12-step framework for quantum-safe migration aligned with NIST FIPS 203/204/205, NSA CNSA 2.0, and applicable sector policy and compliance context.
~13 min readForecasts for quantum computers capable of breaking RSA, ECC, and Diffie-Hellman vary materially and do not establish a break date. The Harvest Now, Decrypt Later (HNDL) threat model makes data lifetime relevant before hardware certainty: encrypted data can be collected now for future decryption attempts.
NIST finalized the first three post-quantum cryptography standards in August 2024:FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). Those standards create implementable options; adoption timing remains system- and policy-specific.
This checklist organizes guidance from NIST, NSA, CISA, and sector-specific regulators into a framework with source-backed control dates, algorithm decision criteria, and measurable maturity.
Why data lifetime can move action ahead of hardware certainty:
Final standards, binding federal dates, sector guidance, and draft deprecation proposals are different evidence classes. Each entry below names its scope and links to the primary source.
| Date | Authority | Status | Scoped requirement or guidance | Primary source |
|---|---|---|---|---|
| August 13, 2024 | NIST | Final standards | FIPS 203, 204, and 205 became the first finalized NIST PQC standards. | NIST release (opens in new tab) |
| Fall 2024 | OCC | Supervisory guidance | Banks are encouraged to inventory where encryption is used and assess third-party PQC transition plans. | OCC risk perspective (opens in new tab) |
| October 22, 2026 | OMB M-26-15 | Agency requirement | Federal agency PQC Migration Plans are due within 120 days of the June 24, 2026 memo; this date is derived from that window. | OMB M-26-15 (opens in new tab) |
| December 31, 2027 | EO 14412 | Executive order | NIST is directed to complete a PQC migration pilot on an appropriate subset of its systems. | White House EO 14412 (opens in new tab) |
| December 31, 2030 | EO 14412 | Executive order | Non-NSS federal high-value assets and high-impact systems are directed to transition key establishment to PQC. | White House EO 14412 (opens in new tab) |
| December 31, 2031 | EO 14412 | Executive order | Non-NSS federal high-value assets and high-impact systems are directed to transition digital signatures to PQC. | White House EO 14412 (opens in new tab) |
| 2030–2031 | NSA CNSA 2.0 | NSS requirement | For applicable NSS, unsupported equipment and services phase out by the end of 2030 and CNSA 2.0 use is required by the end of 2031 unless otherwise noted. | NSA CNSA 2.0 FAQ (opens in new tab) |
| After 2030 / 2035 | NIST IR 8547 | Initial public draft | The initial public draft proposes deprecation of specified quantum-vulnerable schemes after 2030 and broader disallowance after 2035. | NIST IR 8547 IPD (opens in new tab) |
Applicability varies by agency, system classification, sector, contract, and final rulemaking. Draft guidance is labeled; this timeline is not legal or compliance advice.
OCC encryption-inventory guidance, third-party transition planning, institution-specific obligations
HIPAA Security Rule risk analysis, applicable record-retention duties, OCR enforcement
OMB M-26-15, EO 14412, and CNSA 2.0 for applicable national security systems
Sector-specific guidance, long-lived ICS/OT upgrade cycles, and contract-specific obligations
NIST finalized the first three PQC standards in 2024. Additional algorithms and implementation guidance remain in development; production selection must follow current standards, protocol support, and use-case constraints.
Default for TLS, VPN, encrypted communications. Smaller ciphertext than alternatives. Best general-purpose choice.
Default for code signing, certificates, authentication. Fast signing/verification. Larger keys than classical.
Conservative choice when lattice assumptions concern you. Hash-based security well understood. Large signatures but proven foundation.
Smallest signatures of lattice schemes. Requires careful implementation to avoid side-channel attacks. Wait for NIST finalization.
Implementation Note: Most organizations should start with ML-KEM for key exchange and ML-DSA for signatures. SLH-DSA serves as a fallback if future cryptanalysis weakens lattice-based schemes. Hybrid deployments (classical + PQC in parallel) provide defense-in-depth during transition.
Track your organization's progress toward quantum cryptography readiness.
Form a cross-functional quantum readiness team with C-suite sponsorship.
Deploy approved discovery methods to identify in-scope cryptographic implementations.
Calculate your Mosca Inequality for each data category.
Create a phased migration plan working backward from regulatory deadlines.
Assess NIST-standardized algorithms against your use cases.
Architect systems for algorithm flexibility.
Survey all vendors on their PQC roadmaps.
Deploy PQC in non-production environments first.
Upgrade TLS implementations to support ML-KEM key exchange.
Address the HNDL backlog and re-encrypt high-value archived data.
Conduct post-migration audit to verify all identified vulnerabilities addressed.
Institute continuous monitoring of NIST announcements and cryptanalysis research.
Aligned with industry-leading regulatory and technical standards.
A phased approach from foundation through sustainment, with clear deliverables and maturity indicators.
Form a cross-functional quantum readiness team with C-suite sponsorship. Assign board-level or CISO ownership. Integrate quantum risk into existing enterprise risk management frameworks.
Quantum Risk Governance Charter with named accountable executive
Executive receives quarterly quantum risk briefings
Deploy approved discovery methods to identify in-scope cryptographic implementations across applications, infrastructure, and third-party dependencies. Build a Cryptographic Bill of Materials (CBOM).
Approved-scope CBOM snapshot with quantum vulnerability classification and residual-gap disclosure
95%+ coverage of enterprise systems in inventory
Calculate your Mosca Inequality for each data category. Identify data with secrecy requirements exceeding the quantum threat timeline. Prioritize M&A records, litigation holds, healthcare PHI, financial archives.
HNDL exposure matrix with risk-ranked data categories
Board-approved prioritization of crown jewel data
Create a phased migration plan against applicable control dates. Map CNSA 2.0 dates for covered government work, distinguish supervisory guidance from binding requirements, and align with institution-specific obligations.
Board-approved PQC migration roadmap with budget
Roadmap milestones incorporated into IT strategic plan
Assess NIST-standardized algorithms against your use cases. Test ML-KEM for key exchange, ML-DSA for signatures. Evaluate performance impact on latency-sensitive applications.
Algorithm selection matrix with performance benchmarks
Lab testing completed on candidate algorithms
Architect systems for algorithm flexibility. Implement abstraction layers that allow cryptographic modules to be swapped without application changes. Design for negotiable cipher suites.
Crypto-agility architecture specification
Reference implementation in development environment
Survey all vendors on their PQC roadmaps. Obtain written timelines for when products will support NIST standards. Update procurement requirements to request PQC readiness evidence.
Vendor PQC readiness assessment with risk ratings
PQC requirements in new contract language
Deploy PQC in non-production environments first. Test hybrid TLS configurations. Validate certificate chain handling with PQC signatures. Measure performance overhead.
Pilot deployment report with performance metrics
Successful hybrid TLS handshakes in test environment
Upgrade TLS implementations to support ML-KEM key exchange. Deploy hybrid cipher suites that combine classical and post-quantum algorithms. Prioritize external-facing endpoints.
Production TLS upgrade completion report
100% of external endpoints support PQC cipher suites
Address the HNDL backlog. Re-encrypt high-value archived data with post-quantum cryptography (PQC) algorithms. Update key management systems. Rotate certificates to PQC-signed versions.
Data-at-rest migration completion with exceptions documented
Crown jewel data protected with PQC algorithms
Conduct post-migration audit to verify all identified vulnerabilities addressed. Run governed validation against PQC implementations. Validate compliance with applicable regulations.
Independent audit report confirming PQC implementation
Clean audit findings on cryptographic controls
Institute continuous monitoring of NIST announcements, cryptanalysis research, and quantum computing progress. Keep CBOM current. Drill crypto-agility procedures annually.
Crypto monitoring program with defined triggers for action
Annual crypto-agility drill completed successfully
Score each dimension 1-5 to assess your current state and track progress.
| Dimension | 1 - Initial | 2 - Aware | 3 - Planned | 4 - Active | 5 - Optimized |
|---|---|---|---|---|---|
| Governance | No ownership | CISO aware | Charter approved | Board reporting | Integrated ERM |
| Inventory | None | Partial manual | Automated scan | Full CBOM | Continuous update |
| Risk Assessment | Not started | Ad hoc review | HNDL mapped | Prioritized plan | Quantified risk |
| Crypto-Agility | Hardcoded | Some flexibility | Architecture spec | Implemented | Tested annually |
| Vendor Mgmt | Not addressed | Some inquiries | All surveyed | Contract terms | Ongoing validation |
| Implementation | No PQC | Lab testing | Pilot deployed | Production live | Full migration |
QScout packages first findings and completed assessment outputs on timelines set during operator scoping, with enterprise evidence reporting. QStrike provides comprehensive 4-month testing with proof-of-concept demonstrations.