Every PQC deadline, on one clock.
The dates below are taken from the published texts — each labeled by legal weight, so draft guidance is never dressed up as binding law. PQCA’s compliance engine tracks these same mandates against your live inventory, per control, with evidence.
Manufacturers must report actively exploited vulnerabilities and severe incidents — the CRA’s first binding obligations.
Binding · EU
FIPS 140-2 modules leave the active list — procurement against them ends for US federal systems.
Binding · US
Products with digital elements sold in the EU carry security and vulnerability-handling obligations — cryptographic hygiene included.
Binding · EU
NSA guidance expects operating systems in national-security service to support and prefer CNSA 2.0 algorithms (ML-KEM, ML-DSA) by end-2027.
Guidance · US NSS
NCSC’s published timeline expects full cryptographic discovery and a funded transition plan by 2028.
Guidance · UK
Under NIST’s initial public draft, RSA-2048-class security moves to deprecated status — permitted, but flagged, ahead of the proposed 2035 disallow.
Draft · Global
The EU coordinated PQC roadmap expects high-risk systems migrated by the end of 2030.
Guidance · EU
The most critical cryptography — long-shelf-life data, root keys, CA infrastructure — migrated by 2031.
Guidance · UK
NSA’s completion target: CNSA 2.0 as the baseline across NSS, with classical-only deployments needing explicit waivers.
Guidance · US NSS
Proposed in NIST’s initial public draft: RSA-2048-class cryptography disallowed for US federal use — the anchor date most global programs plan against.
Draft · Global
All remaining systems quantum-safe by 2035 under the NCSC timeline.
Guidance · UK
Gulf and Jordanian supervisors are folding cryptographic inventories and PQC transition roadmaps into reviews on rolling, institution-specific timelines.
Guidance · MENA
Dates reflect published standards and mandates as of July 2026 and are reviewed as texts evolve. Binding entries carry direct legal or procurement force for the named scope; guidance entries are published national timelines; draft entries come from NIST IR 8547’s initial public draft and remain proposed. None of this is legal advice — map your own obligations in a briefing.