THE QUANTUM THREAT / INTERMEDIATE

What Governments Have Told Organisations To Do, And By When

A short guide to the main US and UK post-quantum milestones, which are binding and which are guidance, and where to find the full regional detail.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

The earlier articles in this group explain why public-key cryptography needs replacing. Governments have turned that into dates. This article gives a short orientation to the milestones most organisations hear about first, and the status of each one, as of October 2026.

It is deliberately brief. For sector rules such as PCI DSS and DORA, and for jurisdictions beyond the US and UK, see Cryptography Compliance and the Regulatory Deadline Tracker, which is kept up to date with live countdowns.

The Common Shape Of Most Roadmaps

National roadmaps differ in detail but mostly follow the same sequence. The joint 2023 factsheet from CISA, the NSA and NIST set it out early: build a quantum readiness roadmap, create a cryptographic inventory, assess dependencies in your technology supply chain, and talk to vendors about their post-quantum plans.1 Later national guidance attaches dates to those steps.

The milestones below come from documents with very different legal force, so read the status labels carefully.

  1. First Post-Quantum Standards

    NIST publishes FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).

  2. NIST Transition Plan Released As A Draft

    NIST IR 8547 sets out proposed dates for retiring quantum-vulnerable algorithms.

  3. UK NCSC Publishes Migration Timelines

    Guidance setting milestones for 2028, 2031 and 2035.

  4. US Executive Order 14412 Signed

    Directs dated post-quantum transitions for high-value federal systems.

  5. UK: Discovery And Initial PlanUpcoming

    Define goals, complete discovery and build an initial migration plan.

  6. NIST: Deprecate 112-Bit Public-Key AlgorithmsProposed

    Draft proposal. The few 112-bit symmetric options would be disallowed in 2030.

  7. US Federal: Post-Quantum Key EstablishmentUpcoming

    High-value assets and high impact systems, excluding national security systems.

  8. UK: Priority MigrationsUpcoming

    Complete the earliest, highest-priority migrations.

  9. US Federal: Post-Quantum SignaturesUpcoming

    Same systems as the 2030 key establishment target.

  10. UK: Complete Migration; US: NSM-10 TargetUpcoming

    NCSC guidance and the US policy target for mitigating quantum risk.

  11. NIST: Disallow Quantum-Vulnerable AlgorithmsProposed

    Draft proposal covering all RSA, elliptic curve and Diffie-Hellman key sizes.

Selected US and UK post-quantum milestones, as of October 2026. Proposed means a draft or a rule not yet in force.

United States

NIST published its first three post-quantum standards, FIPS 203, FIPS 204 and FIPS 205, in August 2024.2 NIST IR 8547 is NIST’s plan for moving to them. It proposes deprecating RSA, elliptic curve and Diffie-Hellman algorithms at the 112-bit security level after 2030 and disallowing all quantum-vulnerable public-key algorithms after 2035.3 As of October 2026 it remains an initial public draft, so these dates are proposals; the comment period closed in January 2025.

National Security Memorandum 10, quoted in the NIST draft, sets 2035 as the primary target for mitigating as much quantum risk as is feasible.3

Executive Order 14412, signed on 22 June 2026, goes further for federal systems. It directs the Office of Management and Budget to issue guidance requiring agencies to move their high-value assets and high impact systems, other than national security systems, to post-quantum key establishment by 31 December 2030 and post-quantum signatures by 31 December 2031. It also directs a proposed procurement rule requiring covered federal contractors to comply with NIST’s post-quantum FIPS by 31 December 2030.4 The order binds federal agencies; for contractors, the requirement depends on that rule being made.

CNSA 2.0 is the NSA’s algorithm suite setting future requirements for national security systems.5 It specifies ML-KEM-1024, ML-DSA-87, AES-256 and SHA-384 or SHA-512, plus the stateful hash-based signatures LMS and XMSS, according to a TLS profile by NSA authors that is still an Internet-Draft rather than an IETF standard.6 Suppliers to national security systems should read the NSA’s own CNSA 2.0 documents for the full transition schedule.

United Kingdom

The National Cyber Security Centre published its migration timelines on 20 March 2025. By 2028, organisations should define migration goals, carry out full discovery and build an initial plan. By 2031 they should complete their highest-priority migrations and refine the roadmap. By 2035 they should complete migration of all systems, services and products.7 This is guidance rather than law. The NCSC accepts that a small number of rarely used technologies may be harder to move by 2035, but it asks all organisations to work towards these dates.

  1. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  2. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  3. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(iii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  4. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete migration to post-quantum cryptography across systems and products.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations. Source · Verified 7 Oct 2026

Live countdowns for four of the milestones above. The tracker lists many more.

Europe And Quantum Key Distribution

European agencies have also stated which technology to back. In January 2024 France’s ANSSI, Germany’s BSI, the Netherlands’ NLNCSA and Sweden’s National Communications Security Authority jointly concluded that post-quantum cryptography should take priority over quantum key distribution, which they judged suitable only for niche uses.8 EU-level roadmaps and financial sector rules are covered in Cryptography Compliance.

Footnotes

  1. CISA, NSA and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography”, 21 August 2023. cisa.gov ↩

  2. NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩

  3. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. csrc.nist.gov ↩ ↩2

  4. The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩

  5. NSA, “NSA Releases Future Quantum-Resistant (QR) Algorithm Requirements for National Security Systems”, 7 September 2022. nsa.gov ↩

  6. A. Becker and M. Jenkins (NSA), “Commercial National Security Algorithm (CNSA) Suite 2.0 Profile for TLS 1.3”, IETF Internet-Draft draft-becker-cnsa2-tls-profile-05, 19 July 2026. ietf.org ↩

  7. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

  8. ANSSI, BSI, NLNCSA and Swedish National Communications Security Authority, “Position Paper on Quantum Key Distribution”, 25 January 2024. cyber.gouv.fr ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.