up:: For Policymakers MOC

Is anyone coordinating this internationally?

No treaty exists, no international body has authority, and the transition is nonetheless converging, because most of the world adopted the output of a single American standards competition.

That competition ran openly for 8 years with international participation, which is why the result carries legitimacy that a purely national standard wouldn’t. The algorithms are the shared layer. Everything above them, meaning the deadlines, the deployment strategy, and the parameter choices, is set nationally and doesn’t automatically fit together.

The practical consequence is that 2 allied governments can each complete their migration on schedule and discover their systems don’t interoperate.

The short version:

  • No treaty and no governing body. Coordination happens through standards organizations, published national guidance, and industry groups.
  • The algorithms are shared. NIST’s competition drew international submissions and its winners were adopted well beyond the U.S.
  • Three things diverge: whether to pair the new algorithms with the old, which strength to require, and what date to finish by.
  • The protocol layer is where interoperability is actually negotiated, in the internet standards bodies rather than between governments.
  • A separate standards track exists at ISO, which matters for countries that prefer not to depend on a U.S. federal standard.
  • The gap that bites first is procurement, because a supplier serving several jurisdictions has to satisfy the strictest one.

Who actually does the coordinating?

Five kinds of body, none of them with authority over a government.

WhoWhat they coordinateWhat they can’t do
NISTThe algorithms themselves, through an open competition with international participationBind any country other than the U.S.
ISO and IECA parallel international standards track for encryption algorithmsMove at the speed of a national mandate
The IETFHow the algorithms are actually used inside internet protocols, which is where interoperability is settled in practiceSet deadlines or compel adoption
ETSIEuropean technical specifications, including hybrid key exchangeBind member states
Industry coalitionsMigration roadmaps, inventory tooling, and shared practiceAnything binding

Source: IETF, “Post-Quantum Use In Protocols (PQUIP) Working Group,” datatracker.ietf.org; ETSI, “Quantum-Safe Cryptography,” etsi.org; PQC Coalition, pqcc.org.

The IETF row is the one that’s underappreciated in policy discussions. Governments set deadlines, and engineers in a standards body decide how a browser and a server actually negotiate which algorithm to use. If that layer works, systems interoperate across borders regardless of whose deadline is earlier. If it fragments, no amount of diplomatic alignment fixes it.

Why did an American competition become the global standard?

Because of how it was run, rather than because of who ran it.

NIST opened the process in 2016 and ran it for 8 years, publishing candidate algorithms for the world to attack. Submissions came from international teams, cryptographers everywhere attempted to break the candidates, and 1 finalist was publicly broken during the process, which demonstrated the scrutiny was real. The first 3 standards were finalized on August 13, 2024.

Source: NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 13, 2024, nist.gov; Castryck and Decru, “An efficient key recovery attack on SIDH,” EUROCRYPT 2023, eprint.iacr.org.

Countries that would decline to adopt a U.S. rule adopted the output of that process, because the process was auditable and the mathematics is checkable by anyone. Germany, France, the U.K., Canada, and Australia all name the same core algorithms in their own guidance.

A separate track exists at ISO for countries or sectors that prefer an international standards body as the source of record, and it moves on a longer timescale than national mandates do.

Source: Classic McEliece team, ISO standardization status, classic.mceliece.org.

The policy read is that trust in the standards process is itself infrastructure. It was built over 8 years of open cryptanalysis, and it’s the reason a global transition is possible without a treaty.

Where do national approaches actually diverge?

Three places, and each one is a real engineering disagreement rather than a political one.

1. Whether to pair the new with the old. Three distinct positions sit here, and hybrid deployment means running a proven classical algorithm alongside a post-quantum one so the combination is never weaker than the classical algorithm alone.

  1. France and Germany treat it as a standing requirement. France applies it to signatures as well as key establishment, and goes furthest of anyone: for products it certifies, ANSSI’s evaluation guidance says a product with post-quantum protection “shall implement hybridation.”
  2. The U.K. treats it as a bridge. Its guidance recommends hybrid be used “as an interim measure” inside a framework that allows a clean move to post-quantum-only later.
  3. The U.S. accepts the new algorithms on their own, on a published schedule.

All three are defensible, because each one guards against something different. Hybrid hedges against a flaw being found in algorithms that are still young, and the SIKE break during the competition is the evidence for that concern. The British position hedges against carrying 2 systems indefinitely and doubling handshake sizes on constrained networks, since the classical half stops adding protection the day a quantum computer arrives. The American position treats the calendar as the real risk and removes the argument so programs can’t slip on it. A full side-by-side of the four authorities is in ANSSI vs BSI vs NCSC vs NSA on Hybrid.

2. Which strength to require. The U.S. national security suite requires the strongest parameter set of each algorithm. The U.K. recommends a middle set for general use. Systems built to those 2 recommendations don’t automatically negotiate a common configuration.

3. What date to finish by. Australia exits traditional public-key cryptography by the end of 2030, 5 years ahead of most peers. The U.K. expects completion by 2035, the EU roadmap by the end of 2035, and Canada by the end of 2035.

Source: ANSSI, cyber.gouv.fr; BSI TR-02102-1, bsi.bund.de; NSA CNSA 2.0 FAQ, media.defense.gov; NCSC, ncsc.gov.uk; ASD Information Security Manual, cyber.gov.au.

One convergence is worth noting against all that divergence. Three regimes arrived independently at the end of 2030: the U.S. federal civilian key-establishment date, Australia’s full exit, and the EU roadmap’s high-risk target. Three authorities reaching the same year without coordinating is stronger evidence than any single one of them.

What does a lack of coordination actually cost?

Four costs, in the order they arrive.

  1. Suppliers build to the strictest requirement. A vendor selling into several jurisdictions satisfies the hardest one and passes the cost through to every customer, including those in jurisdictions with softer rules.
  2. Coalition systems need deliberate engineering. Shared intelligence systems, joint military communications, and cross-border payment and identity infrastructure each need the compatibility question answered explicitly. The cheap moment to answer it is while systems are being specified.
  3. The weakest link routes everybody’s traffic. International communications cross networks in countries with no migration program at all. A message is protected by the weakest configuration on its path. See What happens to countries that cannot afford this.
  4. Divergence gets locked into hardware. Equipment with a 15-year service life carries whatever configuration it shipped with, so a temporary disagreement between allies becomes a permanent one in the field.

What would coordination actually look like?

Five measures, ordered by how quickly they could be done.

  1. Align procurement language across allied governments, so a supplier meets 1 specification rather than 5. This needs no legislation and reaches the market immediately.
  2. Agree a common configuration for coalition systems, even where domestic approaches differ. Countries can disagree about hybrid at home and still specify a shared profile for joint systems.
  3. Fund participation in the protocol standards bodies, since that’s where interoperability is actually decided and where under-resourced countries have no presence.
  4. Publish schedules in a comparable format, so that a supplier or an ally can read across them without translating between guidance documents.
  5. Extend capacity assistance, because a country left behind is a routing path that stays vulnerable for everyone. See What happens to countries that cannot afford this.

Questions people ask

Is there a treaty or an international agreement? No. Coordination happens through standards bodies, published national guidance, and industry practice.

Does everyone use the same algorithms? Broadly yes for the core algorithms, which is the significant achievement here. The disagreements are about deployment strategy, parameter strength, and timing rather than about the mathematics.

Could a country reject the NIST standards? It could, and the practical cost would be isolation from the systems everyone else uses. The ISO track exists partly to give an alternative source of record for the same underlying mathematics.

Who decides how browsers and servers negotiate this? The internet standards bodies, principally the IETF. That’s where cross-border interoperability is genuinely settled, and it operates independently of any government’s deadline.

Does the EU speak with 1 voice? Partly. The Cyber Resilience Act binds manufacturers selling into the EU market, and the post-quantum dates live in a separate coordinated roadmap addressed to member states. France and Germany co-led that roadmap and hold the hybrid-first position.

What’s the biggest coordination risk? Divergence getting frozen into long-lived hardware, because a disagreement resolved in 2032 doesn’t reach equipment fielded in 2028 with a 15-year life.

Where should a legislature focus? Procurement alignment with allies, and a common profile for coalition systems. Both are achievable without new legislation and both get harder every year that equipment is purchased.

Where to go next

Go deeper into the technical detail

The technical index of standards bodies is The Mandates MOC, and the interoperability treatment is Cryptographic Interoperability.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.