CRYPTOGRAPHY COMPLIANCE / INTERMEDIATE

The Global Quantum Deadline Map: 2030, 2031 And 2035

Governments and supervisors have published post-quantum migration dates that cluster around the same few years. Here is what each date means, who it applies to and how binding it is.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Post-quantum migration dates now come from many directions: cyber agencies, finance ministries, central banks and heads of government. On first reading they look scattered. Put on one page, they fall into a clear pattern of three waves, with most jurisdictions converging on 2035 as the end point.

This article maps the main published dates as of October 2026, explains who each one applies to, and labels whether it is binding, supervisory or guidance. The labels matter as much as the dates.

Three Waves

Most roadmaps share the same sequence, even when the exact years differ.

  1. Discover And PlanUpcoming

    Build a cryptographic inventory, assess risk and write a migration plan.

  2. Migrate The Most Important SystemsUpcoming

    Move high-risk, high-value or critical systems to post-quantum cryptography.

  3. FinishUpcoming

    Complete migration of remaining systems as far as feasible.

The three waves that recur across national and supervisory roadmaps. Individual dates vary by jurisdiction; see the table and countdowns below.

The G7 Cyber Expert Group, reviewing guidance from many jurisdictions, observed that it often points to 2035 as the overall target, and suggested that the most critical financial systems might be addressed in 2030 to 2032.1 The group is explicit that its roadmap is non-authoritative and sets no regulatory expectations.

Why The Dates Converge

The repetition of 2035 is not a coincidence. The EU roadmap explains its own choice of that year by pointing to three earlier sources: the US goal, set in National Security Memorandum 10, of mitigating as much quantum risk as feasible by 2035; NIST’s draft transition guidance, which proposes disallowing traditional public-key algorithms after 2035; and the UK NCSC timeline, which also ends in 2035.2 Each new roadmap tends to align with the ones before it, which helps multinational organisations plan.

The length of the runway is also deliberate. Migration depends on a chain of events: standards must be agreed before vendors can build them into products, and products must exist before organisations can deploy them at scale. The NCSC judges that a decade allows that whole chain to play out, which is how it arrived at 2035.3 The EU roadmap estimates that fully migrating all relevant systems could take five to ten years, which is why it says the later steps must begin straight away instead of waiting until the 2026 milestone is met.2

Earlier dates for the most important systems reflect harvest now, decrypt later. Data that must stay confidential for many years is already exposed if it is recorded today, so it needs protection well before the end point.

Who Has Set Which Dates

The table summarises the main published milestones. Each row is a different kind of instrument, so read the status column before the dates.

Jurisdiction And IssuerApplies ToEarly MilestonePriority SystemsCompletionStatus
United Kingdom, NCSCUK organisations, especially large organisations and critical national infrastructureDiscovery and initial plan by 2028Highest-priority migration by 2031All systems by 2035Guidance
European Union, NIS Cooperation GroupEU Member StatesFirst steps and national roadmaps by end 2026High-risk use cases by end 2030Medium-risk by end 2035, low-risk as far as feasibleGuidance
United States, Executive Order 14412Federal high-value assets and high-impact systems, excluding national security systemsOMB (Office of Management and Budget) guidance within 90 days of 22 June 2026Key establishment by 31 December 2030, through OMB guidanceSignatures by 31 December 2031, through OMB guidanceBinding on federal agencies
United States, OMB M-26-15Federal civilian agenciesPlans within 120 days; discovery 2026 to 2027Prioritised migration 2028 to 2030Full migration phase 2035Binding on federal agencies
Canada, Canadian Centre for Cyber SecurityGovernment of Canada non-classified systemsInitial departmental plan by April 2026, then annual progress reportsHigh-priority systems by end 2031Remaining systems by end 2035Guidance (federal roadmap)
Singapore, Cyber Security AgencyCritical information infrastructure ownersMigration plan by 31 March 2027New systems procured from 1 January 2028 should support quantum-safe algorithms or be ready for themComplete by 31 December 2031Supervisory
Saudi Arabia, SAMASAMA-regulated financial institutionsCryptographic asset procedures by end Q4 2026; risk assessment by end Q1 2027Plans for priority assets (no date)Not datedBinding
Switzerland, FINMAFINMA-supervised institutionsPQC roadmap by mid-2027Firms set their own datesFirms set their own datesSupervisory recommendation
G7 Cyber Expert GroupFinancial sector, as a referenceInventory phaseCritical systems 2030 to 2032Overall 2035Non-binding statement
Published post-quantum milestones as of October 2026. Status describes the instrument, not how seriously to take it.

Sources for each row: NCSC,3 EU roadmap,2 Executive Order 14412,4 OMB M-26-15,5 Canada,6 Singapore,7 SAMA8 and FINMA.9 Australia’s Signals Directorate has also advised that traditional asymmetric cryptography should stop being used by the end of 2030, which makes it one of the earliest national targets.10

Reading The Dates Carefully

Several patterns stand out.

The early dates are about planning, not migration. The nearest milestones, from SAMA, the EU roadmap, Singapore and FINMA, all ask for inventories, risk assessments, plans or roadmaps. None of them asks a private firm to finish migrating in 2026 or 2027.

Binding dates mostly apply to governments. The US executive order and OMB memorandum bind federal agencies. Canada’s roadmap covers federal systems. The main binding instrument on private firms in this table is SAMA’s circular, and its dates are about inventory and assessment.

Key exchange comes before signatures. The US splits its deadline into key establishment (2030) and digital signatures (2031). That order reflects the harvest now, decrypt later threat: recorded traffic can be decrypted later, so protecting key exchange is the more urgent task, while forged signatures only become possible once a capable quantum computer exists.

Completion does not always mean every system. The EU roadmap asks for low-risk use cases to move as far as feasible by 2035. The NCSC expects a small set of rarely used technologies to be harder to move by that date.3

The Countdowns

The live countdowns below cover the dated milestones mentioned in this article. Each links to its source.

  1. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  2. Upcoming

    European Union · NIS Cooperation Group Guidance

    All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 1. Applies to EU Member States. Source · Verified 7 Oct 2026

  3. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Submit a quantum-safe migration plan to CSA.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

  4. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  5. Upcoming

    Switzerland · FINMA Supervisory

    Draw up a post-quantum cryptography roadmap.

    FINMA Guidance 05/2026. Applies to FINMA-supervised institutions (recommendation). Source · Verified 7 Oct 2026

  6. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  7. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  8. Upcoming

    Australia · Australian Signals Directorate Guidance

    Stop using traditional asymmetric cryptography such as RSA, Diffie-Hellman, ECDH and ECDSA.

    Planning for post-quantum cryptography (September 2025) and the ISM Guidelines for cryptography (ISM-0472, 0474, 0475, 0476). Applies to Australian government and organisations following the ISM. Source · Explainer · Verified 7 Oct 2026

  9. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for high-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 2. Applies to EU Member States. Source · Verified 7 Oct 2026

  10. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Complete migration to quantum-safe cryptography.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

  11. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum digital signatures by this date. M-26-15 plans this as its 2031 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(iii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

  12. Upcoming

    Canada · Canadian Centre for Cyber Security Guidance

    Migrate high-priority non-classified government systems.

    ITSM.40.001 Roadmap for the migration to post-quantum cryptography. Applies to Government of Canada non-classified systems. Source · Verified 7 Oct 2026

  13. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete early, highest-priority migration activities and refine the plan into a roadmap for completing migration by 2035.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially large organisations and critical national infrastructure. Source · Explainer · Verified 7 Oct 2026

  14. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete migration to post-quantum cryptography across systems and products.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations. Source · Verified 7 Oct 2026

  15. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1). Applies to EU Member States. Source · Explainer · Verified 7 Oct 2026

  16. Upcoming

    Canada · Canadian Centre for Cyber Security Guidance

    Complete migration of the remaining non-classified government systems.

    ITSM.40.001 Roadmap for the migration to post-quantum cryptography. Applies to Government of Canada non-classified systems. Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

What To Do With A Map Like This

For most organisations, the useful question is which dates their own regulators or customers are likely to adopt. A firm supervised in the EU should expect national expectations to follow the EU roadmap. A supplier to the US government should watch the federal contractor rule that the executive order requires. A bank in the Gulf should read SAMA’s circular as a signal of where regional supervisors are heading, even if it is not supervised by SAMA. The wider regional picture is covered in Regulations Across Regions.

Whatever the jurisdiction, the first wave asks for the same thing. An inventory built and maintained now serves every one of these timelines.

Footnotes

  1. G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩

  2. NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩ ↩2 ↩3

  3. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2 ↩3

  4. The White House, “Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026. govinfo.gov ↩

  5. US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩

  6. Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, June 2025. cyber.gc.ca ↩

  7. Cyber Security Agency of Singapore, “Quantum-Safe Handbook”, 16 July 2026. gov.sg ↩

  8. Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩

  9. FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩

  10. Australian Signals Directorate, “Planning for post-quantum cryptography”, last reviewed 22 September 2025. cyber.gov.au ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.