up:: For Business Leaders MOC

What do regulators expect of us?

If you’re a U.S. federal agency, a national security system operator, or a manufacturer selling connected products into the European Union, an instrument already names you and carries a date.

If you’re an ordinary private company, no regulator has made post-quantum cryptography mandatory. The obligation reaches you anyway, through certifications you hold, contracts you signed, and the security requirements your largest customers pass down at renewal. That path is slower and less visible, and it arrives on a commercial calendar rather than a regulatory one.

Across every jurisdiction that has published anything, the first expectation is identical: know where your cryptography is.

Not legal advice

This is general education about published requirements. Whether any particular instrument binds your organization is a determination you make with your own counsel.

The short version:

  • Every mandate starts with an inventory. The U.S., the U.K., the EU, and the telecom sector all name cryptographic discovery as the first deliverable.
  • 2035 is the softest date in the conversation, and it’s the one people quote. The requirements that bite land in 2027, 2028, and 2030.
  • The EU rule reaches companies anywhere. Any manufacturer worldwide placing a connected product on the EU market carries obligations from December 11, 2027.
  • The strictest jurisdiction you touch sets your clock, rather than the country you’re incorporated in.
  • Deadlines are finish dates. A 2030 obligation behind a multi-year migration puts the start date in the past.
  • Nobody sends a letter. An algorithm changes status on an approved list, and a contract you signed years ago quietly stops being satisfiable.

What do all the mandates agree on?

One instruction, stated by every authority that has published guidance: build a cryptographic inventory before anything else. You can’t plan, price, or sequence a migration across systems whose cryptography nobody has mapped, and most existing asset inventories don’t record encryption at the algorithm level.

  • The U.S. put every federal civilian agency on an annual algorithm-level inventory cycle, due every year since May 2023.
  • The U.K.’s national cyber authority anchors its entire timeline on completing a discovery exercise by 2028.
  • The joint U.S. guidance from CISA, the NSA, and NIST puts the project team and cryptographic discovery first, ahead of every other step.
  • The mobile industry’s own assessment names a cryptographic inventory and a risk assessment as its first 2 concrete deliverables.

Source: Office of Management and Budget, Memorandum M-23-02, November 18, 2022, OMB M-23-02; NCSC, “Timelines for migration to post-quantum cryptography,” March 20, 2025, ncsc.gov.uk; CISA, NSA, and NIST, “Quantum-Readiness: Migration to Post-Quantum Cryptography,” August 21, 2023, cisa.gov.

That agreement is useful, because it means the first move is the same whichever instrument turns out to bind you. An inventory pays off regardless of how the specific dates shift.

Which rule actually reaches our organization?

It depends on where you operate, who you sell to, and what sector you’re in. Many organizations sit under more than 1 at once.

If you areThe instrumentWhat it requiresThe dates
A U.S. federal civilian agencyExecutive Order 14412 and the OMB inventory memoAnnual algorithm-level inventory, then migrationInventory annually since May 2023; for High Value Assets and high impact systems, key establishment by December 31, 2030; digital signatures by December 31, 2031
A U.S. national security system, or a vendor selling into oneThe NSA’s CNSA 2.0 suiteThe strongest post-quantum parameter set per functionRequired in new acquisitions from January 1, 2027; exclusive for software signing and networking gear by 2030; web, cloud, and operating systems by 2033
Any manufacturer worldwide placing a connected product on the EU marketThe EU Cyber Resilience ActState-of-the-art confidentiality plus multi-year security updatesReporting obligations from September 11, 2026; full obligations from December 11, 2027
A U.K. large organization or critical infrastructure operatorNCSC migration timelinesDiscovery and plan, then priority migration, then completionDiscovery and plan by 2028; highest-priority systems by 2031; all systems by 2035
An Australian government supplier handling protected dataThe ASD Information Security ManualTransition plan, then full exit from today’s public-key encryptionPlan by end of 2026; critical systems commenced by end of 2028; traditional public-key out by end of 2030
A Canadian federal systemThe CCCS roadmapDepartmental plans, then prioritized migrationPlans by April 2026; high-priority systems by 2031; remainder by 2035

Source: The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” June 22, 2026, whitehouse.gov; NSA, “CNSA 2.0 FAQ,” media.defense.gov; EUR-Lex, Regulation (EU) 2024/2847, official text; NCSC, “Timelines for migration to post-quantum cryptography,” March 20, 2025, ncsc.gov.uk; ASD, “Guidelines for cryptography,” Information Security Manual, cyber.gov.au; Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001),” June 23, 2025, cyber.gc.ca.

The one that surprises executives most is the EU rule, because it attaches to the market rather than to the company. A business headquartered in Texas or Singapore with EU customers is in scope exactly as an EU manufacturer is, and the penalties for breaching its essential requirements run to 15 million euro or 2.5% of worldwide annual turnover, whichever is higher.

Source: European Commission, Cyber Resilience Act summary, digital-strategy.ec.europa.eu.

Why is 2035 the wrong date to plan against?

Because it’s a policy goal with a hedge written into it, and the requirements with consequences land years earlier.

DateWhat lands
Annually since May 2023U.S. federal cryptographic inventories, including contractor-operated systems
September 11, 2026EU reporting obligations for actively exploited vulnerabilities and severe incidents
January 1, 2027Post-quantum required in all new U.S. national security system acquisitions
December 11, 2027Full EU Cyber Resilience Act obligations, for any manufacturer selling into the EU
2028U.K. discovery and migration plan expected complete; Australian critical systems commenced
By 2030U.S. national security signing and networking gear exclusive to post-quantum; Australia’s full exit from traditional public-key encryption
December 31, 2030U.S. federal civilian key establishment migrated, for High Value Assets and high impact systems
December 31, 2031U.S. federal civilian digital signatures migrated
After 2035Today’s public-key encryption disallowed on the U.S. schedule, at any key size

Source: NIST IR 8547 initial public draft, csrc.nist.gov; NSA CNSA 2.0 FAQ, media.defense.gov; Executive Order 14412, whitehouse.gov.

Two qualifiers keep this honest. The 2030 and 2035 algorithm-retirement years live in a NIST initial public draft, so they represent stated intent and could shift in the final publication. And 3 separate regimes arrived at the end of 2030 independently: the U.S. federal civilian key-establishment date, Australia’s full exit, and the EU roadmap’s high-risk target. Three authorities converging on a year without coordinating is worth more than any single one of them.

How does a government rule reach a private company?

Through 5 stages, and most companies get caught by stage 3 or 4 rather than by stage 1.

StageThe mechanismWho it reaches
1. Government sets the ruleExecutive order, agency memo, or national standardFederal agencies and national security systems
2. Regulators translate itSector supervisors in finance, telecom, energy, and health adopt the federal templateRegulated industries
3. Procurement carries itContract terms, purchase requirements, and product certification become conditions of saleAny vendor selling to government or to regulated buyers
4. Vendors pass it downSuppliers get asked for a components list and dated commitmentsThe supply chain, several tiers deep
5. Insurers and auditors price itPublished guidance becomes the reasonable-organization baselineEveryone else

Stage 5 is the one worth understanding, because it operates without anybody sending you anything. Non-binding guidance still defines what a careful organization was expected to be doing, and that’s the reference a regulator, an auditor, an insurer, or an opposing lawyer reaches for after something goes wrong. The joint U.S. guidance has been public since August 2023.

Where is our own deadline actually written?

In your filing cabinet, most likely, and it’s findable with 3 questions.

  1. What have we already promised? Pull every agreement, framework, and certification that specifies validated or approved cryptography. Each one inherits the retirement schedule of whatever approved list it points at.
  2. Where do we operate and sell? List every jurisdiction the business touches, which is longer than the country of incorporation. The strictest one sets your clock.
  3. What will our largest customers require at renewal? Enterprise security language flows downhill, and for many companies the requirement arrives in a vendor questionnaire before any regulator is involved.

The earliest date the 3 questions produce is the one that binds. In practice it usually attaches to a specific product line, certification, or single large account rather than to the company as a whole, and that surface is frequently owned by a team that has never heard of this subject.

The full method, with the clause language to search for, is The Binding-Date Questions.

Questions people ask

Is post-quantum cryptography legally required for us? If you’re a U.S. federal agency, a national security system operator, in scope for Australia’s security manual, or selling connected products into the EU, yes and it’s dated. For everyone else, no regulator has required it, and the obligation typically arrives through your own certifications and contracts anyway.

Does the EU rule give us a post-quantum deadline? It gives an obligations date of December 11, 2027, and it never names post-quantum cryptography. Its requirements for state-of-the-art confidentiality and multi-year security updates are what pull post-quantum readiness into EU market access over time.

We have no government contracts. Are we out of scope? Directly, mostly yes. In practice the requirement reaches you through regulated customers, procurement conditions, product certification, and the insurers and auditors who use the published guidance as their baseline.

Can we wait until the draft schedule is final? The dates deserve the draft qualifier, and the direction is already propagating through procurement language and vendor roadmaps written against the draft. Waiting means inheriting somebody else’s reading of it at renewal.

What does “disallowed” actually mean for a product we already certified? Deprecated means still permitted with formally accepted risk. Disallowed means prohibited for that purpose. When an algorithm your certification relies on becomes disallowed, agreements requiring validated cryptography stop being satisfiable with that configuration.

How often should we re-check our deadline? On triggers rather than a calendar: entering a new market, closing an acquisition, gaining a certification, a major customer renewal, or the U.S. schedule going final.

Who should own this internally? One accountable owner in the risk function or the security office, with the sourcing distributed: counsel owns the jurisdiction analysis, contracts owns the promises list, and sales operations owns the renewal watch.

Where to go next

Go deeper into the technical detail

The technical version, with every instrument and citation, is The Mandates MOC.

These open the Post-Quantum Field Guide, a separate site written for security professionals.


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.