Blog

Post Quantum Cryptography Regulations

The NIST post quantum cryptography timeline, NCSC milestones and EU roadmap compared, with the US federal deadlines that now reach contractors too.

Comparing post-quantum cryptography guidance by nation

National guidance converges on 2035 for full migration and diverges sharply before that. The UK expects discovery complete by 2028 and priority migration by 2031. US federal deadlines are 2030 for key establishment and 2031 for signatures. Australia is earliest at 2030 for asymmetric retirement.

What the NIST post-quantum cryptography timeline requires

NIST published the first three post-quantum standards on 13 August 2024: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA signatures and FIPS 205 for SLH-DSA signatures.

The transition schedule sits in NIST IR 8547, which sets out when quantum-vulnerable algorithms lose approved status. RSA, ECDSA, ECDH, DSA and finite-field Diffie-Hellman are deprecated after 2030, meaning use is permitted but discouraged and must be risk-accepted, and disallowed after 2035, meaning use is no longer permitted for federal systems.

A separate and more demanding requirement applies to US national security systems through the NSA's CNSA 2.0 suite, which mandates ML-KEM-1024, ML-DSA-87, AES-256 and SHA-384 or SHA-512, with LMS and XMSS for software and firmware signing.

UK: the NCSC migration timelines

The NCSC published Timelines for migration to post-quantum cryptography on 20 March 2025, its first dedicated migration timeline document. It sets three milestones.

By 2028, organisations should have defined migration goals, completed a full discovery exercise across services and infrastructure, built an initial migration plan identifying highest-priority activities, supplier and physical infrastructure dependencies, required investment and any long-lived hardware roots of trust, and communicated requirements to suppliers.

By 2031, they should have completed the highest-priority migration activities protecting the most critical assets, readied infrastructure for a post-quantum future, and refined the plan into a clear route to full migration.

By 2035, migration should be complete across all systems, services and products, with the NCSC acknowledging that a small set of rarely used technologies may prove harder to migrate by that date.

The guidance is aimed principally at technical decision-makers and risk owners in large organisations, critical national infrastructure operators including industrial control systems, and organisations with bespoke IT. For most small and medium organisations the NCSC expects migration to arrive through service and technology providers. The milestones are guidance rather than binding deadlines for most commercial organisations, though sector regulators may adopt them.

US: federal mandates after Executive Order 14412

The US position hardened substantially in June 2026. Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, was signed on 22 June 2026 and converted guidance into obligation.

Federal agencies must transition high value assets and high impact systems to NIST-approved post-quantum algorithms for key establishment by 31 December 2030, and for digital signatures by 31 December 2031. Agencies were required to designate a post-quantum migration lead within 30 days and submit migration plans within 90 days. NIST was directed to run a migration pilot on its own systems, to complete by 31 December 2027.

The provision with the widest reach is procurement. The FAR Council was directed to publish, within 180 days, a proposed rule requiring covered contractors to comply with applicable NIST FIPS including post-quantum algorithms by 31 December 2030. The order also mandates cryptographic bill of materials guidance and directs acceleration of the cryptographic module validation programme.

Two companion documents followed within days. The Department of War published a post-quantum strategy on 23 June 2026 requiring all its systems to support post-quantum cryptography or be phased out by the end of 2030, and to use it by the end of 2031, extending obligations across the defence industrial base. OMB Memorandum M-26-15, issued 24 June 2026, set the operational schedule for civilian agencies.

The practical significance for UK organisations is the contractor route. Post-quantum requirements now reach any supplier to US federal customers regardless of where it is established.

EU: the coordinated roadmap

The EU approach runs through the NIS Cooperation Group, which published a coordinated post-quantum roadmap in June 2025 following a European Commission recommendation in April 2024.

It sets three milestones: initial national transition roadmaps and first steps covering identification and awareness by 31 December 2026; high-risk use cases addressed, with resources allocated and post-quantum deployed by default, by 31 December 2030; and full transition as far as feasible by 31 December 2035. The roadmap places particular emphasis on standardised and tested hybrid solutions.

For regulated entities, obligations also arrive indirectly. DORA imposes ICT risk and third-party oversight requirements on financial entities, and NIS2 imposes supply chain security obligations on entities in scope, both of which increasingly encompass cryptographic dependency.

Other national positions

How the NIST post-quantum cryptography timeline compares with UK and EU dates

Where the guidance agrees and where it diverges

Agreement is broad on three points. The endpoint is 2035 in almost every jurisdiction. Discovery and inventory come first, and every framework treats them as the prerequisite rather than an optional preparatory step. And the NIST algorithms are the common technical basis, which means an organisation selecting ML-KEM and ML-DSA is aligned with the UK, US, EU, Canada and Australia simultaneously.

Divergence matters in three places. On dates before 2035 the frameworks differ by several years, and an organisation operating across jurisdictions must plan to the earliest applicable date rather than the average. On hybrid deployment, France and Germany treat hybrid as the required approach, while US guidance treats it as acceptable but not mandated. On enforceability, UK guidance remains advisory for most commercial organisations while US federal requirements are now binding and reach contractors.

The Chinese position is worth watching for interoperability rather than compliance reasons. If national standards adopt algorithms outside the NIST set, organisations operating in both markets face a dual-stack requirement rather than a single migration.

Planning against the NIST post-quantum cryptography timeline

Three practical conclusions follow for UK organisations.

Plan to 2031, not 2035. The NCSC expects highest-priority migration complete by then, US federal signature deadlines fall in the same year, and platform providers including Cloudflare, Google and Microsoft have set internal targets of 2029. Planning to the 2035 endpoint assumes the most favourable available date on every dimension.

Treat 2028 as the operative UK milestone. Discovery, inventory, supplier communication and an initial plan are all expected by then, and discovery is the longest single activity in most programmes, which places the start of that work inside the current planning cycle.

Identify which jurisdictions actually apply. Organisations supplying US federal customers, operating in the EU under DORA or NIS2, or subject to sector regulation should establish the earliest binding date across that set and plan to it. For many UK organisations the binding constraint will arrive through a customer contract rather than a domestic regulator.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services, nuclear and transport.

We map regulatory obligations to the estate and build migration plans that meet the earliest applicable deadline, starting with the discovery and inventory work the NCSC expects by 2028 through our PKI health check and cryptographic bill of materials services, and continuing into target architecture and certificate lifecycle management delivery.

For the algorithms these frameworks specify, see our comparison of the NIST post-quantum algorithms.

Frequently asked questions

What is the NIST post-quantum cryptography timeline?

NIST published FIPS 203, 204 and 205 on 13 August 2024. Under NIST IR 8547, RSA, ECDSA, ECDH, DSA and finite-field Diffie-Hellman are deprecated after 2030 and disallowed after 2035 for US federal systems. Executive Order 14412 additionally requires agency migration of key establishment by 2030 and signatures by 2031.

Are the NCSC 2035 dates legally binding in the UK?

Not for most commercial organisations. The NCSC timelines are guidance aimed at large organisations, critical national infrastructure operators and those with bespoke IT. Sector regulators may adopt them, and contractual obligations from customers, particularly US federal ones, may impose binding requirements earlier.

Do US post-quantum requirements apply to UK companies?

They can, through procurement. Executive Order 14412 directed the FAR Council to propose a rule requiring covered contractors to comply with post-quantum FIPS by 31 December 2030, and the Department of War strategy extends requirements across the defence industrial base. Suppliers to US federal customers should expect these terms regardless of where they are established.

Which country has the earliest post-quantum deadline?

Australia. The Australian Signals Directorate has advised ceasing use of traditional asymmetric cryptography by 2030, ahead of the 2035 endpoint adopted by the UK, US, EU and Canada. US federal deadlines of 2030 for key establishment and 2031 for signatures are close behind for systems in scope.

Is hybrid cryptography required or optional?

It depends on jurisdiction. France's ANSSI and Germany's BSI treat hybrid deployment as the required approach during transition, and the EU roadmap emphasises standardised hybrid solutions. US guidance permits hybrid without mandating it. Most current deployments use hybrid key establishment regardless.

How often does this guidance change?

Frequently. The US position changed materially three times between June 2025 and June 2026, ending with binding deadlines and contractor obligations. Any migration plan should be reviewed at least annually against current published guidance rather than the version it was written to.
Author
Unsung Ltd
September 28, 2026
-