QianHeng乾珩 PQC Docs Hub量子文档 ✦ Ask AI✦ 问问文档 ⚐ Scan⚐ 扫一扫

Regional Mandates

Standards become obligations through national authorities — and they do not all say the same thing. The US mandates specific algorithms outright (chiefly for federal and national-security systems, with critical-infrastructure operators being directed to migrate rather than every industry being mandated today); Germany and France insist on hybrid deployment; the UK and EU set roadmaps. The recurring deadlines to plan around are roughly 2030 (deprecate RSA/ECC) and 2035 (disallow them).

The headline deadlines

Across jurisdictions, two dates dominate planning. Around 2030, classical RSA/ECC begins to be deprecated; by 2035, it is to be disallowed for protected systems. These come most explicitly from US guidance (NIST IR 8547) and are echoed in the UK roadmap and EU recommendation. See Timeline.

By jurisdiction

JurisdictionAuthorityStance / deadline
USANSA, White House, NISTCNSA 2.0 advisory (updated 30 May 2025) mandates ML-KEM-1024, ML-DSA-87, LMS/XMSS, AES-256, SHA-384/512: software/firmware signing exclusive by 2030; networking prefer by 2026 / exclusive by 2030; browsers, servers & cloud support by 2025 / exclusive by 2033. NSM-10 (4 May 2022); OMB M-23-02 (18 Nov 2022); NIST IR 8547 (IPD Nov 2024) — deprecate RSA/ECC ~2030, disallow 2035. EO 14306 (Jun 2025) amended the earlier EO 14144: it required CISA to publish a PQC product-category list by 1 Dec 2025 (CISA subsequently published and maintains it); TLS 1.3 (or successor) by 2030. EO 14412 (22 Jun 2026) makes federal migration to NIST-approved FIPS PQC national policy: most sensitive federal systems to PQC encryption by end-2030, authentication by end-2031; federal contractors to comply with PQC FIPS by end-2030
Germany (DE)BSITR-02102-1 (current 2026-01); recommends ML-KEM plus FrodoKEM, Classic McEliece and HQC, with ML-DSA/SLH-DSA/LMS-HSS/XMSS for signatures, and strongly recommends hybrid
France (FR)ANSSIPosition paper (4 Jan 2022) + follow-up (11 Oct 2023); phased transition, hybrid-first / defense-in-depth (hybrid required for both KEMs and signatures), viewing PQC-only as premature. Roadmap: Phase 1 hybrid now; Phase 2 from ~2025; optional PQC-only from ~2030
UKNCSCMigration timelines (Mar 2025): by 2028 discovery + plan; by 2031 highest-priority migrations done; by 2035 migration complete
EUEuropean Commission / member statesRecommendation (EU) 2024/1101 (11 Apr 2024) Coordinated Implementation Roadmap; NIS Cooperation Group PQC roadmap (Jun 2025): national strategies by end-2026, high-risk critical infrastructure by 2030, medium-risk by 2035; ENISA PQC studies
China (CN)SCA / 商密National commercial cryptography regime under the SCA; domestic bodies launched a next-generation (quantum-resistant) algorithm call in 2025; no formal commercial-cryptography PQC standard equivalent to NIST FIPS 203/204/205 yet — see China Overview

USA — mandate-driven

The US is the most prescriptive. The NSA's CNSA 2.0 advisory (updated 30 May 2025) names exact algorithms and parameter sets — ML-KEM-1024, ML-DSA-87, the stateful hash-based LMS/XMSS (per SP 800-208), plus AES-256 and SHA-384/512. Its CNSA 2.0 FAQ sets staged milestones: software and firmware signing exclusive by 2030; networking equipment preferred by 2026 and exclusive by 2030; web browsers, servers and cloud services supporting CNSA 2.0 by 2025 and exclusive by 2033. NSM-10 (4 May 2022) set the national direction, OMB M-23-02 (18 Nov 2022) drove inventories, the joint CISA/NSA/NIST "Quantum-Readiness: Migration to PQC" factsheet (21 Aug 2023) and NCCoE SP 1800-38 give practical guidance, and NIST IR 8547 (initial public draft Nov 2024) defines the deprecate-then-disallow timeline for RSA/ECC. In June 2025, Executive Order 14306 amended the earlier EO 14144: it dropped the near-term mandatory PQC procurement triggers but retained the requirement that CISA publish a list of PQC product categories by 1 December 2025 — which CISA subsequently published and maintains — and the goal of TLS 1.3 (or a successor) by 2030.

On 22 June 2026, the US issued Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks", which further establishes as national policy the migration of federal information systems to NIST-approved FIPS PQC and directs support for critical-infrastructure owners and operators in their migration. It sets deadlines: encryption migration for the most sensitive federal systems by the end of 2030, authentication migration by the end of 2031, and federal contractors to comply with PQC FIPS by the end of 2030. It should be read alongside NSM-10, OMB M-23-02, CNSA 2.0, NIST IR 8547 and EO 14306.

Germany and France — hybrid first

European regulators are notably more cautious and both center on hybrid. Germany's BSI (TR-02102-1, current version 2026-01) is conservative: it recommends ML-KEM but also keeps FrodoKEM, Classic McEliece and HQC in view, recommends ML-DSA, SLH-DSA, LMS-HSS and XMSS for signatures, and strongly recommends pairing PQC with classical cryptography. France's ANSSI (position paper of 4 Jan 2022, with an 11 Oct 2023 follow-up) takes a phased, hybrid-first / defense-in-depth line — requiring hybrid for both KEMs and signatures — and regards PQC-only deployment as premature; its published roadmap is Phase 1 hybrid now, Phase 2 from around 2025, and optional PQC-only from around 2030. In June 2026, ANSSI sent a further procurement and certification signal: from 2027 it will no longer certify security products that lack quantum-safe encryption, and it is pushing enterprises to procure quantum-safe products by 2030. This is a recent regulatory-enforcement development and should be understood together with ANSSI's existing technical line of hybrid-first, with PQC-only possible only after 2030. If you operate in the EU, plan for hybrid as the baseline, not an option.

UK and EU — roadmaps

The UK's NCSC published "Timelines for migration to post-quantum cryptography" (Mar 2025), setting three checkpoints: by 2028, discovery and a migration plan; by 2031, highest-priority migrations complete; by 2035, migration complete. At the EU level, Recommendation (EU) 2024/1101 (11 Apr 2024) establishes a Coordinated Implementation Roadmap, followed by the NIS Cooperation Group PQC roadmap (Jun 2025) — which calls for national strategies by end-2026, high-risk critical infrastructure migrated by 2030, and medium-risk systems by 2035 — and ENISA PQC studies, harmonizing direction without dictating a single algorithm set.

China

China runs its commercial cryptography regime under the regulatory framework of the State Cryptography Administration (SCA / 商密). In 2025, domestic bodies launched a next-generation, quantum-resistant cryptographic algorithm call; as of now there is no formal commercial-cryptography PQC standard equivalent to NIST FIPS 203/204/205. (The CACR ran an earlier national post-quantum competition, 2018–2020.) This track is covered separately in China Overview.

Warning
A US CNSA 2.0 deployment and an ANSSI-compliant one are not interchangeable: the former mandates specific PQC-only parameter sets for many uses, while the latter requires hybrid. Multinationals must map requirements per jurisdiction and design for the strictest — usually meaning hybrid plus crypto-agility.

Standards & references

  • UK NCSC — Timelines for migration to post-quantum cryptography (Mar 2025)
  • USA — NSA CNSA 2.0 algorithms advisory and FAQ (updated 30 May 2025); White House NSM-10 (4 May 2022); OMB M-23-02 (18 Nov 2022); CISA/NSA/NIST "Quantum-Readiness: Migration to PQC" factsheet (21 Aug 2023); NCCoE SP 1800-38; EO 14306 (Jun 2025); EO 14412 "Securing the Nation Against Advanced Cryptographic Attacks" (22 Jun 2026); NIST IR 8547
  • Germany — BSI TR-02102-1 (current version 2026-01)
  • France — ANSSI position paper on the migration to PQC (4 Jan 2022) and follow-up (11 Oct 2023)
  • EU — Recommendation (EU) 2024/1101 (11 Apr 2024); NIS Cooperation Group PQC roadmap (Jun 2025: end-2026 / 2030 / 2035); ENISA PQC studies

区域强制要求

标准要通过各国主管机构才成为义务,而各方口径并不一致。美国直接强制指定算法(主要面向联邦与国家安全系统,并对关键基础设施运营者提出迁移要求,而非当前已强制所有行业);德国与法国坚持混合部署;英国与欧盟则设定路线图。规划时反复出现的期限大致是 2030 年(弃用 RSA/ECC)与 2035 年(禁用)。

关键期限

跨辖区来看,有两个时间点主导着规划。2030 年前后,经典 RSA/ECC 开始被弃用;到 2035 年,受保护系统必须禁用这些算法。这一口径在美国指南(NIST IR 8547)中表述得最为明确,英国路线图与欧盟建议也与之呼应。详见 时间线

按司法辖区

辖区主管机构立场 / 期限
美国NSA、白宫、NISTCNSA 2.0 建议(2025 年 5 月 30 日更新)强制 ML-KEM-1024、ML-DSA-87、LMS/XMSS、AES-256、SHA-384/512:软件固件签名 2030 年前唯一;网络设备 2026 年前优选、2030 年前唯一;浏览器、服务器与云 2025 年前支持、2033 年前唯一。NSM-10(2022-05-04);OMB M-23-02(2022-11-18);NIST IR 8547(2024-11 公开草案),约 2030 弃用、2035 禁用 RSA/ECC。第 14306 号行政令(2025-06)修订了此前的第 14144 号行政令:要求 CISA 于 2025-12-01 前发布 PQC 产品类别清单(CISA 后续发布并维护该清单);2030 年前采用 TLS 1.3 或其后继。第 14412 号行政令(2026-06-22)将联邦迁移到 NIST 批准的 FIPS PQC 确立为国家政策:最敏感联邦系统加密迁移期限 2030 年底、认证迁移 2031 年底,联邦承包商须于 2030 年底前符合 PQC FIPS
德国(DE)BSITR-02102-1(现行 2026-01);推荐 ML-KEM 并保留 FrodoKEM、Classic McEliece 与 HQC,签名用 ML-DSA/SLH-DSA/LMS-HSS/XMSS,并强烈推荐混合
法国(FR)ANSSI立场文件(2022-01-04)与后续(2023-10);分阶段过渡,混合优先 纵深防御(KEM 与签名均要求混合),认为纯 PQC 为时尚早。路线 第一阶段先混合 第二阶段约 2025 年起 可选纯 PQC 约 2030 年起。2026-06 信号:自 2027 年起不再认证缺乏量子安全加密的安全产品,推动企业 2030 年前采购量子安全产品
英国NCSC迁移时间线(2025-03):2028 年前完成发现与规划;2031 年前完成最高优先级迁移;2035 年前完成全部迁移
欧盟欧盟委员会 / 成员国建议(EU)2024/1101(2024-04-11)协调实施路线图;NIS 合作组 PQC 路线图(2025-06):2026 年底前出台国家战略,高风险关键基础设施 2030 年前、中风险 2035 年前;ENISA PQC 研究
中国(CN)SCA / 商密在国家密码管理局(SCA)监管框架下运行商用密码体系;2025 年,国内相关机构启动新一代抗量子密码算法征集;截至目前尚未形成等同于 NIST FIPS 203/204/205 的正式商用密码 PQC 标准,详见 中国概览

美国 强制驱动

美国的要求最为具体明确。NSA 的 CNSA 2.0 建议(2025 年 5 月 30 日更新)指定了确切的算法与参数集,ML-KEM-1024ML-DSA-87、有状态哈希签名 LMS/XMSS(依 SP 800-208),以及 AES-256SHA-384/512。其 CNSA 2.0 常见问答给出分阶段里程碑:软件与固件签名 2030 年前唯一;网络设备 2026 年前优选、2030 年前唯一;浏览器、服务器与云服务 2025 年前支持、2033 年前唯一。NSM-10(2022-05-04)确立国家方向,OMB M-23-02(2022-11-18)推动资产清点,CISA/NSA/NIST《量子就绪 向 PQC 迁移》要点(2023-08-21)与 NCCoE SP 1800-38 提供落地指引,NIST IR 8547(2024-11 公开草案)定义 RSA/ECC 先弃用后禁用的时间表。2025 年 6 月,第 14306 号行政令修订了此前的第 14144 号行政令:取消了近期强制 PQC 采购触发条款,但保留了相关要求——EO 要求 CISA 于 2025-12-01 前发布 PQC 产品类别清单;CISA 后续发布并维护该清单——以及 2030 年前采用 TLS 1.3 或其后继的目标。

2026 年 6 月 22 日,美国发布第 14412 号行政令《Securing the Nation Against Advanced Cryptographic Attacks》,进一步将联邦信息系统迁移到 NIST 批准的 FIPS PQC 确立为国家政策,并要求支持关键基础设施所有者与运营者迁移;其中最敏感联邦系统的加密迁移期限为 2030 年底、认证迁移为 2031 年底,联邦承包商须在 2030 年底前符合 PQC FIPS。该命令应与 NSM-10、OMB M-23-02、CNSA 2.0、NIST IR 8547 以及 EO 14306 一并阅读。

德国与法国 混合优先

欧洲监管机构明显更为审慎,且都以混合为核心。德国 BSI(TR-02102-1,现行 2026-01 版)立场保守:推荐 ML-KEM,同时把 FrodoKEM、Classic McEliece 与 HQC 一并纳入考量,签名推荐 ML-DSA、SLH-DSA、LMS-HSS 与 XMSS,并强烈建议将 PQC 与经典密码搭配。法国 ANSSI(2022-01-04 立场文件,并于 2023-10 跟进)采取分阶段、混合优先与纵深防御的路线——KEM 与签名均要求混合——认为纯 PQC 部署为时尚早;其公布的路线为第一阶段先混合 第二阶段约 2025 年起 可选纯 PQC 约 2030 年起。2026 年 6 月,ANSSI 进一步释放采购与认证信号:自 2027 年起不再认证缺乏量子安全加密的安全产品,并推动企业到 2030 年采购量子安全产品。该信息属于监管执行层面的最新动向,应与 ANSSI 原有“混合优先、2030 后可考虑纯 PQC”的技术路线结合理解。若在欧盟运营,应把混合作为基线而非可选项。

英国与欧盟 路线图

英国 NCSC 发布《向后量子密码迁移的时间线》(2025-03),设三个节点:2028 年前完成发现与迁移规划;2031 年前完成最高优先级迁移;2035 年前完成全部迁移。在欧盟层面,建议(EU)2024/1101(2024-04-11)确立协调实施路线图,随后有 NIS 合作组 PQC 路线图(2025-06)——要求 2026 年底前出台国家战略、高风险关键基础设施 2030 年前迁移、中风险系统 2035 年前迁移——与 ENISA PQC 研究,在不指定单一算法集的前提下统一方向。

中国

中国在国家密码管理局(SCA)监管框架下运行商用密码体系。2025 年,国内相关机构启动新一代抗量子密码算法征集;截至目前尚未形成等同于 NIST FIPS 203/204/205 的正式商用密码 PQC 标准。CACR 早前曾举办一轮国家后量子密码竞赛(2018 至 2020)。该路线单独见 中国概览

警告
符合美国 CNSA 2.0 的部署与符合 ANSSI 的部署并不可互换:前者在许多场景强制特定的纯 PQC 参数集,后者要求混合。跨国机构须按辖区逐一梳理要求,并按最严标准设计,通常即混合加密码敏捷性。

标准与参考

  • 英国 NCSC 向后量子密码迁移的时间线(2025-03)
  • 美国 NSA CNSA 2.0 算法建议与常见问答(2025-05-30 更新);白宫 NSM-10(2022-05-04);OMB M-23-02(2022-11-18);CISA/NSA/NIST《量子就绪 向 PQC 迁移》要点(2023-08-21);NCCoE SP 1800-38;第 14306 号行政令(2025-06);第 14412 号行政令《Securing the Nation Against Advanced Cryptographic Attacks》(2026-06-22);NIST IR 8547
  • 德国 BSI TR-02102-1(现行 2026-01 版)
  • 法国 ANSSI 向 PQC 迁移立场文件(2022-01-04)及后续(2023-10)
  • 欧盟 建议(EU)2024/1101(2024-04-11);NIS 合作组 PQC 路线图(2025-06:2026 年底 / 2030 / 2035);ENISA PQC 研究
⚑ Report an error⚑ 纠错与校正