Regulatory and standards dates
Deadline Board
The public deadlines that constrain a cryptographic migration: what applies, from when, to whom. Each row names the body that issued it and links to the document that sets it, so the date can be checked at source rather than taken on our word.
The board
Five published dates.
These are dates set by regulators and standards bodies, not forecasts of our own. We state how far away each one is in whole days, measured from a single reference date shown below, and we do not attempt anything finer than a day.
As at 2026-07-27
Ordered by date, earliest first. Where two rows share a date, the framework name breaks the tie alphabetically. Relative figures are whole days computed from each ISO date against the reference date above, and are recomputed when the site is rebuilt. Nothing on this page counts down while you read it.
EU DORA
Applies now · 556 days in force2025-01-17 · EU · EUR-Lex
Digital Operational Resilience Act applies — EU financial entities must manage ICT & third-party risk, including cryptographic posture.
NSA CNSA 2.0 · new acquisitions
In 158 days2027-01-01 · US · NSS · NSA
CNSSP 15, as cited by NSA: from 1 January 2027 all new National Security System acquisitions must be CNSA 2.0 compliant (ML-KEM, ML-DSA, SHA-384/512) unless otherwise noted.
NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)
NIST IR 8547 · RSA/ECC deprecated
In 1,618 days2030-12-31 · US · Federal · NIST CSRC
NIST draft transition guidance: 112-bit-strength classical public-key crypto (RSA-2048, ECDSA P-256) deprecated after 2030.
NSA CNSA 2.0 · algorithms mandated
In 1,983 days2031-12-31 · US · NSS · NSA
NSA: by 31 December 2031 CNSA 2.0 algorithms are mandated for use across National Security Systems unless otherwise noted. Equipment that cannot support them must be phased out a year earlier.
NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)
NIST IR 8547 · RSA/ECC disallowed
In 3,444 days2035-12-31 · US · Federal · NIST CSRC
NIST draft transition guidance: classical public-key algorithms disallowed for federal use after 2035.
What this board does not do
It does not rank these dates by risk, because the ordering that matters depends on which of them binds your estate. It does not carry a date for a cryptographically relevant quantum computer; there is no defensible one to publish. If you want an arithmetic answer for your own systems, the migration window at The Quantum Window takes your own inputs and shows the working.
Where the standards themselves are tracked
Several of the dates above refer to algorithms rather than to policies: FIPS 203, 204 and 205 are the standards those deadlines move estates towards. The status of each publication is already maintained on one page and is not restated here, so the two surfaces cannot drift apart.
Embed
Put this board on your own page.
One variant is published, and it is the one below. Paste the snippet into any page and the five rows render inside an iframe, fluid to the width of their container at a fixed height.
<iframe
src="https://www.theosquantum.com/embed/deadlines"
title="Deadline Board: public post-quantum regulatory and standards deadlines"
width="100%"
height="580"
loading="lazy"
style="border:0;background:transparent"
></iframe>Terms
- Free to use, on any site, commercial or not.
- No account, no key, no token. The route is public and takes no parameters.
- No cookies, no analytics, no fingerprinting, and no request to a third party.
- Attribution is not required. The leaf carries one small link back to this page and you may leave it or remove it.
What renders
- The same five rows as above, in the same order, from the same data.
- A transparent document background and no iframe border, so nothing paints a box across your layout.
- Rows on one self-contained panel, which keeps the text legible whether your page is light or dark.
- No site navigation, no footer, no cookie banner, no call to action, and nothing that animates.
- A visible reference date. The figures change only when this site is rebuilt.
The fixed height of 580 pixels is sized so all five rows fit without an internal scrollbar, down to a 320-pixel-wide container. A smaller value gives the iframe a scrollbar, so it is better left as published.
Which of these dates binds your estate
The answer depends on what cryptography you actually run and where. AutoPQC discovers it, maps it to the NIST standards these deadlines point at, and sequences the work. A demo walks through that on a real estate.