PREPARING FOR MIGRATION / BEGINNER

The Official Clocks: What Governments Expect By 2030 And 2035

The UK, EU, Canada and US have published post-quantum migration dates. They differ in detail but share one shape, which makes them useful for planning.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Several governments now put dates on post-quantum migration. Read side by side, they tell a consistent story: understand your cryptography and plan in the next year or two, finish the most important systems around 2030 or 2031, and complete the rest by 2035.

This article gives a planning summary as of October 2026. It does not cover every rule or sector. For the legal status, exact wording and sector rules such as PCI DSS and DORA, see Cryptography Compliance and the live Regulatory Deadline Tracker.

The Common Shape

JurisdictionPlan and discoverHighest priority doneMigration complete
United Kingdom (NCSC guidance)By 2028By 2031By 2035
European Union (Member State roadmap)End of 2026End of 2030 for high-risk use casesEnd of 2035 for medium-risk use cases; low-risk as far as feasible
Canada (federal non-classified systems)April 2026 plan, then yearly reportsEnd of 2031End of 2035
United States (federal agencies, excluding national security systems)Plan due 22 October 2026Key establishment by end of 2030, signatures by end of 2031, for high value assets and high impact systemsRemaining systems by 2035, based on risk and commercial availability
Headline post-quantum milestones by jurisdiction, as of October 2026. Most are guidance; the US dates bind federal agencies but exclude national security systems.

United Kingdom. The National Cyber Security Centre asks organisations to set migration goals, complete a full discovery exercise and build an initial plan by 2028, carry out their highest-priority migrations by 2031, and finish by 2035.1 This is guidance, aimed mainly at large organisations and critical national infrastructure operators.

European Union. The roadmap agreed by Member States through the NIS Cooperation Group sets three milestones: first steps and national roadmaps by 31 December 2026, high-risk use cases migrated by 31 December 2030, and medium-risk use cases by 31 December 2035, with low-risk ones completed as far as feasible.2 It is addressed to Member States rather than directly to companies.

Canada. The Canadian Centre for Cyber Security’s roadmap for federal non-classified systems asks departments for an initial plan by April 2026, annual progress reports from then on, high-priority systems migrated by the end of 2031, and the rest by the end of 2035.3

United States. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, signed on 22 June 2026, directs OMB to require federal agencies to move their high value assets and high impact systems to post-quantum key establishment by 31 December 2030 and to post-quantum signatures by 31 December 2031.4 OMB memorandum M-26-15 puts that into practice. Agencies must submit a migration plan within 120 days of 24 June 2026, which falls on 22 October 2026, and must support TLS 1.3 no later than 2 January 2030. The memo’s final phase aims to complete the remaining systems by 2035, taking account of risk and of what products are commercially available. It does not apply to national security systems.5

Where The Standards Fit

NIST’s draft transition report, IR 8547, proposes deprecating the weaker parameter sets of today’s public-key algorithms after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035.6 As of October 2026 it is still an initial public draft, yet OMB requires agencies to align their plans with it. The EU roadmap also cites it when explaining its own 2035 date.2

Countdowns

The tracker entries below update daily. Each links to its source.

  1. Upcoming

    European Union · NIS Cooperation Group Guidance

    All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 1. Applies to EU Member States. Source · Verified 7 Oct 2026

  2. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  3. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  4. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for high-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 2. Applies to EU Member States. Source · Verified 7 Oct 2026

  5. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(iii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  6. Upcoming

    Canada · Canadian Centre for Cyber Security Guidance

    Migrate high-priority non-classified government systems.

    ITSM.40.001 Roadmap for the migration to post-quantum cryptography. Applies to Government of Canada non-classified systems. Source · Verified 7 Oct 2026

  7. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete migration to post-quantum cryptography across systems and products.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations. Source · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

What This Means For Planning

The dates converge. Wherever you operate, a reasonable working assumption is that discovery and planning should be well under way by 2027 or 2028, that systems handling your most sensitive or long-lived data should be migrated by about 2030, and that the remainder should follow by 2035. The governance article explains how to turn those dates into a funded programme.

Footnotes

  1. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

  2. NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, 23 June 2025. digital-strategy.ec.europa.eu ↩ ↩2

  3. Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, effective 23 June 2025. cyber.gc.ca ↩

  4. The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, as published in the Daily Compilation of Presidential Documents. govinfo.gov ↩

  5. Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩

  6. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, 12 November 2024. csrc.nist.gov ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.