Last reviewed: September 2026. We update this tracker every quarter and note what changed at the bottom of the page.
If you run security or technology at a company in Latin America, the short answer is this: your own government has not set a post-quantum deadline, but the dates set in Washington, Brussels and London will reach you anyway, mostly through your vendors and your foreign counterparties. The date that shows up most often is 2035 for finishing the migration. The dates that should drive your planning are 2030 and 2031, when the most sensitive systems are expected to be done.
The table below lists each post-quantum migration deadline we track, who set it, whether it binds anyone, and what it asks for. Further down we explain what each one means in practice for companies in Colombia, Mexico, Chile, Brazil and the rest of the region.
The post-quantum deadlines table
Each row is a published document. “Binding” means someone is legally or contractually obliged to comply, not that the date is a good idea.
| Jurisdiction | Document and date | Binding on | 2026 to 2028 | 2030 to 2031 | 2035 |
|---|---|---|---|---|---|
| United States (standards) | NIST IR 8547, initial public draft, November 2024 | Federal agencies through NIST standards; widely copied by industry | None | RSA and ECC at 112-bit security (RSA-2048, P-256) deprecated after 2030 | All RSA and ECC disallowed after 2035 |
| United States (policy) | Executive Order 14412, signed 22 June 2026 | Federal agencies; covered contractors once the FAR rule lands | NIST pilot migration of its own systems done by 31 Dec 2027 | Key establishment in high value assets and high impact systems by 31 Dec 2030; digital signatures by 31 Dec 2031 | None stated in the order |
| United States (execution) | OMB Memorandum M-26-15, June 2026 | Federal agencies | Migration plans due about 120 days after the memo (late October 2026); discovery and inventory 2026 to 2027; pilots 2027 to 2028 | Key establishment through 2030; signatures in 2031 | Remaining systems by 2035 |
| United States (national security) | NSA CNSA 2.0 | National Security Systems and their vendors | New systems expected to support CNSA 2.0 from 2027 | Networking equipment exclusive use by 2030 | Full quantum resistance across National Security Systems |
| European Union | Coordinated implementation roadmap, NIS Cooperation Group, 23 June 2025 | Member states (coordination, not a regulation) | Start the transition, national strategies and inventories by end of 2026 | Critical infrastructure no later than end of 2030 | As much as feasible by 2035 |
| United Kingdom | NCSC migration timelines, 20 March 2025 | Guidance for UK organizations (not binding) | Discovery, goals and initial plan by 2028 | Highest priority migrations by 2031 | Complete migration of all systems |
| Canada | ITSM.40.001 roadmap, June 2025 | Federal departments | Initial departmental plans by April 2026, then annual reporting | High priority systems by end of 2031 | Remaining systems by end of 2035 |
| G7 financial sector | G7 Cyber Expert Group statement, 13 January 2026 | Nobody (explicitly non-binding) | Awareness, discovery and inventory | Most critical systems around 2030 to 2032 | Overall target for the financial sector |
| Google (own systems) | Blog post, 25 March 2026 | Google itself | None | Whole migration by 2029, authentication and signatures first | None |
| Microsoft (own products) | Security blog, 30 June 2026 | Microsoft itself | None | Quantum Safe Program target moved to 2029 | None |
| Latin America | No regulator deadline found | None | None | None | None |
Two notes on reading it. First, the NIST IR 8547 dates are proposals in a draft, but they have become the reference point for almost everyone else. The White House order treats the 2030 date as a real compliance date for federal systems. Second, the Google and Microsoft rows are company commitments, not regulation. We include them because they change the products you buy, which is how most deadlines will reach you.
Why do so many roadmaps end in 2035?
Because NIST picked it and everyone else lined up behind it. The G7 statement says it directly: guidance from several jurisdictions and standards bodies “often points to 2035 as an overall target date.” The UK, Canada, the EU and the NSA all use it.
The reasoning is partly about the threat and partly about the calendar. Nobody can say when a quantum computer capable of breaking RSA-2048 will exist; our piece on when Q-Day could arrive covers the estimates. What everyone can say is that replacing cryptography across a large organization takes most of a decade. The NCSC’s argument is that ten years is enough time for standards, products and adoption to mature. Working backward from 2035 with that lead time is what puts the start date at now.
The earlier 2030 to 2031 dates exist because of “harvest now, decrypt later.” Data encrypted today with RSA or elliptic-curve key exchange can be recorded and decrypted years later. For key exchange protecting long-lived data, finishing in 2035 is too late, so the White House order, the EU roadmap and the G7 all pull the most sensitive systems forward.
What changed in 2026?
The United States moved from guidance to obligation. Until June 2026 the US position was mostly NIST standards plus a national security memorandum. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” signed on 22 June 2026, turned the NIST draft dates into deadlines for federal agencies. OMB M-26-15 followed days later with a five-phase schedule running to 2035 and a requirement that agencies submit migration plans, which puts the first plans on OMB’s desk around late October 2026.
The same year, the two largest software vendors set dates for themselves. Google said on 25 March 2026 that it would complete its own post-quantum migration by 2029. Microsoft followed on 30 June 2026, moving its Quantum Safe Program target to 2029 and writing that cryptographically relevant quantum computers “could arrive sooner than previously expected.”
And the financial sector got its first coordinated document. The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, published its roadmap statement on 13 January 2026. It is non-binding, but it is what supervisors in G7 countries will point to when they start asking banks for plans.
Which deadlines apply to a company in Latin America?
Legally, almost none. Practically, several. As of September 2026 we found no post-quantum deadline from any Latin American regulator, including the four financial supervisors we checked in Colombia, Mexico, Chile and Brazil. Our guide on the post-quantum roadmap for Latin American banks details what each one has and hasn’t said.
The dates still reach you through four channels.
Your vendors change the defaults
When Microsoft and Google commit to 2029, their operating systems, browsers, cloud services and identity platforms change underneath you. Some of that has already happened: Chrome 131 turned on hybrid ML-KEM key exchange by default in November 2024, OpenSSH 10.0 made it the default in April 2025, and iOS 26 advertises it on TLS 1.3 connections. Your connections to these services may already be partly post-quantum. Your internal systems, hardware security modules and older applications almost certainly aren’t, and that gap is where incidents and failed integrations will show up.
US government contracts
Executive Order 14412 asks the FAR Council to propose a rule requiring covered federal contractors to comply with NIST’s FIPS standards, including the post-quantum ones. If your company sells software or services to US federal agencies, directly or as a subcontractor, you will see those clauses. Nearshore software firms in Colombia, Mexico and Costa Rica that work for US integrators should read their contracts with this in mind.
Foreign counterparties in finance
Banks in the region connect to correspondent banks, card networks and payment infrastructure in G7 countries. When those institutions start migrating their critical systems toward the G7’s 2030 to 2032 window, they will ask their counterparties for compatible interfaces, and then for evidence of a plan. None of this requires a regulation in Bogotá or Mexico City.
European partners and data
The EU roadmap asks member states to start inventories by the end of 2026 and to move critical infrastructure by the end of 2030. Latin American companies that process data for European clients, or operate subsidiaries in the EU, will inherit questionnaires built on those dates.
What should you plan against if your regulator is silent?
Plan against the dates your largest counterparty will use. For most companies in the region that means the NIST and US federal pair (2030 for key establishment in sensitive systems, 2035 for everything) or, for financial institutions, the G7’s 2030 to 2032 window for critical systems.
A reasonable internal calendar built from the table looks like this:
| By | Milestone | Borrowed from |
|---|---|---|
| Mid-2027 | Complete cryptographic inventory of critical systems; named owner and budget | OMB M-26-15 phase 1, EU end-2026 start, NCSC discovery |
| 2028 | Migration plan approved; vendor contracts include post-quantum clauses; pilots running | NCSC 2028 milestone, OMB phase 2 |
| 2030 | Key exchange protecting long-lived data migrated, hybrid where needed | EO 14412, EU critical infrastructure, NIST deprecation |
| 2031 to 2032 | Signatures and authentication in critical systems migrated | EO 14412, NCSC priority migrations, G7 critical systems |
| 2035 | No RSA or elliptic-curve cryptography left outside hybrid schemes | NIST IR 8547, UK, Canada, G7 |
The inventory is the step with the least room to move, because everything after it depends on knowing where your cryptography is. Our guide to building a cryptographic inventory (CBOM) walks through it.
Could these deadlines move?
Yes, in both directions. The G7 statement says its dates “are subject to change based on changes in the risk environment,” and the NIST document is still a draft. The movement in 2026 has all been toward earlier dates: Google and Microsoft brought their own targets forward to 2029, and the US government turned proposed dates into binding ones.
There are also good reasons for skepticism about the threat side. Estimates of when a cryptographically relevant quantum computer will exist still vary widely, and serious researchers expect it later than the most aggressive forecasts. That uncertainty does not help much with planning, though. The migration takes years whichever way the estimates go, and harvested data is already sitting somewhere.
Changes to this page
September 2026: first edition. Includes Executive Order 14412 and OMB M-26-15 (June 2026), the Microsoft 2029 target (June 2026) and the Consejo Consultivo Quantum Safe México created by the Mexican Internet Association on 22 September 2026, which issues recommendations but sets no deadlines.
If you need to turn this table into a plan with owners and dates for your own systems, our post-quantum cryptography migration work starts from exactly these milestones. Companies that first want to know how exposed they are can begin with a quantum readiness assessment, and banks will find the sector detail on our banking and finance page.
Sources
- NIST, IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
- Skadden, New executive orders and government strategy advance US quantum innovation and mandate PQC transition, June 2026
- The White House, OMB M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 2026
- European Commission, EU reinforces its cybersecurity with post-quantum cryptography, 23 June 2025
- UK NCSC, Timelines for migration to post-quantum cryptography, 20 March 2025
- Canadian Centre for Cyber Security, Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001), June 2025
- G7 Cyber Expert Group, Statement on a coordinated roadmap for the transition to PQC in the financial sector, January 2026
- The Quantum Insider, Quantum security deadlines are here, 8 May 2026
- Google, Our cryptography migration timeline, 25 March 2026
- Microsoft Security blog, Microsoft advances quantum-safe security as the risk timeline shifts, 30 June 2026