The Global Quantum Deadline Map: 2030, 2031 And 2035
Governments and supervisors have published post-quantum migration dates that cluster around the same few years. Here is what each date means, who it applies to and how binding it is.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Post-quantum migration dates now come from many directions: cyber agencies, finance ministries, central banks and heads of government. On first reading they look scattered. Put on one page, they fall into a clear pattern of three waves, with most jurisdictions converging on 2035 as the end point.
This article maps the main published dates as of October 2026, explains who each one applies to, and labels whether it is binding, supervisory or guidance. The labels matter as much as the dates.
Three Waves
Most roadmaps share the same sequence, even when the exact years differ.
- Discover And PlanUpcoming
Build a cryptographic inventory, assess risk and write a migration plan.
- Migrate The Most Important SystemsUpcoming
Move high-risk, high-value or critical systems to post-quantum cryptography.
- FinishUpcoming
Complete migration of remaining systems as far as feasible.
The G7 Cyber Expert Group, reviewing guidance from many jurisdictions, observed that it often points to 2035 as the overall target, and suggested that the most critical financial systems might be addressed in 2030 to 2032.1 The group is explicit that its roadmap is non-authoritative and sets no regulatory expectations.
Why The Dates Converge
The repetition of 2035 is not a coincidence. The EU roadmap explains its own choice of that year by pointing to three earlier sources: the US goal, set in National Security Memorandum 10, of mitigating as much quantum risk as feasible by 2035; NIST’s draft transition guidance, which proposes disallowing traditional public-key algorithms after 2035; and the UK NCSC timeline, which also ends in 2035.2 Each new roadmap tends to align with the ones before it, which helps multinational organisations plan.
The length of the runway is also deliberate. Migration depends on a chain of events: standards must be agreed before vendors can build them into products, and products must exist before organisations can deploy them at scale. The NCSC judges that a decade allows that whole chain to play out, which is how it arrived at 2035.3 The EU roadmap estimates that fully migrating all relevant systems could take five to ten years, which is why it says the later steps must begin straight away instead of waiting until the 2026 milestone is met.2
Earlier dates for the most important systems reflect harvest now, decrypt later. Data that must stay confidential for many years is already exposed if it is recorded today, so it needs protection well before the end point.
Who Has Set Which Dates
The table summarises the main published milestones. Each row is a different kind of instrument, so read the status column before the dates.
| Jurisdiction And Issuer | Applies To | Early Milestone | Priority Systems | Completion | Status |
|---|---|---|---|---|---|
| United Kingdom, NCSC | UK organisations, especially large organisations and critical national infrastructure | Discovery and initial plan by 2028 | Highest-priority migration by 2031 | All systems by 2035 | Guidance |
| European Union, NIS Cooperation Group | EU Member States | First steps and national roadmaps by end 2026 | High-risk use cases by end 2030 | Medium-risk by end 2035, low-risk as far as feasible | Guidance |
| United States, Executive Order 14412 | Federal high-value assets and high-impact systems, excluding national security systems | OMB (Office of Management and Budget) guidance within 90 days of 22 June 2026 | Key establishment by 31 December 2030, through OMB guidance | Signatures by 31 December 2031, through OMB guidance | Binding on federal agencies |
| United States, OMB M-26-15 | Federal civilian agencies | Plans within 120 days; discovery 2026 to 2027 | Prioritised migration 2028 to 2030 | Full migration phase 2035 | Binding on federal agencies |
| Canada, Canadian Centre for Cyber Security | Government of Canada non-classified systems | Initial departmental plan by April 2026, then annual progress reports | High-priority systems by end 2031 | Remaining systems by end 2035 | Guidance (federal roadmap) |
| Singapore, Cyber Security Agency | Critical information infrastructure owners | Migration plan by 31 March 2027 | New systems procured from 1 January 2028 should support quantum-safe algorithms or be ready for them | Complete by 31 December 2031 | Supervisory |
| Saudi Arabia, SAMA | SAMA-regulated financial institutions | Cryptographic asset procedures by end Q4 2026; risk assessment by end Q1 2027 | Plans for priority assets (no date) | Not dated | Binding |
| Switzerland, FINMA | FINMA-supervised institutions | PQC roadmap by mid-2027 | Firms set their own dates | Firms set their own dates | Supervisory recommendation |
| G7 Cyber Expert Group | Financial sector, as a reference | Inventory phase | Critical systems 2030 to 2032 | Overall 2035 | Non-binding statement |
Sources for each row: NCSC,3 EU roadmap,2 Executive Order 14412,4 OMB M-26-15,5 Canada,6 Singapore,7 SAMA8 and FINMA.9 Australia’s Signals Directorate has also advised that traditional asymmetric cryptography should stop being used by the end of 2030, which makes it one of the earliest national targets.10
Reading The Dates Carefully
Several patterns stand out.
The early dates are about planning, not migration. The nearest milestones, from SAMA, the EU roadmap, Singapore and FINMA, all ask for inventories, risk assessments, plans or roadmaps. None of them asks a private firm to finish migrating in 2026 or 2027.
Binding dates mostly apply to governments. The US executive order and OMB memorandum bind federal agencies. Canada’s roadmap covers federal systems. The main binding instrument on private firms in this table is SAMA’s circular, and its dates are about inventory and assessment.
Key exchange comes before signatures. The US splits its deadline into key establishment (2030) and digital signatures (2031). That order reflects the harvest now, decrypt later threat: recorded traffic can be decrypted later, so protecting key exchange is the more urgent task, while forged signatures only become possible once a capable quantum computer exists.
Completion does not always mean every system. The EU roadmap asks for low-risk use cases to move as far as feasible by 2035. The NCSC expects a small set of rarely used technologies to be harder to move by that date.3
The Countdowns
The live countdowns below cover the dated milestones mentioned in this article. Each links to its source.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
European Union · NIS Cooperation Group Guidance
All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Submit a quantum-safe migration plan to CSA.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
- Upcoming
Switzerland · FINMA Supervisory
Draw up a post-quantum cryptography roadmap.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
- Upcoming
Australia · Australian Signals Directorate Guidance
Stop using traditional asymmetric cryptography such as RSA, Diffie-Hellman, ECDH and ECDSA.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for high-risk use cases.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Complete migration to quantum-safe cryptography.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Migrate high-priority non-classified government systems.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete early, highest-priority migration activities and refine the plan into a roadmap for completing migration by 2035.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete migration to post-quantum cryptography across systems and products.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Complete migration of the remaining non-classified government systems.
What To Do With A Map Like This
For most organisations, the useful question is which dates their own regulators or customers are likely to adopt. A firm supervised in the EU should expect national expectations to follow the EU roadmap. A supplier to the US government should watch the federal contractor rule that the executive order requires. A bank in the Gulf should read SAMA’s circular as a signal of where regional supervisors are heading, even if it is not supervised by SAMA. The wider regional picture is covered in Regulations Across Regions.
Whatever the jurisdiction, the first wave asks for the same thing. An inventory built and maintained now serves every one of these timelines.
Footnotes
-
G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩
-
NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩ ↩2 ↩3
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2 ↩3
-
The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩
-
US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩
-
Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, June 2025. cyber.gc.ca ↩
-
Cyber Security Agency of Singapore, “Quantum-Safe Handbook”, 16 July 2026. gov.sg ↩
-
Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩
-
FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩
-
Australian Signals Directorate, “Planning for post-quantum cryptography”, last reviewed 22 September 2025. cyber.gov.au ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.