PQC compliance & regional mandates
PQC migration is increasingly mandated, with divergent regional timelines, allowed algorithm sets, and restrictions. 'Harvest-now, decrypt-later' makes the deadline effectively already here for long-lived secrets.
| Region | Authority | Mandate / timeline | Notes |
|---|---|---|---|
| US - NSA/DoD | CNSA 2.0 | PQC required for National Security Systems; software/firmware signing PQC-ready ~2025, broad adoption phased to 2030-2033 | ML-KEM-1024, ML-DSA-87, LMS/XMSS for firmware, AES-256, SHA-384/512.fact |
| US - civilian | NIST + CISA + OMB | NSM-10 + OMB M-23-02 inventory of cryptographic systems; migrate per NIST standards; CISA/NSA/NIST joint guidance | Agencies inventory and prioritize; no single hard cutover date.fact |
| EU | EU Coordinated Roadmap + BSI (DE) + ANSSI (FR) | Coordinated PQC transition roadmap (2026); BSI recommends hybrid; ANSSI phased guidance to hybrid then PQC-only | Europe leans HYBRID (classical+PQC) during transition; national agencies set specifics.fact |
| UK | NCSC | Migration timeline to ~2035 with milestones (discovery by 2028, high-priority migration by 2031) | Staged national timeline.fact |
| Other / restrictions | various (e.g. China OSCCA/SM algorithms; export controls) | Some states mandate national algorithm suites; export-control and sovereignty concerns shape which PQC is 'allowed' where | PQC choice is also geopolitical (national suites, procurement rules).interp |
Curated + graded knowledge base, aggregated from the research corpus and refreshed by a scheduled tracker. Grades: fact demo target estimate interp. The live feed is machine-collected and unverified. contact resistant@tuta.com