Post-Quantum Cryptography in 2026: Standards, Draft Timelines, and Migration

Separate final NIST post-quantum standards from draft transition timelines, then build a crypto inventory and vendor-led migration plan.

Back to Blog
(Updated )
3 min read
Isometric conceptual visualization of classical cryptography transitioning into quantum-resistant lattice-based cryptography

Post-quantum planning is no longer hypothetical, but not every date in NIST material has the same status. FIPS 203, 204, and 205 are final standards. NIST IR 8547 remains an Initial Public Draft, so its proposed 2030 and 2035 transition milestones should not be presented as finalized policy.

Current as of 2026-08-15

NIST’s PQC announcement confirms FIPS 203, 204, and 205 were approved August 13, 2024. NIST IR 8547 is still labeled Initial Public Draft.

Decision summary

  • Use final FIPS standards as the technical baseline.
  • Label IR 8547’s transition dates as proposals while it remains a draft.
  • Start with cryptographic discovery and information-lifetime analysis.
  • Do not deploy algorithms directly without supported products, protocols, and implementation validation.

What is final

FIPS 203 specifies ML-KEM for key establishment. FIPS 204 specifies ML-DSA for digital signatures. FIPS 205 specifies SLH-DSA as a hash-based signature standard. These standards are final even though implementation guidance, product support, and additional algorithms continue to evolve.

What remains draft

IR 8547 proposes a transition approach for deprecating and removing quantum-vulnerable algorithms from NIST standards. The commonly cited 2030 deprecation and 2035 removal dates come from that Initial Public Draft. Organizations can use them for scenario planning, but should not describe them as a final mandate.

Inventory before migration

  • Protocols, certificates, keys, libraries, hardware modules, and embedded systems.
  • Data classes and how long confidentiality or authenticity must last.
  • Vendor products, dependencies, and contract renewal dates.
  • Externally managed services where cryptography is hidden from the customer.
  • Recovery, interoperability, and performance requirements.

Plan controlled adoption

Prioritize systems with long-lived sensitive data and long replacement cycles. Ask vendors for standards support, validation status, hybrid transition options, upgrade paths, and rollback. Pilot interoperability and operational monitoring before a broad change.

Next step for your environment

Build a cryptographic inventory and mark every date by authority level: final standard, draft proposal, vendor commitment, or internal target. If you need a documented baseline before changing production systems, start with an ITECS technology and security assessment.

Record the current baseline, accountable owner, source date, acceptance evidence, exceptions, and review trigger. Recheck assumptions before every consequential change, preserve rollback instructions, and close the work only when the intended result and unintended effects have been verified in the real environment. Keep the decision record with the system documentation so the next review starts from evidence rather than memory.

Sources and update trigger

Review trigger: Review when NIST changes IR 8547 status, revises a FIPS publication, or adds migration guidance.

continue reading

More ITECS blog articles

Browse all articles

About ITECS Team

The ITECS team consists of experienced IT professionals dedicated to delivering enterprise-grade technology solutions and insights to businesses in Dallas and beyond.

View full profile and articles

Share This Article

Continue Reading

Explore more insights and technology trends from ITECS

View All Articles