Government positions, deadline by deadline
Public discussion collapses laws, executive orders, regulator expectations, IT roadmaps and vendor targets into the single word 'deadline'. CRQC models them separately: instrument type, authority, jurisdiction, affected entities, requirement, milestone date, bindingness, source status and review date.
United States
White House / OMB · NSA · NISTNSM-10 (4 May 2022) set 2035 as the target for migrating National Security Systems; OMB M-23-02 (18 November 2022) required civilian agency cryptographic inventories and funding estimates under the Quantum Computing Cybersecurity Preparedness Act (Pub. L. 117-260). NIST finalised FIPS 203/204/205 on 13 August 2024. Executive Order 14412, 'Securing the Nation Against Advanced Cryptographic Attacks' (22 June 2026, 91 FR, published 25 June 2026) and implementing memorandum OMB M-26-15 (24 June 2026) convert the roadmap into a mandate: agency PQC migration plans within 120 days and a five-phase execution programme.
2026-06-22 · Executive Order 14412 signed
United Kingdom
National Cyber Security Centre (GCHQ)NCSC's 'Timelines for migration to post-quantum cryptography' guidance sets three dated phases: by 2028 complete discovery and assessment and build an initial migration plan; by 2031 complete migration of the highest-priority systems and refine the plan; by 2035 complete migration across all systems and services.
2028 · Discovery and initial plan
European Union
European Commission (DG CNECT) · NIS Cooperation Group · ENISACommission Recommendation (EU) 2024/1101 of 11 April 2024 invited Member States to build a coordinated roadmap. The NIS Cooperation Group's 'Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography' was adopted on 23 June 2025: Member States should start the transition by the end of 2026, protect high-risk use cases as soon as possible and no later than the end of 2030, and complete the transition of remaining systems as far as possible by 2035.
2026-12 · Transition starts
France
ANSSIANSSI's position paper on the post-quantum transition (2022, with a 2023 follow-up) requires hybrid schemes — classical plus post-quantum — for products seeking French security visas. It particularly recommends hybrid mitigation for products protecting information beyond 2030 or likely to remain in use after 2030. Protocol-level guidance now covers TLS 1.3, IPsec/IKEv2 and SSHv2.
2022-03-30 · ANSSI position paper dated
Netherlands
AIVD · TNO · CWI (PQC Migration Handbook) · NCSC-NLThe PQC Migration Handbook, published by AIVD, TNO and CWI, is the national reference for migration planning. Its renewed second edition is dated 29 November 2024. The EU roadmap applies at Member-State level, but no separate Dutch completion date is attributed here without a Dutch primary document.
2024-11-29 · PQC Migration Handbook, second edition
Canada
Canadian Centre for Cyber Security (CSE) · Treasury Board SecretariatITSM.40.001, 'Roadmap for the migration to post-quantum cryptography for the Government of Canada' (June 2025), sets the plan; the Security Policy Implementation Notice 'Migrating the Government of Canada to Post-Quantum Cryptography', effective 9 October 2025, makes it mandatory under the Policy on Government Security. Departmental migration plans and reporting begin in 2026, high-priority non-classified systems migrate by end-2031, and remaining systems by end-2035.
2026-04 · Initial departmental plans due
Australia
Australian Signals Directorate / ACSCThe ISM 'Guidelines for Cryptography' (current version updated 9 June 2026) and the 'Planning for post-quantum cryptography' fact sheet (last updated 22 September 2025) require ASD-approved cryptographic equipment to support post-quantum algorithms, and provide for RSA, Diffie-Hellman, ECDH and ECDSA to be no longer approved after 2030 — five years ahead of the UK, EU and Canadian horizons.
2026-06-09 · ISM cryptography guidelines published
Singapore
Cyber Security Agency of Singapore · Monetary Authority of SingaporeMAS advisory MAS/TCRS/2024/01, 'Addressing the Cybersecurity Risks Associated with Quantum' (20 February 2024), directs financial institution CEOs to build quantum risk awareness, maintain cryptographic inventories and trial PQC. CSA opened public consultation on the draft Quantum-Safe Migration Handbook and Quantum Readiness Index on 22 October 2025 (comments due end-December 2025) and published the final version on 16 July 2026.
2026-07-16 · Handbook and Readiness Index published
Japan
CRYPTREC (Digital Agency · MIC · METI, with NICT and IPA)The CRYPTREC Ciphers List (CRYPTREC LS-0001-2022R2) added ML-KEM to the e-Government Recommended Ciphers List for key exchange during FY2025 (year ending March 2025) — the list's own header cites 30 March 2023 as the original issue date and 30 March 2026 as the latest revision date, so the exact day ML-KEM was added should be confirmed against the dated list text rather than assumed. ML-DSA and SLH-DSA (post-quantum signatures) are not yet on the Recommended list; CRYPTREC's MT-1501-2026 working paper records the outstanding questions on adding remaining PQC categories.
2026-03-30 · Ciphers List revised with ML-KEM
China
State Cryptography Administration and state research programmesThe Institute of Commercial Cryptography Standards (ICCS), under the State Cryptography Administration, launched the Next-Generation Commercial Cryptographic Algorithms program (NGCC) via an announcement dated 5 February 2025, opening a global call for public-key algorithm submissions (including PQC families) with staged submission and evaluation rounds continuing through 2025-2026. No published national completion date comparable to the UK, EU, Canadian or Australian schedules was found.
2025-02-05 · NGCC programme launched
Taiwan
Ministry of Digital Affairs / Administration for Digital IndustriesTaiwan's Administration for Digital Industries (Ministry of Digital Affairs), with the Post-Quantum Cryptography Critical Infrastructure Alliance (PQC-CIA) and the Institute for Information Industry (III), published the country's first Post-Quantum Cryptography Migration Guide (version 1.00) on 16 April 2025, aimed at helping domestic industry align with the NIST standards.
2025-04-16 · First PQC migration guide published
Hong Kong
Hong Kong Monetary AuthorityThe HKMA published the whitepaper 'Quantum Preparedness of Hong Kong's Banking Sector' and launched the Quantum Preparedness Index (QPI) on 27 July 2026, circulated to all Authorized Institutions. The initial sector QPI score was reported at 2.3 out of 10; about half of Authorized Institutions have no structured cryptographic-upgrade plan, and among those that do, the average implementation timeframe is 5.6 years.
2026-07-27 · Quantum Preparedness Index (QPI) published
| Jurisdiction | Authority | Public position | Next dated milestone | Band |
|---|---|---|---|---|
| United States | White House / OMB · NSA · NIST | NSM-10 (4 May 2022) set 2035 as the target for migrating National Security Systems; OMB M-23-02 (18 November 2022) required civilian agency cryptographic inventories and funding estimates under the Quantum Computing Cybersecurity Preparedness Act (Pub. L. 117-260). NIST finalised FIPS 203/204/205 on 13 August 2024. Executive Order 14412, 'Securing the Nation Against Advanced Cryptographic Attacks' (22 June 2026, 91 FR, published 25 June 2026) and implementing memorandum OMB M-26-15 (24 June 2026) convert the roadmap into a mandate: agency PQC migration plans within 120 days and a five-phase execution programme. | 2026-06-22 · Executive Order 14412 signed | Executing |
| United Kingdom | National Cyber Security Centre (GCHQ) | NCSC's 'Timelines for migration to post-quantum cryptography' guidance sets three dated phases: by 2028 complete discovery and assessment and build an initial migration plan; by 2031 complete migration of the highest-priority systems and refine the plan; by 2035 complete migration across all systems and services. | 2028 · Discovery and initial plan | Executing |
| European Union | European Commission (DG CNECT) · NIS Cooperation Group · ENISA | Commission Recommendation (EU) 2024/1101 of 11 April 2024 invited Member States to build a coordinated roadmap. The NIS Cooperation Group's 'Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography' was adopted on 23 June 2025: Member States should start the transition by the end of 2026, protect high-risk use cases as soon as possible and no later than the end of 2030, and complete the transition of remaining systems as far as possible by 2035. | 2026-12 · Transition starts | Executing |
| France | ANSSI | ANSSI's position paper on the post-quantum transition (2022, with a 2023 follow-up) requires hybrid schemes — classical plus post-quantum — for products seeking French security visas. It particularly recommends hybrid mitigation for products protecting information beyond 2030 or likely to remain in use after 2030. Protocol-level guidance now covers TLS 1.3, IPsec/IKEv2 and SSHv2. | 2022-03-30 · ANSSI position paper dated | Executing |
| Netherlands | AIVD · TNO · CWI (PQC Migration Handbook) · NCSC-NL | The PQC Migration Handbook, published by AIVD, TNO and CWI, is the national reference for migration planning. Its renewed second edition is dated 29 November 2024. The EU roadmap applies at Member-State level, but no separate Dutch completion date is attributed here without a Dutch primary document. | 2024-11-29 · PQC Migration Handbook, second edition | Mobilizing |
| Canada | Canadian Centre for Cyber Security (CSE) · Treasury Board Secretariat | ITSM.40.001, 'Roadmap for the migration to post-quantum cryptography for the Government of Canada' (June 2025), sets the plan; the Security Policy Implementation Notice 'Migrating the Government of Canada to Post-Quantum Cryptography', effective 9 October 2025, makes it mandatory under the Policy on Government Security. Departmental migration plans and reporting begin in 2026, high-priority non-classified systems migrate by end-2031, and remaining systems by end-2035. | 2026-04 · Initial departmental plans due | Executing |
| Australia | Australian Signals Directorate / ACSC | The ISM 'Guidelines for Cryptography' (current version updated 9 June 2026) and the 'Planning for post-quantum cryptography' fact sheet (last updated 22 September 2025) require ASD-approved cryptographic equipment to support post-quantum algorithms, and provide for RSA, Diffie-Hellman, ECDH and ECDSA to be no longer approved after 2030 — five years ahead of the UK, EU and Canadian horizons. | 2026-06-09 · ISM cryptography guidelines published | Executing |
| Singapore | Cyber Security Agency of Singapore · Monetary Authority of Singapore | MAS advisory MAS/TCRS/2024/01, 'Addressing the Cybersecurity Risks Associated with Quantum' (20 February 2024), directs financial institution CEOs to build quantum risk awareness, maintain cryptographic inventories and trial PQC. CSA opened public consultation on the draft Quantum-Safe Migration Handbook and Quantum Readiness Index on 22 October 2025 (comments due end-December 2025) and published the final version on 16 July 2026. | 2026-07-16 · Handbook and Readiness Index published | Executing |
| Japan | CRYPTREC (Digital Agency · MIC · METI, with NICT and IPA) | The CRYPTREC Ciphers List (CRYPTREC LS-0001-2022R2) added ML-KEM to the e-Government Recommended Ciphers List for key exchange during FY2025 (year ending March 2025) — the list's own header cites 30 March 2023 as the original issue date and 30 March 2026 as the latest revision date, so the exact day ML-KEM was added should be confirmed against the dated list text rather than assumed. ML-DSA and SLH-DSA (post-quantum signatures) are not yet on the Recommended list; CRYPTREC's MT-1501-2026 working paper records the outstanding questions on adding remaining PQC categories. | 2026-03-30 · Ciphers List revised with ML-KEM | Mobilizing |
| China | State Cryptography Administration and state research programmes | The Institute of Commercial Cryptography Standards (ICCS), under the State Cryptography Administration, launched the Next-Generation Commercial Cryptographic Algorithms program (NGCC) via an announcement dated 5 February 2025, opening a global call for public-key algorithm submissions (including PQC families) with staged submission and evaluation rounds continuing through 2025-2026. No published national completion date comparable to the UK, EU, Canadian or Australian schedules was found. | 2025-02-05 · NGCC programme launched | Evidence insufficient |
| Taiwan | Ministry of Digital Affairs / Administration for Digital Industries | Taiwan's Administration for Digital Industries (Ministry of Digital Affairs), with the Post-Quantum Cryptography Critical Infrastructure Alliance (PQC-CIA) and the Institute for Information Industry (III), published the country's first Post-Quantum Cryptography Migration Guide (version 1.00) on 16 April 2025, aimed at helping domestic industry align with the NIST standards. | 2025-04-16 · First PQC migration guide published | Mobilizing |
| Hong Kong | Hong Kong Monetary Authority | The HKMA published the whitepaper 'Quantum Preparedness of Hong Kong's Banking Sector' and launched the Quantum Preparedness Index (QPI) on 27 July 2026, circulated to all Authorized Institutions. The initial sector QPI score was reported at 2.3 out of 10; about half of Authorized Institutions have no structured cryptographic-upgrade plan, and among those that do, the average implementation timeframe is 5.6 years. | 2026-07-27 · Quantum Preparedness Index (QPI) published | Planning |