Post-quantum cryptography just got real deadlines, and most enterprises aren't ready

For a decade, post-quantum cryptography was a research problem with no urgency attached. That changed this year. NIST IR 8547 sets a hard line: RSA-2048 and ECC-256, the algorithms securing the overwhelming majority of internet traffic today, are to be deprecated by 2030 and formally disallowed after 2035. The NSA's CNSA 2.0 framework goes further for national security systems — quantum-safe algorithms are already required for all new NSS deployments as of January 2027, with full application migration due by 2030 and complete infrastructure migration by 2035.
These aren't research targets anymore. They're compliance deadlines that will cascade from federal agencies through defense contractors, regulated financial institutions, and eventually any vendor who wants to sell into those markets. The G7 Cyber Expert Group's January 2026 roadmap confirms the same pattern is starting in the financial sector: 2026–2027 for awareness and strategy, cryptographic inventory in 2027–2028, and migration execution for critical systems from 2030 to 2032.
The problem isn't the math — it's the inventory
The cryptographic algorithms themselves — CRYSTALS-Kyber (now ML-KEM) for key exchange, CRYSTALS-Dilithium (ML-DSA) for signatures — have been NIST-standardized since 2024. That part is largely solved. The actual blocker for most organizations is more mundane: nobody has a complete map of where RSA and ECC are actually used.
Cryptography is embedded everywhere — TLS termination points, VPN concentrators, code-signing pipelines, IoT firmware, database-at-rest encryption, internal service-to-service auth, even decades-old EDI systems that nobody remembers configuring. A typical enterprise cryptographic inventory project takes 12 to 18 months before migration even begins, because discovery tooling has to crawl certificate stores, hardware security modules, embedded device firmware, and third-party SaaS dependencies that IT doesn't directly control.
Why 2030 is closer than it looks
Migrating a public-facing TLS certificate to a post-quantum key exchange is comparatively easy — most major browsers and CDNs already support hybrid classical/PQC handshakes. The hard part is everything downstream: hardware that can't be firmware-updated (industrial control systems, older HSMs, embedded medical devices), vendor software that hardcodes RSA and won't get a PQC-compatible release before end-of-life, and internal PKI hierarchies that require reissuing every certificate in the chain.
There's also a harvest-now-decrypt-later threat model driving urgency independent of any deadline. Encrypted data intercepted today — financial records, health data, classified communications, intellectual property with multi-decade value — can be stored and decrypted retroactively once a sufficiently powerful quantum computer exists. For data with a shelf life beyond 2035, the migration deadline is effectively already in the past; anything encrypted with RSA-2048 today and worth protecting for ten more years is already exposed to this threat.
What to actually do before 2027
Security teams that are behind should stop waiting for a “PQC project” to get funded as a standalone initiative and instead fold cryptographic inventory into whatever asset-management or zero-trust program already has budget. Three concrete steps matter more than anything else right now: first, run automated discovery against certificate stores and TLS endpoints to find every RSA/ECC deployment, prioritized by data sensitivity and shelf life. Second, identify hardware and vendor software that cannot be updated in place — those systems need replacement budgets requested now, not in 2029. Third, pilot hybrid classical/PQC key exchange on at least one external-facing service this year; production experience with ML-KEM handshakes surfaces integration problems (increased handshake size, latency on constrained devices) that are far cheaper to fix in a pilot than during a compliance-driven crunch.
The organizations that treat 2030 as the start of migration, rather than the deadline for completing it, are the ones that will be explaining a multi-year remediation plan to regulators instead of showing a completed one.