NSM-10 issued
National Security Memorandum 10 sets 2035 as the NSS migration target and directs inventory work.
The White House · published 2022-05-04 · reviewed 2026-09-06
Every date below comes from a published government document. Compare national roadmaps without turning guidance into law—or an evidence gap into a guessed deadline.
Two separate obligation tracks: OMB memoranda bind civilian agencies, CNSA 2.0 binds National Security Systems and their suppliers. NIST IR 8547, the source of the widely quoted 2030 deprecation / 2035 disallowance dates, is still an initial public draft — those dates are proposals, not law.
12 published milestones · 2022–2035
National Security Memorandum 10 sets 2035 as the NSS migration target and directs inventory work.
The White House · published 2022-05-04 · reviewed 2026-09-06
NSA Cybersecurity Advisory U/OO/194427-22 sets the algorithm suite and adoption phases for National Security Systems.
National Security Agency · published 2022-09-07 · reviewed 2026-09-06
Civilian agencies must maintain prioritised cryptographic inventories and submit funding estimates.
Office of Management and Budget · published 2022-11-18 · reviewed 2026-09-06
ML-KEM, ML-DSA and SLH-DSA published as final federal standards.
NIST · published 2024-08-13 · reviewed 2026-09-06
Draft transition schedule proposing deprecation from 2030 and disallowance by 2035; these dates remain proposals.
NIST · published 2024-11-12 · reviewed 2026-09-06
Initial public draft; comment period closed 10 January 2025. Its 2030/2035 dates are proposals.
Directs a mandated federal migration to post-quantum cryptography; published in the Federal Register on 25 June 2026.
The White House · published 2026-06-22 · reviewed 2026-09-06
OMB M-26-15 requires plans no later than 120 days after its 24 June 2026 issuance.
Office of Management and Budget · published 2026-06-24 · reviewed 2026-09-06
OMB M-26-15 Phase 1 runs through 2026–2027; Phase 2 pilots and early migration run through 2027–2028.
Office of Management and Budget · published 2026-06-24 · reviewed 2026-09-06
NIST IR 8547 (draft) would deprecate 112-bit-security classical algorithms from 2030.
NIST · published 2024-11-12 · reviewed 2026-09-06
Initial public draft; comment period closed 10 January 2025. Its 2030/2035 dates are proposals.
OMB M-26-15 Phase 3 targets PQC key establishment for high-value, high-impact and other prioritised systems by the end of 2030.
Office of Management and Budget · published 2026-06-24 · reviewed 2026-09-06
OMB M-26-15 Phase 4 targets PQC digital signatures for high-value, high-impact and other prioritised systems.
Office of Management and Budget · published 2026-06-24 · reviewed 2026-09-06
OMB M-26-15 Phase 5 targets remaining systems by 2035; NSM-10 separately sets 2035 as the NSS migration target.
The White House · published 2022-05-04 · reviewed 2026-09-06