Key length
The minimum key sizes each source publishes for protecting data until a given year. The rules that apply to you come first, and every figure links to the document it comes from. New to this? Start with why key length matters and which year to enter.
No rules selected, so every source is listed as comparison.
Data encrypted today with RSA or elliptic-curve key exchange and needing secrecy until 2035 can be recorded now and decrypted later if a large quantum computer arrives first.
- Symmetric
- 128
- Factoring modulus
- 3,072
- Discrete log
- 3,072 / 256
- Elliptic curve
- 256
- Hash
- 256
Signatures: ML-DSA, SLH-DSA
- Symmetric
- 128
- Factoring modulus
- Hybrid only
- Discrete log
- Hybrid only
- Elliptic curve
- Hybrid only
- Hash
- 256
Signatures: ML-DSA-65 or -87, SLH-DSA (192 or 256), LMS or XMSS; classical signatures until end of 2035
- Symmetric
- 128
- Factoring modulus
- 3,072
- Discrete log
- 3,072 / 250
- Elliptic curve
- 250
- Hash
- 256
Signatures: ML-DSA hybrid with a classical signature; SLH-DSA may be used alone
- Symmetric
- 256
- Factoring modulus
- Transition only
- Discrete log
- Transition only
- Elliptic curve
- Transition only
- Hash
- 384
Signatures: ML-DSA-87; LMS or XMSS for firmware
- Symmetric
- not imported
- Factoring modulus
- Retired
- Discrete log
- Retired
- Elliptic curve
- Retired
- Hash
- not imported
| Source | Window | Symmetric ? | Factoring modulus ? | DL key / group ? | Elliptic curve ? | Hash ? | Post-quantum ? | Your key |
|---|---|---|---|---|---|---|---|---|
| NIST1 | 2031 to open | 128 | 3,072 | 3,072 / 256 | 256 | 256 | ML-KEM (FIPS 203) Sig: ML-DSA, SLH-DSA | |
| BSI4 | 2026 to 2032 | 128 | Hybrid only | Hybrid only | Hybrid only | 256 | Hybrid with a classical scheme: ML-KEM-768 or -1024, FrodoKEM-976 or -1344, or Classic McEliece Sig: ML-DSA-65 or -87, SLH-DSA (192 or 256), LMS or XMSS; classical signatures until end of 2035 | |
| ANSSI5 | 2031 to open | 128 | 3,072 | 3,072 / 250 | 250 | 256 | Hybrid with a classical scheme: ML-KEM-768 preferred (512 allowed), FrodoKEM-976 preferred; post-quantum recommended for use beyond 2030 Sig: ML-DSA hybrid with a classical signature; SLH-DSA may be used alone | |
| NSA CNSA 2.06 | 2025 to open | 256 | Transition only | Transition only | Transition only | 384 | ML-KEM-1024 Sig: ML-DSA-87; LMS or XMSS for firmware | |
| ASD7 | not imported | Retired | Retired | Retired | not imported | ASD-approved PQC (ISM) |
All sizes in bits and all are minimums. Grey italic values fall outside the source's own window and show where it last stood. D draft, S superseded edition, 2nd not yet checked against the primary document. The Lenstra and Verheul, Lenstra 2004 and RFC 3766 models are not yet implemented.
References
- NIST SP 800-57 Pt 1 Rev 5, NIST, 2020-05.
- NIST SP 800-57 Pt 1 Rev 6 initial public draft, NIST, 2025-12-05, draft.
- NIST IR 8547 initial public draft, NIST, 2024-11-12, draft.
- BSI TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths, version 2026-01, BSI, 2026-01-23.
- ANSSI-PG-083, Règles et recommandations concernant le choix et le dimensionnement des mécanismes cryptographiques, v3.00, ANSSI, 2026-03-20.
- NSA CNSA 2.0 algorithms advisory, NSA, 2025-05-30.
- ASD, Planning for post-quantum cryptography, ASD, 2025-09-22.
How your rules compare
Each line is one source's minimum over the years it covers, with your rules in colour. The shaded band spans the least and most demanding sources and the dashed line is the median.
PQC transition
Where governments have set post-quantum migration dates, how far deployment has come, and how close quantum hardware is to the published estimates for breaking today's public-key cryptography.
Migration deadlines around the world
Where governments and regulators have published post-quantum dates, where only a sector regulator or a planning requirement exists, and where nothing has been set. Select a country for its instruments; the timeline below has every dated milestone.
Every dated milestone
Dated obligations and targets from governments and regulators, with the jurisdictions you picked highlighted. Filled markers were checked against the primary document; hollow dashed markers rest on reporting about it. Each year column ends on 31 December, so a marker on a column's right edge means the end of that year.
Earliest migration date in the filtered set: 2026, South Korea, public-sector rollout of KpqC algorithms begins. Stated target. Where several jurisdictions apply, the earliest one is the one to plan against.
Where adoption actually stands
Key establishment and authentication are at very different stages, so they are tracked separately. The telemetry figure is a dated snapshot of one network's traffic, not a measure of the whole internet.
Key establishment
Protects confidentiality now against later decryption.
- Algorithm standardizedML-KEM final as FIPS 203, August 2024.
- Protocol specifiedHybrid X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024 for TLS 1.3 in draft-ietf-tls-ecdhe-mlkem, late in IETF process.
- Default in major librariesOpenSSL 3.5 LTS (April 2025) offers a hybrid X25519MLKEM768 key share by default.
- Majority of browser trafficCloudflare Radar snapshot above.
- Required in procurementCISA lists categories such as browsers, servers and cloud services where only PQC-capable products should be bought (January 2026). FAR rule for contractors still pending.
Authentication
Signatures and certificates, which only need to hold until migration.
- Algorithms standardizedML-DSA and SLH-DSA final (FIPS 204, 205). FN-DSA (FIPS 206) still in draft.
- Certificate format for the webMerkle Tree Certificates in the IETF PLANTS working group; Chrome and Cloudflare running a feasibility study.
- CA issuanceLet's Encrypt plans an MTC staging environment in late 2026 and production in 2027 (secondary).
- Browser trustChrome plans a separate quantum-resistant root store, with onboarding for more CAs targeted around the third quarter of 2027 (secondary).
- Required by policyUS federal high value assets must move signatures by 31 December 2031 under EO 14412.
What it would take, against what has been built
Falling points are published estimates of the physical qubits needed to break the target. Rising green points are the largest gate-model devices actually built, with error-corrected logical qubits shown separately and vendor roadmaps drawn hollow. The two are not like-for-like, because the estimates assume about 0.1% gate error sustained through hours or days of error-corrected computation, which no device has yet run. The gap between the lines is still the clearest single picture of how close things are.
Dates operators set for themselves
Large operators have moved their own targets ahead of the regulatory 2035 horizon.
- Google
Own systems off classical key exchange2029
source - Cloudflare
Own systems off classical key exchange2029
source - Microsoft
Early adoption, then full transition2029 and 2033
source - US federal (EO 14412)
High value assets on PQC key establishmentend of 2030
source - NIST (draft IR 8547)
Quantum-vulnerable algorithms disallowedafter 2035
source
Operator dates are from secondary reporting and cover their own systems, not their customers.
What the new algorithms cost on the wire
Public key and signature or ciphertext sizes in bytes, on a logarithmic scale. These are raw encodings from the standards; certificate and protocol framing add more. Size, more than speed, is what makes post-quantum authentication hard in the WebPKI.
Developments log
Findings, standards, policy and operator decisions in the order they happened, each linked to where it was reported. This is where a new paper or rule shows up first, before it is folded into the charts above.
- 2026
- 21 SeptStandardFIPS 140-2 certificates move to the historical listEvery remaining FIPS 140-2 validation became historical, leaving FIPS 140-3 as the only active standard for new federal procurements, with a large backlog of modules still awaiting validation. FedRAMP
- SeptStandardChina publishes NGCC round 1 candidates84 public-key algorithms and 35 hash algorithms enter first-round evaluation, with the block cipher track still to follow. China is standardising its own post-quantum algorithms rather than adopting the NIST set. Institute of Commercial Cryptography Standards, China
- AugPolicyMAS sets an end-of-decade quantum resilience expectation for financial institutionsSupervisory expectations with milestones rather than a statutory deadline. Monetary Authority of Singapore (secondary)
- 13 JulPolicyDepartment of War suspends CMMC Phase 2Third-party certification, due from 10 November 2026, is paused pending a 60-day review; Phase 1 self-assessments against NIST SP 800-171 remain mandatory. US Department of War
- JulPolicyHKMA publishes first Quantum Preparedness Index resultsHong Kong banks score 2.3 of 10 against a target of 10 by 2030. Hong Kong Monetary Authority (secondary)
- JulPolicyFINMA Guidance 05/2026 asks Swiss institutions for PQC roadmapsRoadmaps recommended by mid-2027. FINMA (Switzerland) (secondary)
- JulOperatorOratomic raises a $300M Series A to build a fault-tolerant neutral-atom machineReported alongside Google and Cloudflare 2029 targets and Microsoft's 2029 and 2033 plan. Supercomputing News (secondary)
- 24 JunPolicyOMB M-26-15 sets agency plan, inventory and migration phasesPlans due late October 2026, key establishment by 2030, signatures in 2031, the rest by 2035. OMB (secondary)
- 23 JunPolicyDepartment of War PQC strategyEvery system supports PQC or is phased out by end of 2030, and uses it by end of 2031. DoW (secondary)
- 22 JunPolicyExecutive Order 14412 pulls US federal dates forwardHigh value assets on PQC key establishment by end of 2030 and signatures by end of 2031; contractors through the FAR. The White House (secondary)
- MayResource estimateRSA-2048 on a half-million-qubit modular atomic processorDistributing Shor's algorithm across modules costs only 16% more time than one large module. Xue and Covey
- AprStandardCRYPTREC clears ML-KEM for Japanese government useRemoves the main procurement barrier; a national roadmap is expected in 2027. Encryption Consulting (secondary)
- 31 MarResource estimateElliptic curve keys under 500,000 qubits, minutes of runtimeGoogle withheld the circuits and published a zero-knowledge proof of the resource counts. Babbush et al., Google Quantum AI (secondary)
- 31 MarResource estimateShor's algorithm with about 10,000 neutral atomsSpace-efficient layouts trade qubits for runtimes of days to weeks. Cain et al., Oratomic and Caltech (secondary)
- 20 MarStandardANSSI publishes version 3.00 of its cryptographic mechanisms guideRSA and finite-field groups at 2048 bits through 2030 and 3072 from 2031; post-quantum mechanisms must be hybridised, except hash-based signatures. ANSSI
- 27 FebStandardChrome sets out its Merkle Tree Certificates pathNo immediate plan to add PQC X.509 certificates to the Chrome Root Store. Google Chrome
- 4 FebPolicyIndia's task force report sets milestones from 2027 to 2033Critical infrastructure first, with PQC the default across communication systems by 2033. DST India, National Quantum Mission (secondary)
- FebResource estimatePinnacle architecture puts RSA-2048 under 100,000 qubitsUses quantum LDPC codes; needs richer connectivity than a planar grid. Webster et al., Iceberg Quantum (secondary)
- 23 JanStandardBSI TR-02102-1 2026-01 ends the sole use of classical asymmetric mechanismsClassical key agreement alone until end of 2031 (2030 for very high protection), classical signatures until end of 2035, post-quantum KEMs in hybrid form. BSI
- 23 JanPolicyCISA lists product categories where only PQC-capable products should be boughtIncludes browsers, servers and cloud services. CISA (secondary)
- 13 JanPolicyG7 Cyber Expert Group points the financial sector at 2035Critical systems between 2030 and 2032; explicitly non-binding. G7 Cyber Expert Group (secondary)
- JanPolicyEuropean Commission proposes making the PQC transition binding under NIS2COM(2026) 13; adoption expected late 2026 or early 2027. Encryption Consulting (secondary)
- JanHardwareQuEra runs 96 logical qubits on 448 atomsA distance-4 code, well short of the distance Shor's algorithm needs at length. QRL Hub (secondary)
- 2025
- 5 DecStandardNIST SP 800-57 Part 1 Rev 6 draftAdds ML-KEM, ML-DSA and SLH-DSA and drops dated approval tables. NIST
- NovHardwareQuantinuum Helios reaches 48 logical qubits from 98 ionsThe best encoding ratio so far, using a distance-2 code. Quantum Zeitgeist (secondary)
- 9 OctStandardICCS opens submissions for next-generation public-key algorithmsFinal submission requirements and evaluation criteria published, with a submission deadline of 30 June 2026. Institute of Commercial Cryptography Standards, China
- OctPolicySingapore's CSA publishes a Quantum-Safe Handbook and readiness indexPressure applied through procurement and the Cyber Trust Mark rather than a date. Cyber Security Agency of Singapore (secondary)
- SeptHardwareCaltech builds a 6,100-atom neutral-atom arrayThe largest qubit array so far, not yet used for computation. Physics World (secondary)
- 23 JunPolicyEU coordinated roadmap and Canada's ITSM.40.001Both set high-priority migration around 2030 to 2031 and completion by 2035. European Commission and member states (secondary)
- 30 MayStandardNSA updates the CNSA 2.0 algorithms advisoryML-KEM-1024 and ML-DSA-87, with LMS or XMSS for firmware. NSA
- 21 MayResource estimateRSA-2048 under one million qubits on the 2019 hardware modelA twentyfold drop from the 2019 estimate from algorithms and error correction alone. Google Quantum AI
- 20 MarPolicyUK NCSC publishes 2028, 2031 and 2035 milestonesDiscovery and planning, priority migration, then completion. NCSC (UK)
- 5 FebStandardChina launches the NGCC programmeA global call for public-key, hash and block cipher algorithms, run by ICCS under the Chinese Cryptography Standardization Technical Committee. Institute of Commercial Cryptography Standards, China
- 2024
- DecHardwareGoogle's Willow chip shows error correction below the surface code thresholdFirst experimental evidence that the noise assumptions behind these estimates are achievable. The Quantum Insider (secondary)
- 12 NovStandardNIST IR 8547 draft proposes 2030 deprecation and 2035 disallowanceStill a draft; widely used as the planning baseline. NIST
- 2023
- DecHardwareIBM Condor passes 1,000 qubits1,121 superconducting qubits; IBM then shifted focus from count to quality. PostQuantum (secondary)
- AugResource estimateRegev proposes the first fundamental change to Shor's factoring algorithm in decadesFewer gates per run at the cost of more qubits; later refined by Ragavan and Vaikuntanathan. The Quantum Insider (secondary)
- 2019
- MayResource estimateRSA-2048 in 8 hours with 20 million noisy qubitsThe reference estimate for six years. Gidney and Ekerå
- 2012
- Resource estimateSurface code estimate of around a billion qubitsFowler et al.; the starting point most comparisons use. Parker and Vermeer
Sources and verification
Every document the page draws on. Primary means the cited section of the document itself was read. Secondary means the entry rests on reporting about the document. All entries are from an initial import and still need a second reader.
| Document | Publisher | Status | Binding | Published | Verification |
|---|---|---|---|---|---|
| ANSSI-PG-083, Règles et recommandations concernant le choix et le dimensionnement des mécanismes cryptographiques, v3.00 | ANSSI | Final | Guidance | 2026-03-20 | Primary checked |
| ASD, Planning for post-quantum cryptography | ASD | Final | Guidance (ISM) | 2025-09-22 | Primary checked |
| Securing elliptic curve cryptocurrencies against quantum vulnerabilities (arXiv 2603.28846) | Babbush et al., Google Quantum AI | Final | Preprint | 2026-03-31 | Secondary only |
| Bank of Israel quantum preparedness requirement, as reported | Bank of Israel | Final | Supervisory | 2025 | Secondary only |
| BSI TR-02102-1, Cryptographic Mechanisms: Recommendations and Key Lengths, version 2026-01 | BSI | Final | Guidance | 2026-01-23 | Primary checked |
| Securing Tomorrow, Today (joint statement) | BSI, ANSSI and partner agencies | Final | Guidance | 2024-11 | Secondary only |
| Shor's algorithm is possible with approximately 10,000 reconfigurable atomic qubits | Cain et al., Oratomic and Caltech | Final | Preprint | 2026-03-31 | Secondary only |
| ITSM.40.001 | Canadian Centre for Cyber Security | Final | Guidance | 2025-06-23 | Primary checked |
| Product categories for technologies that use PQC standards | CISA | Final | Procurement guidance | 2026-01-23 | Secondary only |
| Cloudflare Radar post-quantum adoption | Cloudflare | Final | Telemetry | 2026-06 | Secondary only |
| Quantum-Safe Handbook and Quantum Readiness Index, as reported | Cyber Security Agency of Singapore | Final | Guidance | 2025-10 | Secondary only |
| Atom Computing claims 1,180 qubits | Decrypt | Final | News | 2023-10 | Secondary only |
| Department of War PQC Strategy | DoW | Final | Mandatory for scope | 2026-06-23 | Secondary only |
| Implementation of Quantum Safe Ecosystem in India (task force report) | DST India, National Quantum Mission | Final | Government | 2026-02-04 | Secondary only |
| PQC migration deadlines by country, 2026 guide | Encryption Consulting | Final | News | 2026-06 | Secondary only |
| NIS Cooperation Group coordinated implementation roadmap | European Commission and member states | Final | Coordinated | 2025-06-23 | Secondary only |
| Will FedRAMP provide guidance on the sunsetting of FIPS 140-2? | FedRAMP | Final | Guidance | 2026-07 | Primary checked |
| FINMA Guidance 05/2026, as reported | FINMA (Switzerland) | Final | Supervisory | 2026-07 | Secondary only |
| G7 CEG statement on a PQC roadmap for the financial sector | G7 Cyber Expert Group | Final | Non-binding | 2026-01-13 | Secondary only |
| NZISM position on PQC, as reported | GCSB (New Zealand) | Final | Guidance | 2025 | Secondary only |
| How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubits | Gidney and Ekerå | Final | Academic | 2019-05 | Primary checked |
| Cultivating a robust and efficient quantum-safe HTTPS | Google Chrome | Final | Root program | 2026-02-27 | Primary checked |
| How to factor 2048 bit RSA integers with less than a million noisy qubits | Google Quantum AI | Final | Academic | 2025-05-21 | Primary checked |
| HKMA Quantum Preparedness Index, first results | Hong Kong Monetary Authority | Final | Supervisory | 2026-07 | Secondary only |
| IBM unveils 433-qubit Osprey chip (with IBM's earlier chips) | IEEE Spectrum | Final | News | 2022-11 | Secondary only |
| Announcement on launching the Next-generation Commercial Cryptographic Algorithms Program (NGCC) | Institute of Commercial Cryptography Standards, China | Final | Government | 2025-02-05 | Primary checked |
| Call for proposals for the next-generation public-key cryptographic algorithms | Institute of Commercial Cryptography Standards, China | Final | Government | 2025-10-09 | Primary checked |
| NGCC round 1 candidates, public-key and hash tracks | Institute of Commercial Cryptography Standards, China | Final | Government | 2026-09 | Primary checked |
| MAS supervisory expectations on quantum resilience, as reported | Monetary Authority of Singapore | Final | Supervisory | 2026-08 | Secondary only |
| Interim report on the government PQC transition | National Cyber Command Office (Japan) | Final | Government | 2025-11 | Secondary only |
| Timelines for migration to post-quantum cryptography | NCSC (UK) | Final | Guidance | 2025-03-20 | Primary checked |
| PQC Transition Master Plan Plan not publicly released | NIS and MSIT (Korea) | Final | Government | 2023-07 | Secondary only |
| NIST SP 800-57 Pt 1 Rev 5 Rev 6 draft (Dec 2025) drops dated tables in favour of SP 800-131A | NIST | Final | Guidance | 2020-05 | Primary checked |
| NIST IR 8547 initial public draft | NIST | Draft | Guidance | 2024-11-12 | Primary checked |
| NIST SP 800-57 Pt 1 Rev 6 initial public draft | NIST | Draft | Guidance | 2025-12-05 | Primary checked |
| NSA CNSA 2.0 algorithms advisory | NSA | Final | Mandatory for NSS | 2025-05-30 | Primary checked |
| OMB M-26-15 | OMB | Final | Mandatory for scope | 2026-06-24 | Secondary only |
| OpenSSL 3.5 LTS release | OpenSSL | Final | Software | 2025-04 | Secondary only |
| China's PQC standardization track, as reported | OSCCA and ICCS | Final | Government | 2025-02 | Secondary only |
| Estimating the energy requirements to operate a CRQC (RAND), table of earlier estimates | Parker and Vermeer | Final | Academic | 2023-04 | Primary checked |
| New findings shorten the road to CRQCs (6,100-atom array) | Physics World | Final | News | 2026-06 | Secondary only |
| IBM Condor 1,121-qubit processor, and Sycamore context | PostQuantum | Final | News | 2023-12 | Secondary only |
| Qubit tracker, QuEra 96 logical qubits and code distance | QRL Hub | Final | News | 2026-05 | Secondary only |
| Quantum logical qubit leaderboard | Quantum Zeitgeist | Final | News | 2026-06 | Secondary only |
| IBM plans a 100,000-qubit system by 2033, as reported | SpinQ | Final | Roadmap | 2025-01 | Secondary only |
| Neutral-atom quantum computing, Oratomic's $300M bet | Supercomputing News | Final | News | 2026-07 | Secondary only |
| Three papers in three months are rewriting the quantum threat timeline | The Quantum Insider | Final | News | 2026-03-31 | Secondary only |
| Executive Order 14412 | The White House | Final | Mandatory for scope | 2026-06-22 | Secondary only |
| National Encryption Policy and Post-Quantum Migration Program, as reported | UAE Cyber Security Council | Final | Government | 2025 | Secondary only |
| Department of War suspends CMMC Phase II requirements | US Department of War | Final | Policy | 2026-07-13 | Primary checked |
| The Pinnacle architecture (arXiv 2602.11457) | Webster et al., Iceberg Quantum | Final | Preprint | 2026-02 | Secondary only |
| Factoring 2048 bit RSA integers with a half-million-qubit modular atomic processor | Xue and Covey | Final | Preprint | 2026-05 | Primary checked |
Other cryptographic requirements
Key sizes are only part of what an assessor asks about. These frameworks set requirements on inventory, key management, protocol versions, certificate lifetimes and the ability to change algorithms, and they increasingly overlap with the post-quantum work. Each cell says what the framework requires, with the clause it comes from.
Control matrix
Rows are control areas, columns are frameworks. Select a cell for the full requirement and its source. Switch off the frameworks that do not apply to you, and scroll sideways to see the rest.
| Control area | PCI DSS v4.0.1 | NIS2 and EU 2024/2690 | DORA RTS | CA/B Forum TLS BRs | US federal (NIST, FISMA) | FedRAMP | CMMC and NIST SP 800-171 | ISO/IEC 27001 |
|---|---|---|---|---|---|---|---|---|
| Approved algorithms and strengths | Strong cryptography, at least 112-bit effective strength | Policy must name approved protocols and algorithms | Selection criteria based on leading practices and standards | RSA 4096 for new S/MIME CA keys; 3072-bit sub-CAs to issue | FIPS-validated cryptography; PQC FIPS on a deadline | FIPS 140-validated or NSA-approved modules | FIPS-validated cryptography for CUI | Organization sets its own rules |
| Protocol versions | Strong protocols for card data over open networks | Approved protocols named in the policy | Encryption of data at rest, in transit and in use | Not in scope | TLS 1.3 across federal systems | Transmission protection through validated modules | Encrypt CUI in transit and at rest | Covered by the organization's rules |
| Cryptographic inventory | Two inventories, mandatory since 31 March 2025 | Implied through asset management | Flows from asset classification | Not in scope | Cryptographic inventories under OMB M-23-02 | Modules and certificates listed in the SSP | Validation evidence in the SSP | Implied by the rules and asset controls |
| Monitoring and ability to change algorithms | Monitor viability and hold a response plan | Crypto agility expected in the policy | Update cryptographic technology as cryptanalysis develops | Shorter lifetimes are the agility mechanism | Dated migration to post-quantum algorithms | FIPS 140-2 to 140-3 transition | Module transitions handled as deficiencies | Rules reviewed as threats change |
| Key management | Key lifecycle controls for stored account data | Key lifecycle, including expiry dates | Dedicated key management article | Key protection and compromise rules for CAs | NIST key management guidance | Key establishment and management control | Establish and manage keys | Full key lifecycle |
| Certificate lifetime and validation | Certificates must be valid, not expired or revoked | Covered by key lifespan rules | Covered by key lifecycle rules | 200 days now, 100 in 2027, 47 in 2029 | No general federal maximum | PKI certificates under SC-17 | Not covered | Part of key lifecycle |
| Governance and review | Annual documented review | Documented policy, management accountability | Board-approved policy, recorded exceptions | Audit against the requirements | Named migration lead and reporting | Authorization and continuous monitoring | Self-assessment in force; certification paused | Topic-specific policy, audited |
| Post-quantum obligation | Through the viability and response clauses | State of the art, plus ENISA guidance | Recital names quantum advancements | No PQ profile yet | Dated and binding | Through validated PQC modules and EO 14412 | Through the DoW PQC strategy | Not mentioned |
Approved algorithms and strengths
Protocol versions
Cryptographic inventory
Monitoring and ability to change algorithms
Key management
Certificate lifetime and validation
Governance and review
Post-quantum obligation
Frameworks
- PCI DSS v4.0.1, PCI Security Standards Council. Anyone storing, processing or transmitting payment card data. Entries rest partly on secondary reporting.
- NIS2 and Implementing Regulation (EU) 2024/2690, European Union. Essential and important entities; the implementing regulation binds digital infrastructure and digital providers. Entries rest partly on secondary reporting.
- DORA RTS, Commission Delegated Regulation (EU) 2024/1774, European Union. EU financial entities and their ICT providers.
- CA/Browser Forum TLS Baseline Requirements, CA/Browser Forum. Publicly trusted TLS certificates only; private PKI is out of scope.
- US federal baseline (FISMA, NIST SP 800-53 and EO 14412), United States. Federal agencies and, through the FAR, their contractors. Entries rest partly on secondary reporting.
- FedRAMP Rev5 baseline and cryptographic module policy, FedRAMP. Cloud services sold to US federal agencies. Entries rest partly on secondary reporting.
- CMMC Level 2 and NIST SP 800-171 Rev 2, US Department of War and NIST. Defence contractors handling controlled unclassified information. Entries rest partly on secondary reporting.
- ISO/IEC 27001:2022 Annex A 8.24, ISO and IEC. Organizations certified to ISO/IEC 27001. Entries rest partly on secondary reporting.
Questions and background
Why key sizes change, what a cryptoperiod is, why post-quantum migration starts now, and how to read the rest of the site. Each answer links to the sources behind it.
The basics
Why does key length matter at all?
Every cryptographic key can in principle be recovered by an attacker with enough computing time. Key length sets how much time that is. For a well-designed algorithm, each extra bit of security doubles the work an attacker has to do, so the difference between 112-bit and 128-bit security is a factor of about 65,000 in attack cost.
The difficulty is that attack cost keeps falling. Computers get faster and cheaper, and researchers find better attacks on the underlying mathematics. A key that was comfortably out of reach when it was generated can drift within reach while the data it protects still matters. Choosing a key length is choosing how far ahead of that curve you want to stay.
Sources: NIST. See also: Key length.
What does “acceptable through 2030” actually mean?
It is a statement about probability under stated assumptions, not a guarantee. When an authority says a key size is acceptable through a given year, it means that under its current assumptions about attacker computing power, the growth of that power and progress in cryptanalysis, the expected cost of breaking the key stays above an acceptable threshold until then.
If the assumptions change, the date changes. That is why the figures are revised, why different authorities publish different numbers, and why this site records the edition and date of every figure it shows.
What is a cryptoperiod?
A cryptoperiod is the span of time during which a specific key is authorized for use. NIST divides it into the originator-usage period, during which a key may be used to encrypt or sign, and the recipient-usage period, during which data protected with it may still be decrypted or verified. The second is usually longer, because data encrypted on the last day of use still has to be readable afterwards.
A cryptoperiod limits the damage if the assumptions behind a key turn out to be wrong. It caps how much data a single compromised key exposes, how long an attacker has to work on a key while it is still in use, and how long the key sits in systems and backups where it can leak for reasons that have nothing to do with mathematics.
The right cryptoperiod depends on the setting as much as the algorithm. Sensitive or high-volume data, keys held in software rather than hardware, and keys handled by many people or systems all argue for shorter periods. Shorter periods only help if the organization can actually rotate keys that often without outages, which is why automation matters.
Sources: NIST.
Which year should I enter on the key length page?
Enter the last year the data must stay secure, not the year the key stops being used. For confidentiality, that is the end of the recipient-usage period plus the time the data must remain secret. A key used for one year to encrypt records that must stay confidential for twenty years needs to be sized for twenty-one years.
For signatures, it is the last year anyone needs to rely on the signature being genuine. Signatures can often be renewed by re-signing or timestamping while the old algorithm is still trusted, so the horizon is usually shorter than for encryption.
See also: Key length.
Why do different authorities give different numbers?
They start from different assumptions and different missions. NIST sets minimums for US federal systems and moves in fixed steps of security strength. BSI and ANSSI build in more margin and set their own horizons. NSA's CNSA 2.0 protects national security systems and asks for the largest parameter sets.
None of them is wrong. The practical question is which of them applies to you, which is why the key length page puts your chosen rules first and shows the strictest figure among them.
Sources: NIST, BSI, ANSSI, NSA. See also: Key length.
Concepts
What does “bits of security” mean?
Security strength is a way of comparing very different algorithms on one scale. An algorithm offers n bits of security when the best known attack takes about 2 to the power n operations, the same as trying every key of an ideal n-bit cipher.
This is why a 128-bit AES key, a 3072-bit RSA key and a 256-bit elliptic-curve key are treated as roughly equivalent. They have very different sizes, but NIST rates all three at about 128 bits of security because the best attacks against each take about the same effort.
Sources: NIST.
What is the difference between symmetric and public-key cryptography?
Symmetric cryptography, such as AES, uses the same secret key to encrypt and decrypt. It is fast and its key size maps directly onto its security, so a 128-bit key gives about 128 bits of security. The limitation is that both sides need the key before they can talk.
Public-key cryptography, such as RSA and elliptic curves, uses a key pair. The public half can be shared openly and the private half stays secret. It solves the problem of agreeing on keys with someone you have never met, and it makes digital signatures possible. Its keys are much larger for the same security because it rests on mathematical problems that have faster attacks than trying every key. Almost every secure connection uses public-key cryptography to agree on a symmetric key and then symmetric cryptography for the data itself.
What is the factoring modulus?
RSA's security rests on factoring. The public key contains a large number, the modulus, made by multiplying two secret prime numbers together. Multiplying them is easy, but recovering the two primes from the product is extremely hard for large numbers, and anyone who can do it can derive the private key.
The modulus size, 2048 or 3072 bits, is what the key length tables mean by RSA key size. Factoring algorithms improve steadily, which is why RSA keys have to be much larger than symmetric keys for the same security. A 2048-bit modulus gives about 112 bits of security and a 3072-bit modulus about 128.
Sources: NIST. See also: Key length.
What are the two numbers for discrete logarithm keys?
Classic Diffie-Hellman and DSA work in a group of numbers modulo a large prime, and their security rests on the discrete logarithm problem, which is recovering an exponent from the result of repeated multiplication. Two sizes matter. The first is the size of the prime that defines the group, written first in the tables. The second is the size of the subgroup the computations actually use.
Each size defends against a different kind of attack. The best attacks on the whole group scale like factoring, so the group prime needs to be about as large as an RSA modulus. Generic attacks on the subgroup take roughly the square root of its size, so the subgroup needs about twice as many bits as the security target. That is why the tables show pairs such as 3072 and 256.
Sources: NIST, ANSSI. See also: Key length.
Why are elliptic-curve keys so much shorter than RSA keys?
Elliptic-curve cryptography uses the discrete logarithm problem on the points of a curve instead of on numbers modulo a prime. No attack is known that exploits the structure of well-chosen curves the way factoring algorithms exploit RSA, so the best classical attacks are generic and take about the square root of the group size.
That means a curve needs about twice as many bits as the security target, so a 256-bit curve gives about 128 bits of security, compared with 3072 bits for RSA. The smaller keys and signatures are why elliptic curves took over most of the web. They are just as vulnerable to a quantum computer as RSA, however, because Shor's algorithm solves the elliptic-curve discrete logarithm too.
Sources: NIST. See also: Key length.
Why do hash functions need twice the output size?
A hash function turns any input into a fixed-size fingerprint. The most demanding property is collision resistance, meaning nobody can find two different inputs with the same fingerprint. Because of the birthday effect, finding some collision takes only about the square root of the number of possible outputs, so a 256-bit hash gives about 128 bits of collision resistance.
Finding an input that matches a particular given fingerprint is much harder and takes about the full output size. Signatures and certificates depend on collision resistance, which is why the tables pair a 256-bit hash with 128-bit security.
Sources: BSI. See also: Key length.
What is a KEM, and how is it different from Diffie-Hellman?
A key encapsulation mechanism, or KEM, is how the new post-quantum algorithms establish a shared secret. One side publishes a public key. The other side uses it to generate a random secret together with a ciphertext that only the holder of the private key can open, and sends the ciphertext back. Both sides end up with the same secret, which then keys the symmetric encryption.
Diffie-Hellman reaches the same result differently, with both sides contributing a public value and combining it with their own private value. Protocols such as TLS 1.3 can carry either, which is why ML-KEM could be added to TLS as a new key exchange option without redesigning the protocol.
Sources: NIST.
What are lattice, hash-based and code-based algorithms?
They are families of post-quantum algorithms named after the mathematical problem their security rests on. None of these problems has a known efficient quantum attack.
Lattice-based algorithms rest on problems about finding short vectors in high-dimensional grids. ML-KEM for key establishment and ML-DSA for signatures are both lattice-based, fast and compact, which is why they are the main standards. FrodoKEM uses a less structured lattice, which is slower and larger but considered more conservative, and BSI and ANSSI both recommend it.
Hash-based signatures, such as SLH-DSA, LMS and XMSS, rest only on the security of hash functions, which is very well understood. Their signatures are large, so they suit uses such as firmware signing where size matters less than confidence.
Code-based algorithms rest on the difficulty of decoding error-correcting codes. Classic McEliece has decades of analysis behind it but public keys of hundreds of kilobytes or more. HQC was selected by NIST in 2025 as a backup key establishment standard based on a different problem from ML-KEM.
Sources: BSI, ANSSI. See also: Algorithm sizes.
What does stateful mean for LMS and XMSS?
LMS and XMSS build a signature key out of a large number of one-time keys, and each one may only ever be used once. The signer has to keep track of which have been used, which is the state. If the state is lost or copied, for example by restoring a backup or cloning a virtual machine, a one-time key can be reused and security fails.
That makes them unsuitable for general use but a good fit for tightly controlled signing, such as software and firmware updates signed from a hardware module. CNSA 2.0 requires them for exactly that. SLH-DSA is the stateless alternative, at the cost of larger signatures.
Sources: NSA.
What are NIST's post-quantum security categories?
NIST rates post-quantum parameter sets against the effort to break AES or SHA of a given size, rather than in bits. Category 1 is at least as hard to break as finding an AES-128 key, category 3 matches AES-192 and category 5 matches AES-256. Categories 2 and 4 are defined by collision search on SHA-256 and SHA-384.
The number in a parameter set name usually indicates its category. ML-KEM-512, 768 and 1024 are categories 1, 3 and 5, and ML-DSA-44, 65 and 87 are categories 2, 3 and 5. Authorities that want more margin, such as CNSA 2.0, require the category 5 sets.
What are Shor's and Grover's algorithms?
They are the two quantum algorithms that matter for cryptography. Shor's algorithm solves factoring and discrete logarithms efficiently, which breaks RSA, Diffie-Hellman and elliptic curves completely rather than weakening them. No increase in key size fixes that, which is why those algorithms have to be replaced.
Grover's algorithm speeds up brute-force search, in theory halving the effective size of a symmetric key. In practice the attack has to run as one very long sequential computation and parallelises poorly, so the real reduction is much smaller. That is why symmetric keys and hash functions need little or no change.
See also: Quantum estimates.
What is the difference between physical and logical qubits?
Physical qubits are the actual hardware elements, and they make errors far too often to run a long computation directly. Error correction combines many physical qubits into one logical qubit that behaves reliably. The more physical qubits per logical qubit, measured by the code distance, the lower the error rate.
A cryptographically relevant attack needs on the order of a thousand or more logical qubits running reliably for hours or days. The estimates on this site count physical qubits, which is why they run from hundreds of thousands to millions, and why a device announced with a few dozen logical qubits at a small code distance is still a long way from that.
See also: Quantum estimates.
What is a CRQC?
A cryptographically relevant quantum computer is one able to run Shor's algorithm at the scale needed to break keys in real use, such as RSA-2048 or a 256-bit elliptic curve. No such machine is known to exist.
Estimates of when one might exist vary widely, and for planning purposes the date matters less than two other numbers, which are how long your data must stay secret and how long your migration will take. If those two add up to more than the time until a CRQC exists, the data is at risk.
See also: Quantum estimates.
Post-quantum
No one has a quantum computer that can break RSA. Why act now?
Because data can be recorded today and decrypted later. An attacker who captures encrypted traffic now and stores it only needs a capable quantum computer at some point before the data stops mattering. If records must stay confidential for ten years and a capable machine arrives in eight, they are already exposed, even though nothing can break them today.
Migration also takes years. Inventories, protocol changes, hardware refresh cycles and supplier updates mean that organizations starting when a machine is announced will be too late. The published estimates of what such a machine needs have fallen sharply, from about 20 million qubits in 2019 to under a million in 2025 on the same hardware assumptions, and further on other architectures.
Sources: Google Quantum AI, Gidney and Ekerå. See also: Quantum estimates.
Why does key establishment come before signatures?
Encrypted data can't be protected retroactively. If the key exchange behind a recorded session is broken later, the session is exposed, and nothing done afterwards changes that. A signature is different. It only needs to hold until it is replaced, and a forged signature is only useful while the old algorithm is still trusted.
That asymmetry is why US federal policy requires post-quantum key establishment for high value assets by the end of 2030 and signatures a year later, and why most national timelines follow the same order.
Sources: The White House. See also: Deadlines.
What is hybrid cryptography, and why do BSI and ANSSI require it?
A hybrid scheme combines a classical algorithm such as ECDH with a post-quantum one such as ML-KEM, so that an attacker has to break both. The post-quantum algorithms are much newer and have had far less scrutiny. Hybrid protects against the possibility that one of them turns out to be weaker than expected, while still protecting against a quantum computer.
The most widely deployed example is X25519MLKEM768 in TLS 1.3, which runs an elliptic-curve Diffie-Hellman exchange and an ML-KEM encapsulation in the same handshake and combines both results into the session key. It is already the default in current browsers and major TLS libraries, and it accounts for most of the post-quantum traffic measured on the web.
BSI and ANSSI both require post-quantum key establishment to be used in hybrid form. ANSSI allows hash-based signatures such as SLH-DSA to be used alone, because their security rests on well-understood hash functions. NSA takes a different view and requires CNSA 2.0 algorithms on their own once the transition dates pass.
Do symmetric keys and hashes also need to change?
Much less. The quantum algorithm that breaks RSA and elliptic curves, Shor's algorithm, has no counterpart against symmetric ciphers and hash functions. The best known quantum attack on them, Grover's algorithm, gives a much smaller speed-up that is also hard to run in practice.
NIST continues to treat AES-128 as acceptable, while CNSA 2.0 requires AES-256 and SHA-384 or SHA-512 for national security systems. The large changes are all on the public-key side.
Why do the quantum estimates keep falling?
Two things improve at once. Better algorithms reduce how many logical qubits and operations an attack needs, and better error correction reduces how many physical qubits each logical qubit costs. The 2019 to 2025 drop for RSA-2048 came entirely from those improvements on unchanged hardware assumptions.
The 2026 estimates go further by assuming different hardware, such as neutral atoms or error-correcting codes that need richer connectivity. They are not directly comparable with the earlier series, which is why the chart only joins estimates made under the same hardware model, and why the runtime matters as much as the qubit count.
Sources: Google Quantum AI, Gidney and Ekerå. See also: Quantum estimates.
Deadlines and rules
Which deadline applies to me?
Usually more than one. A company can be bound by its national government, its sector regulator, the jurisdictions of its customers and the requirements of the standards it certifies against. The practical answer is to plan against the earliest deadline among those that actually apply to your systems, which the transition page shows once you select your jurisdictions.
Read the scope carefully. Many dates apply only to government systems, high-value assets or critical infrastructure, and a date that does not bind you directly may still reach you through procurement requirements.
See also: Deadlines.
What is the difference between mandatory, guidance and a stated target?
A mandatory requirement binds its scope through law, regulation or procurement, and failing it has consequences. Guidance is advice from an authority without direct enforcement, although regulators and auditors often treat it as the expected standard. A stated target is a goal a government has announced without a mechanism to enforce it.
The classification follows the one the Hong Kong Monetary Authority used in its comparison of national programmes, and it is shown next to every jurisdiction on the timeline.
Sources: Hong Kong Monetary Authority. See also: Deadlines.
Why is China treated differently?
China is standardising its own post-quantum algorithms rather than adopting the NIST set, as it did with SM2, SM3 and SM4. Its programme published round 1 candidates in September 2026, with 84 public-key and 35 hash algorithms, and no migration deadline yet.
For organizations operating in China, that means a second set of algorithms on a different schedule, and parameter choices that will not map directly onto ML-KEM and ML-DSA.
Sources: Institute of Commercial Cryptography Standards, China, Institute of Commercial Cryptography Standards, China. See also: Deadlines.
Operations
What is crypto agility, and why do regulators ask for it?
Crypto agility is the ability to change algorithms, key sizes or protocols without redesigning the systems that use them. It matters because every recommendation on this site will change again. A system that can swap algorithms by configuration can follow the next revision. A system with algorithms fixed in hardware, firmware or data formats has to be rebuilt.
Regulators have started to require it directly. DORA requires financial entities to have provisions for updating cryptographic technology as cryptanalysis develops, NIS2's implementing regulation expects it in the cryptographic policy, and PCI DSS requires a documented plan to respond to anticipated changes in cryptographic vulnerabilities.
See also: Other requirements.
Why is everyone asking for a cryptographic inventory?
Because you can't migrate what you can't find. Cryptography is embedded in applications, libraries, devices, certificates and third-party services, and most organizations don't know where all of it is. An inventory records which algorithms, key sizes, protocols and certificates are used where, and for what.
PCI DSS has required an inventory of cipher suites and protocols since March 2025, US federal agencies have maintained inventories of quantum-vulnerable systems since 2022, and most national migration plans make an inventory the first milestone.
See also: Other requirements.
Why are TLS certificates getting shorter?
Shorter validity limits how long a mis-issued or compromised certificate stays useful, and it forces automation. Once renewal is automatic, changing key types or algorithms becomes a configuration change that propagates within one certificate lifetime, which is the web PKI's form of crypto agility.
Maximum validity for publicly trusted TLS certificates fell to 200 days in March 2026 and will fall to 100 days in March 2027 and 47 days in March 2029.
See also: Other requirements.
What is FIPS 140 validation, and why isn't using AES enough?
FIPS 140 is the US standard for cryptographic modules, the hardware or software that actually implements the algorithms. NIST's Cryptographic Module Validation Program tests modules against it and publishes certificates. FedRAMP, CMMC and federal systems require validated modules, not just approved algorithms, because a correct algorithm can still be implemented badly.
The standard is in transition. All FIPS 140-2 certificates moved to historical status on 21 September 2026, so new federal procurements depend on FIPS 140-3 certificates, and many modules are still waiting in the validation queue. Post-quantum algorithms follow the same path, since they can only be used in these regimes once validated modules implementing them exist.
Sources: FedRAMP. See also: Other requirements.
About the data
Where does the data come from, and how do I know it's right?
Every figure links to the document it comes from, and every source is marked by how it was checked. Primary means the cited section of the document itself was read. Secondary means the entry rests on reporting about the document and still needs checking.
The distinction matters. Checking against primary documents has already corrected errors that were repeated across widely cited summaries, including the number of the US executive order and what BSI actually requires for hybrid key establishment. Surveys and trackers from firms that sell post-quantum products are treated as leads, not evidence.
See also: Sources.
How is the site kept current?
New findings and rules go into the developments log first, with their source, and are folded into the tables and charts once they have been checked. Every section shows the date it was last reviewed. The data is published as open JSON under CC BY 4.0 so that anyone can check it, build on it or send corrections.
See also: Developments log.