NIST IR 8547 transition timeline: 2030 and 2035 explained
NIST's transition report proposes the dates most organisations now plan around. As of September 2026 it remains an initial public draft, which affects how you should cite it.
- NIST IR 8547 was published as an initial public draft on 12 November 2024; comments closed on 10 January 2025.
- As of September 2026 NIST has not published a final version; the initial public draft is the current text.
- It proposes deprecating RSA, ECDSA and classical key establishment at 112-bit security strength after 2030.
- It proposes disallowing quantum-vulnerable signatures and key establishment at all security strengths after 2035.
- NIST does not expect to need to transition away from its symmetric standards such as AES.
Status of the document
NIST IR 8547, Transition to Post-Quantum Cryptography Standards, was released as an initial public draft (ipd) on 12 November 2024. The public comment period closed on 10 January 2025, and NIST has published the comments it received [1]. When we checked NIST's publication pages in September 2026, the ipd was still the current version and no final version had been published [1]. Cite it as a draft, and check the CSRC page before relying on exact wording.
Deprecated and disallowed
The report uses NIST's standard transition terms. In SP 800-131A, "deprecated" means the algorithm and key length may be used but the user must accept some security risk; "disallowed" means it is no longer allowed for the stated purpose [2].
Digital signatures
| Algorithm | Security strength | Proposed transition |
|---|---|---|
| ECDSA and RSA (FIPS 186) | 112 bits | Deprecated after 2030; disallowed after 2035 |
| ECDSA and RSA (FIPS 186) | 128 bits and above | Disallowed after 2035 |
Source: NIST IR 8547 ipd, Table 2 [3].
Key establishment
| Scheme | Security strength | Proposed transition |
|---|---|---|
| Finite-field DH and MQV (SP 800-56A) | 112 bits | Deprecated after 2030; disallowed after 2035 |
| Elliptic-curve DH and MQV (SP 800-56A) | 112 bits | Deprecated after 2030; disallowed after 2035 |
| RSA key establishment (SP 800-56B) | 112 bits | Deprecated after 2030; disallowed after 2035 |
| All of the above | 128 bits and above | Disallowed after 2035 |
Source: NIST IR 8547 ipd, Table 4 [3]. In practice, 112-bit security corresponds to parameters such as RSA-2048 [2], so a large share of today's deployed RSA falls into the 2030 category.
What is not affected
NIST says its symmetric standards are less vulnerable to quantum attack and that it does not expect to need to transition away from them; AES-128, AES-192 and AES-256 remain acceptable [3]. Hash functions are treated similarly. A QBOM should therefore mark symmetric-only uses as "not applicable" for migration, so they do not inflate the backlog.
Hybrid schemes and the 2035 goal
The report acknowledges hybrid solutions as temporary measures during the transition, noting that they add complexity to implementations and architectures, which can increase security risks and costs [3]. It ties the overall timeline to the U.S. goal, set in National Security Memorandum 10, of mitigating as much quantum risk as feasible by 2035 [3]. NSM-10 was signed on 4 May 2022 and directs agencies to migrate vulnerable cryptographic systems to quantum-resistant cryptography [4].
Turning the draft into QBOM policy
- Flag every RSA, ECDSA, DH and ECDH asset as quantum-vulnerable, with its security strength.
- Set a policy due date of 2030 for 112-bit assets and 2035 for stronger ones, or earlier dates where a stricter framework applies (see post-quantum compliance timelines).
- Record the target standard for each asset, for example ML-KEM or ML-DSA (see NIST PQC standards).
- Re-check the policy when NIST publishes a final version.
Common mistakes
- Treating 2035 as the start date. The 2030 deprecation affects 112-bit parameters, which are common in deployed RSA and elliptic-curve systems. Plan for 2030 first.
- Ignoring vendor-controlled cryptography. Appliances, HSMs and SaaS services count too; ask suppliers for their CBOM and roadmap (see PQC procurement requirements).
- Counting symmetric uses. Including AES in the backlog makes the programme look larger than it is and hides the real work.
How IntelliXBOM helps
IntelliXBOM maps cryptographic inventory to framework controls, so assets can be reported against the IR 8547 draft dates, and produces timestamped evidence of the state at each review. Version history and diffs show which quantum-vulnerable assets have been replaced between reviews. This article summarises public guidance and is not legal advice; confirm current requirements with NIST and your regulator.
Frequently asked questions
Is NIST IR 8547 final?
No. It was published as an initial public draft on 12 November 2024 and, as of September 2026, NIST had not published a final version. Treat its dates as proposed and check NIST's publication page for updates.
Is RSA-2048 deprecated in 2030?
Under the draft, quantum-vulnerable algorithms at the 112-bit security strength, which includes RSA-2048, would be deprecated after 2030 and disallowed after 2035. Stronger quantum-vulnerable parameters would be disallowed after 2035.
Does NIST IR 8547 affect AES?
No. NIST says it does not expect to need to transition away from its symmetric standards, and AES-128, AES-192 and AES-256 remain acceptable under the draft.
Sources
- NIST IR 8547 ipd: publication details and comment periodNIST Computer Security Resource Centercsrc.nist.gov/pubs/ir/8547/ipd
- SP 800-131A Rev. 2, Transitioning the Use of Cryptographic Algorithms and Key LengthsNISTcsrc.nist.gov/pubs/sp/800/131/a/r2/final
- NIST IR 8547 (Initial Public Draft), Transition to Post-Quantum Cryptography Standards (November 2024)NISTnvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf
- President Biden Signs Memo to Combat Quantum Computing Threat (NSM-10, 4 May 2022)NSAwww.nsa.gov/Press-Room/News-Highlights/Article/Article/3020175/president-biden-signs-memo-to-combat-quantum-computing-threat/
Sources checked in September 2026. Regulations and guidance change; always refer to the issuing body’s current publication. This content is for general information and is not legal advice.