Australia
ExecutingThe ISM 'Guidelines for Cryptography' (current version updated 9 June 2026) and the 'Planning for post-quantum cryptography' fact sheet (last updated 22 September 2025) require ASD-approved cryptographic equipment to support post-quantum algorithms, and provide for RSA, Diffie-Hellman, ECDH and ECDSA to be no longer approved after 2030 — five years ahead of the UK, EU and Canadian horizons.
The ISM is binding on Commonwealth entities, so 2030 is a compliance date rather than an aspiration for that population. Vendor guidance highlights cloud, managed services, legacy hardware, OT and IoT as the hard cases.
Australian government entities under the Information Security Manual (mandatory for non-corporate Commonwealth entities); advisory for industry
Band rationaleThe most aggressive published national end date, carried inside a mandatory government standard.
- 2022-07-06
Planning for PQC fact sheet published
ASD's planning guidance was first published; its current revision is dated 22 September 2025.
Bindingness · guidance - 2026-06-09
ISM cryptography guidelines published
Guidelines for Cryptography published with the post-quantum requirements.
Bindingness · mandate - 2030-12
Classical asymmetric algorithms withdrawn
RSA, DH, ECDH and ECDSA no longer approved for ASD-approved cryptographic equipment after 2030.
Bindingness · mandate
A 2030 cut-off compresses procurement cycles for anything with a long refresh life, and Australian requirements propagate to suppliers worldwide.
- ·Prioritise hard-to-update systems now — 2030 is inside a single hardware refresh cycle
- ·Ask cloud and managed service providers for dated commitments
- ·Legacy OT and IoT need replacement plans, not patches
- A1effectiveInformation Security Manual — Guidelines for CryptographyAustralian Signals DirectoratePublished 2026-06-09Reviewed 2026-09-06
- A2guidancePlanning for post-quantum cryptographyASD / ACSCPublished 2025-09-22Reviewed 2026-09-06