[
  {
    "slug": "nist-ir-8547",
    "name": "NIST IR 8547: U.S. federal deprecation timeline",
    "body": "NIST (U.S.)",
    "date": "Initial public draft 2024-11-12",
    "status": "Draft (final pending as of 2026-09)",
    "summary": "NIST IR 8547 sets the U.S. federal timeline for retiring quantum-vulnerable public-key cryptography: RSA, ECDSA, EdDSA, ECDH, and finite-field DH at 112-bit security are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035.",
    "milestones": [
      [
        "2030",
        "Quantum-vulnerable algorithms at 112-bit security (RSA-2048, P-256, and similar) deprecated"
      ],
      [
        "2035",
        "All quantum-vulnerable public-key algorithms disallowed for U.S. federal use"
      ]
    ],
    "notes": [
      "Hybrid modes that combine an approved post-quantum algorithm with a classical one are not caught by the 2035 disallowance.",
      "Applies to federal information systems via FIPS 140-3 and SP 800-131A; widely used as the de facto industry timeline."
    ],
    "url": "https://csrc.nist.gov/pubs/ir/8547/ipd",
    "page": "https://pqaudit.org/timelines/nist-ir-8547/"
  },
  {
    "slug": "cnsa-2-0",
    "name": "CNSA 2.0: U.S. National Security Systems",
    "body": "NSA (U.S. National Security Agency)",
    "date": "2022-09-07 (algorithm list updated 2025-05)",
    "status": "In force",
    "summary": "CNSA 2.0 is the NSA's required algorithm suite for U.S. National Security Systems. It mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware signing, AES-256, and SHA-384/512, with a phased timeline that starts in 2025 and ends with exclusive post-quantum use by 2035. From 2027-01-01 all new NSS acquisitions must be CNSA 2.0 compliant.",
    "milestones": [
      [
        "2025",
        "Software and firmware signing, web browsers, servers, and cloud services: support and prefer CNSA 2.0"
      ],
      [
        "2026",
        "Traditional networking equipment (VPNs, routers): support and prefer CNSA 2.0"
      ],
      [
        "2027-01-01",
        "All new National Security System acquisitions must be CNSA 2.0 compliant"
      ],
      [
        "2030",
        "Software/firmware signing and networking equipment: exclusive CNSA 2.0 use"
      ],
      [
        "2033",
        "Operating systems, browsers, servers, cloud services, custom applications: exclusive CNSA 2.0 use"
      ],
      [
        "2035",
        "All National Security Systems quantum-resistant"
      ]
    ],
    "notes": [
      "Required algorithms: ML-KEM-1024 (FIPS 203), ML-DSA-87 (FIPS 204), LMS and XMSS (SP 800-208) for firmware signing, AES-256, SHA-384 or SHA-512.",
      "Hybrid schemes are allowed for interoperability but the post-quantum component must be CNSA 2.0 compliant."
    ],
    "url": "https://media.defense.gov/2022/Sep/07/2003071834/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS_.PDF",
    "page": "https://pqaudit.org/timelines/cnsa-2-0/"
  },
  {
    "slug": "eu-pqc-roadmap",
    "name": "EU Coordinated Implementation Roadmap for PQC",
    "body": "European Commission / NIS Cooperation Group, with ENISA",
    "date": "2025-06-23",
    "status": "Adopted",
    "summary": "The EU's coordinated roadmap, published 2025-06-23, asks all member states to start transitioning by the end of 2026, to secure high-risk systems and critical infrastructure with post-quantum cryptography by the end of 2030, and to complete the transition for all systems by 2035.",
    "milestones": [
      [
        "2026-12-31",
        "National PQC transition roadmaps published and first steps taken"
      ],
      [
        "2030-12-31",
        "High-risk use cases and critical infrastructure migrated"
      ],
      [
        "2035-12-31",
        "Full transition for all systems"
      ]
    ],
    "notes": [
      "Member-state agencies BSI (Germany) and ANSSI (France) additionally recommend hybrid schemes and, in some cases, FrodoKEM and Classic McEliece."
    ],
    "url": "https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography",
    "page": "https://pqaudit.org/timelines/eu-pqc-roadmap/"
  },
  {
    "slug": "uk-ncsc-pqc-timeline",
    "name": "UK NCSC migration timeline",
    "body": "UK National Cyber Security Centre",
    "date": "2025-03-20",
    "status": "Published guidance",
    "summary": "The UK NCSC's timeline, published 2025-03-20, sets three phases: complete discovery and planning by 2028, complete high-priority migrations by 2031, and complete the migration of all systems, services, and products by 2035.",
    "milestones": [
      [
        "2028",
        "Discovery complete: cryptographic inventory and migration plan"
      ],
      [
        "2031",
        "High-priority migrations complete"
      ],
      [
        "2035",
        "Migration complete for all systems, services, and products"
      ]
    ],
    "notes": [
      "NCSC recommends ML-KEM-768/1024, ML-DSA-65/87, and SLH-DSA, and prefers pure post-quantum over hybrid in the long run."
    ],
    "url": "https://www.ncsc.gov.uk/guidance/pqc-migration-timelines",
    "page": "https://pqaudit.org/timelines/uk-ncsc-pqc-timeline/"
  },
  {
    "slug": "us-nsm-10-quantum-act",
    "name": "U.S. NSM-10 and the Quantum Computing Cybersecurity Preparedness Act",
    "body": "White House (NSM-10) and U.S. Congress (Public Law 117-260)",
    "date": "NSM-10: 2022-05-04; Act signed 2022-12-21; OMB M-23-02: 2022-11-18",
    "status": "In force",
    "summary": "NSM-10 directs U.S. federal agencies to inventory quantum-vulnerable cryptography and migrate, with a goal of mitigating quantum risk by 2035. The Quantum Computing Cybersecurity Preparedness Act (2022-12-21) makes the inventory and OMB reporting a legal requirement, and OMB M-23-02 sets the annual inventory process.",
    "milestones": [
      [
        "2022-05-04",
        "NSM-10 issued; annual cryptographic inventories begin"
      ],
      [
        "2022-12-21",
        "Quantum Computing Cybersecurity Preparedness Act signed into law"
      ],
      [
        "2035",
        "Target for mitigating quantum risk across federal systems"
      ]
    ],
    "notes": [],
    "url": "https://www.whitehouse.gov/briefing-room/statements-releases/2022/05/04/national-security-memorandum-on-promoting-united-states-leadership-in-quantum-computing-while-mitigating-risks-to-vulnerable-cryptographic-systems/",
    "page": "https://pqaudit.org/timelines/us-nsm-10-quantum-act/"
  }
]