Three governments, one window
For years, teams treated post-quantum migration as an American problem with a distant 2035 date. That framing no longer holds. The United States, the United Kingdom, and the European Union have each published concrete timelines, and they converge on the same window of 2030 to 2035. A multinational enterprise does not face three separate programs. It faces one overlapping clock, and the earliest milestone on that clock now sits inside this decade.
How the three timelines line up
The United States moved first and hardest. Executive Order 14412 requires post-quantum key establishment on high-impact federal systems by 2030 and digital signatures by 2031, and it extends a 2030 date to covered contractors through federal acquisition rules 1. The contractor clause reaches the commercial supply chain, so the American date behaves like a market standard rather than a government-only rule.
The United Kingdom set a three-phase path through its National Cyber Security Centre. Organizations should complete cryptographic discovery and a migration plan by 2028, finish high-priority upgrades by 2031, and complete migration by 2035 2. The NCSC frames discovery as the first hard milestone, not a preliminary step.
The European Union published a coordinated roadmap through the NIS Cooperation Group. Member States should adopt national transition plans by 2026, secure critical infrastructure by 2030, and complete the transition by 2035 3. The roadmap ties directly to NIS2 and to the financial-sector resilience rules under DORA, which pulls regulated industries onto the same schedule.
What the alignment means for enterprises
The convergence is good news disguised as bad news. Because the three regimes point at the same cryptographic problem and the same replacement standards, the discovery work you do once satisfies all of them. You do not run a separate inventory for Washington, London, and Brussels. You build one complete cryptographic inventory, map each finding to the post-quantum standards, and then report against whichever regulator asks.
The trap is treating the deadlines as far away because 2035 anchors the conversation. The binding near-term dates already landed. U.S. federal systems answer to 2030, UK organizations answer to a 2028 discovery milestone, and EU Member States answer to 2026 for their national plans. A migration of this scale takes years, so the enterprises that start discovery now will meet every one of these dates from the same body of work.
One inventory, every jurisdiction
This is exactly why QuTrust builds a single cryptographic inventory across all seven surfaces and maps every finding to the standards each regulator recognizes. One analysis, one roadmap, and evidence you can hand to a U.S. auditor, a UK regulator, or an EU supervisor without translating it three times. The clock is one clock. Your migration should be one program.