[{"data":1,"prerenderedAt":295},["ShallowReactive",2],{"news-index":3},[4,118,208],{"id":5,"title":6,"author":7,"authorTitle":8,"authorUrl":9,"body":10,"canonical":9,"category":81,"date":82,"description":83,"draft":84,"extension":85,"faqs":9,"findingsSource":9,"image":86,"keyFindings":9,"meta":87,"modified":82,"navigation":88,"path":89,"pullquote":9,"recommendations":9,"references":90,"related":100,"seo":107,"signposts":9,"slug":108,"stats":9,"stem":109,"tags":110,"tldr":116,"__hash__":117},"news\u002Fresources\u002Fnews\u002F2028-the-post-quantum-deadline-nobody-is-talking-about.md","2028 Is the Post-Quantum Deadline Nobody Is Talking About","Steve Enlow II","",null,{"type":11,"value":12,"toc":74},"minimark",[13,18,31,35,48,51,55,58,61,65],[14,15,17],"h2",{"id":16},"the-number-everyone-quotes-is-the-wrong-one","The number everyone quotes is the wrong one",[19,20,21,22,26,27,30],"p",{},"Ask a security leader when post-quantum migration is due and most will answer 2035. That date is real, and it is also the least useful one on the calendar. The deadline that governs what your team does this year is not the finish line. It is the starting gun, and two regulators have already fired it. The UK's National Cyber Security Centre expects cryptographic discovery finished by 2028, and the European Union expects Member States to publish national transition roadmaps by 2026 ",[23,24,25],"span",{},"1",", ",[23,28,29],{},"2",". Both dates measure the same thing: whether you know where your vulnerable cryptography lives.",[14,32,34],{"id":33},"why-discovery-is-the-real-deadline","Why discovery is the real deadline",[19,36,37,38,40,41,43,44,47],{},"Every credible migration plan begins with an inventory, because you cannot replace an algorithm you have not found. The NCSC makes this explicit by carving discovery out as its own phase and dating it to 2028, ahead of the high-priority upgrades it expects by 2031 and the full migration it expects by 2035 ",[23,39,25],{},". The EU roadmap does the same thing from a different angle, requiring national plans by 2026 so that critical infrastructure can hit its 2030 target ",[23,42,29],{},". NIST reinforces the sequencing in its transition guidance, which treats identifying and prioritizing quantum-vulnerable systems as the work that everything else depends on ",[23,45,46],{},"3",".",[19,49,50],{},"The reason is practical, not bureaucratic. Discovery is the slowest and least predictable part of the whole program. Vulnerable cryptography hides in source code, in dependencies, in certificates, in infrastructure configuration, in compiled binaries, and in the tokens your services issue at runtime. Teams routinely find that the real exposure lives in surfaces they never scanned, so the inventory takes longer than anyone budgets. If you wait until 2033 to start looking, you will not finish looking in time to migrate.",[14,52,54],{"id":53},"the-trap-of-anchoring-on-2035","The trap of anchoring on 2035",[19,56,57],{},"Anchoring on 2035 creates a comfortable illusion of time, and that illusion is expensive. A leader who hears 2035 mentally schedules the work for the early 2030s. A leader who understands that discovery is due in 2028, and that a defensible EU roadmap is due in 2026, schedules the work now. The gap between those two mindsets is the difference between a migration you control and a migration that controls you.",[19,59,60],{},"The near-term dates also carry the audit risk. A regulator in 2029 will not ask whether you finished migrating. It will ask whether you know your exposure and whether you have a credible plan. Those are discovery questions, and you either have the inventory to answer them or you do not.",[14,62,64],{"id":63},"start-the-clock-on-your-terms","Start the clock on your terms",[19,66,67,68,73],{},"Discovery is knowable today, and it is the one part of the program you can complete before any deadline forces you to. ",[69,70,72],"a",{"href":71},"\u002Fqutrust","QuTrust"," builds your cryptographic inventory across all seven surfaces, classifies each finding by quantum risk, and turns the result into a roadmap you can defend to the NCSC, an EU supervisor, or a U.S. auditor. The finish line is 2035. The starting gun already fired. Run.",{"title":8,"searchDepth":75,"depth":75,"links":76},2,[77,78,79,80],{"id":16,"depth":75,"text":17},{"id":33,"depth":75,"text":34},{"id":53,"depth":75,"text":54},{"id":63,"depth":75,"text":64},"Analysis","2026-07-08","Everyone cites 2035, but the UK NCSC wants cryptographic discovery done by 2028 and the EU wants roadmaps by 2026. Here is why discovery is the real near-term deadline.",false,"md","\u002Fassets\u002Fog-default.png",{},true,"\u002Fresources\u002Fnews\u002F2028-the-post-quantum-deadline-nobody-is-talking-about",[91,94,97],{"label":92,"url":93},"National Cyber Security Centre, \"Timelines for migration to post-quantum cryptography,\" NCSC (UK), 2025.","https:\u002F\u002Fwww.ncsc.gov.uk\u002Fguidance\u002Fpqc-migration-timelines",{"label":95,"url":96},"European Commission and NIS Cooperation Group, \"A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,\" Jun. 2025.","https:\u002F\u002Fdigital-strategy.ec.europa.eu\u002Fen\u002Flibrary\u002Fcoordinated-implementation-roadmap-transition-post-quantum-cryptography",{"label":98,"url":99},"National Institute of Standards and Technology, \"NIST IR 8547: Transition to Post-Quantum Cryptography Standards,\" NIST, 2024.","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fir\u002F8547\u002Fipd",[101,104],{"label":102,"url":103},"What Executive Order 14412 Requires","\u002Fresources\u002Fnews\u002Fus-executive-order-14412-post-quantum-deadline",{"label":105,"url":106},"One Clock, Three Jurisdictions: How the U.S., UK, and EU Deadlines Line Up","\u002Fresources\u002Fnews\u002Fus-uk-eu-post-quantum-deadlines-aligned",{"title":6,"description":83},"2028-the-post-quantum-deadline-nobody-is-talking-about","resources\u002Fnews\u002F2028-the-post-quantum-deadline-nobody-is-talking-about",[111,112,113,114,115],"cryptographic discovery","PQC migration","NCSC PQC timelines","EU PQC roadmap","quantum readiness","While the headlines fixate on 2035, the UK expects cryptographic discovery finished by 2028 and the EU expects national roadmaps by 2026, which makes discovery the deadline that actually starts the clock.","67WEfPJ7m4JJlGTuL3ZJ8LM0paKIKuvUnas3hG4cD-4",{"id":119,"title":120,"author":7,"authorTitle":8,"authorUrl":9,"body":121,"canonical":9,"category":81,"date":188,"description":189,"draft":84,"extension":85,"faqs":9,"findingsSource":9,"image":86,"keyFindings":9,"meta":190,"modified":188,"navigation":88,"path":106,"pullquote":9,"recommendations":9,"references":191,"related":197,"seo":200,"signposts":9,"slug":201,"stats":9,"stem":202,"tags":203,"tldr":206,"__hash__":207},"news\u002Fresources\u002Fnews\u002Fus-uk-eu-post-quantum-deadlines-aligned.md","One Clock, Three Jurisdictions: How the U.S., UK, and EU Post-Quantum Deadlines Line Up",{"type":11,"value":122,"toc":182},[123,127,130,134,144,153,162,166,169,172,176],[14,124,126],{"id":125},"three-governments-one-window","Three governments, one window",[19,128,129],{},"For years, teams treated post-quantum migration as an American problem with a distant 2035 date. That framing no longer holds. The United States, the United Kingdom, and the European Union have each published concrete timelines, and they converge on the same window of 2030 to 2035. A multinational enterprise does not face three separate programs. It faces one overlapping clock, and the earliest milestone on that clock now sits inside this decade.",[14,131,133],{"id":132},"how-the-three-timelines-line-up","How the three timelines line up",[19,135,136,140,141,143],{},[137,138,139],"strong",{},"The United States"," moved first and hardest. Executive Order 14412 requires post-quantum key establishment on high-impact federal systems by 2030 and digital signatures by 2031, and it extends a 2030 date to covered contractors through federal acquisition rules ",[23,142,25],{},". The contractor clause reaches the commercial supply chain, so the American date behaves like a market standard rather than a government-only rule.",[19,145,146,149,150,152],{},[137,147,148],{},"The United Kingdom"," set a three-phase path through its National Cyber Security Centre. Organizations should complete cryptographic discovery and a migration plan by 2028, finish high-priority upgrades by 2031, and complete migration by 2035 ",[23,151,29],{},". The NCSC frames discovery as the first hard milestone, not a preliminary step.",[19,154,155,158,159,161],{},[137,156,157],{},"The European Union"," published a coordinated roadmap through the NIS Cooperation Group. Member States should adopt national transition plans by 2026, secure critical infrastructure by 2030, and complete the transition by 2035 ",[23,160,46],{},". The roadmap ties directly to NIS2 and to the financial-sector resilience rules under DORA, which pulls regulated industries onto the same schedule.",[14,163,165],{"id":164},"what-the-alignment-means-for-enterprises","What the alignment means for enterprises",[19,167,168],{},"The convergence is good news disguised as bad news. Because the three regimes point at the same cryptographic problem and the same replacement standards, the discovery work you do once satisfies all of them. You do not run a separate inventory for Washington, London, and Brussels. You build one complete cryptographic inventory, map each finding to the post-quantum standards, and then report against whichever regulator asks.",[19,170,171],{},"The trap is treating the deadlines as far away because 2035 anchors the conversation. The binding near-term dates already landed. U.S. federal systems answer to 2030, UK organizations answer to a 2028 discovery milestone, and EU Member States answer to 2026 for their national plans. A migration of this scale takes years, so the enterprises that start discovery now will meet every one of these dates from the same body of work.",[14,173,175],{"id":174},"one-inventory-every-jurisdiction","One inventory, every jurisdiction",[19,177,178,179,181],{},"This is exactly why ",[69,180,72],{"href":71}," builds a single cryptographic inventory across all seven surfaces and maps every finding to the standards each regulator recognizes. One analysis, one roadmap, and evidence you can hand to a U.S. auditor, a UK regulator, or an EU supervisor without translating it three times. The clock is one clock. Your migration should be one program.",{"title":8,"searchDepth":75,"depth":75,"links":183},[184,185,186,187],{"id":125,"depth":75,"text":126},{"id":132,"depth":75,"text":133},{"id":164,"depth":75,"text":165},{"id":174,"depth":75,"text":175},"2026-07-01","The U.S. (EO 14412), UK (NCSC), and the EU roadmap now set post-quantum deadlines converging on 2030 to 2035. Here is how the three timelines line up for enterprises.",{},[192,195,196],{"label":193,"url":194},"The White House, \"Securing the Nation Against Advanced Cryptographic Attacks,\" Executive Order 14412, Washington, DC, USA, Jun. 22, 2026.","https:\u002F\u002Fwww.whitehouse.gov\u002Fpresidential-actions\u002F2026\u002F06\u002Fsecuring-the-nation-against-advanced-cryptographic-attacks\u002F",{"label":92,"url":93},{"label":95,"url":96},[198,199],{"label":102,"url":103},{"label":6,"url":89},{"title":120,"description":189},"us-uk-eu-post-quantum-deadlines-aligned","resources\u002Fnews\u002Fus-uk-eu-post-quantum-deadlines-aligned",[112,204,113,114,205,115],"EO 14412","2035 deadline","The U.S., UK, and EU have set post-quantum deadlines that converge between 2030 and 2035, so a multinational enterprise faces one overlapping clock rather than three separate programs.","gMn0qT0_HzKeqJvOsXNDEMwYX8hGJfV_Tn1BTQXn4gc",{"id":209,"title":210,"author":7,"authorTitle":8,"authorUrl":9,"body":211,"canonical":9,"category":270,"date":271,"description":272,"draft":84,"extension":85,"faqs":9,"findingsSource":9,"image":86,"keyFindings":9,"meta":273,"modified":271,"navigation":88,"path":103,"pullquote":9,"recommendations":9,"references":274,"related":282,"seo":285,"signposts":9,"slug":286,"stats":9,"stem":287,"tags":288,"tldr":293,"__hash__":294},"news\u002Fresources\u002Fnews\u002Fus-executive-order-14412-post-quantum-deadline.md","The U.S. Just Moved the Post-Quantum Deadline Up: What Executive Order 14412 Requires",{"type":11,"value":212,"toc":264},[213,217,229,233,238,244,248,251,255,258],[14,214,216],{"id":215},"the-deadline-moved-and-it-moved-forward","The deadline moved, and it moved forward",[19,218,219,220,222,223,225,226,228],{},"On June 22, 2026, the White House signed Executive Order 14412, and it pulled the U.S. federal post-quantum timeline forward in a way that reaches well past federal agencies ",[23,221,25],{},". High-impact federal systems must adopt post-quantum key establishment by December 31, 2030, and post-quantum digital signatures by December 31, 2031 ",[23,224,25],{},". The order also directs the Federal Acquisition Regulatory Council to give covered contractors until the end of 2030 to meet the National Institute of Standards and Technology standards, including the post-quantum algorithms ",[23,227,29],{},". If your company sells to the government, or sells to anyone who does, the order now sets your clock too.",[14,230,232],{"id":231},"what-the-order-actually-requires","What the order actually requires",[19,234,235,236,47],{},"The order splits the migration into two phases that mirror how cryptography actually breaks. Key establishment comes first, because an adversary who records encrypted traffic today can decrypt it later once a large quantum computer exists. That threat, known as harvest now, decrypt later, does not wait for the migration to finish. Authentication comes second, because forged signatures let an attacker impersonate a server or sign malicious code after quantum computers arrive. NIST already published the algorithms that answer both needs, starting with FIPS 203 for key encapsulation ",[23,237,46],{},[19,239,240,241,243],{},"The operational requirements matter as much as the dates. Within 30 days, each agency names a migration lead who owns the cryptographic inventory and the migration plan. Within 90 days, the Office of Management and Budget issues guidance that requires agencies to review their inventories of high-value assets and high-impact systems and submit a plan ",[23,242,25],{},". The order treats the cryptographic inventory as the first deliverable, not the last, and that ordering is the tell for everyone else.",[14,245,247],{"id":246},"why-this-reaches-the-private-sector","Why this reaches the private sector",[19,249,250],{},"Read the contractor clause carefully, because it changes the calculus for commercial teams that assumed 2035 gave them room. When federal buyers require post-quantum readiness in procurement, that requirement flows down every tier of the supply chain. A software vendor, a cloud provider, and a managed service that all touch federal data now inherit a 2030 date whether or not they consider themselves a government contractor. Markets tend to standardize on the strictest live requirement, and Executive Order 14412 just made 2030 the number that matters in the United States.",[14,252,254],{"id":253},"what-to-do-now","What to do now",[19,256,257],{},"Start where the order starts: with discovery. You cannot plan a migration you cannot see, and a plan you submit against a stale inventory will not survive an audit. Build a complete cryptographic inventory across every surface where vulnerable algorithms hide, classify each finding by quantum risk, and map it to the standard that replaces it. Then turn that inventory into a prioritized roadmap with dates your leadership can track.",[19,259,260,261,263],{},"This is the work ",[69,262,72],{"href":71}," does. It analyzes the seven cryptographic surfaces in one engine, maps every finding to FIPS 203, 204, and 205, and builds the migration roadmap for you, in our cloud or inside your own perimeter. Executive Order 14412 did not create the quantum threat. It removed the excuse to wait.",{"title":8,"searchDepth":75,"depth":75,"links":265},[266,267,268,269],{"id":215,"depth":75,"text":216},{"id":231,"depth":75,"text":232},{"id":246,"depth":75,"text":247},{"id":253,"depth":75,"text":254},"Policy","2026-06-24","Executive Order 14412 sets 2030 and 2031 post-quantum deadlines for U.S. federal high-impact systems and covered contractors. Here is what changes and what to do now.",{},[275,276,279],{"label":193,"url":194},{"label":277,"url":278},"\"Trump sets new deadlines for agencies and contractors to adopt post-quantum cryptography,\" Cybersecurity Dive, Jun. 2026.","https:\u002F\u002Fwww.cybersecuritydive.com\u002Fnews\u002Fquantum-cryptography-white-house-executive-order\u002F823530\u002F",{"label":280,"url":281},"National Institute of Standards and Technology, \"FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard,\" NIST, Aug. 2024.","https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Ffips\u002F203\u002Ffinal",[283,284],{"label":105,"url":106},{"label":6,"url":89},{"title":210,"description":272},"us-executive-order-14412-post-quantum-deadline","resources\u002Fnews\u002Fus-executive-order-14412-post-quantum-deadline",[289,112,204,290,291,292],"post-quantum cryptography","2030 deadline","federal compliance","for enterprises","Executive Order 14412 requires U.S. federal high-impact systems to adopt post-quantum key establishment by 2030 and digital signatures by 2031, and it puts covered contractors on the same clock.","LYAMKTdQYmVDCJspI81Eu3PDgKY0VaN2y2UvnUr5fJc",1784747239462]