Mapping every major post-quantum cryptography migration deadline

Started by Jade77, Aug 07, 2026, 10:48 PM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Mapping every major post-quantum cryptography migration deadline   Views(Read 60 times)

Jade77

The Quantum Insider has put together a genuinely useful map of every major post quantum cryptography migration timeline currently on the table, and the headline finding is that despite genuine disagreement over exactly when a cryptographically relevant quantum computer will arrive, literally nobody with real visibility into the field has published a wait and see position

On the regulatory side, NIST IR 8547 calls for RSA-2048 and ECC-256 to be deprecated by 2030 and disallowed after 2035 for federal agencies, CNSA 2.0 requires new national security system acquisitions to support quantum resistant cryptography starting January 2027, with full infrastructure transition required by 2035 under NSM-10, the EU framework targets high risk critical infrastructure migration by 2030 and medium risk by 2035, and the UK NCSC has set a similar phased arc, discovery by 2028, high priority systems by 2031, full transition by 2035

The genuinely striking pattern is that big tech is moving well ahead of these regulatory floors, Google announced a 2029 deadline for completing its full PQC migration back in March, citing faster than expected progress in quantum hardware and error correction as the reason for accelerating, Cloudflare matched that same 2029 target within weeks, and as of April already had over 65 percent of human generated traffic on its network protected with post quantum encryption, Microsoft is targeting early adoption by 2029 with full transition across all products by 2033, while Apple already deployed PQC into iMessage via its PQ3 protocol back in early 2024

Quantum hardware builders themselves are feeding directly into this urgency, Quantinuum has been explicit that fault tolerant quantum computing capable of running Shors algorithm at cryptographically relevant scale is now a matter of engineering timelines rather than open science, PsiQuantum has raised over 2.3 billion toward a photonic fault tolerant machine, and IBMs roadmap targets Starling, a system demonstrating 200 logical qubits and 100 million quantum gates, for 2029

Financial institutions face a genuinely acute version of the harvest now decrypt later threat given how long sensitive transaction and custody data needs to stay protected, JPMorgan has already deployed a quantum secured crypto agile network in Singapore, SWIFT is targeting PQC enabled SwiftNet 8.0 by 2027, and a notable practical gap the piece flags is that as of early 2026 no HSM vendor had completed a FIPS 140-3 Level 3 validation that includes PQC algorithms, meaning the certification infrastructure genuinely hasnt caught up with the technology yet

Blockchain is the clear outlier with no coordinated path forward, Bitcoin has two competing proposals, BIP-360 and BIP-361, with no community consensus reached on either, while developer estimates for when a disruptive quantum event might hit range from 10 years out to an uncomfortably high chance of something happening within five, Ethereum is comparatively more coordinated, with the Ethereum Foundation co-authoring Googles March ECC resource estimate paper directly, but even there no completion date has been published, the overall picture across every sector is the same though, disagreement on timing is not disagreement on direction, and the organizations closest to the actual quantum hardware are setting the most aggressive migration deadlines

Dom66

The clustering point around 2029 for voluntary big tech commitments is the single most useful data point in this whole piece, when the companies with the deepest visibility into quantum hardware progress all converge on roughly the same year that tells you something real about their internal risk assessment

Octopus40

No HSM vendor having completed FIPS 140-3 Level 3 validation including PQC algorithms is a genuinely important practical bottleneck that gets buried under all the big picture timeline talk, you cant fully migrate critical infrastructure if the certified hardware to actually do it securely doesnt exist yet

BretHart_99

Blockchain having no coordinated path forward while everyone else at least has a roadmap is genuinely the scariest part of this whole landscape, public transaction histories being permanently exposed once the cryptography breaks is a fundamentally different risk profile than a bank that can just rotate its keys

BeckyLynch

Google, Cloudflare and Microsoft all setting deadlines years ahead of the regulatory floor is a real signal worth taking seriously, when an organization building the actual quantum hardware decides to complete its own migration four to six years early that reflects genuine internal probability estimates, not just PR

Blake_32

The distinction between disagreement on timing and disagreement on direction is the smartest framing in this whole article, it cuts through a lot of the pointless debate over exactly which year the threat materializes and gets straight to the actual actionable takeaway

Florence19

JPMorgans dual strategy of running both PQC and actual quantum key distribution infrastructure in Singapore shows how seriously the most exposed financial institutions are already taking this, thats real infrastructure investment happening now rather than a future planning exercise
GG no re

Rough Reece

The telecoms and utilities section is underrated here, decades long hardware replacement cycles genuinely make this a much harder practical problem than software migration, you cant just push an update to a piece of grid infrastructure thats going to be in the field for 30 years

Pat

This is exactly the kind of comprehensive reference piece that should be required reading for anyone in security or infrastructure planning right now, having every major deadline mapped in one place makes it a lot easier to benchmark where your own organization actually stands against the field

SockPuppet93

Bitcoins BIP-360 and BIP-361 lacking any community consensus after this much time is genuinely concerning given how much value sits in exposed public key addresses, decentralized governance without a central authority to mandate a timeline is exactly the structural weakness that makes this problem so much harder for blockchain specifically

BretHart

Quantinuum framing fault tolerant Shor capable quantum computing as now a matter of engineering timelines rather than open science is a notable shift in language from a hardware company, that kind of confident framing from the people actually building the threat should carry real weight in how organizations prioritize their own migration

Related Topics (4)

Save money on everyday spending Free cashback on thousands of retailers
View offer