Home
/
Quantum readiness
Post-quantum readiness

Quantum readiness is an
evidence problem
before it is a migration problem.

Before an organization can replace vulnerable cryptography, it must know where that cryptography is used, what it protects, which systems depend on it, and how a new mechanism behaves in production. Regulators have now put dates on that work.

Plan a discovery pilot
See how discovery works
FIPS 203 / 204 / 205
final Aug 13, 2024
EO 14412
signed Jun 22, 2026
CNSA 2.0
new NSS acquisitions Jan 1, 2027
EU roadmap
inventories by end 2026
FIPS 203 / 204 / 205
final Aug 13, 2024
EO 14412
signed Jun 22, 2026
CNSA 2.0
new NSS acquisitions Jan 1, 2027
EU roadmap
inventories by end 2026
The regulatory landscape

Three tiers of obligation, and they are not equally binding

The single most useful analytical step for a security leader is separating enforceable mandates from authoritative guidance and from harmonisation targets. Programs get mis-scoped when all three are treated the same way.

Tier 1

Hard mandate

Binding deadlines with specified algorithms. Non-compliance carries procurement or legal consequence.

CNSA 2.0
EO 14412
OMB M-26-15
Tier 2

Authoritative guidance

Staged milestones from national cyber authorities. Not statute, but the expected standard of care.

UK NCSC
Canada CCCS
ANSSI
Tier 3

Harmonisation target

Coordinated direction without binding enforcement yet. Often precedes national implementation.

EU NIS CG
G7 CEG
FINRA

Read the tier before the date

NIST IR 8547 remains an initial public draft. CNSSP 15 governs CNSA 2.0 for national security systems; EO 14412 and OMB M-26-15 set the current federal civilian schedule. Reviewed August 11, 2026.

The schedule

What is already decided

Published dates in finalized instruments, not forecasts. The pressure on an enterprise programme comes from this column, not from a prediction about hardware.

AUG 2024

FIPS 203, 204 and 205 finalized

ML-KEM, ML-DSA and SLH-DSA published as approved standards, concluding an eight-year evaluation. FIPS 206 (FN-DSA, based on FALCON) remains in preparation.

Executive Order 14412 signed

JUN 2026

Sets federal civilian deadlines: post-quantum key establishment by end of 2030 and digital signatures by end of 2031, and directs a FAR rule for covered contractors.

END 2026

EU inventories initiated

Member states publish national PQC strategies and begin cryptographic inventories under the NIS Cooperation Group roadmap.

JAN 2027

CNSA 2.0 acquisition gate

New acquisitions for national security systems must be CNSA 2.0 compliant unless otherwise noted, shaping requirements for vendors and integrators.

2028

UK NCSC phase one

Discovery of cryptographic dependencies complete and a core migration plan in place.

2030

First hard civilian deadline

Federal HVAs and high-impact systems transition key establishment; unsupported CNSA 2.0 equipment and services are phased out; EU critical infrastructure and Australia target transition.

2031

Signatures and CNSA 2.0 use

Federal HVAs and high-impact systems transition digital signatures, and CNSA 2.0 algorithms are mandated for NSS use unless otherwise noted.

2035

Full transition horizon

OMB targets remaining federal civilian systems, NSA intends all NSS to be quantum-resistant, and the UK and Canada target completion. NIST IR 8547 proposes disallowing 112-bit classical strength.

Why now

The risk clock is set by your data, not by a prediction of Q-day

You do not need a date for cryptographically relevant quantum computing to justify starting. The calculation uses inputs you already own.

Data value lifetime
How long must confidentiality hold? Organization-specific
+
Migration lead time
Discovery, pilots, dependencies, rollout. Multi-year
>
Quantum uncertainty window
When attack becomes plausible.
Unknown
Act now when

Data lifetime plus migration time extends into the uncertainty window. Harvest-now-decrypt-later matters when encrypted information stays valuable long enough to be attacked in future, which makes data classification and retention primary readiness inputs rather than compliance afterthoughts.

Deployment is not readiness

Supporting PQC is not the same as using PQC

A library, server or application may support ML-KEM while a live session still negotiates a classical alternative. Readiness has to distinguish four separate states, and only the last one protects data.

CAPABILITY

Available

The component ships with a post-quantum implementation.

CONFIGURATION

Configured

The mechanism is enabled in the effective configuration.

NEGOTIATION

Negotiated

Both endpoints agree on it during handshake.

STATE 04

Observed

Verified in production behavior, not inferred from config.

A governed transition

Organize migration by horizons, not a single deadline

Each horizon answers a distinct question and produces a distinct output.

NOW

Baseline

Know where you stand. Discover quantum-vulnerable mechanisms, affected services, data lifetime, ownership and dependency gaps.

  • Inventory scope and coverage
  • HNDL exposure lens
  • Vendor readiness questions
NEXT

Coexistence

Prove what works together. Select bounded pilots, test hybrid options, observe negotiation and define rollback criteria.

  • Interoperability testing
  • Performance and operational impact
  • Actual-use validation
THEN

Migration waves

Sequence change safely. Group systems by shared dependency, criticality, data lifetime and vendor readiness, then track intended state against evidence.

  • Wave ownership
  • Exit criteria
  • Drift monitoring
Standards desk

Anchor every claim in a primary source

Final standards, policy, guidance and Qinsight interpretation are deliberately separated so every conclusion can be traced to the right level of authority.

Final

FIPS 203

ML-KEM, key encapsulation

Aug 13, 2024
Final

FIPS 204

ML-DSA, digital signatures

Aug 13, 2024
Final

FIPS 205

SLH-DSA, hash-based signatures

Aug 13, 2024
In preparation

FIPS 206

FN-DSA, based on FALCON

Not yet published
NSA policy

CNSA 2.0

Algorithm suite for national security systems

ML-KEM-1024 · ML-DSA-87 · LMS/XMSS
Initial draft

NIST IR 8547

Proposed transition schedule

Not binding
Mandate

EO 14412

Federal civilian PQC deadlines for HVAs and high-impact systems

Jun 22, 2026
Roadmap

EU NIS CG

Coordinated member-state implementation

Published Jun 2025
Common questions

Quantum readiness, answered

Direct answers grounded in standards, published timelines and practical migration constraints.

01
When will quantum computers break RSA?
02
Is post-quantum migration legally required?
03
Is NIST IR 8547 binding?
04
Which algorithms should we migrate to?
05
Do we need hybrid or pure post-quantum?
06
How long does enterprise migration take?
Research note

Regulatory content reviewed August, 2026.

Confirm obligations with counsel and the controlling instrument for your organization.

Start with evidence, not a countdown

Establish where vulnerable cryptography runs, what depends on it, and how long your data must stay protected.