Post-quantum migration deadlines: US, EU, UK, G7 and LatAm

A dated table of the post-quantum cryptography deadlines set by the US, the EU, the UK, Canada and the G7, what each one binds, and why companies in Latin America will feel them before their own regulators act.

Strategy · Published September 23, 2026 · 8 min read

Last reviewed: September 2026. We update this tracker every quarter and note what changed at the bottom of the page.

If you run security or technology at a company in Latin America, the short answer is this: your own government has not set a post-quantum deadline, but the dates set in Washington, Brussels and London will reach you anyway, mostly through your vendors and your foreign counterparties. The date that shows up most often is 2035 for finishing the migration. The dates that should drive your planning are 2030 and 2031, when the most sensitive systems are expected to be done.

The table below lists each post-quantum migration deadline we track, who set it, whether it binds anyone, and what it asks for. Further down we explain what each one means in practice for companies in Colombia, Mexico, Chile, Brazil and the rest of the region.

The post-quantum deadlines table

Each row is a published document. “Binding” means someone is legally or contractually obliged to comply, not that the date is a good idea.

Jurisdiction Document and date Binding on 2026 to 2028 2030 to 2031 2035
United States (standards) NIST IR 8547, initial public draft, November 2024 Federal agencies through NIST standards; widely copied by industry None RSA and ECC at 112-bit security (RSA-2048, P-256) deprecated after 2030 All RSA and ECC disallowed after 2035
United States (policy) Executive Order 14412, signed 22 June 2026 Federal agencies; covered contractors once the FAR rule lands NIST pilot migration of its own systems done by 31 Dec 2027 Key establishment in high value assets and high impact systems by 31 Dec 2030; digital signatures by 31 Dec 2031 None stated in the order
United States (execution) OMB Memorandum M-26-15, June 2026 Federal agencies Migration plans due about 120 days after the memo (late October 2026); discovery and inventory 2026 to 2027; pilots 2027 to 2028 Key establishment through 2030; signatures in 2031 Remaining systems by 2035
United States (national security) NSA CNSA 2.0 National Security Systems and their vendors New systems expected to support CNSA 2.0 from 2027 Networking equipment exclusive use by 2030 Full quantum resistance across National Security Systems
European Union Coordinated implementation roadmap, NIS Cooperation Group, 23 June 2025 Member states (coordination, not a regulation) Start the transition, national strategies and inventories by end of 2026 Critical infrastructure no later than end of 2030 As much as feasible by 2035
United Kingdom NCSC migration timelines, 20 March 2025 Guidance for UK organizations (not binding) Discovery, goals and initial plan by 2028 Highest priority migrations by 2031 Complete migration of all systems
Canada ITSM.40.001 roadmap, June 2025 Federal departments Initial departmental plans by April 2026, then annual reporting High priority systems by end of 2031 Remaining systems by end of 2035
G7 financial sector G7 Cyber Expert Group statement, 13 January 2026 Nobody (explicitly non-binding) Awareness, discovery and inventory Most critical systems around 2030 to 2032 Overall target for the financial sector
Google (own systems) Blog post, 25 March 2026 Google itself None Whole migration by 2029, authentication and signatures first None
Microsoft (own products) Security blog, 30 June 2026 Microsoft itself None Quantum Safe Program target moved to 2029 None
Latin America No regulator deadline found None None None None

Two notes on reading it. First, the NIST IR 8547 dates are proposals in a draft, but they have become the reference point for almost everyone else. The White House order treats the 2030 date as a real compliance date for federal systems. Second, the Google and Microsoft rows are company commitments, not regulation. We include them because they change the products you buy, which is how most deadlines will reach you.

Why do so many roadmaps end in 2035?

Because NIST picked it and everyone else lined up behind it. The G7 statement says it directly: guidance from several jurisdictions and standards bodies “often points to 2035 as an overall target date.” The UK, Canada, the EU and the NSA all use it.

The reasoning is partly about the threat and partly about the calendar. Nobody can say when a quantum computer capable of breaking RSA-2048 will exist; our piece on when Q-Day could arrive covers the estimates. What everyone can say is that replacing cryptography across a large organization takes most of a decade. The NCSC’s argument is that ten years is enough time for standards, products and adoption to mature. Working backward from 2035 with that lead time is what puts the start date at now.

The earlier 2030 to 2031 dates exist because of “harvest now, decrypt later.” Data encrypted today with RSA or elliptic-curve key exchange can be recorded and decrypted years later. For key exchange protecting long-lived data, finishing in 2035 is too late, so the White House order, the EU roadmap and the G7 all pull the most sensitive systems forward.

What changed in 2026?

The United States moved from guidance to obligation. Until June 2026 the US position was mostly NIST standards plus a national security memorandum. Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks,” signed on 22 June 2026, turned the NIST draft dates into deadlines for federal agencies. OMB M-26-15 followed days later with a five-phase schedule running to 2035 and a requirement that agencies submit migration plans, which puts the first plans on OMB’s desk around late October 2026.

The same year, the two largest software vendors set dates for themselves. Google said on 25 March 2026 that it would complete its own post-quantum migration by 2029. Microsoft followed on 30 June 2026, moving its Quantum Safe Program target to 2029 and writing that cryptographically relevant quantum computers “could arrive sooner than previously expected.”

And the financial sector got its first coordinated document. The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, published its roadmap statement on 13 January 2026. It is non-binding, but it is what supervisors in G7 countries will point to when they start asking banks for plans.

Which deadlines apply to a company in Latin America?

Legally, almost none. Practically, several. As of September 2026 we found no post-quantum deadline from any Latin American regulator, including the four financial supervisors we checked in Colombia, Mexico, Chile and Brazil. Our guide on the post-quantum roadmap for Latin American banks details what each one has and hasn’t said.

The dates still reach you through four channels.

Your vendors change the defaults

When Microsoft and Google commit to 2029, their operating systems, browsers, cloud services and identity platforms change underneath you. Some of that has already happened: Chrome 131 turned on hybrid ML-KEM key exchange by default in November 2024, OpenSSH 10.0 made it the default in April 2025, and iOS 26 advertises it on TLS 1.3 connections. Your connections to these services may already be partly post-quantum. Your internal systems, hardware security modules and older applications almost certainly aren’t, and that gap is where incidents and failed integrations will show up.

US government contracts

Executive Order 14412 asks the FAR Council to propose a rule requiring covered federal contractors to comply with NIST’s FIPS standards, including the post-quantum ones. If your company sells software or services to US federal agencies, directly or as a subcontractor, you will see those clauses. Nearshore software firms in Colombia, Mexico and Costa Rica that work for US integrators should read their contracts with this in mind.

Foreign counterparties in finance

Banks in the region connect to correspondent banks, card networks and payment infrastructure in G7 countries. When those institutions start migrating their critical systems toward the G7’s 2030 to 2032 window, they will ask their counterparties for compatible interfaces, and then for evidence of a plan. None of this requires a regulation in Bogotá or Mexico City.

European partners and data

The EU roadmap asks member states to start inventories by the end of 2026 and to move critical infrastructure by the end of 2030. Latin American companies that process data for European clients, or operate subsidiaries in the EU, will inherit questionnaires built on those dates.

What should you plan against if your regulator is silent?

Plan against the dates your largest counterparty will use. For most companies in the region that means the NIST and US federal pair (2030 for key establishment in sensitive systems, 2035 for everything) or, for financial institutions, the G7’s 2030 to 2032 window for critical systems.

A reasonable internal calendar built from the table looks like this:

By Milestone Borrowed from
Mid-2027 Complete cryptographic inventory of critical systems; named owner and budget OMB M-26-15 phase 1, EU end-2026 start, NCSC discovery
2028 Migration plan approved; vendor contracts include post-quantum clauses; pilots running NCSC 2028 milestone, OMB phase 2
2030 Key exchange protecting long-lived data migrated, hybrid where needed EO 14412, EU critical infrastructure, NIST deprecation
2031 to 2032 Signatures and authentication in critical systems migrated EO 14412, NCSC priority migrations, G7 critical systems
2035 No RSA or elliptic-curve cryptography left outside hybrid schemes NIST IR 8547, UK, Canada, G7

The inventory is the step with the least room to move, because everything after it depends on knowing where your cryptography is. Our guide to building a cryptographic inventory (CBOM) walks through it.

Could these deadlines move?

Yes, in both directions. The G7 statement says its dates “are subject to change based on changes in the risk environment,” and the NIST document is still a draft. The movement in 2026 has all been toward earlier dates: Google and Microsoft brought their own targets forward to 2029, and the US government turned proposed dates into binding ones.

There are also good reasons for skepticism about the threat side. Estimates of when a cryptographically relevant quantum computer will exist still vary widely, and serious researchers expect it later than the most aggressive forecasts. That uncertainty does not help much with planning, though. The migration takes years whichever way the estimates go, and harvested data is already sitting somewhere.

Changes to this page

September 2026: first edition. Includes Executive Order 14412 and OMB M-26-15 (June 2026), the Microsoft 2029 target (June 2026) and the Consejo Consultivo Quantum Safe México created by the Mexican Internet Association on 22 September 2026, which issues recommendations but sets no deadlines.

If you need to turn this table into a plan with owners and dates for your own systems, our post-quantum cryptography migration work starts from exactly these milestones. Companies that first want to know how exposed they are can begin with a quantum readiness assessment, and banks will find the sector detail on our banking and finance page.

Sources

  1. NIST, IR 8547 (initial public draft), Transition to Post-Quantum Cryptography Standards, November 2024
  2. Skadden, New executive orders and government strategy advance US quantum innovation and mandate PQC transition, June 2026
  3. The White House, OMB M-26-15, Execution of the Migration to Post-Quantum Cryptography, June 2026
  4. European Commission, EU reinforces its cybersecurity with post-quantum cryptography, 23 June 2025
  5. UK NCSC, Timelines for migration to post-quantum cryptography, 20 March 2025
  6. Canadian Centre for Cyber Security, Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001), June 2025
  7. G7 Cyber Expert Group, Statement on a coordinated roadmap for the transition to PQC in the financial sector, January 2026
  8. The Quantum Insider, Quantum security deadlines are here, 8 May 2026
  9. Google, Our cryptography migration timeline, 25 March 2026
  10. Microsoft Security blog, Microsoft advances quantum-safe security as the risk timeline shifts, 30 June 2026

Questions we get about this

What is the deadline for post-quantum cryptography migration?

There is no single global deadline. The most common end date is 2035, used by NIST's IR 8547 draft, the UK NCSC, Canada, the EU roadmap and the G7 Cyber Expert Group. Earlier milestones fall in 2030 and 2031 for the most sensitive systems, and the US federal government now has binding dates of 31 December 2030 and 31 December 2031.

When will RSA and elliptic-curve cryptography be deprecated?

NIST's IR 8547 draft, published in November 2024, proposes deprecating quantum-vulnerable algorithms at the 112-bit security level, such as RSA-2048 and ECC P-256, after 2030. It proposes disallowing RSA and elliptic-curve cryptography entirely after 2035. Hybrid schemes that pair a classical algorithm with an approved post-quantum one are treated differently.

Does any Latin American country have a post-quantum cryptography deadline?

Not as of September 2026. We found no PQC deadline or directive from Colombia's Superintendencia Financiera, Mexico's CNBV or Banxico, Chile's CMF or the Banco Central do Brasil. The pressure on the region comes from suppliers, US and European counterparties and the G7 financial roadmap.

Is the G7 post-quantum roadmap binding?

No. The G7 Cyber Expert Group statement of January 2026 says it does not set guidance or regulatory expectations. It proposes 2035 as an overall target for the financial sector and suggests addressing the most critical systems around 2030 to 2032.

What does Executive Order 14412 require?

Signed on 22 June 2026, it requires US federal agencies to move key establishment in their high value assets and high impact systems to post-quantum cryptography by 31 December 2030, and digital signatures by 31 December 2031. It also asks the FAR Council to propose a rule that brings covered federal contractors under the same NIST standards.

Keep reading

Get in before the queue forms

We are taking a short list of companies for our first readiness assessments and post-quantum migrations. Tell us what you are working on and we will get back to you within two business days.

Write to us