NIST IR 8547: U.S. federal deprecation timeline
Direct answerNIST IR 8547 sets the U.S. federal timeline for retiring quantum-vulnerable public-key cryptography: RSA, ECDSA, EdDSA, ECDH, and finite-field DH at 112-bit security are deprecated after 2030 and all quantum-vulnerable public-key algorithms are disallowed after 2035.
- Issued by
- NIST (U.S.)
- Date
- Initial public draft 2024-11-12
- Status
- Draft (final pending as of 2026-09)
- Source
- https://csrc.nist.gov/pubs/ir/8547/ipd
Milestones
- 2030Quantum-vulnerable algorithms at 112-bit security (RSA-2048, P-256, and similar) deprecated
- 2035All quantum-vulnerable public-key algorithms disallowed for U.S. federal use
Notes
- Hybrid modes that combine an approved post-quantum algorithm with a classical one are not caught by the 2035 disallowance.
- Applies to federal information systems via FIPS 140-3 and SP 800-131A; widely used as the de facto industry timeline.
Algorithms this timeline points to
ML-KEM, ML-DSA, SLH-DSA, FN-DSA, HQC, LMS / HSS, XMSS / XMSS^MT
Who can help you meet it
Cryptography audit firms listed on this index: zkSecurity, Trail of Bits, NCC Group (Cryptography Services), Cryspen, Kudelski Security, Quarkslab, Least Authority, Galois, atsec information security, Riscure (Keysight), Cure53, X41 D-Sec. See the audit checklist for what a migration review covers.