Post Quantum Cryptography Regulations
Comparing post-quantum cryptography guidance by nation
National guidance converges on 2035 for full migration and diverges sharply before that. The UK expects discovery complete by 2028 and priority migration by 2031. US federal deadlines are 2030 for key establishment and 2031 for signatures. Australia is earliest at 2030 for asymmetric retirement.
What the NIST post-quantum cryptography timeline requires
NIST published the first three post-quantum standards on 13 August 2024: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA signatures and FIPS 205 for SLH-DSA signatures.
The transition schedule sits in NIST IR 8547, which sets out when quantum-vulnerable algorithms lose approved status. RSA, ECDSA, ECDH, DSA and finite-field Diffie-Hellman are deprecated after 2030, meaning use is permitted but discouraged and must be risk-accepted, and disallowed after 2035, meaning use is no longer permitted for federal systems.
A separate and more demanding requirement applies to US national security systems through the NSA's CNSA 2.0 suite, which mandates ML-KEM-1024, ML-DSA-87, AES-256 and SHA-384 or SHA-512, with LMS and XMSS for software and firmware signing.
UK: the NCSC migration timelines
The NCSC published Timelines for migration to post-quantum cryptography on 20 March 2025, its first dedicated migration timeline document. It sets three milestones.
By 2028, organisations should have defined migration goals, completed a full discovery exercise across services and infrastructure, built an initial migration plan identifying highest-priority activities, supplier and physical infrastructure dependencies, required investment and any long-lived hardware roots of trust, and communicated requirements to suppliers.
By 2031, they should have completed the highest-priority migration activities protecting the most critical assets, readied infrastructure for a post-quantum future, and refined the plan into a clear route to full migration.
By 2035, migration should be complete across all systems, services and products, with the NCSC acknowledging that a small set of rarely used technologies may prove harder to migrate by that date.
The guidance is aimed principally at technical decision-makers and risk owners in large organisations, critical national infrastructure operators including industrial control systems, and organisations with bespoke IT. For most small and medium organisations the NCSC expects migration to arrive through service and technology providers. The milestones are guidance rather than binding deadlines for most commercial organisations, though sector regulators may adopt them.
US: federal mandates after Executive Order 14412
The US position hardened substantially in June 2026. Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, was signed on 22 June 2026 and converted guidance into obligation.
Federal agencies must transition high value assets and high impact systems to NIST-approved post-quantum algorithms for key establishment by 31 December 2030, and for digital signatures by 31 December 2031. Agencies were required to designate a post-quantum migration lead within 30 days and submit migration plans within 90 days. NIST was directed to run a migration pilot on its own systems, to complete by 31 December 2027.
The provision with the widest reach is procurement. The FAR Council was directed to publish, within 180 days, a proposed rule requiring covered contractors to comply with applicable NIST FIPS including post-quantum algorithms by 31 December 2030. The order also mandates cryptographic bill of materials guidance and directs acceleration of the cryptographic module validation programme.
Two companion documents followed within days. The Department of War published a post-quantum strategy on 23 June 2026 requiring all its systems to support post-quantum cryptography or be phased out by the end of 2030, and to use it by the end of 2031, extending obligations across the defence industrial base. OMB Memorandum M-26-15, issued 24 June 2026, set the operational schedule for civilian agencies.
The practical significance for UK organisations is the contractor route. Post-quantum requirements now reach any supplier to US federal customers regardless of where it is established.
EU: the coordinated roadmap
The EU approach runs through the NIS Cooperation Group, which published a coordinated post-quantum roadmap in June 2025 following a European Commission recommendation in April 2024.
It sets three milestones: initial national transition roadmaps and first steps covering identification and awareness by 31 December 2026; high-risk use cases addressed, with resources allocated and post-quantum deployed by default, by 31 December 2030; and full transition as far as feasible by 31 December 2035. The roadmap places particular emphasis on standardised and tested hybrid solutions.
For regulated entities, obligations also arrive indirectly. DORA imposes ICT risk and third-party oversight requirements on financial entities, and NIS2 imposes supply chain security obligations on entities in scope, both of which increasingly encompass cryptographic dependency.
Other national positions

How the NIST post-quantum cryptography timeline compares with UK and EU dates

Where the guidance agrees and where it diverges
Agreement is broad on three points. The endpoint is 2035 in almost every jurisdiction. Discovery and inventory come first, and every framework treats them as the prerequisite rather than an optional preparatory step. And the NIST algorithms are the common technical basis, which means an organisation selecting ML-KEM and ML-DSA is aligned with the UK, US, EU, Canada and Australia simultaneously.
Divergence matters in three places. On dates before 2035 the frameworks differ by several years, and an organisation operating across jurisdictions must plan to the earliest applicable date rather than the average. On hybrid deployment, France and Germany treat hybrid as the required approach, while US guidance treats it as acceptable but not mandated. On enforceability, UK guidance remains advisory for most commercial organisations while US federal requirements are now binding and reach contractors.
The Chinese position is worth watching for interoperability rather than compliance reasons. If national standards adopt algorithms outside the NIST set, organisations operating in both markets face a dual-stack requirement rather than a single migration.
Planning against the NIST post-quantum cryptography timeline
Three practical conclusions follow for UK organisations.
Plan to 2031, not 2035. The NCSC expects highest-priority migration complete by then, US federal signature deadlines fall in the same year, and platform providers including Cloudflare, Google and Microsoft have set internal targets of 2029. Planning to the 2035 endpoint assumes the most favourable available date on every dimension.
Treat 2028 as the operative UK milestone. Discovery, inventory, supplier communication and an initial plan are all expected by then, and discovery is the longest single activity in most programmes, which places the start of that work inside the current planning cycle.
Identify which jurisdictions actually apply. Organisations supplying US federal customers, operating in the EU under DORA or NIS2, or subject to sector regulation should establish the earliest binding date across that set and plan to it. For many UK organisations the binding constraint will arrive through a customer contract rather than a domestic regulator.
How Unsung helps
Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.
We map regulatory obligations to the estate and build migration plans that meet the earliest applicable deadline, starting with the discovery and inventory work the NCSC expects by 2028 through our PKI health check and cryptographic bill of materials services, and continuing into target architecture and certificate lifecycle management delivery.
For the algorithms these frameworks specify, see our comparison of the NIST post-quantum algorithms.
Frequently asked questions
What is the NIST post-quantum cryptography timeline?
Are the NCSC 2035 dates legally binding in the UK?
Do US post-quantum requirements apply to UK companies?
Which country has the earliest post-quantum deadline?
Is hybrid cryptography required or optional?
How often does this guidance change?


