Government Post-Quantum Deadlines: NIST, NSA CNSA 2.0 and Federal Migration
Two clocks
US agencies run two overlapping timelines. NIST sets general standards, and the NSA sets rules for national security systems.
NIST timeline
NIST published the draft IR 8547 in November 2024. It plans a phased move away from RSA, elliptic curves and related algorithms:
- 2030: algorithms with 112-bit security (such as RSA-2048 and ECC P-256) are deprecated for new use.
- 2035: quantum-vulnerable algorithms are to be disallowed.
The standards behind the move are ML-KEM, ML-DSA and SLH-DSA, explained in the NIST process guide. Check whether the final version of IR 8547 has replaced the draft.
NSA CNSA 2.0 timeline
- January 1, 2027: new national security system acquisitions must be CNSA 2.0 compliant.
- Software and firmware signing: move first, with exclusive use by about 2030.
- 2030 to 2033: phase out legacy networking gear and move operating systems, custom applications and cloud services.
- Early 2030s: secondary sources describe full enforcement around 2031 to 2033, and summaries differ, so confirm with the NSA FAQ.
Who it binds
CNSA 2.0 is mandatory only for national security systems, but vendors and contractors tend to follow it, so its effect spreads into the commercial world. See crypto agility.
Why a deadline helps the quantum story
Dates turn a vague worry into a project plan. Harvest now, decrypt later is the reason agencies will not wait for a machine to exist before acting.
What it means for crypto
Blockchains are not bound by these dates, but their communities read them as a warning. Read the chains and governments guide.
Status check as of October 9, 2026
| Item | What we can verify | What we could not confirm |
|---|---|---|
| NIST IR 8547 | The NIST page shows an initial public draft from November 12, 2024, with comments closed January 10, 2025. NIST's PQC project page says it will deprecate and ultimately remove quantum-vulnerable algorithms from its standards by 2035, with high-risk systems moving much earlier. | A final version. The pages we read did not show one, and did not themselves list the 2030 date. |
| FIPS 203, 204, 205 | Released August 2024 (ML-KEM, ML-DSA, SLH-DSA). NIST says they can and should be put into use now. | Nothing to hedge here. |
| FIPS 206 (FN-DSA, based on Falcon) | NIST says standardization is underway. A vendor guide says the draft was submitted for approval on August 28, 2025. | A published draft or final date. That vendor guide expects a final in late 2026 or early 2027, which is an expectation, not a NIST commitment. |
| HQC (backup key method) | NIST selected it as a backup method. The NIST page says standardization is underway. | The designation FIPS 207 appeared only in a forum reference, so treat the number as unconfirmed. |
CNSA 2.0 dates, as summarized
A PostQuantum.com summary of the NSA advisory (written in September 2022, so check the NSA's current text) lists: new equipment acquisitions compliant from January 1, 2027; software and firmware signing moved by 2030; legacy networking gear that cannot be upgraded phased out by 2030; niche systems updated or replaced by 2033; full enforcement expected around the end of 2031; and 2035 as the outer limit for national security systems.
New in 2026: the June executive order
A Quantum Computing Report summary of Executive Order 14412 says covered contractors must follow NIST post-quantum standards by December 31, 2030, and agencies must move high-value assets by the end of 2031, with a NIST pilot by late 2027. Check the signed text. Details are in the orders guide.
A worked example: one vendor, three clocks
Picture a company selling VPN gear. If it wants national security customers, the equipment must be compliant for sales from January 1, 2027. If it sells to federal agencies as a contractor, the order's 2030 date may apply. If it sells to ordinary businesses, NIST's guidance is the benchmark. One product roadmap has to satisfy all three, which is why early movers tend to build crypto agility first.
Dates to watch
- January 1, 2027: CNSA 2.0 acquisition date.
- Any NIST posting of a final IR 8547 or a FIPS 206 draft or final. Check csrc.nist.gov.
Sources and further reading
- The Quantum Insider: post-quantum migration timelines
- PostQuantum.com: NSA CNSA 2.0
- PQC knowledge base: NIST timeline
- NIST CSRC: IR 8547 initial public draft
- NIST CSRC: post-quantum cryptography project
- Encryption Consulting: FN-DSA (FIPS 206) status
- Quantum Computing Report: executive order dates
Reported as of 2026-10-09. Government programs change often, so check the primary documents before relying on any figure.
Frequently asked questions
When must RSA and ECC be retired?
In NIST's draft plan, 112-bit security algorithms are deprecated by 2030 and quantum-vulnerable algorithms are disallowed after 2035.
What happens on January 1, 2027?
Under CNSA 2.0, new acquisitions for national security systems must be CNSA 2.0 compliant.
Does this apply to Solana or Bitcoin?
No, these rules apply to government systems. Blockchain communities decide their own upgrades.
Are the exact dates certain?
Sources disagree on some intermediate NSA dates and NIST's plan was a draft. Verify with the primary documents.
Is NIST IR 8547 final?
The NIST page we read still showed the November 2024 initial public draft. Check csrc.nist.gov for updates.
What is FIPS 206?
The planned standard for FN-DSA, a signature scheme based on Falcon. We could not confirm a published draft or final.
What is HQC?
A backup key establishment method NIST selected in March 2025. Its standard number is not confirmed in our sources.
Do these dates bind private companies?
CNSA 2.0 binds national security systems. The 2026 order reportedly reaches federal contractors. Others follow NIST guidance voluntarily or by contract.
Keep reading
- The NIST Post-Quantum Process Explained
How NIST ran its multi-year post-quantum cryptography competition, from public call to the first standards in 2024, and what work is still continuing. - Crypto Agility Explained: Preparing for Algorithm Change
Crypto agility is the ability to swap cryptographic algorithms without rebuilding a system. Learn why it matters for the post-quantum shift and for blockchains. - US Quantum Executive Orders of June 2026 Explained
What the two June 22, 2026 White House executive orders on quantum technology and post-quantum cryptography say, and what they do not do. - Harvest Now, Decrypt Later: The Quantum Threat Explained
Harvest now, decrypt later means collecting encrypted data today to unlock it with a future quantum computer. What it is and who should care.
All Quantum policy and governments guides | Back to top | Search the site
Main pages: Quantum computing explained | Quantum and crypto | Companies | Quantum news | Glossary