Deadline tracker // updated Aug 2026

Every PQC deadline, on one clock.

The dates below are taken from the published texts — each labeled by legal weight, so draft guidance is never dressed up as binding law. PQCA’s compliance engine tracks these same mandates against your live inventory, per control, with evidence.

EU CRA
Reporting obligations apply

Manufacturers must report actively exploited vulnerabilities and severe incidents — the CRA’s first binding obligations.

11 Sep 2026
Binding · EU
FIPS 140-2
Legacy validated modules move to Historical

FIPS 140-2 modules leave the active list — procurement against them ends for US federal systems.

21 Sep 2026
Binding · US
OMB M-26-15
Agency PQC migration plans due to OMB

Every federal civilian agency files its prioritized migration plan under EO 14412 and OMB M-26-15 — the first hard federal deliverable of the transition. National-security systems are expressly excluded.

22 Oct 2026
Binding · US
EU CRA
Cyber Resilience Act core obligations apply

Products with digital elements sold in the EU carry security and vulnerability-handling obligations — cryptographic hygiene included.

11 Dec 2027
Binding · EU
PCI PTS HSM
PTS v4 new-device approvals end

PCI approval labs stop accepting new HSM submissions against PTS v4, ahead of v5 — the first PTS revision to carry post-quantum requirements.

30 Jun 2027
Industry · Global
CNSA 2.0
Operating systems support and prefer CNSA 2.0

NSA guidance expects operating systems in national-security service to support and prefer CNSA 2.0 algorithms (ML-KEM, ML-DSA) by end-2027.

31 Dec 2027
Guidance · US NSS
CBJ · Jordan
Sectoral roadmap — first dated milestone

The first of three dated milestones on the Central Bank of Jordan’s published sectoral PQC roadmap for the Jordanian banking sector.

31 Dec 2027
Guidance · JO
UK NCSC
Discovery complete, migration plan in hand

NCSC’s published timeline expects full cryptographic discovery and a funded transition plan by 2028.

31 Dec 2028
Guidance · UK
NIST IR 8547
112-bit classical security deprecated

Under NIST’s initial public draft, RSA-2048-class security moves to deprecated status — permitted, but flagged, ahead of the proposed 2035 disallow.

31 Dec 2030
Draft · Global
EU roadmap
High-risk use cases quantum-safe

The EU coordinated PQC roadmap expects high-risk systems migrated by the end of 2030.

31 Dec 2030
Guidance · EU
CBJ · Jordan
Sectoral roadmap — second dated milestone

The second dated milestone on CBJ’s published roadmap — landing with the global 2030 cluster of NIST, EU and CNSA dates.

31 Dec 2030
Guidance · JO
UK NCSC
Highest-priority migrations complete

The most critical cryptography — long-shelf-life data, root keys, CA infrastructure — migrated by 2031.

31 Dec 2031
Guidance · UK
CNSA 2.0
Full transition for national-security systems

NSA’s completion target: CNSA 2.0 as the baseline across NSS, with classical-only deployments needing explicit waivers.

1 Jan 2033
Guidance · US NSS
NIST IR 8547
112-bit security disallowed

Proposed in NIST’s initial public draft: RSA-2048-class cryptography disallowed for US federal use — the anchor date most global programs plan against.

31 Dec 2035
Draft · Global
CBJ · Jordan
Sectoral roadmap — third dated milestone

The last dated milestone on CBJ’s published roadmap, coinciding with NIST IR 8547’s 2035 disallowance date.

31 Dec 2035
Guidance · JO
UK NCSC
Migration complete across the estate

All remaining systems quantum-safe by 2035 under the NCSC timeline.

31 Dec 2035
Guidance · UK
MENA
UAE · Saudi NCA · CBJ supervisory reviews

Gulf and Jordanian supervisors are folding cryptographic inventories and PQC transition roadmaps into reviews on rolling, institution-specific timelines.

Rolling
Guidance · MENA

Dates reflect published standards and mandates as of July 2026 and are reviewed as texts evolve. Binding entries carry direct legal or procurement force for the named scope; guidance entries are published national timelines; draft entries come from NIST IR 8547’s initial public draft and remain proposed. None of this is legal advice — map your own obligations in a briefing.