August 21, 2026
Sumanth Srirangam

2029 Is the New 2035: The Post-Quantum Deadline Just Moved Up

TL;DR

  • The date most enterprises had circled for post-quantum migration was 2035. In a few weeks of 2026, Microsoft, the White House, and the EU effectively moved it forward.
  • The trigger was research: new results sharply cut the computing power needed to break today's encryption, and policy and industry are now racing to stay ahead of it.
  • Migration takes years, so the gap between "we have time" and "we are late" is closing. The three moves that matter, inventory, crypto-agility, and hybrid post-quantum cryptography, can start this quarter.

For most boards, quantum risk lived under a comfortable heading: important, but 2035. That heading is being rewritten in real time. Over a handful of weeks in 2026, the companies and governments that set the pace for enterprise security stopped treating post-quantum migration as a distant milestone and started treating it as a near-term deadline. If you built your roadmap around 2035, the assumptions underneath it have already shifted.

What Just Changed

The clearest signal came from the biggest vendor. Microsoft has accelerated its post-quantum cryptography shift to 2029, six years ahead of the widely cited 2035 horizon. When the company whose software sits inside almost every enterprise moves its own timeline, every organisation that depends on it inherits the new date.

Policy moved in the same direction, and faster. On 22 June 2026, the United States signed two executive orders directing federal agencies to accelerate post-quantum cryptography and requiring compliance to flow down to their contractors. Days later, industry began responding in public: Cloudflare, among others, published its migration commitments directly off the back of the order. On the funding side, Washington announced roughly $2 billion in quantum funding under the CHIPS and Science Act in May 2026, capital behind the mandate, not just words.

Europe is on the same clock. The EU's roadmap sets the end of 2026 as the first phase for deploying post-quantum tools, 2030 as the deadline for high-risk use cases, and 2035 for the rest. Read together, the pattern is unmistakable: the front of the timeline, not the back, is where the action now is.

Why the Date Moved

Deadlines do not accelerate on their own. This one moved because the threat did.

The migration horizon was always tied to a question no one could answer precisely: how many qubits does it take to break today's encryption, and when will a machine have them? In 2026, the answer got smaller. A team from Google disclosed a sharply improved algorithm to break 256-bit elliptic curve cryptography using far fewer qubits and gates than previously thought, and researchers from Caltech and Oratomic demonstrated an error-correction approach that could make Shor's algorithm practical with as few as 10,000 reconfigurable qubits, enough to threaten RSA-2048 and P-256. Every estimate built on the old numbers is now conservative.

This is why the standards floor is being overtaken. NIST's own transition guidance already deprecates RSA-2048 and ECC after 2030 and disallows them after 2035. Microsoft's 2029 and the EU's 2030 high-risk deadline are the market moving inside that window, because waiting until the last permitted date leaves no room for a migration that takes years to complete.

Why This Is Now a Boardroom Problem

The shift that matters is not technical, it is where the conversation is happening. Quantum migration has moved from the research team's backlog to the audit committee's agenda, for three concrete reasons.

It is becoming a compliance obligation. Once a government mandates post-quantum readiness and pushes it down to contractors, the requirement stops being optional and starts appearing in procurement questionnaires, vendor contracts, and board risk reviews. Enterprises that supply regulated sectors will be asked to prove their own readiness.

The threat is already live. Adversaries are running harvest now, decrypt later operations, capturing encrypted data today to decrypt once quantum hardware matures. Data with a long shelf life, identity, health, financial, and legal records, is exposed the moment it is intercepted, not the day a quantum computer switches on.

And migration is slow. Cryptography is buried across TLS, PKI, certificates, firmware, VPNs, and vendor products that were never designed to swap algorithms. A full transition is a multi-year re-engineering exercise, which is precisely why a 2029 or 2030 target demands work that starts now.

What To Do This Quarter

The urgency is no longer theoretical. In July 2026, Hong Kong's central bank published its first Quantum Preparedness Index, scoring its banking sector 2.3 out of 10. Around 32 percent of banks had taken no preparatory action at all. Half lacked a formal post-quantum transition plan. The HKMA has set a target of 10 by 2030. The gap between where most institutions are and where regulators expect them to be is now a number on a regulator's dashboard.

The same gap is visible in enterprise data. DigiCert's Quantum Readiness Outlook, published 23 July 2026 across 1,001 IT and security decision-makers in the US, UK and Australia, found that 87 percent of enterprises are planning, testing or implementing PQC. Only 7 percent have actually deployed quantum-safe or hybrid cryptography across most of their digital certificates. Deployment increased by just two percentage points year on year. Planning and doing are two different risk postures. Only one of them closes the window.

The good news: the first moves are well understood, and none of them require waiting for perfect information. Three steps carry most of the value.

First, find your cryptography. You cannot migrate what you have not mapped, and most organisations discover several times more keys and certificates than they expected. A Cryptographic Bill of Materials turns a guess into an evidence base, and regulators are now asking for it directly.

Second, design for crypto-agility. Standards will keep evolving, so the goal is not to hard-code today's algorithm but to build systems that can swap algorithms through configuration rather than re-engineering. Agility is what stops this from becoming a repeat project every time the standards shift.

Third, deploy post-quantum cryptography in hybrid mode, classical and quantum-safe algorithms running side by side, starting with your longest-lived, most sensitive data. Hybrid protects you if either layer is later found wanting, and avoids a risky all-or-nothing cutover. The mechanics of sequencing this are covered in depth in our PQC migration guide.

No single product does all of this. Resilience comes from combining discovery, agility, and quantum-safe cryptography into one strategy, which is the principle behind a full-stack platform like QShield rather than five disconnected tools. The organisations that begin now migrate on their own timeline. Those that wait will migrate on the deadline's.

See where your organisation stands before the deadline decides for you. 

Book a quantum readiness assessment and map your path to quantum-safe.

Sources

  1. The Hacker News, Microsoft Accelerates Post-Quantum Cryptography Shift to 2029 (also reporting the Google ECC and Caltech/Oratomic research) :https://thehackernews.com/2026/07/microsoft-accelerates-post-quantum.html
  2. Skadden, Arps, New Executive Orders and Government Strategy Advance US Quantum Innovation and Mandate Post-Quantum Cryptography Transition :https://www.skadden.com/insights/publications/2026/06/new-executive-orders-and-government-strategy
  3. Cloudflare, The White House's Post-Quantum Executive Order Is an Important Milestone :https://blog.cloudflare.com/post-quantum-eo-2026/
  4. PRNewswire (USA News Group), The Quantum Sector Hits an Inflection Point: Federal Money, Real Milestones, and a Security Race Running in Parallel :https://www.prnewswire.com/news-releases/the-quantum-sector-hits-an-inflection-point-federal-money-real-milestones-and-a-security-race-running-in-parallel-302818222.html
  5. CSO Online, Harvest Now, Decipher Later: The Quantum Threat Few Are Preparing For (EU roadmap timelines) :https://www.csoonline.com/article/4180902/reap-now-decipher-later-thats-the-approach-to-cybersecurity-in-the-quantum-age.html
  6. NIST, IR 8547: Transition to Post-Quantum Cryptography Standards :https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
  7. COIN Desk: https://www.coindesk.com/markets/2026/07/28/hong-kong-s-central-bank-puts-a-number-on-lenders-quantum-preparedness-it-s-very-low
  8. DIGI CERT: https://www.digicert.com/news/quantum-security-deployment-remains-stuck

Frequently asked questions

Did the post-quantum migration deadline actually change?
Why did the timeline move up in 2026?
What should an enterprise do first?
Does this apply outside the United States?

More blogs