Insider Brief
- The article examines post-quantum cryptography migration timelines from governments, technology companies, financial institutions, infrastructure operators, and blockchain communities.
- Major organizations have set different transition targets, with regulatory deadlines extending to 2035 while several technology companies are targeting earlier migration milestones around 2029.
- The analysis finds that organizations broadly agree on starting post-quantum migration planning despite differences in estimates for when cryptographically relevant quantum computers may arrive.
Every major organization has published a timeline. Governments, technology companies, financial institutions, critical infrastructure operators, and blockchain communities – all of the major players disagree on when a cryptographically relevant quantum computer will arrive, but none of them have published a “wait and see” position. As TQI’s Year of Quantum Security coverage has tracked, 2026 has become the year where that broad agreement on action became concrete – with deadlines, roadmaps, and product commitments replacing general awareness.
This article maps what the major players have actually committed to, where the ranges cluster, and what the spread tells organizations still deciding how to prioritize their own migration.
What Governments Have Committed to and When
Regulatory deadlines form the bottom line. It’s important to note that they are the bare minimum expectations, not the goal post.
NIST IR 8547, the transition framework published as an initial public draft in November 2024, calls for RSA-2048 and ECC-256 to be deprecated by 2030 and disallowed after 2035. These dates apply to federal agencies and extend to organizations handling federal data or operating in regulated environments. As TQI has covered, the three finalized standards such as ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) – provide the algorithm foundation for that migration.
CNSA 2.0 requires new acquisitions into National Security Systems to support quantum-resistant cryptography from January 1, 2027.
Software and firmware signing must use quantum-resistant signatures by 2030, systems that cannot be upgraded must be retired, and quantum-resistant encryption must be the exclusive standard for web, cloud, and operating systems by 2033, with most other transitions completing on a similar timeline. Full quantum-resistant infrastructure across all systems is required by 2035 under NSM-10. TQI’s coverage of government deadlines and their implications covers how these requirements flow through to contractors and regulated sectors.
The EU framework, published by the NIS Cooperation Group in June 2025, calls for member states to publish national PQC strategies and initiate cryptographic inventories by the end of 2026, critical infrastructure transition for high-risk use cases by 2030, and medium-risk use case migration completed by 2035.
The G7 Cyber Expert Group issued a coordinated financial sector roadmap in January 2026, establishing 2026-2027 as the start of awareness, strategy development, and initial planning across G7 financial institutions. Cryptographic discovery and inventory follows in 2027-2028, with risk assessment and tailored migration plans targeted for 2028-2029. Migration execution for critical systems runs from 2030 to 2032, with testing through 2034 and full validation from 2035 onward. The UK NCSC has set phased targets along a similar arc – cryptographic discovery by 2028, high-priority system migration by 2031, full transition by 2035.
Why Big Tech is Moving Ahead of Regulatory Deadlines
Technology companies are running ahead of regulatory requirements. Major platform providers are treating 2029 as their operating target, four to six years ahead of the regulatory deadline.
Google announced in March 2026 a 2029 deadline for completing its post-quantum cryptography migration. The company cited faster-than-expected progress in quantum hardware development, error correction, and factoring resource estimates as the drivers for accelerating from earlier planning assumptions. Google’s Heather Adkins and Sophie Schmieg stated directly that the new timeline reflects a view that the risk distribution has changed and that its 2029 target is both an internal commitment and a signal to the broader industry.
Cloudflare followed within weeks, announcing it is matching Google’s 2029 target for full post-quantum security – including post-quantum authentication, which is significantly harder to migrate than encryption. As of April 2026, over 65% of human-generated traffic on Cloudflare‘s network is already protected using post-quantum encryption. The company’s published roadmap adds post-quantum authentication to Cloudflare-to-origin connections by mid-2026 and visitor-to-Cloudflare connections by mid-2027.
Microsoft’s Quantum Safe Program targets full transition by 2033, two years ahead of NIST’s 2035 government deadline and four years behind Google’s 2029 target. The phased approach integrates ML-KEM and ML-DSA into SymCrypt, the core cryptographic library for Windows and Azure, in Phase 1. Phase 2 migrates core infrastructure services, including identity authentication and key management. Phase 3 extends PQC across Windows, Azure, Microsoft 365, and data and AI services by 2033. Early adoption across the ecosystem is expected by 2029, with quantum-safe options gradually becoming the default in subsequent years.
Apple deployed post-quantum cryptography into iMessage via its PQ3 protocol in early 2024, protecting both initial key exchange and ongoing message keys. Amazon’s AWS offers quantum-safe options for certificate authorities and identity systems, and has integrated post-quantum key exchange into AWS KMS and TLS libraries.
IBM has focused heavily on tooling rather than publishing a specific migration completion date. The IBM Quantum Safe platform includes the Quantum Safe Explorer for cryptographic inventory and discovery, and the z16 mainframe ships with hardware acceleration for post-quantum algorithms. IBM‘s position reflects an emphasis on helping enterprise customers manage migration complexity rather than setting a single internal target date.
What the Hardware Builders Say About the Timeline
The companies building the hardware that creates the threat are also preparing for it.
Quantinuum has been explicit about the significance of its March 2026 demonstration of 94 error-protected logical qubits performing beyond-break-even computations. The company has stated publicly that fault-tolerant quantum computing capable of running Shor’s algorithm at cryptographically relevant scale is a matter of engineering timelines.
PsiQuantum, which has raised over $2.3 billion toward a photonic fault-tolerant quantum computer , has described its architecture as targeting utility-scale quantum computing within this decade. In 2025, PsiQuantum and the State of Illinois announced a joint initiative to build a utility-scale quantum computing facility targeting completion within the next few years.
IBM’s published Quantum roadmap targets Starling, a system designed to demonstrate 200 logical qubits and 100 million quantum gates in 2029 – which IBM describes as the threshold for early fault-tolerant quantum advantage in specific computational tasks.
The consistent thread across quantum hardware companies is that fault-tolerant systems with meaningful logical qubit counts are a near-decade-scale engineering project. That framing is what drives the urgency behind the migration timelines above.
How Financial Institutions are Approaching the Migration
The financial sector sits at an intersection of regulatory pressure, long-lived sensitive data, and the kind of institutional complexity that makes migration genuinely difficult.
JPMorgan Chase has deployed a quantum-secured crypto-agile network (Q-CAN) connecting two data centers over 29 miles of fiber in Singapore, using QKD-secured infrastructure operating at 100 Gbps. The bank pursues a dual strategy incorporating both post-quantum cryptography and quantum key distribution, and in March 2025 published a certified quantum randomness milestone with Quantinuum.
According to PostQuantum’s analysis of payments-sector quantum readiness, SWIFT is expected to make SwiftNet 8.0 PQC-enabled by 2027, with a 15-month migration window for participating institutions.
The harvest-now-decrypt-later threat is particularly acute for financial institutions. As TQI has covered, adversaries may already be collecting encrypted financial communications with the intention of decrypting them once quantum hardware matures. Transaction records, settlement data, and long-lived custody information all fall into this category.
The Hong Kong Monetary Authority announced a Quantum Preparedness Index in February 2026 to score banking sector readiness. Singapore’s MAS issued advisory guidance in 2024 recommending cryptographic asset inventories and migration strategies. TQI’s coverage of cryptographic inventory challenges is relevant here – as of early 2026, a significant practical constraint remains in that no HSM vendor has completed a FIPS 140-3 Level 3 validation that includes PQC algorithms within the validated module boundary, meaning the certification infrastructure has not yet caught up with the technology.
Why Telecoms and Utilities Face a Harder Transition
Much of the infrastructure of telecommunications and utilities has hardware lifecycle timelines measured in decades, and replacement cycles are slow.
The EU’s Cyber Resilience Act, which entered into force in December 2024 with full application from December 2027, requires systems to support security updates and vulnerability handling in ways that analysts interpret as making crypto-agility a practical compliance requirement for vendors selling into European markets.
TQI’s analysis of quantum networking and its industrial potential covers how telecoms in the US, EU, and Asia are building quantum-safe infrastructure – from EPB’s quantum hub in Chattanooga to the EU’s EuroQCI initiative. For utilities and energy infrastructure, the CISA Post-Quantum Cryptography Initiative coordinates migration guidance for critical infrastructure operators, with particular emphasis on operational technology environments where hardware replacement is constrained.
The UK NCSC guidance is among the most specific for critical national infrastructure: cryptographic discovery by 2028, high-priority system migration by 2031, full transition by 2035.
Why Blockchain Has No Clear Migration Path Yet
The blockchain community operates without a central authority capable of mandating timelines, which makes its migration one of the more complex political and technical problems in the post-quantum landscape.
Bitcoin Improvement Proposal 360 (BIP-360), introduced in February 2026, proposes a new address type that keeps public keys off-chain until spending, reducing the attack surface for future transactions. BIP-361, proposed in April 2026, outlines a three-phase migration plan including a mechanism to freeze coins in wallets that fail to migrate. The Bitcoin community has not reached consensus on either proposal.
Developer Bit Paine described the timeline pressure plainly: “I still think roughly 10 years is the more likely timeframe, but I assign an uncomfortably high likelihood that we see something disruptive within five years.”
On the other hand, Ethereum’s position is more coordinated. The Ethereum Foundation was a co-author on the March 2026 Google paper on ECC resource estimates, and Ethereum Improvement Proposals addressing quantum resistance are active. Ethereum Foundation researcher Justin Drake described his confidence in a quantum-capable computer arriving by 2032 as having “shot up significantly.”
The main problem, when it comes to blockchain is that – public transaction histories are permanent and cannot be retroactively re-encrypted. The Federal Reserve’s 2025 research on Bitcoin’s quantum exposure highlights this directly – unlike traditional financial institutions that can rotate keys, public blockchains preserve every historical transaction in a form that will become readable if the underlying cryptography is broken.
Readers looking to dive further into the blockchain side of the story, might find – the Growing Quantum Security Challenge Facing Bitcoin and Digital Assets, helpful.
What the Full Range of Deadlines Tells You
Mapping the timelines together produces the following picture:
| Actor | Key Deadline | Scope |
| NSA CNSA 2.0 | January 2027 | New acquisitions into NSS must support PQC |
| 2029 | Full PQC migration across all infrastructure | |
| Cloudflare | 2029 | Full PQC including authentication |
| Microsoft | Early adoption 2029, full transition 2033 | All Microsoft products and services |
| NIST IR 8547 | 2030 deprecation, 2035 disallowed | Federal agencies and regulated sectors |
| EU NIS Cooperation Group | 2030 (high-risk), 2035 (medium-risk) | EU critical infrastructure |
| UK NCSC | 2031 (high-priority), 2035 (full) | UK critical national infrastructure |
| Bitcoin community | No consensus | Active proposals, no mandated timeline |
| Ethereum Foundation | Actively working toward PQC | No published completion date |
The range runs from 2027 to 2035. The clustering point for voluntary commitments from organizations with the deepest visibility into quantum hardware progress is 2029.
Also, there are two observations worth drawing from this.
First, the organizations closest to the hardware are setting the most aggressive timelines. Google operates one of the world’s largest quantum computing programs. The same team that produced the March 2026 paper on ECC resource estimates 2029 as its own migration deadline. When an organization building quantum hardware decides to complete its own migration four years ahead of the regulatory deadline, that is worth treating as a signal about its internal probability distribution.
Second, disagreement on timing is not the same as disagreement on direction. Estimates for when a cryptographically relevant quantum computer will arrive range from the early 2030s to the mid-2040s depending on assumptions about hardware progress, error correction, and algorithmic efficiency. But no major organization operating at scale has published a “wait and see” position.
In short, the organizations best positioned for whatever the actual timeline turns out to be are those treating migration as infrastructure work beginning now, rather than a planning exercise contingent on greater certainty.
For readers looking to expand their knowledge, TQI’s coverage of why RSA and ECC are being replaced, and the cryptographic inventory challenges organizations face at the start of migration, provides useful context.




