The NIST PQC migration roadmap, 2025 to 2035.
NIST has deprecated RSA-2048 and ECC-256 after 2030 and disallowed them after 2035. Most institutions need eight years to migrate. Most have not started. This is the phased roadmap regulators expect to see, mapped to the governance standard your board can cite.
The dates that drive the roadmap.
NIST finalizes PQC standards.
FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) published.
RSA-2048 and ECC-256 deprecated.
NIST IR 8547: classical asymmetric algorithms move to deprecated status; auditors begin flagging.
Classical asymmetric crypto disallowed.
Federal systems must complete migration. Regulated industries follow within the same window.
The four-phase roadmap.
Discovery and governance.
Stand up cryptographic inventory (CBOM/QASI), assign QRAF accountability, classify data by confidentiality lifetime, and produce a baseline Q-Risk Score. NIST IR 8547 explicitly names discovery as the first phase; CISA, NSA, and NIST issued the joint Quantum-Readiness factsheet making this the regulator-expected starting point.
Source: NIST IR 8547 §3.1 · CISA/NSA/NIST joint factsheet (2023)
Vendor roadmaps and contracts.
Require PQC roadmaps from every vendor with signing or encryption authority. Insert crypto-agility clauses into renewals. Begin pilot deployments of ML-KEM (FIPS 203) for key establishment behind feature flags. NIST has formally deprecated RSA-2048 and ECC-256 after 2030 and disallowed them after 2035.
Source: NIST IR 8547 §3.2 · FIPS 203 (ML-KEM) · FIPS 204 (ML-DSA)
Migration of customer-facing and identity surfaces.
Roll out ML-DSA (FIPS 204) signing identities, certificate-chain refresh, hybrid TLS, and PQC for high-value customer authentication. This is where most institutions discover their machine-identity and workload-credential gaps; if your QASI inventory is not complete, this phase stalls.
Source: NIST IR 8547 §3.3 · FIPS 204 · SP 800-208 (stateful hash sigs)
Completion, attestation, and decommissioning.
Decommission RSA-2048 and ECC-256 across all production surfaces. Issue executive attestation. Complete vendor compliance evidence. Map Q-Risk Score above 80 and produce the Section 8 board briefing. By NIST's deadline, anything still relying on classical asymmetric crypto is an audit finding.
Source: NIST IR 8547 §3.4 (disallowed after 2035) · QCI-QS1 Clause 8
The NIST-finalized algorithms you will be deploying.
FIPS 203 — ML-KEM
Module-Lattice-based Key Encapsulation Mechanism. Replaces RSA and ECDH for TLS, VPN, and key exchange. Formerly known as CRYSTALS-Kyber.
FIPS 204 — ML-DSA
Module-Lattice-based Digital Signature Algorithm. Replaces RSA and ECDSA for code signing, document signing, and certificate chains. Formerly CRYSTALS-Dilithium.
FIPS 205 — SLH-DSA
Stateless Hash-based Digital Signature Algorithm. Backup signature scheme based on different mathematical assumptions, recommended for high-assurance signing.
How the NIST roadmap maps to QCI-QS1 governance.
NIST tells you what to migrate to. QCI-QS1 tells your board, your auditors, and your examiners how to govern the migration in evidence they can cite. The two are designed to interlock.
Eight years sounds long. It is not.
A scored Q-Risk posture, a phased NIST-aligned roadmap, and the board-ready evidence behind every recommendation. Mapped to QCI-QS1 so your auditors recognize the work.