Deadline tracker // updated Jul 2026

Every PQC deadline, on one clock.

The dates below are taken from the published texts — each labeled by legal weight, so draft guidance is never dressed up as binding law. PQCA’s compliance engine tracks these same mandates against your live inventory, per control, with evidence.

EU CRA
Reporting obligations apply

Manufacturers must report actively exploited vulnerabilities and severe incidents — the CRA’s first binding obligations.

11 Sep 2026
Binding · EU
FIPS 140-2
Legacy validated modules move to Historical

FIPS 140-2 modules leave the active list — procurement against them ends for US federal systems.

21 Sep 2026
Binding · US
EU CRA
Cyber Resilience Act core obligations apply

Products with digital elements sold in the EU carry security and vulnerability-handling obligations — cryptographic hygiene included.

11 Dec 2027
Binding · EU
CNSA 2.0
Operating systems support and prefer CNSA 2.0

NSA guidance expects operating systems in national-security service to support and prefer CNSA 2.0 algorithms (ML-KEM, ML-DSA) by end-2027.

31 Dec 2027
Guidance · US NSS
UK NCSC
Discovery complete, migration plan in hand

NCSC’s published timeline expects full cryptographic discovery and a funded transition plan by 2028.

31 Dec 2028
Guidance · UK
NIST IR 8547
112-bit classical security deprecated

Under NIST’s initial public draft, RSA-2048-class security moves to deprecated status — permitted, but flagged, ahead of the proposed 2035 disallow.

31 Dec 2030
Draft · Global
EU roadmap
High-risk use cases quantum-safe

The EU coordinated PQC roadmap expects high-risk systems migrated by the end of 2030.

31 Dec 2030
Guidance · EU
UK NCSC
Highest-priority migrations complete

The most critical cryptography — long-shelf-life data, root keys, CA infrastructure — migrated by 2031.

31 Dec 2031
Guidance · UK
CNSA 2.0
Full transition for national-security systems

NSA’s completion target: CNSA 2.0 as the baseline across NSS, with classical-only deployments needing explicit waivers.

1 Jan 2033
Guidance · US NSS
NIST IR 8547
112-bit security disallowed

Proposed in NIST’s initial public draft: RSA-2048-class cryptography disallowed for US federal use — the anchor date most global programs plan against.

31 Dec 2035
Draft · Global
UK NCSC
Migration complete across the estate

All remaining systems quantum-safe by 2035 under the NCSC timeline.

31 Dec 2035
Guidance · UK
MENA
UAE · Saudi NCA · CBJ supervisory reviews

Gulf and Jordanian supervisors are folding cryptographic inventories and PQC transition roadmaps into reviews on rolling, institution-specific timelines.

Rolling
Guidance · MENA

Dates reflect published standards and mandates as of July 2026 and are reviewed as texts evolve. Binding entries carry direct legal or procurement force for the named scope; guidance entries are published national timelines; draft entries come from NIST IR 8547’s initial public draft and remain proposed. None of this is legal advice — map your own obligations in a briefing.