up:: For Policymakers
What are other countries doing?
Every major economy has reached the same conclusion and written it down. That’s worth stating first, because the debate about whether this risk is real was settled inside governments some time ago, independently, in several languages.
Where they differ is on dates, on method, and on how much they’re willing to compel rather than recommend. Australia is running 5 years ahead of everyone. France insists on an approach the others merely permit. Canada has published the most specific schedule. And the divergence itself is turning into its own problem.
The short version:
- Australia is the outlier. Its rules direct that today’s public-key cryptography stop being used by the end of 2030, 5 years ahead of the emerging international consensus.
- Canada has the most detailed schedule: departmental plans by April 2026, high-priority systems done by end of 2031, everything else by end of 2035.
- The United States deprecates today’s encryption after 2030 and disallows it after 2035.
- France takes a distinctive position, requiring the new encryption be combined with the old rather than replacing it outright.
- Germany and Japan work through detailed technical reference documents their public sectors procure against.
- The EU is coordinating rather than commanding, with a Quantum Act proposal announced in the Commission’s 2026 work program.
How do the deadlines compare?
| Country or body | The authority | What it requires |
|---|---|---|
| Australia | Australian Signals Directorate, Information Security Manual | RSA, Diffie-Hellman, ECDH, and ECDSA to cease being used by the end of 2030 |
| Canada | Canadian Centre for Cyber Security, ITSM.40.001 | Departmental plans by April 2026, annual reporting, high-priority systems by end of 2031, the rest by end of 2035 |
| United States | NIST IR 8547, plus executive orders and OMB memoranda | The weaker key sizes deprecated after 2030; all of today’s public-key encryption disallowed after 2035 regardless of size |
| France | ANSSI | Hybrid-first: combine a recognized classical scheme with a post-quantum one, with no loss of security |
| Germany | BSI, TR-02102-1 | Recommended algorithms, key lengths, and periods of use, updated roughly every January |
| Japan | CRYPTREC | A tiered ciphers list that Japanese government procurement references |
| European Union | ENISA, plus the forthcoming Quantum Act | EU-level guidance and coordination rather than national regulation |
Source: Australian Signals Directorate, “Guidelines for cryptography,” Information Security Manual, cyber.gov.au; Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001),” June 23, 2025, cyber.gc.ca; NIST IR 8547 (Initial Public Draft), November 2024; BSI, “TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths,” bsi.bund.de.

Source: India DST task force (4 Feb 2026); EO 14412; NSA CNSA 2.0 FAQ; Canada TBS; NCSC; EU NIS CG; ASD ISM.
The table above is the standard comparison, and the chart shows why it’s incomplete. Every jurisdiction in it is wealthy and Western, which makes the resulting picture a map of who can afford to publish a roadmap rather than a map of who’s moving fastest. India set a 2029 target for critical infrastructure and mandates vendor component disclosures from FY 2027-28, which is more prescriptive than anything the U.S. asks of its private sector. See What about the rest of the world.
Why is Australia 5 years ahead?
Because it decided the consensus date leaves too little margin.
The Australian Signals Directorate directs that traditional public-key cryptography cease being used by the end of 2030, where most other national guidance treats 2035 as the outer boundary. For an Australian government system, that turns a distant obligation into a near-term program.
It’s the most useful natural experiment available in this whole area. Australia will find out first whether these timelines are achievable, and every other country gets to watch.
What’s France doing differently?
France requires that the new encryption be used alongside the old rather than instead of it.
ANSSI’s position is hybrid-first: combine a recognized classical scheme with a post-quantum scheme so the result is at least as strong as the classical one alone. The reasoning is straightforward. The new algorithms are young, and the old ones are extremely well studied, so running both means a flaw discovered in either one doesn’t leave you exposed.
Most other authorities permit this approach. France requires it, and the requirement has a specific mechanism behind it: for products going through French security-visa evaluation, ANSSI’s guidance states that a product including post-quantum protection “shall implement hybridation.” The one exception is a product whose protection rests only on hash-based signatures, where pairing is optional. That distinction between advising an approach and certifying against it matters for anyone building a system that has to satisfy several regulators at once.
Germany holds the same line as a recommendation rather than a certification rule, and ANSSI says so itself, describing its position as “aligned with the one of other European cybersecurity agencies like BSI in Germany.” The U.K. is the one that genuinely differs, treating the pairing as a temporary bridge rather than a destination. The four positions side by side are in ANSSI vs BSI vs NCSC vs NSA on Hybrid.
Why does the divergence matter?
This is the part that reaches past any single country’s policy, and it’s the argument for treating this as an international question rather than a national one.
Encryption only works when both sides agree. A secure connection is negotiated between both ends. When a bank in one country has migrated and its counterparty abroad is still on the old method, the connection falls back to what they share. So the country that moved early ends up with the security of the country that moved late.
Different deadlines create a decade of mismatch. Australia finishing in 2030 while others finish in 2035 means 5 years where cross-border systems are negotiating between different generations of cryptography.
The data doesn’t respect the borders anyway. Information collected today crosses many jurisdictions on its way anywhere, so a nation’s exposure is never bounded by its own networks or its own timetable.
And a large part of the world has no timetable at all. The countries listed above are wealthy ones with mature national cyber agencies. Most countries have neither, which is covered separately at What happens to countries that can’t afford to migrate?
Is anybody trying to align this?
Partly. The algorithms themselves came out of an open international competition, and the same standards are being adopted across all of these jurisdictions, which means the technical core is genuinely shared. That’s a real achievement and it’s the reason interoperability is even possible.
What isn’t aligned is the schedule, the enforcement, and the question of what happens to organizations that miss. Those remain national decisions, and there’s no body with authority to harmonize them.
More at Is anyone coordinating this internationally?
Questions people ask
Is any country ahead on actually doing it, rather than requiring it? Requirements and completion are different things everywhere, and no government has published credible evidence of finishing. Watch Australia first, because its date arrives first.
Does my country’s deadline apply to private companies? Usually the direct obligation falls on government systems and their suppliers, with private-sector effects arriving through procurement, sector regulators, and contract terms rather than a general mandate. That varies by country and it’s the main thing to check locally.
Do these countries trust each other’s standards? In practice they’ve all converged on the same algorithm choices, which is the strongest form of trust available here. The differences are about how and when to deploy them.
What about countries not on this list? Most of the world isn’t on this list, and that’s the substance of the equity problem rather than an omission.
Where to go next
- What laws and rules already exist? covers the U.S. instruments in detail.
- What happens to countries that can’t afford to migrate? is the part this page doesn’t solve.
- Is anyone coordinating this internationally? covers what alignment exists.
Go deeper into the technical detail
The technical index of every regulation, including the ones not covered here, is The Mandates MOC, with per-country notes at ACSC (Australia), CCCS (Canada), BSI, ANSSI Cryptographic Mechanisms, CRYPTREC (Japan), and ENISA.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Beyond these 6. India published a national roadmap in February 2026 with a critical-infrastructure full-adoption target of 2029, earlier than any timeline on this page, and most of the world has published nothing at all. See What about the rest of the world.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.