
Post-quantum migration stopped being a recommendation when governments attached dates to it. The dates are close together but the mechanisms differ, and operators that sell into more than one jurisdiction need to understand each. This is a plain reading of the four that matter most to critical infrastructure.
United States: CNSA 2.0
The National Security Agency’s Commercial National Security Algorithm Suite 2.0 sets a schedule for national security systems and the vendors that supply them. Networking equipment is expected to support the post-quantum algorithms by 2026 and to use them exclusively by 2030. Because federal procurement follows this suite, its dates propagate into the requirements of any supplier to US government networks. The algorithms named are the NIST standards finalised in August 2024: ML-KEM for key establishment (FIPS 203) and ML-DSA for signatures (FIPS 204).
Saudi Arabia: NCS 2:2025
The National Cybersecurity Authority’s second national strategy, NCS 2:2025, mandates a move to quantum-safe security across critical national infrastructure and government networks. It is anchored in the Vision 2030 digital-infrastructure programme, which is why the mandate reaches operators in energy, water, healthcare, finance and telecommunications rather than government alone.
European Union: 2027
ENISA has published transition guidance for critical-infrastructure operators, and the EU’s coordinated roadmap sets 2027 as the deadline for those operators to begin their post-quantum transition, with the Cyber Resilience Act requiring quantum-safe practices for connected products. The obligation falls on the operator, so it applies regardless of which vendor’s equipment is in place.
France: ANSSI, 2027 and 2030
France drew the sharpest line. From 2027, ANSSI, the national cybersecurity agency, stops certifying security products that are not post-quantum. Certification is the effective gate for deployment in French government and critical-infrastructure networks, so the practical meaning is that non-quantum-safe products lose their market. From 2030, those operators may buy only quantum-safe products. ANSSI’s approach is hybrid first, layering post-quantum algorithms on classical ones, then moving to standalone post-quantum as confidence grows, and it moves in step with Germany’s BSI.
What the dates have in common
Each mandate names the same algorithm families, so a product built on ML-KEM and ML-DSA meets all four. Each falls on the operator rather than the vendor, which means the operator carries the schedule risk. And each has a first date in 2026 or 2027, which is inside the replacement cycle of most network equipment. That last point is why the transition has to happen on the networks operators already run.
