CodoraTech CodoraTech
Trends April 8, 2026

Fixed Deadlines, Distant Hardware: Where Post-Quantum Cryptography Stands

Fixed Deadlines, Distant Hardware: Where Post-Quantum Cryptography Stands

How CodoraTech is funded: CodoraTech is supported by advertising and, in some articles, by affiliate links. Where an article contains affiliate links, we say so at the top of that article.

Two things about post-quantum cryptography are true at the same time and are usually reported as if only one could be. The migration deadlines are finished, dated, and in some cases contractually binding on suppliers. The hardware that would justify them is roughly four orders of magnitude short of the published resource estimate, and credentialled cryptographers argue that the headline factorisation records are constructed rather than real. Neither fact cancels the other, because the deadlines were never set by hardware forecasts. They were set by how long today’s encrypted data has to stay secret.

Dates already fixed

  • 13 August 2024: NIST publishes FIPS 203, FIPS 204 and FIPS 205
  • 11 March 2025: HQC selected as a backup key-encapsulation algorithm
  • After 2030: 112-bit RSA and elliptic-curve algorithms deprecated in the NIST IR 8547 draft
  • After 2035: those algorithms disallowed; the NSA intends all national security systems to be quantum-resistant
  • 2028, 2031 and 2035: the UK NCSC’s three migration checkpoints

Five algorithms, and the dates they were signed off

NIST published three post-quantum standards on 13 August 2024: FIPS 203 for ML-KEM, derived from CRYSTALS-KYBER; FIPS 204 for ML-DSA, derived from CRYSTALS-Dilithium; and FIPS 205 for SLH-DSA, derived from SPHINCS+. The Federal Register notice announcing their issuance is dated 14 August 2024.

Two more are in the pipeline. FIPS 206, covering FN-DSA and derived from FALCON, has been selected but was not yet published at the time of writing. On 11 March 2025 NIST selected a fifth algorithm, HQC, as a backup key-encapsulation mechanism built on different mathematics from ML-KEM: insurance against a structural break in lattice assumptions rather than a performance gain. The competition’s reasoning sits in NIST IR 8413 and NIST IR 8545.

Deprecated after 2030, disallowed after 2035

The document that actually constrains procurement is NIST IR 8547, Transition to Post-Quantum Cryptography Standards, issued as an initial public draft in November 2024. It defines its two terms precisely. Deprecated means the algorithm and key length may be used, but the user must accept some security risk. Disallowed means the algorithm or key length is no longer allowed for applying cryptographic protection.

At 112-bit security strength, ECDSA, RSA signatures, finite-field Diffie-Hellman and MQV, elliptic-curve Diffie-Hellman and MQV, and RSA key establishment are all deprecated after 2030 and disallowed after 2035. At 128-bit strength and above the classical algorithms are disallowed after 2035 with no deprecation phase at all. The version consulted here was still a draft, so implementers should check whether a final has been issued before treating those dates as settled.

Three institutional clocks now run in parallel:

  • NIST IR 8547, draft of November 2024: 112-bit classical public-key algorithms deprecated after 2030, disallowed after 2035
  • NSA CNSA 2.0, released 7 September 2022: no transition required before 31 December 2025 for validated systems; all new national security system acquisitions CNSA 2.0 compliant from 1 January 2027; unsupported equipment phased out by 31 December 2030; the algorithms mandated from 31 December 2031; all such systems quantum-resistant by 2035
  • UK NCSC roadmap, published 20 March 2025: identify affected cryptographic services and produce a migration plan by 2028, execute highest-priority upgrades between 2028 and 2031, complete the transition across all systems by 2035

One logical qubit, outliving its parts by a factor of about two

The strongest published error-correction result comes from Google Quantum AI and collaborators in Nature on 9 December 2024. Working with a 105-qubit Willow-generation processor alongside a 72-qubit device, they ran surface codes at distances 3, 5 and 7 and measured an error suppression factor of 2.14 plus or minus 0.02 at distance 7 using a neural network decoder. The distance-7 logical qubit survived 291 plus or minus 6 microseconds, exceeding the lifetime of all its constituent physical qubits by a factor of 2.4 plus or minus 0.3, at an error per cycle of 0.143 percent plus or minus 0.003.

In proportion, that is one logical qubit outliving its physical parts by about a factor of two. A genuine threshold crossing, and very far from a cryptographic attack.

The distance still to travel has a published number. Craig Gidney of Google Quantum AI wrote in arXiv preprint 2505.15917, dated 21 May 2025, that in a 2019 paper with Martin Ekera he had co-published an estimate that 2048-bit RSA integers could be factored in eight hours by a quantum computer with 20 million noisy qubits, and that he now estimates such an integer could be factored in less than a week with fewer than a million noisy qubits, assuming a uniform gate error rate of 0.1 percent.

Set the two side by side: fewer than 1,000,000 physical qubits in the estimate against 105 in the best published error-corrected demonstration, a gap of roughly four orders of magnitude. Gidney’s figure is a resource estimate rather than a demonstration, and it fell twentyfold in six years. That trajectory, not any delivered machine, is why the deadlines sit where they do. IBM’s roadmap targets a large-scale fault-tolerant system called Starling by 2029, which is a vendor roadmap, not a result.

An 8-bit home computer, an abacus and a dog

The sceptical case is made by people with standing to make it. Peter Gutmann of the University of Auckland and Stephan Neuhaus of ZHAW Zurich University of Applied Sciences published Replication of Quantum Factorisation Records with an 8-bit Home Computer, an Abacus, and a Dog as IACR ePrint 2025/1237 in July 2025. Their argument is that quantum factorisation to date is performed using sleight-of-hand numbers that have been selected to make them very easy to factorise using a physics experiment, whereas genuine RSA key generation requires factors differing by more than 100 bits, a condition no quantum demonstration has met.

ZHAW’s own summary is that all currently publicised quantum factorisations used trickery that will not work for ordinary RSA keys. The authors reproduced the published records with a 1981 8-bit home computer, an abacus and a dog, and proposed criteria for judging future claims on their merits. Bruce Schneier, writing about the paper, said he was unsurprised and framed the remaining engineering barriers as a question of whether they are moon landing hard or sun landing hard.

The expert consensus is less dismissive but still not a countdown. Michele Mosca and Marco Piani of evolutionQ surveyed 26 experts for the Quantum Threat Timeline Report 2025, published by the Global Risk Institute on 9 March 2026. The panel rated a cryptographically relevant quantum computer within ten years as quite possible, at 28 to 49 percent, and within fifteen years as likely, at 51 to 70 percent. evolutionQ sells quantum security services, so its authors are not disinterested parties, though the instrument is a survey of independent experts and the publisher is a risk institute rather than a product vendor.

The deadline is set by how long your data must stay secret

The US Office of Management and Budget stated the operative risk in its July 2024 Report on Post-Quantum Cryptography: a malicious cyber actor could collect encrypted data in bulk today, store that data, and decrypt it if a cryptographically relevant quantum computer becomes capable. On timing OMB is deliberately non-committal, saying only that steady advancements may yield such a machine in the coming decade.

Its priority rule follows from the risk rather than the forecast. The categories to migrate first are high-impact information systems, agency high value assets, and systems holding data expected to remain mission-sensitive in 2035. The deciding variable is the required secrecy lifetime of the data, not the arrival date of the hardware. OMB puts the cost of migrating prioritised federal civilian systems at approximately 7.1 billion dollars in 2024 dollars across the years 2025 to 2035.

That framing is what makes the two halves of this article compatible. If the sceptics are right that quantum factorisation records are constructed and the machines are decades away, an organisation encrypting data that must stay confidential into the 2040s is still exposed today, because the interception happens now and the decryption happens whenever it happens. If the optimists are right, the same organisation is exposed sooner. Neither branch produces a reason to wait, and neither requires believing a specific forecast.

The practical consequence is unglamorous. The first deliverable in every published roadmap, NIST’s, the NSA’s and the NCSC’s alike, is a cryptographic inventory: which systems use which algorithms, which are supplier-controlled, and how long each one’s data must stay secret. That work depends on no prediction about qubit counts, and it is the part that takes years.

Sources: NIST Computer Security Resource Center, Post-Quantum Cryptography Standardization · NIST IR 8547 (initial public draft) · Nature (Google Quantum AI and Collaborators) · arXiv (Gidney, 2505.15917) · US Office of Management and Budget, Report on Post-Quantum Cryptography