Home / Standards / PQC Compliance Timeline
STANDARDS

The PQC compliance timeline: every deadline in one place

This PQC compliance timeline runs from NIST's August 2024 release of FIPS 203, 204, and 205 through CNSA 2.0's final 2033 deadline, with federal contractor requirements landing in between. It consolidates every date from NIST, CNSA 2.0, and federal PQC requirements into one chronological reference, so there's a single place to check instead of several pages that can drift out of sync.

Check a domain →
AUGUST 2024

NIST releases three PQC standards

FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), marking the shift from research to implementation. See NIST PQC Standards.
JANUARY 1, 2027

New NSS acquisitions must be CNSA 2.0 compliant

Per CNSA 2.0. See CNSA 2.0.
2030

Software/firmware signing and networking equipment come into scope

CNSA 2.0 covers software and firmware signing and traditional networking equipment starting this year. Equipment and services that can’t support PQC and CNSA must also be phased out by December 31, 2030.
DECEMBER 31, 2031

Full use of CNSA 2.0 algorithms; DoW CMMC PQC deadline

CNSA 2.0 requires full use of its algorithms by this date. It’s also the deadline the June 2026 Department of War PQC strategy sets for adding PQC to CMMC requirements for DoW systems. See Federal PQC Requirements.
2033

Broadest CNSA 2.0 coverage takes effect

Web browsers and servers, cloud services, operating systems, niche devices, large PKI, custom applications, and legacy equipment all come into scope under CNSA 2.0.
Want to know where your own services stand against these dates?

Why does this PQC compliance timeline matter if you're not a federal contractor?

Even outside direct federal mandates, this PQC compliance timeline sets the pace the broader industry is moving at. Major cloud providers and browser vendors are rolling out post-quantum support on similar timelines, and customers, partners, and insurers are increasingly asking about PQC readiness as part of standard risk conversations. Tracking these dates helps you plan migration on your own schedule instead of reacting once a vendor or customer requirement arrives without warning.
Written by the team behind Anvil Secure.