Post-Quantum Cryptography Timelines: When Will Organizations Migrate?
AI-summarised brief · reviewed before publication
The article maps post‑quantum cryptography (PQC) migration timelines across governments, tech firms, financial institutions, critical‑infrastructure operators and blockchain groups. Regulatory frameworks such as NIST IR 8547, CNSA 2.0 and the EU NIS Cooperation Group set minimum deprecation dates for RSA‑2048 and ECC‑256 between 2030 and 2035, with full quantum‑resistant infrastructure required by 2035. Meanwhile, major technology companies are accelerating their own roadmaps, targeting 2029 for complete migration—four to six years ahead of the earliest regulatory deadlines. Google announced a 2029 target in March 2026, citing faster progress in quantum hardware and error‑correction research; Cloudflare quickly aligned with the same schedule. All surveyed entities have published concrete plans, abandoning “wait‑and‑see” stances, and 2026 marks the year when these commitments became publicly concrete.
💡 Why It Matters
- · Early private‑sector timelines pressure standards bodies and regulators to tighten guidance, while giving organizations a clearer benchmark for prioritizing their own PQC upgrades.