Post-Quantum Deadlines: What 2027, 2030 and 2035 Mean for You
NIST, NSA and European agencies have set post-quantum deadlines. What FIPS 203, 204, 205, NIST IR 8547 and CNSA 2.0 mean for businesses and for individuals.
For years, the quantum threat to encryption was discussed as a question of if. Governments have now turned it into a question of when, and they have written the dates down. RSA and elliptic-curve cryptography, the public-key systems that protect most of today's internet, have a published retirement schedule.
This article walks through the deadlines that matter, what they require, and what they mean in practice for companies and for ordinary people. It also explains why a messenger that already runs the new standards, as VOIDEX does, is on the right side of that schedule today rather than in a decade.
Why there are deadlines at all
A large enough quantum computer running Shor's algorithm would break RSA and the elliptic-curve schemes used for key exchange and digital signatures. Nobody has built that machine yet. The reason for urgency is twofold.
First, estimates of what it would take keep falling. In May 2025, Craig Gidney of Google Quantum AI estimated that RSA-2048 could be factored with fewer than one million noisy qubits in under a week, down from roughly twenty million in his 2019 estimate. Later work, summarised in Q-Day in 2026, has pushed the numbers lower still.
Second, encrypted data can be recorded now and decrypted later. Anything that must stay secret for ten or twenty years is already at risk if it travels under quantum-vulnerable encryption today. That is the logic of harvest now, decrypt later, and it is why migration deadlines sit years before any expected quantum breakthrough.
The standards: what "quantum-safe" now means
On 13 August 2024, the US National Institute of Standards and Technology finalised its first three post-quantum standards:
- FIPS 203, ML-KEM. A key encapsulation mechanism based on module lattices, derived from CRYSTALS-Kyber. It replaces classical key exchange. Explained in depth in ML-KEM-768 explained.
- FIPS 204, ML-DSA. A lattice-based digital signature scheme, derived from CRYSTALS-Dilithium, intended as the primary general-purpose signature.
- FIPS 205, SLH-DSA. A stateless hash-based signature scheme, derived from SPHINCS+, slower and larger but resting on very conservative assumptions.
On 11 March 2025, NIST selected HQC as a backup key encapsulation mechanism. HQC is built on error-correcting codes rather than lattices, so if a weakness were ever found in lattice mathematics, a different family would be ready. NIST has said it expects a draft standard for HQC in about a year from selection and a final standard around 2027.
The message from these standards is clear: the replacement algorithms exist, they are specified, and they are ready to deploy.
The deadlines, in order
2027: US national security systems
The NSA's Commercial National Security Algorithm Suite 2.0, announced in 2022, sets the algorithms for US national security systems. Its timeline expects new national security system acquisitions to be CNSA 2.0 compliant from January 2027, with the wider transition continuing through the early 2030s. CNSA 2.0 specifies the highest parameter sets, ML-KEM-1024 and ML-DSA-87, reflecting the classified nature of what those systems protect.
2030: RSA and ECC deprecated
In November 2024, NIST published a draft transition plan, NIST IR 8547. It proposes that quantum-vulnerable algorithms such as RSA and elliptic-curve cryptography at today's common security levels be deprecated after 2030. Deprecated means still permitted, but with the clear understanding that their time is running out.
2030 to 2031: priority systems in Europe and the UK
Other governments have aligned on similar dates. The UK's National Cyber Security Centre published migration timelines in March 2025: organisations should identify their cryptography and plan migration by 2028, complete their highest-priority migrations by 2031, and finish by 2035. In June 2025, EU member states agreed a coordinated implementation roadmap asking for first steps by the end of 2026 and for high-risk use cases to be protected by the end of 2030.
2035: disallowed
Under NIST IR 8547, the quantum-vulnerable algorithms would be disallowed after 2035. At that point, systems following NIST guidance should no longer rely on RSA or elliptic-curve cryptography for protecting data at all. The same year appears across US, UK and EU planning, which makes 2035 the practical finishing line for the world's migration.
What this means for businesses
For organisations, the deadlines are less about flipping a switch and more about a long inventory. Cryptography is buried in everything: VPNs, certificates, databases, payment systems, firmware, partner integrations. Most companies do not have a complete map of where it lives.
Sensible first steps look like this:
- Inventory. Find every place public-key cryptography is used, including in suppliers' products.
- Prioritise by lifespan. Data that must stay confidential beyond 2035 is already exposed to harvesting and should move first.
- Prefer hybrid designs. Combining a classical algorithm with a post-quantum one, as discussed in hybrid post-quantum encryption, protects against both a quantum attacker and the possibility that a new algorithm has an undiscovered flaw.
- Ask vendors for dates. A supplier without a post-quantum roadmap is a supplier with a risk on your books.
- Design for change. The ability to swap algorithms without rebuilding systems, often called crypto-agility, is worth more than any single choice made today.
Communications deserve special attention. Board discussions, negotiations, legal strategy and personal conversations of senior people often need to stay private for many years, which makes them precisely the material worth harvesting now. See private communication for executives.
What this means for individuals
Most people will never manage a migration plan. They will simply receive updates, and in many cases their browsers and operating systems will quietly adopt the new algorithms. That is good news.
The part individuals can choose is which services carry their most sensitive conversations. Messaging is where the choice matters most, because messages are personal, long-lived in meaning, and routinely collected in transit. Signal and Apple's iMessage have both added post-quantum protection in recent years, which is a strong sign of where the industry is heading. The simple question to ask of any messenger is: does it use post-quantum key agreement today, not in a future release?
Where VOIDEX stands
VOIDEX was designed with these standards in place from the start, not retrofitted to meet a deadline.
- Direct messages in VOIDEX Messenger begin with a hybrid key agreement combining X25519 and ML-KEM-768, the FIPS 203 standard, in a PQXDH-style handshake. A double ratchet with post-quantum re-keying then gives every message its own key.
- Identity signatures are hybrid, Ed25519 together with ML-DSA-65, the FIPS 204 standard.
- Key transparency tree heads, the signed checkpoints of VOIDEX's public, append-only key log, are signed with Ed25519 and ML-DSA-65 as well.
- The cryptographic core is open source at github.com/voidexbycnota/voidex-crypto, with a public security report explaining the design.
A fair note on parameters: VOIDEX uses ML-KEM-768 and ML-DSA-65, the mid-level sets NIST recommends for general use and the same KEM level Signal adopted. CNSA 2.0 requires the larger 1024 and 87 sets for US national security systems. For private and commercial communication, the choice VOIDEX makes is the widely recommended one, and the hybrid design means an attacker would have to break both the classical and the post-quantum layer.
In other words, the 2030 and 2035 deadlines describe a future that VOIDEX direct messages already live in.
The calendar is the message
Deadlines rarely feel urgent until they are close. The post-quantum schedule is unusual because the harm can be done long before the date arrives: every message sent today under quantum-vulnerable encryption is a message someone may one day read.
The good news is that the tools are finished. The standards are published, the algorithms are proven in production, and the services that matter most to you can adopt them now.
VOIDEX is invite-only. Request an invitation to message under post-quantum encryption today, or read how VOIDEX encryption works in full.
Sources
- NIST: NIST Releases First 3 Finalized Post-Quantum Encryption Standards (August 2024)
- NIST Post-Quantum Cryptography Standardization project
- NIST: NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption (March 2025)
- NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards (November 2024)
- NSA: Announcing the Commercial National Security Algorithm Suite 2.0 (September 2022)
- UK NCSC: Timelines for migration to post-quantum cryptography (March 2025)
- European Commission: Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography (June 2025)
- Gidney: How to factor 2048 bit RSA integers with less than a million noisy qubits (May 2025)
Enter VOIDEX
VOIDEX is invite-only and free, with no ads and no trackers. Messages are protected by hybrid post-quantum encryption (X25519 with ML-KEM-768) and checked against a public key transparency log. VOIDEX runs in your browser and as apps for Windows and Mac, with iPhone and Android on the way.
Explore the Voidverse
VOIDEX is one private universe: post-quantum encrypted messaging, an anonymous social layer, short video, collectibles and a private window onto the web.



