Compliance & Risk

The Quantum Deadlines Are Already Fixed, and Most Enterprises Cannot Yet List Their Own Cryptography

NIST expects RSA-2048 and ECC P-256 deprecated by 2030 and quantum-vulnerable algorithms fully phased out by 2035. The hard part is not the new maths, it is knowing where the old maths lives.

August 30, 2026 · Compliance & Risk
Fibre optic connectors and cabling on the rear of a rack-mounted network switch

Key Takeaways

  • NIST IR 8547 designates 112-bit algorithms, including RSA-2048 and ECC P-256, for deprecation by 2030, with quantum-vulnerable algorithms expected to be fully phased out by 2035.
  • NSA CNSA 2.0 requires new national security systems to support quantum-resistant cryptography by 2027, and software and firmware signing to use CNSA 2.0 exclusively from 1 January 2027.
  • Further CNSA 2.0 milestones land in 2030 for legacy and networking equipment, 2031 for mandatory use across covered categories, and 2033 for operating systems, custom applications and cloud services.
  • NIST finalised the first post-quantum standards, FIPS 203, 204 and 205, in August 2024, so the algorithms have been available for two years while most migration plans remain unwritten.

The awkward thing about post-quantum cryptography is that nobody has to believe in a quantum computer for the deadlines to bite. The dates are already written down. NIST IR 8547 designates algorithms providing 112 bits of security, which in practice means RSA-2048 and ECC P-256, for deprecation by 2030, and expects quantum-vulnerable algorithms to be fully phased out by 2035. Whether a cryptographically relevant quantum computer arrives in 2032 or 2045 does not change those dates.

The NSA schedule is more granular and closer. Under CNSA 2.0, new national security systems must support quantum-resistant cryptography by 2027, and software and firmware signing moves to exclusive CNSA 2.0 use from 1 January 2027. Legacy equipment that cannot support it must complete transition by 2030, the same year networking equipment moves to exclusive use. 2031 makes CNSA 2.0 mandatory across covered categories absent an explicit exception, 2033 covers operating systems, custom applications and cloud services, and 2035 requires full quantum resistance across all national security systems.

The Algorithms Are Not the Bottleneck

NIST finalised FIPS 203, 204 and 205 in August 2024, which means the replacement primitives have existed for two years. Library support has followed. If migration were a matter of swapping a cipher suite, a competent team could do it in a quarter. It is not, and the reason is unglamorous: most organisations cannot produce a list of where their cryptography actually is.

Cryptography in a large enterprise is not a system, it is a sediment. It sits in TLS terminators and load balancers, in code-signing pipelines nobody has touched since the engineer who built them left, in hardware security modules, in VPN concentrators, in embedded certificates inside appliances whose vendors may not exist in 2030, in database column encryption, in backup archives, in mutual TLS between microservices, and in the firmware of devices that were installed once and have never been inventoried since. A cryptographic bill of materials is the deliverable that gates everything else, and it is the one nobody budgets for.

The later CNSA 2.0 milestones are the ones that reach ordinary enterprise infrastructure. 2031 makes quantum-resistant cryptography mandatory across covered categories unless an exception is granted explicitly, and 2033 extends exclusive use to operating systems, custom applications and cloud services. Read as a procurement signal rather than a federal rule, that is a statement that the platforms and providers most enterprises depend on will be re-architecting their cryptography during the same window, with federal migration costs alone estimated in the billions of dollars.

Deprecated Is Not the Same as Broken

There is a category error worth heading off. Deprecation in 2030 does not mean RSA-2048 is expected to be breakable in 2030. It means the standards bodies will stop sanctioning it for new use, which matters commercially long before it matters mathematically. Auditors follow standards. Procurement questionnaires follow auditors. Cyber insurers, as this publication has covered before, follow whatever gives them a defensible underwriting position. The practical deadline for a private-sector enterprise is not the day the algorithm falls, it is the day a customer contract or a renewal questionnaire starts asking which algorithms are in use.

That is also why the federal timetable matters to organisations that are not federal. National security system requirements propagate outward through the supplier base. A vendor selling into government by 2027 needs quantum-resistant signing, and vendors do not usually maintain two build pipelines. The requirement arrives at commercial customers as a product update rather than as a regulation.

What Harvest Now, Decrypt Later Actually Implies

The one genuinely time-sensitive risk is retrospective. Traffic and data captured today under RSA or elliptic curve key exchange can be stored and decrypted later, once the capability exists. That reframes the deadline for anything with a long confidentiality life: patient records, source code, merger material, legal advice, industrial designs, anything whose exposure in 2038 would still be damaging. For those data classes the migration deadline is not 2030 or 2035; it is whenever the data was first transmitted, which has already passed.

This is the argument that should drive sequencing. Rather than migrating the estate uniformly, the defensible order is by confidentiality lifetime: long-lived secrets first, then signing and identity infrastructure where a forged signature is catastrophic, then everything whose value expires quickly enough that 2030 is genuinely soon enough.

Post-quantum migration will be remembered as an inventory problem that happened to involve mathematics. The organisations that finish comfortably will be the ones that spent 2026 finding out what they have, not the ones that spent it reading about lattices.

Share

More in Compliance & Risk

All Resources →