Deadline tracker // updated Sep 2026

The PQC deadlines that set the pace.

Eighteen of the 41 dated milestones PQCA tracks across eleven jurisdictions — the ones that drive programme sequencing. The soonest binding milestone in the Gulf is now Saudi Arabia’s: SAMA requires the cryptographic inventory complete by 31 Dec 2026. Each is taken from the published texts — each labeled by legal weight, so draft guidance is never dressed up as binding law. PQCA scores readiness against these same mandates from your migration-roadmap progress, per control, with evidence.

EU CRA
Reporting obligations apply

Manufacturers must report actively exploited vulnerabilities and severe incidents — the CRA’s first binding obligations.

11 Sep 2026
Binding · EU
FIPS 140-2
Modules move to the CMVP Historical List

NIST/CMVP moves FIPS 140-2 modules to the Historical List — procurement against them ends for US federal systems. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.

21 Sep 2026
Binding · US
OMB M-26-15
Agency PQC migration plans due to OMB

Every federal civilian agency files its prioritized migration plan under EO 14412 and OMB M-26-15 — the first hard federal deliverable of the transition. National-security systems are expressly excluded.

22 Oct 2026
Binding · US
SAMA · KSA
Cryptographic asset inventory and classification complete

Every cryptographic asset inventoried and classified by sensitivity and migration priority, with the operational agility, constraints and third-party dependencies of priority assets assessed. SAMA circular issued under the Saudi Central Bank Law (Royal Decree M/36) — binding on all banks, credit-information companies, finance companies, payment-services providers and licensed financing-support entities in the Kingdom. rulebook.sama.gov.sa

31 Dec 2026
Binding · KSA
SAMA · KSA
Institution-level quantum risk assessment and work plans

A quantum-computing risk assessment aligned with enterprise risk management, with plans for the risks it finds. Second milestone of the same SAMA circular (Royal Decree M/36).

31 Mar 2027
Binding · KSA
PCI PTS HSM
PTS v4 new-device approvals end

PCI approval labs stop accepting new HSM submissions against PTS v4, ahead of v5 — the first PTS revision to carry post-quantum requirements.

30 Jun 2027
Binding · Global
EU CRA
Cyber Resilience Act core obligations apply

Products with digital elements sold in the EU carry security and vulnerability-handling obligations — cryptographic hygiene included.

11 Dec 2027
Binding · EU
CNSA 2.0
Operating systems support and prefer CNSA 2.0

NSA guidance expects operating systems in national-security service to support and prefer CNSA 2.0 algorithms (ML-KEM, ML-DSA) by end-2027.

31 Dec 2027
Guidance · US NSS
CBJ · Jordan
Sectoral roadmap — first dated milestone

The first of three dated milestones on the Central Bank of Jordan’s published sectoral PQC roadmap for the Jordanian banking sector.

31 Dec 2027
Guidance · JO
UK NCSC
Discovery complete, migration plan in hand

NCSC’s published timeline expects full cryptographic discovery and a funded transition plan by 2028.

31 Dec 2028
Guidance · UK
NIST IR 8547
112-bit classical security deprecated

Under NIST’s initial public draft, RSA-2048-class security moves to deprecated status — permitted, but flagged, ahead of the proposed 2035 disallow.

31 Dec 2030
Draft · Global
EU roadmap
High-risk use cases quantum-safe

The EU coordinated PQC roadmap expects high-risk systems migrated by the end of 2030.

31 Dec 2030
Guidance · EU
CBJ · Jordan
Sectoral roadmap — second dated milestone

The second dated milestone on CBJ’s published roadmap — landing with the global 2030 cluster of NIST, EU and CNSA dates.

31 Dec 2030
Guidance · JO
UK NCSC
Highest-priority migrations complete

The most critical cryptography — long-shelf-life data, root keys, CA infrastructure — migrated by 2031.

31 Dec 2031
Guidance · UK
CNSA 2.0
Full transition for national-security systems

NSA’s completion target: CNSA 2.0 as the baseline across NSS, with classical-only deployments needing explicit waivers.

1 Jan 2033
Guidance · US NSS
NIST IR 8547
112-bit security disallowed

Proposed in NIST’s initial public draft: RSA-2048-class cryptography disallowed for US federal use — the anchor date most global programs plan against.

31 Dec 2035
Draft · Global
CBJ · Jordan
Sectoral roadmap — third dated milestone

The last dated milestone on CBJ’s published roadmap, coinciding with NIST IR 8547’s 2035 disallowance date.

31 Dec 2035
Guidance · JO
UK NCSC
Migration complete across the estate

All remaining systems quantum-safe by 2035 under the NCSC timeline.

31 Dec 2035
Guidance · UK
Saudi NCA
General cryptographic-hygiene controls — no dated PQC milestone

NCA has published no post-quantum mandate, so its controls are scored as general cryptographic hygiene, not as a PQC deadline. Saudi Arabia’s dated post-quantum milestones are SAMA’s, above.

Rolling
Guidance · KSA

Dates reflect published standards and mandates as of September 2026 and are reviewed as texts evolve. PQCA tracks 41 dated milestones in all — 14 binding, 23 guidance, 2 draft and 2 announced — across eleven jurisdictions: Australia, Canada, the EU, France, Germany, global payments, Jordan, Saudi Arabia, the UAE, the UK and the US. Binding entries carry direct legal or procurement force for the named scope; guidance entries are published national timelines; draft entries come from NIST IR 8547’s initial public draft and remain proposed. None of this is legal advice — map your own obligations in a briefing.