Nobody knows exactly when a quantum computer will break RSA or elliptic-curve encryption. But governments have stopped waiting for an answer and started setting deadlines.
Why there are deadlines at all
Replacing encryption across an organisation takes years, and data stolen today can be decrypted later. So governments work backwards: they set target dates that make sure systems are upgraded well before the risk becomes real.
United States: NIST
In November 2024, NIST published a draft transition plan, NIST IR 8547. It proposes that widely used quantum-vulnerable algorithms offering 112-bit security, such as RSA-2048, be deprecated after 2030, and that all quantum-vulnerable public-key algorithms be disallowed after 2035. Deprecated means allowed but discouraged; disallowed means no longer acceptable for US federal use.
United States: NSA CNSA 2.0
For national security systems, the NSA’s Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), announced in 2022, sets faster targets:
| System type | Support and prefer PQC by | Use PQC exclusively by |
|---|---|---|
| Software and firmware signing | 2025 | 2030 |
| Web browsers, servers and cloud services | 2025 | 2033 |
| Traditional networking equipment (e.g. VPNs, routers) | 2026 | 2030 |
| Operating systems | 2027 | 2033 |
The overall US goal, set in National Security Memorandum 10 (2022), is to protect national security systems against quantum attack by 2035.
United Kingdom: NCSC
In March 2025, the UK National Cyber Security Centre published three milestones:
- ◆By 2028: define migration goals, complete discovery of where cryptography is used, and build an initial plan.
- ◆By 2031: complete the highest-priority migrations and refine the plan.
- ◆By 2035: complete migration to post-quantum cryptography across all systems.
European Union
In April 2024, the European Commission recommended that EU member states coordinate a common post-quantum roadmap. The resulting roadmap, published in June 2025, asks member states to start transitioning by the end of 2026, protect high-risk systems by 2030, and migrate as many systems as feasible by 2035.
What this means for private companies
Most of these rules apply directly to government systems. But suppliers to government, banks, telecoms firms and anyone whose customers ask about quantum risk will feel them too.
task_altKey takeaways
- check_circleNIST proposes deprecating RSA-2048-level algorithms after 2030 and disallowing all after 2035.
- check_circleCNSA 2.0 sets 2030–2033 deadlines for US national security systems.
- check_circleThe UK NCSC milestones are 2028, 2031 and 2035; the EU roadmap uses 2026, 2030 and 2035.
Sources and further reading
- open_in_newNIST IR 8547 (draft): Transition to post-quantum cryptography standards
- open_in_newNSA: Announcing the Commercial National Security Algorithm Suite 2.0
- open_in_newUK NCSC: Timelines for migration to post-quantum cryptography
- open_in_newEU: Coordinated implementation roadmap for the transition to PQC