Forge University
Industry News

Post-Quantum Migration Has Deadlines Now. Most Security Teams Still Don't Have a Plan.

September 23, 2026

Rodney Hall, COO— AI-assisted and reviewed prior to publication.

A padlock built from lattice fragments dissolving into crystalline shapes against a dark horizon

Post-quantum migration means replacing RSA and elliptic-curve cryptography with algorithms that resist attack from future quantum computers, and it now runs on fixed government deadlines rather than open-ended guidance. The first hard checkpoint lands January 1, 2027, when new national security system acquisitions must already support the new algorithms. If your organization touches federal contracts, cloud infrastructure, or long-lived encrypted data, that clock is already running against you.

What Is CNSA 2.0 and Why Does It Bind More Than Federal Agencies?

The NSA's Commercial National Security Algorithm Suite 2.0 is the document that turned post-quantum planning into a scheduled requirement instead of a research topic. Unlike most cryptography guidance, which tells organizations to start planning, CNSA 2.0 names the exact algorithms, assigns them to specific system categories, and ties missed milestones to procurement eligibility. The NSA's CNSA 2.0 FAQ lays out a phased schedule that pushes all national security systems toward full compliance by the early 2030s, with software and firmware signing required to use the new algorithms exclusively starting in 2027.

That timeline reaches well past classified networks. A November 2025 Department of War CIO memorandum added its own dates on top of CNSA 2.0, requiring symmetric keys and pre-shared keys tied to older methods to be phased out by December 31, 2030, according to a legal analysis from Wiley. Any contractor, cloud provider, or managed service that sells into that supply chain inherits the same deadline pressure, whether or not the organization itself handles classified information.

What Actually Has to Change Inside Your Infrastructure?

The core work is swapping the cryptographic primitives that protect key exchange and digital signatures across every system that uses them, which is a bigger job than most teams expect once they start counting. NIST finalized the first three post-quantum standards on August 13, 2024: FIPS 203 for key encapsulation, and FIPS 204 and FIPS 205 for digital signatures, according to the official NIST CSRC announcement. Those standards replace RSA and ECDH for key exchange and RSA or ECDSA for signatures across TLS sessions, VPN tunnels, code signing pipelines, and certificate authorities.

The practical difficulty is not the math. It is finding every place the old algorithms are embedded, some of which nobody documented when the system was built. CISA, the NSA, and NIST jointly published a quantum-readiness factsheet that walks organizations through building a cryptographic inventory, assessing supply chain dependence on vulnerable algorithms, and structuring conversations with vendors before a contract renewal locks in outdated cryptography for another cycle. That inventory step is where most migration projects actually stall, because embedded devices, legacy applications, and third-party libraries rarely list which algorithms they use in any accessible way.

Why "Harvest Now, Decrypt Later" Moves Your Real Deadline Earlier

Attackers do not need a working quantum computer today to benefit from one later. Adversaries can capture encrypted traffic now and decrypt it once cryptographically relevant quantum computing exists, which means data with a long confidentiality shelf life is already exposed even though no algorithm has broken yet. CISA's post-quantum initiative page frames this directly, noting that a coordinated international roadmap for the financial sector focuses on system inventory and risk-based planning specifically to reduce harvest-now-decrypt-later exposure. If your organization stores health records, financial data, trade secrets, or government communications with a shelf life measured in decades, your real deadline is not 2030. It is whenever an adversary decided to start collecting your traffic.

How Do You Build a Migration Plan That Doesn't Require a Blank Check?

Start with inventory, not procurement. Before buying anything, security teams need an accurate map of where RSA, ECDH, and ECDSA are actually doing work across the environment, including inside firmware, embedded certificates, and third-party SDKs that were never designed to be inspected easily.

A workable sequence looks like this in practice:

  • Build the cryptographic inventory first, prioritizing systems that handle long-lived sensitive data over systems where a breach would be embarrassing but short-lived.
  • Push vendors for their post-quantum roadmaps now, before renewal cycles lock in hardware or software that cannot support hybrid or pure post-quantum algorithms.
  • Pilot hybrid deployments, pairing a classical algorithm with a post-quantum one, on lower-risk systems before touching anything tied to a compliance deadline.

The milestones below reflect the schedule federal contractors and national security system operators are already working against, drawn from the CNSA 2.0 timeline and the 2025 Department of War memorandum.

MilestoneDateRequirement
New NSS acquisitionsJanuary 1, 2027Must support CNSA 2.0 algorithms to be deployable
Software and firmware signingJanuary 1, 2027Exclusive use of post-quantum signatures required
Symmetric and pre-shared keysDecember 31, 2030Phased out in favor of NIST-approved asymmetric PQC
Full National Security System compliance2033-2035Operating systems, applications, and cloud services fully transitioned

Even organizations with no federal contract exposure are watching these dates, because cloud providers, browser vendors, and certificate authorities are building their roadmaps around the same schedule. Waiting for a mandate that applies directly to your sector means inheriting whatever timeline your suppliers chose for their own compliance.

Which Skills and Certifications Actually Prepare Someone for This Work?

This is architecture and operations work, not a policy memo someone files and forgets. It requires people who understand where cryptography actually lives in an infrastructure stack, how to evaluate vendor claims about hybrid algorithm support, and how to sequence a migration without breaking production TLS termination or certificate chains mid-project.

CompTIA's SecurityX certification, the advanced track built for senior security engineers and architects, covers enterprise cryptographic implementation and the kind of infrastructure decision-making a post-quantum migration actually demands, which makes the CompTIA SecurityX certification a reasonable anchor point if you're building this capability on your team rather than hoping it develops on its own. If you want a clearer picture of how that maps to a study plan and which prerequisite knowledge matters most, the curriculum breakdown on the resources page is a good place to check before committing time to a specific exam track.

None of this gets easier by waiting. The algorithms are finalized, the deadlines are published, and the vendors your organization depends on are already making roadmap decisions that will constrain your options later. If you want a study plan built around cryptography and enterprise security architecture specifically, you can start training whenever you're ready, rather than trying to absorb this from vendor whitepapers during a compliance scramble.

The organizations that come out ahead here are not the ones with the biggest budget. They are the ones who inventoried early, engaged vendors before contracts renewed, and had at least one person on staff who could read a CNSA 2.0 deadline and translate it into an actual project plan instead of a slide in a board deck.

Start training free at Forge University