Canada

Executing
Canadian Centre for Cyber Security (CSE) · Treasury Board Secretariat

ITSM.40.001, 'Roadmap for the migration to post-quantum cryptography for the Government of Canada' (June 2025), sets the plan; the Security Policy Implementation Notice 'Migrating the Government of Canada to Post-Quantum Cryptography', effective 9 October 2025, makes it mandatory under the Policy on Government Security. Departmental migration plans and reporting begin in 2026, high-priority non-classified systems migrate by end-2031, and remaining systems by end-2035.

The roadmap is explicit that inventory means vendors, product versions, hosting platforms, dependencies, contracts and refresh dates — not just TLS endpoints. The SPIN is what makes it enforceable.

Scope

Government of Canada departments and agencies, primarily non-classified systems; CFDIR guidance extends to telecom and critical infrastructure

Band rationale

A published roadmap plus a binding Treasury Board policy instrument — a rare combination.

Readiness dimensions
Policy
Deadline maturity
Technical standards
Execution evidence
Supply-chain enablement
Evidence confidence
Milestones
  1. 2024-07-10

    CFDIR quantum-readiness best practices v04

    Voluntary national guidance for telecom and critical infrastructure.

    Bindingness · guidance
  2. 2025-06

    ITSM.40.001 published

    Cyber Centre roadmap for GC migration to post-quantum cryptography.

    Bindingness · policy roadmap
  3. 2025-10-09

    SPIN takes effect

    Security Policy Implementation Notice makes Government of Canada migration mandatory.

    Bindingness · mandate
  4. 2026-04

    Initial departmental plans due

    ITSM.40.001 sets April 2026 for initial plans and the start of annual progress reporting.

    Bindingness · mandate
  5. 2031-12

    High-priority systems migrated

    High-priority federal non-classified systems complete.

    Bindingness · mandate
  6. 2035-12

    Remaining systems migrated

    Remaining federal non-classified systems complete.

    Bindingness · mandate
Why it matters

Canada pairs a technical roadmap with a compliance instrument, so every cryptographic dependency has to be located and reported, not simply acknowledged.

Migration implications
  • ·Inventory cryptography across the estate, including vendors and product versions
  • ·Map hosting platforms and system dependencies, not just endpoints
  • ·Tie migration to refresh years and contract dates
  • ·Suppliers to GC departments should expect PQC questions in reporting cycles
Evidence
Compare with United StatesCompare with United KingdomCompare with European UnionCompare with FranceCompare with Netherlands