Standardization & Deadlines
Post-quantum cryptography moved from an open research question to finalized NIST standards and increasingly concrete government migration timelines over roughly a decade. This timeline traces the NIST competition, the published FIPS standards, and the government deadlines that now drive migration.
The NIST PQC standardization project
NIST ran a multi-year, open, public competition to select quantum-safe algorithms — the same model that produced AES. Candidates were submitted, cryptanalyzed by the global community, and narrowed over successive rounds.
| Date | Milestone |
|---|---|
| 2016 | NIST issues the formal call for PQC proposals. |
| Nov 2017 | Submission deadline; 69 candidate algorithms accepted into Round 1. |
| Jan 2019 | Round 2 candidates announced (26 algorithms). |
| Jul 2020 | Round 3 finalists announced (7 finalists + alternates). |
| Jul 2022 | First selections: CRYSTALS-Kyber (KEM) plus CRYSTALS-Dilithium, Falcon, and SPHINCS+ (signatures). |
| Aug 13, 2024 | Final standards published: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA). |
| Oct 2024 | Additional digital-signature on-ramp advances to Round 2 (broadening signature diversity). |
| Nov 2024 | NIST IR 8547 published as initial public draft (RSA/ECC deprecation timeline). |
| Mar 11, 2025 | HQC selected in the fourth round for standardization as an additional, code-based KEM beyond ML-KEM (adding KEM diversity). |
| May 2025 | NSA CNSA 2.0 algorithms advisory updated (30 May 2025). |
| Jun 2025 | US Executive Order 14306 amends EO 14144 — drops near-term mandatory PQC procurement triggers, but keeps the CISA PQC product-category list and the TLS 1.3 by 2030 target. |
| Jun 2025 | EU NIS Cooperation Group PQC roadmap — national strategies by end-2026; high-risk critical infrastructure by 2030; medium-risk by 2035. |
| Sep 2025 | SP 800-227 (recommendations for KEMs) finalized. |
| Sep 2025 | Apple enables quantum-secure TLS by default for URLSession and the Network framework on iOS 26, iPadOS 26, macOS 26 and related systems; see Apple's current platform documentation for exact coverage. |
| Nov 2025 | Microsoft makes ML-KEM and ML-DSA APIs generally available via Windows Update in the CNG (Cryptography API: Next Generation) of Windows 11 and Windows Server 2025. |
| May 2026 | NIST signature on-ramp advances to Round 3 (9 candidates, 14 May 2026). |
From competition names to FIPS names
The selected algorithms were renamed as they became standards: Kyber became ML-KEM (FIPS 203), Dilithium became ML-DSA (FIPS 204), and SPHINCS+ became SLH-DSA (FIPS 205). Falcon is being standardized separately as FN-DSA (FIPS 206, in progress). NIST also runs a separate additional-signatures on-ramp — its own process with Rounds 1–3 (Round 3 began May 2026) — to broaden mathematical diversity. This is distinct from the main competition's Round 4, which concluded in March 2025 — selecting HQC, with Classic McEliece and BIKE not selected; Classic McEliece's future may still be discussed in standardization or industry channels outside NIST.
US government mandates and deadlines
Standardization is only half the story. A series of US policy actions converts the standards into binding deadlines.
NSM-10 (2022)
National Security Memorandum 10 (May 2022) directs US federal agencies to begin the transition to quantum-resistant cryptography, mandates cryptographic inventories, and sets the migration in motion across government.
NSA CNSA 2.0
The NSA's Commercial National Security Algorithm Suite 2.0 specifies the quantum-safe algorithms required for US national security systems, with an aggressive adoption schedule:
- Algorithms:
ML-KEM-1024for key establishment andML-DSA-87for general signatures, at the highest parameter sets. - Software and firmware signing: the stateful hash-based signatures
LMSandXMSS. - Milestones: phased adoption with key transitions through 2030–2033, after which CNSA 2.0 algorithms become the default and then the exclusive choice for new and existing national security systems.
NIST IR 8547 — deprecation timeline
NIST Internal Report 8547 lays out the transition away from quantum-vulnerable algorithms for the broader ecosystem:
- After 2030: quantum-vulnerable public-key algorithms at 112-bit security strength are deprecated (discouraged, allowed only with risk acceptance).
- After 2035: 112-bit-strength algorithms are disallowed, and RSA/ECC/finite-field DH and other quantum-vulnerable public-key algorithms at 128-bit security strength and above are also disallowed thereafter.
| Framework | Key dates | Scope |
|---|---|---|
| NSM-10 | 2022 onward | Federal migration kickoff, inventories |
| CNSA 2.0 | Advisory updated May 2025; transitions through 2030–2033 | US national security systems |
| NIST IR 8547 | IPD Nov 2024; deprecate ~2030, disallow 2035 | Broad federal/ecosystem guidance |
| EU Recommendation 2024/1101 | Apr 2024 | EU coordinated implementation roadmap |
| UK NCSC timelines | Mar 2025: 2028 / 2031 / 2035 | UK migration checkpoints |
What this means for your timeline
The standards are final and the deadlines are concrete. With deprecation around 2030 and a multi-year migration ahead, organizations that have not yet inventoried their cryptography are already behind the curve implied by these dates. Use these milestones as fixed anchors when planning your own migration.
Standards & references
- NIST PQC — HQC selected as additional KEM (11 Mar 2025); FIPS 203/204/205 final (13 Aug 2024)
- NIST SP 800-227 — Recommendations for KEMs (finalized Sept 2025)
- NIST IR 8547 — Transition to PQC standards (initial public draft, Nov 2024)
- NIST additional digital-signature on-ramp — Round 2 (Oct 2024)
- NSA CNSA 2.0 — algorithms advisory updated 30 May 2025
- UK NCSC — Timelines for migration to PQC (Mar 2025)
- EU — Recommendation (EU) 2024/1101 (11 Apr 2024)
标准化与截止期
后量子密码用了约十年 从一个开放的研究课题走向 NIST 标准定稿 并被各国政府路线图与特定监管要求推动迁移 本时间线梳理 NIST 竞赛 已发布的 FIPS 标准 以及如今驱动迁移的政府截止期
NIST 后量子密码标准化项目
NIST 举办了一场历时多年的公开竞赛来遴选量子安全算法 沿用了当年遴选 AES 的同一模式 候选方案提交后由全球社区进行密码分析 在一轮轮筛选中逐步收窄
| 时间 | 里程碑 |
|---|---|
| 2016 | NIST 正式发出 PQC 方案征集 |
| 2017 年 11 月 | 提交截止 69 个候选算法进入第一轮 |
| 2019 年 1 月 | 公布第二轮候选 26 个算法 |
| 2020 年 7 月 | 公布第三轮入围方案 7 个决赛者及备选 |
| 2022 年 7 月 | 首批入选:CRYSTALS-Kyber(KEM),以及 CRYSTALS-Dilithium、Falcon、SPHINCS+(签名)。 |
| 2024 年 8 月 13 日 | 最终标准发布:FIPS 203(ML-KEM)、FIPS 204(ML-DSA)、FIPS 205(SLH-DSA)。 |
| 2024 年 10 月 | 追加签名补充征集进入第二轮拓宽签名多样性 |
| 2024 年 11 月 | NIST IR 8547 发布初版公开草案 RSA/ECC 弃用时间线 |
| 2025 年 3 月 11 日 | HQC 入选NIST 在第四轮中选择 HQC 进入标准化 作为除 ML-KEM 之外额外的编码类 KEM 标准化对象 用于增加 KEM 多样性 |
| 2025 年 5 月 | NSA CNSA 2.0 算法建议更新 2025 年 5 月 30 日 |
| 2025 年 6 月 | 美国第 14306 号行政令修订第 14144 号行政令 取消近期强制 PQC 采购触发条款 但保留 CISA PQC 产品类别清单与 2030 年前 TLS 1.3 目标 |
| 2025 年 6 月 | 欧盟 NIS 合作组 PQC 路线图 2026 年底前出台国家战略 高风险关键基础设施 2030 年前 中风险 2035 年前 |
| 2025 年 9 月 | SP 800-227 KEM 建议定稿 |
| 2025 年 9 月 | Apple 在 iOS 26、iPadOS 26、macOS 26 等系统的 URLSession 与 Network.framework 中默认启用量子安全 TLS;具体覆盖范围以 Apple 当期平台文档为准。 |
| 2025 年 11 月 | Microsoft 通过 Windows 更新在 Windows 11 与 Windows Server 2025 的 CNG(Cryptography API: Next Generation)中正式提供 ML-KEM 与 ML-DSA API。 |
| 2026 年 5 月 | NIST 签名补充征集进入第三轮 9 个候选 2026 年 5 月 14 日 |
从竞赛名到 FIPS 名
入选算法在成为标准时被重新命名 Kyber 成为 ML-KEM(FIPS 203)、Dilithium 成为 ML-DSA(FIPS 204)、SPHINCS+ 成为 SLH-DSA(FIPS 205)。Falcon 正作为 FN-DSA 单独标准化 FIPS 206 进行中 NIST 另设一个独立的 追加签名补充征集(on-ramp) 流程 有自己的第 1 至 3 轮 第 3 轮于 2026 年 5 月开始 用于拓宽数学多样性 它与主竞赛的第四轮不同 第四轮已于 2025 年 3 月结束 仅选中 HQC;Classic McEliece 与 BIKE 未入选,其中 Classic McEliece 的后续仍可能在 NIST 以外的标准化或产业渠道中讨论
美国政府的强制要求与截止期
标准化只是事情的一半 一系列美国政策举措把标准转化为有约束力的截止期
NSM-10 2022
第 10 号国家安全备忘录 2022 年 5 月 指示美国联邦机构启动向抗量子密码的过渡 强制开展密码资产清点 并在全政府范围推动迁移
NSA CNSA 2.0
NSA 的商用国家安全算法套件 2.0 规定了美国国家安全系统所需的量子安全算法 并附带激进的采用时间表
- 算法密钥建立用
ML-KEM-1024通用签名用ML-DSA-87均为最高参数集 - 软件与固件签名有状态的基于哈希签名
LMS与XMSS - 里程碑分阶段采用 关键过渡贯穿 2030 至 2033 年此后 CNSA 2.0 算法将成为新建及现有国家安全系统的默认 进而成为唯一选择
NIST IR 8547 弃用时间线
NIST 内部报告 8547 为更广生态描绘了告别量子脆弱算法的过渡路径
- 2030 年后112 比特安全强度的量子脆弱公钥算法被弃用不鼓励 仅在接受风险时允许
- 2035 年后112 比特安全强度的算法被禁用128 比特及以上安全强度的 RSA/ECC/有限域 DH 等量子脆弱公钥算法也在此后被禁用
| 框架 | 关键日期 | 适用范围 |
|---|---|---|
| NSM-10 | 2022 年起 | 联邦迁移启动 资产清点 |
| CNSA 2.0 | 建议 2025 年 5 月更新 过渡贯穿 2030 至 2033 年 | 美国国家安全系统 |
| NIST IR 8547 | 2024 年 11 月草案 约 2030 弃用 2035 禁止 | 广义联邦及生态指引 |
| EU 建议 2024/1101 | 2024 年 4 月 | 欧盟协调实施路线图 |
| UK NCSC 时间线 | 2025 年 3 月 2028 / 2031 / 2035 | 英国迁移节点 |
这对你的时间线意味着什么
标准已定稿 截止期很具体 弃用期限逼近 2030 年 而前方还有长达数年的迁移 尚未清点密码资产的机构 已经赶不上这些日期所隐含的进度 在规划自己的 迁移 时 应把这些里程碑当作固定的锚点
标准与参考
- NIST PQC HQC 入选为追加 KEM 2025 年 3 月 11 日 FIPS 203/204/205 定稿 2024 年 8 月 13 日
- NIST SP 800-227 KEM 建议 2025 年 9 月定稿
- NIST IR 8547 向 PQC 标准过渡 初版公开草案 2024 年 11 月
- NIST 追加签名补充征集 第二轮 2024 年 10 月
- NSA CNSA 2.0 算法建议 2025 年 5 月 30 日更新
- 英国 NCSC 向 PQC 迁移的时间线 2025 年 3 月
- 欧盟 建议(EU)2024/1101 2024 年 4 月 11 日