Q-Shield

Post-Quantum Cryptography Deadlines: Every Date in One Place, With Its Source

The post-quantum migration dates in chronological order, each with the document it comes from and who it applies to: FIPS 140-2 validation sunset in September 2026, the CNSA 2.0 timeline of 2027, RSA-2048 and ECC P-256 deprecated in 2030 under NIST IR 8547, federal high-priority systems by end of 2031 and all remaining systems by end of 2035. Policy dates, not a countdown.

Why one page for the dates

The post-quantum transition is governed by several documents from several bodies, each with its own dates and its own audience. The other pages in this series cite those dates where they are relevant: the CNSA 2.0 page covers the national security track, the RSA-2048 deprecation page explains deprecated versus disallowed, and the migration roadmap page shows how a plan is sequenced against them. This page does one job: list every date in chronological order, name its source, and say who it applies to.

Two rules apply throughout. First, every date here is timebound. It is accurate as of the dated document it comes from, and the issuing body can revise it. Second, none of these dates is a prediction of when a quantum computer will break anything. They are policy dates. The reasons for that distinction are covered at the end.

The dates in order

### September 2026: FIPS 140-2 validation sunsets

  • Source: NIST Cryptographic Module Validation Program transition schedule.
  • What it says: Validation under FIPS 140-2 sunsets in September 2026.
  • Who it applies to: Anyone whose procurement, certification or compliance position depends on using cryptographic modules with a current FIPS validation. In practice that is U.S. federal programs and the vendors who sell validated modules into them, plus private organizations whose own policies reference FIPS validation.
  • Why it is on a post-quantum list: It is not a post-quantum deadline in itself. It is the earliest date on this page, and it affects the same inventory of modules a post-quantum migration has to touch. If you are already cataloguing where validated modules sit, the same inventory serves both purposes.

### 2027: CNSA 2.0 timeline for U.S. national security systems

  • Source: NSA Commercial National Security Algorithm Suite 2.0.
  • What it says: CNSA 2.0 sets a 2027 timeline for U.S. national security systems.
  • Who it applies to: U.S. national security systems and the vendors who supply them. This is a distinct track from civilian federal guidance, with its own authority and its own algorithm suite.
  • Where to read more: CNSA 2.0 compliance requirements covers the algorithms it points at and how the track differs from the civilian one. This page does not restate contract-level obligations, and neither does that one.

### 2030: RSA-2048 and ECC P-256 deprecated under NIST IR 8547

  • Source: NIST IR 8547, Transition to Post-Quantum Cryptography Standards.
  • What it says: RSA-2048 and ECC P-256 are deprecated in 2030. Deprecated means still permitted but discouraged, with the expectation that a migration is under way.
  • Who it applies to: IR 8547 is NIST guidance for U.S. federal systems. It is also the document most private-sector planning references, because NIST standards are what vendors, auditors and customers tend to point at. Referencing it does not make it a legal obligation for a private company; that depends on the company's own regulators and contracts.
  • Where to read more: RSA-2048 deprecation timeline explains the deprecated-to-disallowed path in plain terms.

### End of 2031: high-priority, harvest-exposed federal systems migrated

  • Source: U.S. National Security Memorandum 10 and OMB Memorandum M-23-02 migration timelines.
  • What it says: U.S. federal guidance directs that high-priority, harvest-exposed systems be migrated by the end of 2031.
  • Who it applies to: U.S. federal agencies. "Harvest-exposed" refers to systems whose encrypted traffic could be recorded today and decrypted later, which is why the long-lived secrets move first. The harvest now, decrypt later page explains that threat model.
  • Why it matters beyond government: This is the first date in the sequence that ranks systems by exposure rather than treating them uniformly. That ranking logic is the same one any organization has to apply, whether or not the federal date binds it.

### End of 2035: all remaining federal systems migrated; classical algorithms disallowed

  • Source: The same federal guidance (NSM-10 and OMB M-23-02) for the migration target, and NIST IR 8547 for the algorithm status.
  • What it says: Two things converge on the same year. Federal guidance directs that all remaining systems be migrated by the end of 2035. Separately, IR 8547 disallows RSA-2048 and ECC P-256 after 2035, meaning they are no longer acceptable for the purpose under the guidance.
  • Who it applies to: The migration target applies to U.S. federal agencies. The disallowance is NIST guidance, read by the federal systems it governs and by the private organizations that plan against NIST standards.
  • Why it is the date most people quote: It is the latest date in the current set, so it reads as "the deadline." It is more accurate to treat it as the point after which the old algorithms are out of the standard, with earlier dates marking when the work was expected to start and when the priority systems were expected to finish.

Which track is yours

Three groups read these dates differently.

Suppliers to U.S. national security systems. Your starting document is CNSA 2.0 and your first date is 2027. The civilian dates still matter where your products also sell into civilian federal or commercial markets, but the national security track is the earlier and more specific one.

Civilian U.S. federal agencies and their contractors. Your dates are end of 2031 for high-priority, harvest-exposed systems and end of 2035 for everything else, with IR 8547 setting the algorithm status underneath. The practical implication of two dates is that you need an inventory ranked by exposure before you can tell which systems belong to which date.

Private organizations following NIST guidance. None of the dates above was written for you directly, and this page does not claim any of them is a legal obligation for a private company or for a specific industry. What is true is that IR 8547's 2030 deprecation and 2035 disallowance are the reference points most vendors, customers and auditors will use when they ask about your plan. If a regulator or contract in your sector imposes its own date, that document, not this page, is the authority.

Policy dates, not a countdown

It is worth being explicit about what these dates are not. None of them is an estimate of when a cryptographically relevant quantum computer, one capable of running Shor's algorithm against the key sizes in use today, will exist. That question is genuinely open. Researchers disagree, and no authoritative date exists.

The schedule exists anyway, for two reasons. Migrations of this size have historically taken many years, so the deadlines are set to get them finished with margin regardless of when, or whether on any particular timeline, the capability arrives. And under harvest now, decrypt later, data whose confidentiality must outlive the migration window is exposed today, because traffic recorded now can be decrypted once the capability exists. The dates are a response to that exposure, not a forecast of the threat.

So the right way to read this page is as a set of policy commitments by named bodies, each of which can be revised, none of which depends on a prediction about quantum hardware.

From a list of dates to a plan

A list of dates is only useful once it is matched against your own systems. That takes three steps, in order.

First, a cryptographic inventory: discovering where and how cryptography is used across your systems, because you cannot schedule a migration for systems you have not located. Second, ranking what you find. Q-Shield's five-axis quantum risk scoring (QRS) ranks each asset by exposure so the highest-risk, longest-lived secrets move first, which is the same logic the end-of-2031 federal date encodes. Third, a NIST-aligned migration roadmap that sequences the work toward ML-KEM, including a hybrid ECDH + ML-KEM key exchange where appropriate, against whichever of the dates above is yours.

The migration roadmap page covers how that sequencing works. This page's job ends with the dates and their sources. Check each source's current version before you commit a plan to it.

Turn the published dates into a sequenced plan for your own systems: Q-Shield's cryptographic inventory, five-axis QRS and NIST-aligned migration roadmap.

Get started