Q-Shield
RSA-2048 Deprecation Timeline: What NIST IR 8547 Says and What It Does Not
NIST IR 8547 deprecates RSA-2048 and ECC P-256 in 2030 and disallows them after 2035. What deprecated and disallowed mean in plain terms, why the dates are policy deadlines rather than a prediction of when RSA breaks, and which standards replace them.
The literal answer
NIST IR 8547, the Transition to Post-Quantum Cryptography Standards report, lays out a schedule for retiring the public-key algorithms that a quantum computer could eventually break. For the two algorithms most organizations rely on today, the schedule is:
- RSA-2048 and ECC P-256 are deprecated in 2030.
- Both are disallowed after 2035.
Two things about that answer matter as much as the dates themselves. First, this comes from a dated NIST transition document. It is current guidance, not a law of nature, and NIST can revise it. When you plan against these dates, cite the document and the version you read. Second, the dates say nothing about when RSA-2048 will actually be broken. That point is covered below, because it is the one most often misread.
Deprecated versus disallowed, in plain terms
The two words describe two different states, and the difference is practical.
Deprecated means you may still use the algorithm, but the guidance is telling you to stop. Continued use is tolerated during the transition, with the understanding that you are carrying a known risk and should have a plan to remove it. Think of it as a yellow light: legal to proceed, but you are expected to be moving toward the exit.
Disallowed means the algorithm is no longer acceptable for that purpose under the guidance. Systems that still depend on it are out of compliance with the standard, and in regulated environments that can mean audit findings, failed certifications, or contractual problems. This is the red light.
The years between the two states, from 2030 to 2035, are the window in which NIST expects migrations to be completed. The deprecation date is the signal to be well under way; the disallowed date is when the door closes.
Why the schedule exists
RSA-2048 and ECC P-256 are both public-key algorithms whose security rests on mathematical problems that are hard for classical computers: factoring for RSA, the discrete logarithm for elliptic-curve cryptography. Shor's algorithm, if run on a sufficiently capable quantum computer, solves both of those problems efficiently. That is the threat the transition is designed to get ahead of.
Here is the part that is routinely misstated. The arrival of a cryptographically relevant quantum computer, one large and reliable enough to run Shor's algorithm against real key sizes, is uncertain. Researchers disagree about when it might happen, and no authoritative date exists. The IR 8547 dates are not a prediction of that event. They are policy deadlines, chosen to give organizations enough runway to finish a migration that historically takes many years, with margin before any such machine could appear.
There is a second reason the deadlines come before the machine does. Under harvest now, decrypt later, an adversary can record encrypted traffic today and decrypt it later once a quantum capability exists. Data whose confidentiality must outlive the migration window is therefore exposed now, not at some future date. That is why NIST set the schedule rather than waiting for the threat to materialize and reacting then.
So the honest framing is: nobody knows when, or whether on any particular timeline, RSA-2048 will fall to a quantum computer. What is known is that the transition takes long enough that starting late is the real risk, and NIST has put a schedule on it.
What replaces them
RSA-2048 and ECC P-256 do two different jobs, and the replacements are split the same way.
Key establishment, where two parties agree on a shared secret over an untrusted channel, moves to ML-KEM, standardized as FIPS 203 and published by NIST in August 2024. Where it fits, a hybrid ECDH + ML-KEM key exchange is a common interim step that keeps a classical component alongside the post-quantum one. See What Is ML-KEM (FIPS 203)? for how the standard is built.
Digital signatures, where you prove who sent something and that it was not altered, move to ML-DSA (FIPS 204) and SLH-DSA (FIPS 205). ML-DSA is the general-purpose lattice-based option; SLH-DSA is a stateless hash-based scheme built on different mathematics for teams that want that diversity.
A single system often uses RSA or P-256 for both jobs, in TLS handshakes, in certificate chains, in code signing, in token signing. Each use has to be classified before you know which replacement applies.
The practical first step
The schedule is clear. The hard part is that most organizations cannot say with confidence where RSA-2048 and ECC P-256 are actually in use. Cryptography is embedded in libraries, certificates, hardware tokens, vendor appliances, and long-forgotten internal services, and the list is almost always longer than the team expects.
That makes cryptographic inventory the first concrete step toward meeting the IR 8547 dates: discovering where and how cryptography is used across your systems, because you cannot migrate what you have not located. Q-Shield performs that inventory so the deprecation schedule above becomes a list of specific systems with owners, rather than a date on a calendar. From there, a NIST-aligned migration roadmap can sequence the work toward ML-KEM and the signature standards.
The deadline is published. The threat timing is uncertain. The one variable you fully control is how early you know what you have.
Find out where RSA-2048 and ECC P-256 are still in use across your systems with a Q-Shield cryptographic inventory.
Get started