The PQC deadlines that set the pace.
Eighteen of the 41 dated milestones PQCA tracks across eleven jurisdictions — the ones that drive programme sequencing. The soonest binding milestone in the Gulf is now Saudi Arabia’s: SAMA requires the cryptographic inventory complete by 31 Dec 2026. Each is taken from the published texts — each labeled by legal weight, so draft guidance is never dressed up as binding law. PQCA scores readiness against these same mandates from your migration-roadmap progress, per control, with evidence.
Manufacturers must report actively exploited vulnerabilities and severe incidents — the CRA’s first binding obligations.
Binding · EU
NIST/CMVP moves FIPS 140-2 modules to the Historical List — procurement against them ends for US federal systems. For FIPS 140-3 specifically, PQCA tracks your plan to move onto CMVP-certified modules. It does not validate modules, and it is not a substitute for CMVP.
Binding · US
Every federal civilian agency files its prioritized migration plan under EO 14412 and OMB M-26-15 — the first hard federal deliverable of the transition. National-security systems are expressly excluded.
Binding · US
Every cryptographic asset inventoried and classified by sensitivity and migration priority, with the operational agility, constraints and third-party dependencies of priority assets assessed. SAMA circular issued under the Saudi Central Bank Law (Royal Decree M/36) — binding on all banks, credit-information companies, finance companies, payment-services providers and licensed financing-support entities in the Kingdom. rulebook.sama.gov.sa
Binding · KSA
A quantum-computing risk assessment aligned with enterprise risk management, with plans for the risks it finds. Second milestone of the same SAMA circular (Royal Decree M/36).
Binding · KSA
PCI approval labs stop accepting new HSM submissions against PTS v4, ahead of v5 — the first PTS revision to carry post-quantum requirements.
Binding · Global
Products with digital elements sold in the EU carry security and vulnerability-handling obligations — cryptographic hygiene included.
Binding · EU
NSA guidance expects operating systems in national-security service to support and prefer CNSA 2.0 algorithms (ML-KEM, ML-DSA) by end-2027.
Guidance · US NSS
The first of three dated milestones on the Central Bank of Jordan’s published sectoral PQC roadmap for the Jordanian banking sector.
Guidance · JO
NCSC’s published timeline expects full cryptographic discovery and a funded transition plan by 2028.
Guidance · UK
Under NIST’s initial public draft, RSA-2048-class security moves to deprecated status — permitted, but flagged, ahead of the proposed 2035 disallow.
Draft · Global
The EU coordinated PQC roadmap expects high-risk systems migrated by the end of 2030.
Guidance · EU
The second dated milestone on CBJ’s published roadmap — landing with the global 2030 cluster of NIST, EU and CNSA dates.
Guidance · JO
The most critical cryptography — long-shelf-life data, root keys, CA infrastructure — migrated by 2031.
Guidance · UK
NSA’s completion target: CNSA 2.0 as the baseline across NSS, with classical-only deployments needing explicit waivers.
Guidance · US NSS
Proposed in NIST’s initial public draft: RSA-2048-class cryptography disallowed for US federal use — the anchor date most global programs plan against.
Draft · Global
The last dated milestone on CBJ’s published roadmap, coinciding with NIST IR 8547’s 2035 disallowance date.
Guidance · JO
All remaining systems quantum-safe by 2035 under the NCSC timeline.
Guidance · UK
NCA has published no post-quantum mandate, so its controls are scored as general cryptographic hygiene, not as a PQC deadline. Saudi Arabia’s dated post-quantum milestones are SAMA’s, above.
Guidance · KSA
Dates reflect published standards and mandates as of September 2026 and are reviewed as texts evolve. PQCA tracks 41 dated milestones in all — 14 binding, 23 guidance, 2 draft and 2 announced — across eleven jurisdictions: Australia, Canada, the EU, France, Germany, global payments, Jordan, Saudi Arabia, the UAE, the UK and the US. Binding entries carry direct legal or procurement force for the named scope; guidance entries are published national timelines; draft entries come from NIST IR 8547’s initial public draft and remain proposed. None of this is legal advice — map your own obligations in a briefing.