST proposal.
Reading The Dates Correctly
The status of each date matters when you plan or report against it. The table below summarises them.
| Milestone | Source | Status | Who It Applies To |
|---|---|---|---|
| FIPS 203, 204, 205 | NIST | Final standards | US federal systems; widely adopted elsewhere |
| Deprecate 112-bit classical public key after 2030 | NIST IR 8547 | Draft proposal | US federal systems once final |
| Disallow classical public key after 2035 | NIST IR 8547 | Draft proposal | US federal systems once final |
| CNSA 2.0 dates, 2027 to 2031 | NSA and CNSSP 15 | Published policy | US national security systems |
| Quantum-resistant by 2035 | NSM-10, NSA | Published policy goal | US national security systems |
| FIPS 206 and 207 | NIST | Not yet released as drafts | Not applicable until final |
A common mistake is to treat 2035 as the date to start. NIST’s own framing is that 2035 is the end point, and that high-risk systems should move much earlier.3 The NSA dates show what “earlier” looks like in practice: new purchases from 2027 and most equipment replaced by the end of 2030. Anything with a long service life, such as firmware, embedded devices or archives encrypted under keys agreed with RSA, needs a plan well before the final cut-off.
Even where these dates do not bind your organisation directly, they shape the market. Suppliers to US government customers will build to them, and many regulators have adopted similar horizons. The Regulatory Deadline Tracker lists binding and supervisory deadlines by region.
Footnotes
-
NIST Computer Security Resource Center, “NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards”, checked 7 October 2026. csrc.nist.gov ↩
-
NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024, section 4.1. nvlpubs.nist.gov ↩ ↩2 ↩3
-
NIST Computer Security Resource Center, “Post-Quantum Cryptography” project page, updated 5 August 2026. csrc.nist.gov ↩ ↩2
-
NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩
-
NIST, SP 800-208, “Recommendation for Stateful Hash-Based Signature Schemes”, October 2020. csrc.nist.gov ↩
-
NIST, SP 800-227, “Recommendations for Key-Encapsulation Mechanisms”, September 2025. csrc.nist.gov ↩
-
D. Moody (NIST), post to the NIST pqc-forum mailing list on the status of FIPS 206, 28 August 2025. groups.google.com ↩
-
R. Perlner, on behalf of the NIST FIPS 206 team, “New plan for FN-DSA”, NIST pqc-forum mailing list, 28 September 2026. groups.google.com ↩
-
NIST, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption”, 11 March 2025. nist.gov ↩
-
A. Robinson (NIST), “Upcoming FIPS 207 - Key format”, NIST pqc-forum mailing list, August 2026. groups.google.com ↩
-
NIST Computer Security Resource Center, FIPS publications list, checked 7 October 2026. csrc.nist.gov ↩
-
NSA, “The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ”, version 2.1, December 2024. media.defense.gov ↩ ↩2 ↩3
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.