STANDARDS
A maintained reference for post-quantum cryptography standards and deadlines
This page tracks the post-quantum cryptography standards, frameworks, and dates that govern PQC migration: what NIST, CNSA 2.0, and federal PQC requirements actually mandate today, and which deadlines apply to your organization's own timeline. It's kept current as requirements change, not written once and left to age.
Check a domain →
NIST
CNSA 2.0
FEDERAL
TIMELINE
How the post-quantum cryptography standards compare
Each row below is its own post-quantum cryptography standard, with its own governing body, scope, and timeline. Use this table for a quick comparison, then open the full page for deadlines, algorithm detail, and how it applies to your organization.
Framework
Governed by
Applies to
Key deadline
NIST PQC Standards
NIST
All organizations (baseline algorithms)
Released August 2024
CNSA 2.0
NSA
National Security Systems
Jan 2027 – Dec 2033
Federal PQC Requirements
CMMC / FedRAMP
Federal contractors & cloud providers
2031 (DoW deadline)
NIST PQC Standards
The three algorithm families NIST standardized in August 2024, and what each one protects: key exchange, digital signatures, and a structurally distinct backup.
CNSA 2.0
The NSA’s phased deadlines for National Security Systems, from the first 2027 acquisition requirement through full compliance in 2033.
Federal PQC Requirements
How CMMC, FedRAMP, and the Department of War’s PQC strategy currently treat post-quantum cryptography, and where each one actually stands today.
PQC Compliance Timeline
Every compliance date from NIST, CNSA 2.0, and federal requirements, brought together in one chronological view so nothing drifts out of sync.
Which post-quantum cryptography standard applies to you?
It depends on who you are. NIST’s algorithms are the technical baseline everyone eventually builds on, CNSA 2.0 governs National Security Systems specifically, and Federal PQC Requirements cover contractors working with CMMC or FedRAMP-authorized cloud services. If none of those apply to you directly yet, NIST PQC Standards is still the right place to start, since every other framework builds on it.
Want to know which algorithms your services actually run?