Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Post-Quantum Cryptography

The Deadlines That Already Bind Your Cryptography

Marin Ivezic7 min read

Two dates sit in front of most security executives right now, and only one of them has an institution behind it.

The first is Q-Day: the year a cryptographically relevant quantum computer (CRQC), a machine large and stable enough to recover an RSA-2048 private key, actually runs. Published estimates for that year run from the early 2030s to never, and the spread has not narrowed much in five years. It is a forecast, and forecasts move.

The second date is 2028. That is when the UK’s National Cyber Security Centre expects organizations to have completed cryptographic discovery and produced a costed migration plan. No physics has to cooperate for 2028 to arrive.

Your migration will be judged against the second kind of date.

The dates that are already published

Between 2022 and 2025, four authorities put post-quantum cryptography (PQC) migration milestones in writing. PQC is the family of algorithms designed to resist attack by a quantum computer. In August 2024, NIST standardized three of them: ML-KEM for key establishment (FIPS 203), ML-DSA for digital signatures (FIPS 204), and SLH-DSA as a hash-based signature alternative (FIPS 205). Those are the destinations the deadlines below point at.

AuthorityMilestoneDateSource document
EU NIS Cooperation GroupNational plans published, first transitions underwayEnd 2026A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, June 2025
UK NCSCDiscovery complete, costed migration plan in place2028Timelines for Migration to Post-Quantum Cryptography, March 2025
EU NIS Cooperation GroupHigh-risk use cases migratedEnd 2030A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, June 2025
UK NCSCHighest-priority systems migrated2031Timelines for Migration to Post-Quantum Cryptography, March 2025
Government of CanadaHigh-priority federal systems migratedEnd 2031Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada (ITSM.40.001), June 2025
United States (White House)Federal migration goal2035National Security Memorandum 10 (NSM-10), May 2022
UK NCSCMigration complete2035Timelines for Migration to Post-Quantum Cryptography, March 2025

Two features of that table matter more than the individual rows: how closely the four dates converge, and the vocabulary that compliance regimes bring with them.

Take the convergence first. Four authorities, working from different threat assessments and different legal instruments, landed inside the same five-year window. They did not do that because they share a Q-Day estimate. They did it because a full cryptographic transition across a large enterprise takes somewhere between five and ten years, and 2035 is what you get when you count backward from a plausible threat horizon and add the engineering.

The second feature is that these are compliance dates rather than forecasts. In NIST’s usage, set out in SP 800-131A Revision 2, a deprecated algorithm is still permitted but carries a documented warning, and a disallowed algorithm may not be used at all. Auditors read those words literally, and an RSA-2048 certificate that draws no comment while the algorithm is merely deprecated becomes a finding once it is disallowed, whatever any quantum computer is or is not doing that year.

Why 2035 is not a 2034 problem

Encrypted traffic captured today can be stored and decrypted later, once the capability exists. The industry calls this harvest now, decrypt later, or HNDL, and it moves your effective deadline earlier by the confidentiality lifetime of whatever you are protecting.

The arithmetic is unforgiving and it is also simple. Subtract from the year your data stops being sensitive the number of years it stays sensitive, then subtract again the number of years your migration will take. Health records with a forty-year duty of care, sealed legal filings, source code, key material embedded in shipped hardware: for all of these the answer to “when should we have started” is already in the past.

The regulatory dates and the data shelf-life calculation answer different questions, and a migration plan needs both: the dates tell you when you will be measured, and the shelf-life map tells you which systems to move first.

The deadline your customers set

Regulators publish. Customers negotiate, which is quieter and often faster.

Cryptographic requirements are appearing in three places in commercial agreements. Procurement questionnaires now ask suppliers whether their products support NIST-standardized algorithms and whether a migration plan exists. Contract language increasingly requires the ability to change algorithms during the term rather than at renewal. And RFPs in regulated sectors are starting to specify hybrid modes, where a classical and a post-quantum algorithm run together so that the connection is safe if either one holds.

The financial sector moved first here, as it usually does. The Financial Services Information Sharing and Analysis Center (FS-ISAC) post-quantum cryptography working group set out supplier questions of exactly this kind in Preparing for a Post-Quantum World by Managing Cryptographic Risk, which means the questions arrive pre-written and standardized rather than one bank at a time.

If you sell software, hardware, or a managed service into a regulated buyer, you inherit their 2030 or their 2031. The date on your calendar is set by the earliest deadline among your customers, not by your own risk assessment.

The deadline underwriters and courts will set

This one is not in force yet.

What is established: the standards exist, the deadlines are public, and the threat model is documented by national agencies in four jurisdictions. That combination is what lawyers call foreseeability. It is the difference between a risk nobody could reasonably have anticipated and a risk everyone was told about in writing.

What follows from it is a reasonable expectation rather than a certainty. Cyber insurers price against documented, foreseeable risk, and renewal questionnaires historically pick up new questions within a year or two of a control becoming standard practice. “Do you maintain a cryptographic inventory” is a question an underwriter can ask today and score consistently, which makes it a likely candidate. Organizations able to answer it with evidence will be in a different pricing conversation from those that cannot.

The same logic applies to a dispute in 2032 over data exfiltrated in 2026. Nobody will be asked whether they predicted Q-Day correctly. They will be asked what a comparable organization knew in 2026 and what it did.

What ready means when the question arrives

Whether the question comes from an auditor, a client, or an underwriter, it resolves to five artifacts.

A named owner. One accountable executive, with the migration on their objectives. Programs without an owner produce inventories and stop.

A cryptographic inventory. Every place your organization uses cryptography, what algorithm, what key length, in which system, protecting what data. The structured form of this is a cryptographic bill of materials, or CBOM, which records cryptographic dependencies the way a software bill of materials (SBOM) records software components. Most organizations discover during this step that they have more certificate authorities and more embedded keys than anyone believed.

A data shelf-life map. Which data sets are still sensitive in 2035, 2040, 2050. This is what turns an inventory into a priority order.

Crypto-agility. The ability to change a cryptographic algorithm without re-engineering the system around it. The current transition is not the last one, and the organizations that build the mechanism now pay for it once.

Evidence. Dated documents. A board briefing, a funded roadmap, a risk register entry, a plan with milestones. The artifact that answers the foreseeability question is a paper trail, not a good intention.

Building the capability

None of the five artifacts above is produced by a tool purchase. Each one requires people who can read a NIST standard, tell a physical qubit count from a logical one, recognize where a protocol hides a key exchange, and explain the priority order to a CFO without either alarming or boring them.

That capability is what our certification programs are built to produce, and it is why we assess against migration governance rather than quantum theory. Credential holders finish able to run the discovery, defend the sequencing, and answer the client questionnaire. You can see the current programs and enrollment windows at Quantum Academy.

For the methodology behind the migration itself, the PQC Framework sets out the phased approach in full. For deeper technical background on the threat model and the standards, PostQuantum.com covers both in detail.

The Q-Day debate will continue, and it should. It just is not the debate that determines what your organization has to have finished by 2028.