up:: The Mandates MOC
US vs EU vs UK Post-Quantum Timelines
The three timelines converge on 2035 and differ on almost everything else about how they get there. The United States binds federal civilian agencies through a dated, five-phase executive memorandum. The European Union splits the job across a non-binding member-state roadmap that carries the migration dates and a binding product-security regulation that carries the enforcement. The United Kingdom publishes advisory national guidance that binds nobody in law and that UK government, critical infrastructure and regulated industry follow anyway.
A company operating across all three is subject to three different kinds of obligation on three different clocks, and the earliest date that actually constrains it appears in none of the headlines.
The short version:
- All three target 2035 for completion, and the alignment is genuine rather than coincidental, because the UK and the US both trace that year to the same source, the US National Security Memorandum 10 risk-mitigation goal.
- They bind entirely different parties. The US memorandum binds federal civilian agencies, the EU Cyber Resilience Act binds any manufacturer worldwide placing a connected product on the EU market, and the UK guidance binds no one.
- The middle milestone is where they genuinely diverge. The EU wants high-risk use cases migrated by the end of 2030, the US wants post-quantum key establishment on priority systems by 2030 and signatures by 2031, and the UK has no 2030 date at all.
- The first real deadlines land in 2026, years ahead of every headline year: October 22, 2026 for US agency migration plans, and September 11, 2026 for EU Cyber Resilience Act incident reporting.
- Only one of the three reaches a company with no presence in the jurisdiction. The EU Cyber Resilience Act applies by market access, so a US or UK manufacturer selling into Europe picks it up regardless of where it is headquartered.
Think of three cities that all agree the bridge has to be rebuilt by 2035. One issues a works order to its own public agencies with dated phases and a plan due in October. One passes a law saying anything sold in the city has to meet current structural standards and stay maintainable for years, then separately publishes a schedule its districts are asked to follow. The third publishes an expert timetable and relies on everyone treating the national engineering authority as the authority. Same year on the calendar, three different mechanisms, and a contractor working in all three has to satisfy all three at once.
What is the difference between the US, EU, and UK post-quantum timelines?
The difference is instrument and reach rather than destination. All three jurisdictions expect the post-quantum transition to be finished by 2035, and each arrives at that year through a different kind of legal object with a different enforcement mechanism and a different population of obligated parties.
The US timeline is executive direction to government. The EU timeline is a member-state coordination document sitting beside a binding market-access law. The UK timeline is national technical advice. Reading them as three versions of the same deadline is the most common way organizations misjudge what actually applies to them, because the one with the sharpest legal teeth, the EU Cyber Resilience Act, carries no post-quantum date at all, and the ones carrying the clearest post-quantum dates carry the weakest enforcement.
What is the US post-quantum timeline?
The US federal civilian timeline lives in OMB M-26-15, the June 24, 2026 memorandum “Execution of the Migration to Post-Quantum Cryptography,” which directs every federal civilian agency to execute a prioritized, phased migration and to file a PQC Migration Plan within 120 days. It implements Executive Order 14412 and discharges OMB’s statutory duty under the Quantum Computing Cybersecurity Preparedness Act. It excludes national security systems, which run on the separate and harder CNSA 2.0 schedule.
The memorandum names five phases:
| Phase | Focus | Window |
|---|---|---|
| Phase 1 | Strategy, planning and discovery: inventory, assessment, training, governance, accountable officials, risk assessment | 2026 to 2027 |
| Phase 2 | Pilots and early migration of prioritized systems, and refining the plan | 2027 to 2028 |
| Phase 3 | Prioritized migration: priority systems to PQC for key establishment, and all systems made cryptographically agile | 2028 to 2030 |
| Phase 4 | Signature migration: priority systems to PQC for digital signatures | 2031 |
| Phase 5 | Full migration of remaining systems, based on risk and commercial availability | 2035 |
Source: OMB, M-26-15, “Execution of the Migration to Post-Quantum Cryptography,” June 24, 2026, §3.D, M-26-15 PDF.
Two US dates sit outside the phase table and are load-bearing. Agencies must support TLS 1.3 or a successor by January 2, 2030, carried in from Executive Order 14306, which is transport readiness rather than a completed migration. And §3.A sets the objective of mitigating as much quantum risk as feasible by December 31, 2030, phrased as a risk-weighted target aimed at the priority population rather than a government-wide cutoff.
Running underneath the memorandum is the algorithm clock in NIST IR 8547, which deprecates 112-bit-strength public-key algorithms such as RSA-2048 and P-224 after 2030 and disallows all classical RSA, elliptic-curve and Diffie-Hellman signature and key-establishment schemes after 2035 regardless of key size. IR 8547 remains an Initial Public Draft, so those years are NIST’s stated intent rather than settled rule.
Source: NIST, IR 8547 ipd, “Transition to Post-Quantum Cryptography Standards,” transition schedule table, NIST IR 8547 ipd.
What is the EU post-quantum timeline?
The EU splits the work across two documents, and keeping them apart is the whole trick to reading Europe correctly.
The dates live in the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, a member-state coordination document rather than a statute:
| Milestone | What the roadmap asks for |
|---|---|
| End of 2026 | Member states start transitioning, with national PQC roadmaps defined and planning underway for high- and medium-risk use cases |
| End of 2030 | High-risk use cases migrated, including critical infrastructure across water, energy, health, finance and transport |
| End of 2035 | All migrations completed for every risk level |
Source: European Commission, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,” EC roadmap library.
The enforcement lives somewhere else entirely, in the EU Cyber Resilience Act, Regulation (EU) 2024/2847, which entered into force on December 10, 2024. Manufacturer reporting for actively exploited vulnerabilities applies from September 11, 2026, and the full essential requirements, conformity assessment and CE marking apply from December 11, 2027. Breaching the essential requirements carries administrative fines up to 15 million euro or 2.5 percent of worldwide annual turnover, whichever is higher.
Source: European Commission, “Cyber Resilience Act,” EC digital-strategy CRA page.
The Cyber Resilience Act names no cryptographic algorithm and sets no post-quantum date. Its relevance is structural: it requires state-of-the-art confidentiality protection and multi-year security-update capability, so a product shipped in 2027 with a support period reaching into the 2030s has to remain updatable across the window where classical public-key cryptography is being deprecated. That combination is a crypto-agility obligation in all but name.
A third instrument is frequently mistaken for a fourth deadline. The EU Quantum Act is industrial and research policy for Europe’s quantum technology sector, scheduled in the Commission’s 2026 Work Programme and reported as slipping toward 2027. It names no algorithm and sets no migration deadline.
What is the UK post-quantum timeline?
The UK timeline is NCSC guidance, specifically “Timelines for migration to post-quantum cryptography,” published March 20, 2025. The National Cyber Security Centre is the UK’s national technical authority for cyber security and part of GCHQ, which is where the guidance gets its weight, since it carries no statutory force of its own.
| Milestone | What the NCSC recommends be complete |
|---|---|
| By 2028 | Define migration goals, carry out a full discovery exercise across the estate, and build an initial migration plan |
| By 2031 | Carry out the early, highest-priority migration activities, and refine the plan into a thorough roadmap |
| By 2035 | Complete migration to PQC of all systems, services and products |
Source: NCSC, “Timelines for migration to post-quantum cryptography,” 20 March 2025, ncsc.gov.uk/guidance/pqc-migration-timelines.
The UK adopts the NIST-standardized algorithms wholesale and adds its own parameter picks, ML-KEM-768 for key establishment and ML-DSA-65 for general-purpose signatures, with SLH-DSA reserved for narrow uses such as firmware signing. There is no separate UK algorithm suite. The NCSC also explicitly lifts the burden off small firms running commodity IT, stating that for those organizations migration “should happen seamlessly, as services are updated by their vendors.”
US vs EU vs UK at a glance
| Dimension | United States | European Union | United Kingdom |
|---|---|---|---|
| Timeline instrument | OMB M-26-15, June 24, 2026 | Coordinated Implementation Roadmap for the Transition to PQC | NCSC “Timelines for migration to post-quantum cryptography,” March 20, 2025 |
| Legal force of the timeline | Binding executive direction on covered agencies | Member-state coordination document, not binding law | Advisory guidance, no statutory penalty |
| Who the timeline binds | Heads of federal civilian executive departments and agencies | Member states, which define national roadmaps | Nobody in law; UK government, CNI and regulated industry in practice |
| Separate binding instrument | CNSA 2.0 for national security systems, excluded from M-26-15 | CRA, Regulation (EU) 2024/2847, binding on manufacturers | None; force comes from sector regulators applying supervisory pressure |
| First dated obligation | PQC Migration Plan due October 22, 2026 (120 days from the memo) | CRA manufacturer reporting from September 11, 2026 | Discovery exercise and initial plan by 2028 |
| 2030 milestone | Phase 3 key establishment on priority systems, 2028 to 2030; mitigate as much quantum risk as feasible by December 31, 2030 | High-risk use cases migrated by end of 2030, including water, energy, health, finance and transport | No 2030 milestone; the mid-point is 2031 |
| 2031 milestone | Phase 4, PQC digital signatures on priority systems | No 2031 milestone | Highest-priority migrations complete |
| Completion target | Phase 5, full migration, 2035 | All migrations complete, end of 2035 | Migration of all systems, services and products complete, 2035 |
| Algorithm clock | NIST IR 8547: 112-bit-strength public key deprecated after 2030, all classical RSA, ECC and DH disallowed after 2035 | No EU algorithm schedule; the CRA requires state-of-the-art protection without naming algorithms | No UK schedule; the NCSC adopts the NIST standards and adds parameter picks |
| Named parameter defaults | ML-KEM and ML-DSA/SLH-DSA under FIPS 186-5 for phases 3 and 4 | None named | ML-KEM-768, ML-DSA-65, SLH-DSA for narrow uses |
| Reach beyond the jurisdiction | None; binds US federal agencies only | The CRA binds any manufacturer worldwide placing a connected product on the EU market | None; binds no organization outside the UK |
| Penalty for missing it | Executive accountability through OMB and ONCD reporting; no statutory fine in the memo | CRA essential-requirement breach: up to 15 million euro or 2.5 percent of worldwide annual turnover, whichever is higher | None |
| Sub-national government covered | No. Local, tribal, municipal and territorial appear zero times in M-26-15 | Not addressed; the roadmap is directed at member states | Not addressed; guidance is economy-wide and advisory |
How do the three timelines actually differ?
-
The unit of obligation is different in each. The US binds an entity, a federal civilian agency. The EU Cyber Resilience Act binds a product placed on a market, which is why it reaches manufacturers with no European presence. The UK binds nobody and relies on a profession treating its national technical authority as authoritative. An organization asking “does this apply to me” gets three answers derived from three different tests.
-
The middle of the decade is where they genuinely part company. The EU’s end-2030 milestone names a sector list, so a European water utility or hospital reads a concrete obligation aimed at it. The US 2030 date is risk-weighted and internal, covering key establishment on a priority population defined by FIPS 199 impact level and High Value Asset status. The UK has no 2030 date at all, moving from a 2028 discovery milestone to a 2031 priority-migration milestone.
-
Only the US publishes an algorithm retirement schedule. NIST IR 8547 states which algorithms become deprecated and disallowed and when. Neither the EU roadmap nor the NCSC guidance carries an equivalent, which means an organization outside the US still ends up reading NIST’s dates to know when its cryptography stops being acceptable.
-
Enforcement and dates are attached to different documents in Europe and to the same document in the US and the UK. The EU instrument with real penalties carries no post-quantum date, and the EU document with the post-quantum dates carries no penalty. That separation is why the CRA and the roadmap have to be read together.
-
The hybrid question is answered at member-state level in Europe and at national level elsewhere. The EU roadmap takes no position on hybrid. France’s ANSSI requires it for products it certifies and Germany’s BSI recommends it for long-term confidentiality, while the NCSC treats hybrid as an interim measure on the way to PQC-only. The divergence is covered in full at ANSSI vs BSI vs NCSC vs NSA on Hybrid.
Where do the three agree?
-
On 2035, and the agreement has a traceable source. The UK’s 2035 endpoint aligns with the US National Security Memorandum 10 risk-mitigation goal of 2035, which is also the year NIST IR 8547 uses for disallowance. The convergence reflects a shared reading of how long a migration of this size takes rather than three independent guesses.
-
On discovery first. All three treat cryptographic inventory as the foundational activity that everything else depends on. US Phase 1 covers inventory and assessment in 2026 to 2027, the EU roadmap asks member states to define national roadmaps and plan by the end of 2026, and the NCSC puts a full discovery exercise at its 2028 milestone.
-
On the NIST algorithms. No jurisdiction here has produced a competing algorithm suite. FIPS 203, FIPS 204 and FIPS 205 are the common technical substrate, and national divergence happens on parameters, sequencing and hybrid rather than on the algorithms themselves.
-
On crypto-agility as a requirement rather than a nicety. US Phase 3 requires all systems to be made cryptographically agile, the CRA’s support-period and state-of-the-art duties require products to remain updatable, and the NCSC frames hybrid as something to deploy inside a flexible framework enabling a clean later migration.
-
On leaving sub-national government out. None of the three instruments reaches a city, county, school district or municipal utility. M-26-15 addresses federal agency heads, the EU roadmap addresses member states, and the NCSC publishes advice. The level of government operating schools, public hospitals, courts, transit and emergency dispatch answers to no deadline in any of them.
Which deadline arrives first?
The two earliest dated obligations both land in 2026, well ahead of every year that gets quoted in coverage.
- September 11, 2026. EU Cyber Resilience Act Article 14 manufacturer reporting for actively exploited vulnerabilities and severe incidents.
- October 22, 2026. US federal civilian agency PQC Migration Plans due to OMB and the Office of the National Cyber Director, 120 days from the June 24, 2026 memorandum.
- End of 2026. EU member states are asked to have national PQC roadmaps defined and planning underway.
- December 11, 2027. Full application of the EU Cyber Resilience Act, including the Annex I essential requirements, conformity assessment and CE marking.
- 2028. UK discovery exercise and initial migration plan complete.
Each headline completion year is preceded by a planning or discovery milestone that has to be met years earlier, and in every jurisdiction the earlier milestone is the one that constrains the schedule, because migration cannot be sequenced across cryptography that has not been inventoried.
Which timeline applies to a company operating in all three?
More than one, and they stack rather than override each other. A manufacturer headquartered in the United States that sells a connected product into Europe and operates a UK subsidiary sits under the EU Cyber Resilience Act by market access, reads NCSC guidance as the UK national expectation its regulators will reference, and picks up US federal requirements only through the procurement channel if it sells to federal agencies.
That procurement channel is worth naming precisely, because it is how the US memorandum reaches organizations it does not bind. M-26-15 directs agencies to build PQC integration into their requirements for products in the categories CISA publishes, and to engage FedRAMP-authorized cloud service providers on delineating migration responsibilities. A vendor selling to federal civilian agencies inherits post-quantum readiness expectations through contract terms rather than through the memorandum’s own scope.
The practical consequence is that the binding date for a multinational is usually the earliest one that reaches it through any channel, and for most product companies that date is the EU one, because market access is the broadest of the three mechanisms.
Why do the three jurisdictions disagree?
The disagreement is structural rather than technical, and each mechanism follows from what the issuing body actually controls.
-
The US instrument is an executive memorandum because OMB’s authority runs to federal agencies. OMB directs the executive branch. It cannot legislate for the private sector or for states, so the memorandum reaches everything it can reach and stops, and the private-sector pull comes through procurement and through NIST’s standards being adopted voluntarily.
-
The EU split its approach because competence is split. Cybersecurity of products placed on the single market is a clear EU competence, which is why the Cyber Resilience Act is a directly binding regulation with substantial fines. Deciding how a member state migrates its own national systems is not, which is why the migration dates arrive as a coordination roadmap that member states are asked to follow.
-
The UK issues guidance because the NCSC is a technical authority rather than a regulator. The NCSC advises. Statutory force in the UK sits with sector regulators in finance, telecom and energy, and the design assumption is that those regulators translate NCSC expectations into supervisory language for the sectors they oversee.
Read together, the three are the same technical program expressed through three different constitutional structures, which is why the algorithms match and the enforcement does not.
Common misconceptions
-
“2035 is the deadline everywhere, so there’s time.” The completion year is the last date in each timeline, and every jurisdiction sets earlier milestones that bind first. The two earliest dated obligations, September 11, 2026 and October 22, 2026, have already passed the point where a program can be started from scratch and still be comfortable.
-
“The EU has a post-quantum law.” The EU instrument with binding force, the Cyber Resilience Act, names no cryptographic algorithm and sets no post-quantum date. The EU dates come from a coordination roadmap that is guidance rather than statute. Both are real, and they are different documents doing different jobs.
-
“The EU Quantum Act sets Europe’s PQC deadline.” It sets none. It is industrial and research policy for the quantum technology sector, still a proposal, and reported as moving toward 2027. Europe’s migration dates are in the Coordinated Implementation Roadmap.
-
“UK guidance is optional, so it can be ignored.” It carries no statutory penalty and it is treated as the authoritative national reference by UK government, critical national infrastructure operators and regulated industry, with sector regulators reinforcing it. The practical force is closer to a requirement than the legal form suggests.
-
“M-26-15 covers US government generally.” It covers federal civilian executive agencies. National security systems are explicitly excluded and run on CNSA 2.0, and state, local, tribal and territorial government is outside its scope entirely.
-
“A US company only has to follow US timelines.” The EU Cyber Resilience Act applies by market access rather than by establishment, so a manufacturer anywhere in the world placing a connected product on the EU market is bound by it regardless of headquarters.
Questions people ask
Which jurisdiction has the earliest post-quantum deadline? Measured by the first dated obligation, the EU, because Cyber Resilience Act reporting applies from September 11, 2026. Measured by the first post-quantum-specific milestone, the US, whose agency migration plans were due October 22, 2026 and whose Phase 1 discovery window opened in 2026.
Do the US, EU and UK have the same completion date? Yes, all three target 2035. The UK’s endpoint aligns with the US National Security Memorandum 10 goal, and 2035 is also the disallowance year in NIST IR 8547, so the convergence is deliberate rather than accidental.
Does any of these timelines apply to my private company? Directly, only the EU Cyber Resilience Act, and only if you place a product with digital elements on the EU market. The US memorandum binds federal agencies and reaches vendors through procurement requirements. UK guidance binds no organization, though UK sector regulators reference it.
Which one names the algorithms I have to use? The US, through NIST. FIPS 203, FIPS 204 and FIPS 205 are the standards, and NIST IR 8547 carries the retirement schedule for the classical algorithms. The UK adopts those standards and adds parameter picks of ML-KEM-768 and ML-DSA-65. The EU roadmap names no algorithm.
What happens in 2030 versus 2031? In the EU, high-risk use cases including critical infrastructure are meant to be migrated by the end of 2030. In the US, Phase 3 puts post-quantum key establishment on priority systems by 2030 and Phase 4 puts post-quantum digital signatures on them in 2031. The UK has no 2030 milestone and reaches its priority-migration milestone in 2031.
Why does the US split key establishment and signatures a year apart? Because the two face different clocks. Key establishment is exposed to harvest-now-decrypt-later collection today, since recorded traffic can be decrypted later, while signatures become forgeable only once a quantum computer exists. The Two-Lane Split covers the reasoning.
Is there an equivalent timeline for other countries? Several national authorities publish their own, including France’s ANSSI, Germany’s BSI, and Canada’s CCCS. The positions diverge most visibly on hybrid cryptography, which is compared in full at ANSSI vs BSI vs NCSC vs NSA on Hybrid.
Do any of these reach city or state government? No. M-26-15 addresses federal agency heads and contains the words local, tribal, municipal and territorial zero times, the EU roadmap addresses member states, and NCSC guidance is advisory. Sub-national government sits outside every timeline on this page.
Which document should I read first? For a federal agency or a federal supplier, OMB M-26-15 and NIST IR 8547. For a product manufacturer selling into Europe, the Cyber Resilience Act, specifically the Annex I essential requirements and the Article 71 application dates. For a UK organization, the NCSC timelines guidance.
Are these dates final? The EU Cyber Resilience Act dates are in force law and are settled. The US phase dates are in a current memorandum, though NIST IR 8547 remains an Initial Public Draft, so its deprecation years are stated intent. The NCSC milestones are advisory and revisable. Re-verify against the primary sources at review, since national timelines do get revised.
The map is free and I keep it that way. When three overlapping timelines have to become one sequenced migration plan for an organization that operates in all three, that’s the work I do at LaMarr Labs.
Go deeper
- OMB M-26-15, NIST IR 8547 and NSA CNSA 2.0 for the US instruments in full
- EU Cyber Resilience Act (CRA) and EU Quantum Act for the European picture
- UK NCSC Quantum-safe Cryptography for the UK guidance in full
- ANSSI vs BSI vs NCSC vs NSA on Hybrid for where the national authorities genuinely disagree
- CNSA 2.0 vs the NIST Civilian Track for the two US tracks compared
- The Mandates MOC for the whole regulatory picture
Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.