The Official Clocks: What Governments Expect By 2030 And 2035
The UK, EU, Canada and US have published post-quantum migration dates. They differ in detail but share one shape, which makes them useful for planning.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Several governments now put dates on post-quantum migration. Read side by side, they tell a consistent story: understand your cryptography and plan in the next year or two, finish the most important systems around 2030 or 2031, and complete the rest by 2035.
This article gives a planning summary as of October 2026. It does not cover every rule or sector. For the legal status, exact wording and sector rules such as PCI DSS and DORA, see Cryptography Compliance and the live Regulatory Deadline Tracker.
The Common Shape
| Jurisdiction | Plan and discover | Highest priority done | Migration complete |
|---|---|---|---|
| United Kingdom (NCSC guidance) | By 2028 | By 2031 | By 2035 |
| European Union (Member State roadmap) | End of 2026 | End of 2030 for high-risk use cases | End of 2035 for medium-risk use cases; low-risk as far as feasible |
| Canada (federal non-classified systems) | April 2026 plan, then yearly reports | End of 2031 | End of 2035 |
| United States (federal agencies, excluding national security systems) | Plan due 22 October 2026 | Key establishment by end of 2030, signatures by end of 2031, for high value assets and high impact systems | Remaining systems by 2035, based on risk and commercial availability |
United Kingdom. The National Cyber Security Centre asks organisations to set migration goals, complete a full discovery exercise and build an initial plan by 2028, carry out their highest-priority migrations by 2031, and finish by 2035.1 This is guidance, aimed mainly at large organisations and critical national infrastructure operators.
European Union. The roadmap agreed by Member States through the NIS Cooperation Group sets three milestones: first steps and national roadmaps by 31 December 2026, high-risk use cases migrated by 31 December 2030, and medium-risk use cases by 31 December 2035, with low-risk ones completed as far as feasible.2 It is addressed to Member States rather than directly to companies.
Canada. The Canadian Centre for Cyber Security’s roadmap for federal non-classified systems asks departments for an initial plan by April 2026, annual progress reports from then on, high-priority systems migrated by the end of 2031, and the rest by the end of 2035.3
United States. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, signed on 22 June 2026, directs OMB to require federal agencies to move their high value assets and high impact systems to post-quantum key establishment by 31 December 2030 and to post-quantum signatures by 31 December 2031.4 OMB memorandum M-26-15 puts that into practice. Agencies must submit a migration plan within 120 days of 24 June 2026, which falls on 22 October 2026, and must support TLS 1.3 no later than 2 January 2030. The memo’s final phase aims to complete the remaining systems by 2035, taking account of risk and of what products are commercially available. It does not apply to national security systems.5
Where The Standards Fit
NIST’s draft transition report, IR 8547, proposes deprecating the weaker parameter sets of today’s public-key algorithms after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035.6 As of October 2026 it is still an initial public draft, yet OMB requires agencies to align their plans with it. The EU roadmap also cites it when explaining its own 2035 date.2
Countdowns
The tracker entries below update daily. Each links to its source.
- Upcoming
European Union · NIS Cooperation Group Guidance
All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for high-risk use cases.
- Upcoming
United States · The White House and Office of Management and Budget Binding
OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.
- Upcoming
Canada · Canadian Centre for Cyber Security Guidance
Migrate high-priority non-classified government systems.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete migration to post-quantum cryptography across systems and products.
What This Means For Planning
The dates converge. Wherever you operate, a reasonable working assumption is that discovery and planning should be well under way by 2027 or 2028, that systems handling your most sensitive or long-lived data should be migrated by about 2030, and that the remainder should follow by 2035. The governance article explains how to turn those dates into a funded programme.
Footnotes
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩
-
NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, 23 June 2025. digital-strategy.ec.europa.eu ↩ ↩2
-
Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, effective 23 June 2025. cyber.gc.ca ↩
-
The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, as published in the Daily Compilation of Presidential Documents. govinfo.gov ↩
-
Office of Management and Budget, “Execution of the Migration to Post-Quantum Cryptography” (M-26-15), 24 June 2026. whitehouse.gov ↩
-
NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, 12 November 2024. csrc.nist.gov ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.