Post-quantum cryptography migration has moved from planning to compliance. Here are the dates that should already be in your roadmap.
For years, the conversation around post-quantum cryptography circled the same question: when will a cryptographically relevant quantum computer actually exist? That framing is now a distraction. The deadlines that matter in 2026 are not about Q-Day arriving. They are about regulators, procurement officers, and auditors asking a much simpler question: is your cryptography validated, inventoried, and migration-ready?
Three converging deadlines and one unmistakable political signal make this the most consequential planning window of the decade for every security and infrastructure team.
Deadline one: September 21, 2026: the FIPS 140-3 sunset
FIPS 140-3 modules can remain active for five years after validation, or until September 21, 2026, when all FIPS 140-3 validations will be moved to the historical list. After that date, any cryptographic module validated only under FIPS 140-3 can no longer satisfy federal procurement requirements. Competitors with FIPS 140-3-validated modules gain an immediate and concrete advantage in regulated markets.
This is not a theoretical future risk. FIPS validation times have increased from an average of 367 days for FIPS 140-3 to 542 days for FIPS 140-3, a 42% increase. Organizations that have not already begun the FIPS 140-3 process have no realistic path to certification before the September deadline.
The practical implication: audit your cryptographic module validations now. Anything still on FIPS 140-3 needs either an active FIPS 140-3 replacement plan or a documented risk acceptance. "We didn't know" will not satisfy a procurement officer or auditor after September 21.
Deadline two: December 31, 2026: the EU Member State baseline
All EU Member States should start transitioning to post-quantum cryptography by the end of 2026. At the same time, the protection of critical infrastructures should be transitioned to PQC as soon as possible, no later than the end of 2030.
This involves establishing national quantum-safe roadmaps and launching pilot projects for high and medium-risk use cases, including identifying stakeholders, supporting cryptographic asset management, creating dependency maps, carrying out risk analyses including supply-chain risks, and establishing national awareness, timelines, and implementation plans.
For enterprises in regulated EU sectors including financial services, energy, telecommunications, and healthcare, this translates directly into regulatory expectation. If your organisation cannot demonstrate that this work has begun, you are already behind the curve.
Deadline three: January 1, 2027: the US national security supply chain
All new US National Security System acquisitions must be CNSA 2.0 compliant by January 1, 2027. Defense contractors and suppliers to National Security Systems face the most aggressive PQC timeline in the private sector.
The practical impact extends far beyond US federal agencies. Any vendor or contractor with significant federal exposure faces procurement requirements that effectively extend this timeline into their own cryptographic infrastructure. And where US procurement leads, global supply chain requirements tend to follow.
The White House just made it official: The signal you cannot ignore
On June 22, 2026, the White House issued Executive Order 14409, Securing the Nation Against Advanced Cryptographic Attacks. The order is unambiguous: the move to quantum-resistant cryptography is no longer a research exercise or a future planning item. It is a federal directive with hard deadlines, named owners, and direct procurement consequences.
Federal agencies must transition all high-value assets and high-impact systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Every agency must name a PQC migration lead. NIST will run a PQC migration pilot to be completed by December 2027.
This is not a US-only story. It is the clearest signal yet that every major jurisdiction is moving in the same direction at the same time. When the White House, the European Commission, NIST, and the UK NCSC all issue binding guidance within the same 12-month window, the message is no longer ambiguous: PQC migration is a programme you are either running or falling behind on.
The threat driving all of it: harvest now, decrypt later
Every regulatory deadline above is a response to one threat that is already underway. Adversaries are actively exfiltrating encrypted data at scale, banking on quantum decryption capability arriving within a decade. The encryption protecting data stolen in today's breach may not survive the decade.
This makes long-lived data the genuine emergency: financial records, healthcare data, intellectual property, legal archives, AI training datasets, and authentication logs. The harvest now, decrypt later threat does not care about regulatory deadlines. Any organisation encrypting data with multi-year confidentiality requirements has a practical de facto deadline regardless of which compliance framework governs their sector.
A realistic enterprise migration takes five to fifteen years. The discovery phase alone, just finding where cryptography lives inside the organisation, takes twelve to twenty-four months for large enterprises. Most organisations are already late.
Where to start
Three actions that cannot wait.
- Run a cryptographic inventory. You cannot migrate what you cannot see. Understanding which algorithms, certificates, and modules are deployed across your environment is the foundational step every regulatory framework requires, and consistently the work that takes longer than organisations expect. Utimaco partners with InfoSec Global to provide a comprehensive crypto discovery solution, helping organisations identify, assess, and prioritise their cryptographic assets for a quantum-safe future.
- Validate your HSM roadmap. Hardware security modules are the cryptographic root of trust for key generation, storage, and signing. Your HSM must support NIST-standardised PQC algorithms including ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), and must be on a clear path to FIPS 140-3 validation. Utimaco's u.trust General Purpose HSM Se-Series is designed crypto-agile and supports these algorithms today.
- Build for cryptographic agility now. The organisations that will navigate this transition with the least disruption are those that architect systems so algorithms can be swapped without rebuilding infrastructure. Hybrid deployment, running classical and post-quantum algorithms in parallel, is the pragmatic interim posture while migration proceeds.
The deadlines are set. The standards are final. From Brussels to Washington, every major authority is saying the same thing. The only remaining question is whether your organisation is treating this as the compliance and security programme it actually is.
Utimaco's u.trust General Purpose HSM Se-Series here supports NIST-standardised PQC algorithms including ML-KEM, ML-DSA, and LMS today.
Test PQC algorithms in your own environment for free with the Quantum Protect Simulator here, no hardware required.
Sind Sie bereit, Ihre digitale Zukunft zu sichern?
Schließen Sie sich den über 500 globalen Unternehmen und Regierungsinstitutionen an, die Utimaco für ihre kritische Sicherheitsinfrastruktur vertrauen.
Kontakt VertriebYour download request(s):

Your download request(s):

About Utimaco's Downloads
Visit our Downloads section and select from resources such as brochures, data sheets, white papers and much more. You can view and save almost all of them directly (by clicking the download button).
For some documents, your e-mail address needs to be verified. The button contains an e-mail icon.
A click on such a button opens an online form which we kindly ask you to fill and submit. You can collect several downloads of this type and receive the links via e-mail by simply submitting one form for all of them. Your current collection is empty.