# Key length Minimum key sizes, post-quantum migration deadlines and cryptographic control requirements, each traced to its source document. Reviewed 2026-09-21. ## Classical security-strength equivalence Source: [NIST SP 800-57 Pt 1 Rev 5](https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final), NIST, 2020-05, Table 2. Security strength is also the equivalent ideal symmetric-key size. | Security bits | RSA modulus | Finite-field modulus / subgroup | Elliptic-curve key | Collision-resistant hash | |---|---|---|---|---| | 80 (legacy) | 1024 | 1024 / 160 | 160-223 | 160 | | 112 | 2048 | 2048 / 224 | 224-255 | 224 | | 128 | 3072 | 3072 / 256 | 256-383 | 256 | | 192 | 7680 | 7680 / 384 | 384-511 | 384 | | 256 | 15360 | 15360 / 512 | 512+ | 512 | ## Suggested cryptoperiods Source: [NIST SP 800-57 Pt 1 Rev 5](https://csrc.nist.gov/pubs/sp/800/57/pt1/r5/final), NIST, 2020-05, Table 1. These are starting points; the application and operating environment may justify shorter or longer periods. ### Signing - **Private signature key:** 1–3 years - **Public signature-verification key:** Several years; depends on key size ### Authentication - **Symmetric authentication key:** Originator use <2 years; recipient use