Quantum readiness is an evidence problem before it is a migration problem.
Before an organization can replace vulnerable cryptography, it must know where that cryptography is used, what it protects, which systems depend on it, and how a new mechanism behaves in production. Regulators have now put dates on that work.
Three tiers of obligation, and they are not equally binding
The single most useful analytical step for a security leader is separating enforceable mandates from authoritative guidance and from harmonisation targets. Programs get mis-scoped when all three are treated the same way.
Hard mandate
Binding deadlines with specified algorithms. Non-compliance carries procurement or legal consequence.
Authoritative guidance
Staged milestones from national cyber authorities. Not statute, but the expected standard of care.
Harmonisation target
Coordinated direction without binding enforcement yet. Often precedes national implementation.
Read the tier before the date
NIST IR 8547 remains an initial public draft. CNSSP 15 governs CNSA 2.0 for national security systems; EO 14412 and OMB M-26-15 set the current federal civilian schedule. Reviewed August 11, 2026.
What is already decided
Published dates in finalized instruments, not forecasts. The pressure on an enterprise programme comes from this column, not from a prediction about hardware.
FIPS 203, 204 and 205 finalized
ML-KEM, ML-DSA and SLH-DSA published as approved standards, concluding an eight-year evaluation. FIPS 206 (FN-DSA, based on FALCON) remains in preparation.
JUN 2026
Sets federal civilian deadlines: post-quantum key establishment by end of 2030 and digital signatures by end of 2031, and directs a FAR rule for covered contractors.
EU inventories initiated
Member states publish national PQC strategies and begin cryptographic inventories under the NIS Cooperation Group roadmap.
CNSA 2.0 acquisition gate
New acquisitions for national security systems must be CNSA 2.0 compliant unless otherwise noted, shaping requirements for vendors and integrators.
UK NCSC phase one
Discovery of cryptographic dependencies complete and a core migration plan in place.
First hard civilian deadline
Federal HVAs and high-impact systems transition key establishment; unsupported CNSA 2.0 equipment and services are phased out; EU critical infrastructure and Australia target transition.
Signatures and CNSA 2.0 use
Federal HVAs and high-impact systems transition digital signatures, and CNSA 2.0 algorithms are mandated for NSS use unless otherwise noted.
Full transition horizon
OMB targets remaining federal civilian systems, NSA intends all NSS to be quantum-resistant, and the UK and Canada target completion. NIST IR 8547 proposes disallowing 112-bit classical strength.
The risk clock is set by your data, not by a prediction of Q-day
You do not need a date for cryptographically relevant quantum computing to justify starting. The calculation uses inputs you already own.
Data lifetime plus migration time extends into the uncertainty window. Harvest-now-decrypt-later matters when encrypted information stays valuable long enough to be attacked in future, which makes data classification and retention primary readiness inputs rather than compliance afterthoughts.
Supporting PQC is not the same as using PQC
A library, server or application may support ML-KEM while a live session still negotiates a classical alternative. Readiness has to distinguish four separate states, and only the last one protects data.
Available
The component ships with a post-quantum implementation.
Configured
The mechanism is enabled in the effective configuration.
Negotiated
Both endpoints agree on it during handshake.
Observed
Verified in production behavior, not inferred from config.
Organize migration by horizons, not a single deadline
Each horizon answers a distinct question and produces a distinct output.
Baseline
Know where you stand. Discover quantum-vulnerable mechanisms, affected services, data lifetime, ownership and dependency gaps.
- Inventory scope and coverage
- HNDL exposure lens
- Vendor readiness questions
Coexistence
Prove what works together. Select bounded pilots, test hybrid options, observe negotiation and define rollback criteria.
- Interoperability testing
- Performance and operational impact
- Actual-use validation
Migration waves
Sequence change safely. Group systems by shared dependency, criticality, data lifetime and vendor readiness, then track intended state against evidence.
- Wave ownership
- Exit criteria
- Drift monitoring
Anchor every claim in a primary source
Final standards, policy, guidance and Qinsight interpretation are deliberately separated so every conclusion can be traced to the right level of authority.
FIPS 203
ML-KEM, key encapsulation
FIPS 204
ML-DSA, digital signatures
FIPS 205
SLH-DSA, hash-based signatures
FIPS 206
FN-DSA, based on FALCON
CNSA 2.0
Algorithm suite for national security systems
NIST IR 8547
Proposed transition schedule
EO 14412
Federal civilian PQC deadlines for HVAs and high-impact systems
EU NIS CG
Coordinated member-state implementation
Quantum readiness, answered
Direct answers grounded in standards, published timelines and practical migration constraints.
Nobody knows, and any specific date presented as certain should be treated with suspicion. The useful question is different: does your data need to stay confidential longer than your migration will take? If yes, the timeline debate does not change your decision.
It depends on jurisdiction and sector. CNSA 2.0 binds national security systems and their supply chain, with a January 2027 acquisition gate. Executive Order 14412 sets federal civilian deadlines of 2030 for key establishment and 2031 for signatures. The EU roadmap and UK NCSC guidance set milestones without direct statutory enforcement. Most private-sector organizations face requirements indirectly, through customer contracts and procurement flowdown.
Not yet. It was published as an initial public draft in November 2024 and proposes deprecating 112-bit classical security strength after 2030 and disallowing it after 2035. It is widely cited as though final. Treat it as strong directional guidance and plan against it, but understand the distinction if you are scoping a compliance obligation.
NIST finalized ML-KEM for key establishment, ML-DSA for signatures and SLH-DSA as a hash-based alternative. CNSA 2.0 specifies the higher parameter sets, ML-KEM-1024 and ML-DSA-87, for national security systems. Sequencing depends on where your vulnerable cryptography actually sits, which is a discovery question before it is an algorithm question.
Jurisdictions differ, and where they differ the stricter requirement governs. The EU permits hybrid approaches during transition and France's ANSSI has emphasized hybrid for critical infrastructure. Australia's ASD sets the hardest deadline, ending approval of RSA, ECDH and ECDSA after 2030, and treats hybrid schemes as permitted for interoperability but not recommended as an end state. Organizations operating across jurisdictions should plan for the stricter case.
There is no universal duration. The UK NCSC allocates roughly three years for discovery and initial planning, another three for priority migrations, and a 2035 completion horizon. Estate size, vendor readiness and long-lived hardware determine the actual schedule.
Regulatory content reviewed August, 2026.
Confirm obligations with counsel and the controlling instrument for your organization.
Start with evidence, not a countdown
Establish where vulnerable cryptography runs, what depends on it, and how long your data must stay protected.

