Cryptoramic

Post-quantum readiness

PQC readiness for data and digital trust.

Data can stay sensitive for years. Signed documents may need to remain verifiable for decades. Devices can depend on long-lived trust anchors. Discover where those lifetimes outlast your cryptography.

Two different risks. One inventory to start from.

Protect confidentiality. Preserve trust.

PQC migration concerns what others can read and what your systems will accept as genuine.

Confidentiality

Harvest now, decrypt later

TodayEncrypted data captured
Future quantum attackConfidentiality lost

Traffic recorded today could be decrypted by a future quantum computer capable of breaking the key establishment used to protect it.

Sensitive communications · Long-lived records

What must remain confidential for years?

Authenticity & integrity

Trust now, forge later

TodayVulnerable public key trusted
Future quantum attackForged signatures accepted

A future quantum attacker could use a vulnerable public key to forge signatures. Systems that still trust that key could accept forged documents, malicious software or false credentials.

Signed PDFs · Legal agreements · Archives · Firmware · Certificates

What will still be trusted years from now?

Historical signature validation also depends on trusted timestamps and preserved evidence. Future forgery does not automatically invalidate every past signature. Long-term signature validation (RFC 9321). NIST guidance on the PQC transition. Signature-risk terminology in an IETF PQUIP presentation.

Identify both kinds of exposure

Standards and transition guidance

The milestones to plan around.

NIST proposes an algorithm transition schedule; the EU roadmap sets milestones for Member States and high-risk use cases. Check applicability to your systems before treating a date as your deadline.

2026

European UnionEU milestone for national transitions to be under way.Scope & source

By the end of 2026 Member States are expected to have a national transition strategy under way, including the first steps of inventory and risk assessment. European Commission.

2030

NIST · Proposed112-bit quantum-vulnerable algorithms deprecated.Scope & source

Under the proposed schedule, RSA-2048 and other 112-bit parameter sets are deprecated for new use after 2030. NIST IR 8547 ipd.

European UnionHigh-risk use cases and critical infrastructure migrated.Scope & source

The roadmap sets the end of 2030 as the deadline for high-risk use cases, including critical infrastructure, to have completed the transition. European Commission.

2035

NIST · ProposedAll quantum-vulnerable public-key algorithms disallowed.Scope & source

Under the proposed schedule, RSA, ECDSA, ECDH and the other quantum-vulnerable public-key algorithms are disallowed in NIST guidance after 2035. NIST IR 8547 ipd.

European UnionTransition completed for as many systems as feasible.Scope & source

The roadmap aims for the transition to be completed across Europe by 2035, with an acknowledgement that some legacy and lower-risk systems may take longer. European Commission.

How we got here: standards and roadmaps from 2024–2025

2024 · NIST

The first post-quantum standards are final.

NIST publishes ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205). From this point the replacement algorithms exist as standards, and vendors can be asked when they will support them. NIST.

2024 · NIST

A transition schedule is proposed.

NIST IR 8547 (initial public draft) proposes deprecating quantum-vulnerable algorithms at the 112-bit security level, such as RSA-2048, after 2030 and disallowing all quantum-vulnerable public-key algorithms after 2035. NIST IR 8547 ipd.

2024 · European Union

The Commission asks Member States to coordinate.

The European Commission's Recommendation of 11 April 2024 on a coordinated implementation roadmap for the transition to post-quantum cryptography starts the EU-wide effort. European Commission.

2025 · European Union

The coordinated implementation roadmap is published.

On 23 June 2025 the NIS Cooperation Group publishes the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, with three dated milestones. European Commission.

Start with the dates that apply to your systems

NIST’s proposed algorithm transition schedule and the EU coordinated roadmap serve different audiences. A shared year does not make them the same requirement. Review the applicable framework, the risk of the system and the time needed for its suppliers to deliver a change.

The NIST draft remains a proposal. The EU roadmap asks Member States to begin transitioning by the end of 2026 and prioritizes high-risk use cases by 2030. Dutch NCSC guidance advises organizations to inventory cryptographic assets, assess risk and prepare a migration plan.

Signed today. Still verifiable years from now?

Signed PDFs, legal agreements and archived records may need to prove authenticity long after the software that created them has changed. Include signing certificates, timestamp services, validation software and preservation processes in your assessment.

A future quantum attacker could forge signatures under a vulnerable public key. That does not automatically invalidate every earlier document: historical validation depends on trustworthy timestamps and preserved evidence. Preservation must also account for weakening algorithms and renewal before protection fails. See NCSC guidance on signature threats and RFC 4998 on long-term evidence preservation.

Cryptoramic can inventory cryptographic metadata from supported signed PDFs to help scope this work. Discovery does not validate a document’s signature or establish its legal effect. Review the affected signing and archive workflows with their owners and trust-service providers.

Some dependencies need attention before a deadline

Long-lived confidential information can be exposed to harvest-now-decrypt-later attacks. Supplier release cycles and operational maintenance windows may also take longer than the technical replacement itself. Identify those dependencies early; a deadline alone does not tell you which change comes first.

Illustrative Cryptoramic asset timeline showing how policy and migration dates change the assessment over time.
Review a cryptographic asset over time · Illustrative assessment data

The animation compares realistic, pessimistic, optimistic and delayed scenarios using illustrative data. It shows how a time-based view supports investigation; it does not predict when a cryptographically relevant quantum computer will exist.

Turn a milestone into an assessment question

Choose one application, image or network segment and ask: which cryptography is present, which requirements apply, and which changes depend on someone else? Review findings with the owner, agree an action and verify it before widening the scope.

See a worked assessment, explore regulatory frameworks or scope a first assessment.

Frequently asked questions

When do RSA and elliptic-curve cryptography stop being allowed?

There is no single deadline for every organization. NIST’s draft proposes phasing out weaker algorithms such as RSA-2048 after 2030, and disallowing quantum-vulnerable public-key algorithms after 2035. The EU has separate milestones, including 2030 for high-risk uses. Check which requirements apply to your services before setting a deadline.

What does the EU expect from organizations by 2026?

The 2026 milestone is for Member States to start their transition, not for every organization to finish migrating. The EU roadmap also calls for high-risk uses to move by the end of 2030. Organizations should begin identifying their cryptography and risks, then check the national and sector requirements that apply to them.

What is harvest now, decrypt later?

An attacker saves encrypted information today, hoping a future quantum computer will let them read it. This matters most for information that must stay confidential for years, such as medical records or long-term business secrets. Find where that information is protected and plan to replace vulnerable cryptography before it can be collected.

What is trust now, forge later?

A future quantum computer could let an attacker forge digital signatures that your systems still accept as genuine. That could affect signed PDFs, legal agreements, archives, software updates and certificates. Plan how long those signatures need to remain trustworthy. Trusted timestamps and preserved validation records can help establish when an older signature was valid; existing signatures do not all become invalid automatically.

What is the first step?

Find the cryptography used by one important service and identify who can act on the findings. Start with its certificates, keys, software and connections. Use the results to decide what you can change yourself and where you need supplier support.

Start with the scope that matters most.

Tell us which systems carry your highest-risk data. We will show what discovery finds there and what the dates mean for it.

Book a demo

Product screenshot

Illustrative assessment data