Illustration comparing classical bits with quantum qubits

Post-Quantum Migration Readiness in 2026: The Deadlines Are Now Real

For most of the last decade, post-quantum cryptography (PQC) sat in the “important, but not yet urgent” column of the risk register. That changed between March 2025 and June 2026. In that window, the UK, the European Union and the United States each put dates on the migration, and two of the earliest milestones land before this year is out: US federal agencies must file PQC migration plans by 22 October 2026, and the EU’s first milestone falls on 31 December 2026.

Meanwhile, the evidence on enterprise progress is sobering. DigiCert’s Quantum Readiness Outlook, published on 23 July 2026, found that 87% of organisations are planning, testing or implementing PQC, yet only 7% have deployed quantum-safe or hybrid cryptography across most of their digital certificates, up just two percentage points in a year.

Our six-part Post-Quantum Readiness series covered the fundamentals: the threat, the NIST standards, the CBOM, migration planning and tooling. This article is the late-2026 status check: what the regulators now expect, what has changed since the series was written, and what a realistic readiness check looks like before the year closes.

The Timelines Are Now Written Down

Three jurisdictions, three documents, one consistent message: discovery and planning now, priority systems by around 2030–2031, and everything practical by 2035.

United Kingdom: NCSC migration timelines (20 March 2025)

  • By 2028: define migration goals, carry out a full discovery exercise, and build an initial migration plan.
  • By 2031: carry out early, highest-priority migration activities and refine the plan into a thorough roadmap.
  • By 2035: complete migration to PQC of all systems, services and products.

European Union: Coordinated Implementation Roadmap (published 23 June 2025)

The roadmap, produced by the NIS Cooperation Group’s PQC work stream, is addressed to Member States rather than directly to companies. It does, however, call for NIS2 supervisory bodies and critical-infrastructure providers to be involved from the start, and describes its first steps as “no-regret” moves that also support NIS2 compliance. Its milestones are:

  • By 31 December 2026: the “First Steps” are implemented, initial national transition roadmaps exist, and planning and pilots for high- and medium-risk use cases have started.
  • By 31 December 2030: the transition for high-risk use cases is complete, and quantum-safe software and firmware upgrades are enabled by default.
  • By 31 December 2035: medium-risk use cases are complete, and low-risk use cases as far as feasible.

Crucially, the roadmap defines a use case as high-risk if compromising the confidentiality of its data ten years or more from now would still cause significant damage. That is precisely the data that “harvest now, decrypt later” attackers are motivated to collect today.

United States: OMB Memorandum M-26-15 (24 June 2026)

Issued two days after the Executive Order Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), M-26-15 is the most operationally detailed of the three. It applies to federal civilian agencies (not national security systems) and requires them to:

  • Submit a PQC Migration Plan to OMB and the Office of the National Cyber Director within 120 days, that is, by 22 October 2026.
  • Mitigate “as much quantum risk as feasible” by 31 December 2030, following five phases: strategy and discovery (2026–2027), pilots and early migration (2027–2028), prioritised migration of key establishment (2028–2030), signature migration (2031) and full migration (2035).
  • Align their plans with NIST IR 8547, NIST’s still-draft transition guidance, which proposes deprecating quantum-vulnerable public-key algorithms at the 112-bit security level (such as RSA-2048) after 2030, and disallowing all quantum-vulnerable public-key algorithms (RSA, ECDSA, EdDSA, Diffie-Hellman and ECDH) after 2035.

M-26-15 does not bind private companies directly, but it reaches them quickly through procurement: agencies are told to require PQC integration in the product categories CISA has published, and to agree PQC responsibilities with their cloud providers under the shared responsibility model. Any organisation that sells technology or services into the US public sector should read it as a supplier requirement.

What Has Changed Since Our PQC Series

1. The internet edge has moved, but the enterprise behind it has not

Cloudflare reported in February 2026 that over 60% of the clients connecting to its network now support post-quantum key agreement, up from under 3% at the start of 2024, and recent versions of every major browser now enable hybrid ML-KEM key exchange by default. But only around 10% of the origin servers that Cloudflare connects to on its customers’ behalf support it. In other words, browsers are ready; the organisations they connect to mostly are not.

2. The quantum resource estimates keep falling

In May 2025, Google Quantum AI researcher Craig Gidney estimated that a 2048-bit RSA key could be factored in under a week by a machine with fewer than one million noisy qubits, a twentyfold reduction on the 2019 estimate he co-authored. Research in 2026 has pushed further still: a May 2026 preprint, for example, describes factoring RSA-2048 on a half-million-qubit modular neutral-atom processor, although on an architecture that has not yet been built. None of this means a cryptographically relevant quantum computer exists (M-26-15 itself says one is “not yet known to exist”), but the direction of travel is consistently towards less hardware being needed, not more.

3. The standards are stable enough to act on

NIST’s three core standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA), have been final since August 2024, and NIST’s guidance is unambiguous: they “can and should be put into use now”. FN-DSA (Falcon) and HQC are still going through standardisation; HQC was selected in March 2025 as a backup to ML-KEM based on different mathematics, with a final standard expected in 2027. Waiting for them is not a reason to delay discovery, inventory or ML-KEM pilots.

4. Hybrid is recommended, with a caveat

Our series advocated a hybrid-first approach, and that remains our view for internet-facing TLS, where hybrid ML-KEM key exchange is now the default in browsers. It is worth noting, though, that M-26-15 describes hybrid architectures as “an intricate and resource-intensive stopgap” that requires a deliberate evaluation of trade-offs. Hybrid should be a planned stage with an exit, not a permanent state.

5. Vendors are shipping PQC-capable infrastructure

Key management and hardware security modules are the foundation that PQC keys have to live on. M-26-15 explicitly requires KMS and HSM platforms that can “generate, store, and manage different types of keys (e.g., both ECC and PQC keys)”. In August 2026, Thales launched Luna 8, the first HSM on its next-generation platform, with support for both current and post-quantum algorithms. Checking whether your own HSM and KMS estate can support PQC natively, and when it is due for refresh, now belongs in the migration plan.

The Readiness Gap, in Numbers

Two large 2026 surveys describe the same pattern: high awareness, real planning, very little deployment.

  • DigiCert Quantum Readiness Outlook (published 23 July 2026; 1,001 IT and cybersecurity decision-makers in the US, UK and Australia; fielded by Propeller Insights in May 2026): 87% planning, testing or implementing PQC; 50% have conducted a quantum risk assessment; 44% have developed transition plans and created cryptographic inventories; 7% have quantum-safe or hybrid cryptography across most of their certificates. A quarter (25.6%) named legacy complexity as the biggest barrier to deployment.
  • 2026 Thales Data Threat Report (published March 2026; 3,120 security and IT professionals worldwide; research by S&P Global Market Intelligence): 61% named “harvest now, decrypt later” as their top quantum-related concern, and 59% see prototyping and evaluating PQC algorithms as their main route to becoming quantum-safe.

Read together, fewer than half of organisations have the inventory that every one of the three government timelines treats as step one. That is the gap to close first.

A Practical Readiness Check Before Year-End

You do not need to be migrated by 31 December 2026. You do need to be able to show that migration has started in a structured, evidence-based way. Six questions will tell you where you stand:

  1. Is there a named, accountable owner? M-26-15 is explicit that PQC is not solely a CIO or CISO responsibility; it needs governance, defined roles and executive sponsorship. The same is true outside government.
  2. Do you have a cryptographic inventory, and is it automated? Every framework starts here. Both the EU roadmap and M-26-15 recommend a standardised Cryptographic Bill of Materials (CBOM), and M-26-15 notes that manual discovery is “often insufficient” at enterprise scale. Enterprise Cryptographic Exposure Management platforms such as Quantum Sentinel automate this discovery and inventory, and help prioritise what to migrate first.
  3. Have you classified data by how long it must stay confidential? Use the EU test: if exposure in ten or more years would still cause significant damage, treat it as high-risk and plan to protect it by 2030.
  4. What does your internet-facing estate negotiate today? With every major browser already offering hybrid ML-KEM by default, the fastest visible win is often enabling it on TLS 1.3 endpoints, load balancers and CDNs, then confirming it works.
  5. Is PQC in your procurement and vendor contracts? Ask suppliers, especially HSM, KMS, PKI, VPN, firewall and SaaS vendors, for dated PQC roadmaps, and make crypto-agility a contractual expectation.
  6. Is there a dated plan the board has seen? A phased roadmap with 2027 pilots, 2030 priority targets and 2035 completion, mapped to the timeline that applies to you, is what regulators, auditors and customers will increasingly ask to see.

If you can answer “yes” to the first three, you are ahead of most organisations in the 2026 surveys. If you cannot, the migration planning guide in our series is the place to start.

How Sinevis Can Help

Sinevis’s Post-Quantum Cyber Readiness service takes organisations through five stages (Discover, Assess, Controls, Remediation and Monitor), from cryptographic discovery and CBOM creation through risk-based prioritisation to implementation of PQC-compliant cryptography and crypto-agility.

As an authorised Thales service partner delivering globally, we also design and deploy the key management and encryption foundations a PQC migration depends on, including CipherTrust Manager and Luna HSM. See our technology partners.

Want a quick first data point? Our free tools check the post-quantum posture of any public website or DNS server (DoH, DoT and DoQ).

If you need a readiness assessment you can take to the board before the end of 2026, get in touch or explore our wider cybersecurity services.