From the end of 2030, NIST’s transition roadmap treats RSA-2048 and ECDSA-P256 as deprecated. If your platform still leans on them then, you are running cryptography a standards body has publicly labelled as on the way out — with a hard stop at 2035.
What is happening
NIST IR 8547, Transition to Post-Quantum Cryptography Standards, sets a two-step timeline for the classical public-key algorithms most systems still rely on. Algorithms at the 112-bit security level — RSA-2048, ECDSA and ECDH over P-256, finite-field Diffie-Hellman — are deprecated after 2030 and disallowed after 2035. Deprecated does not mean switched off. It means NIST expects you to stop using it for new work and to be actively migrating, with any continued use treated as an accepted risk you can defend. Disallowed, in 2035, is the real wall.
The point of the 2030 marker is that it is the moment the excuse expires. From that year, “we are still on RSA-2048 because the migration is hard” stops being a plan and starts being a finding. The algorithms that quietly hold up your TLS, your signing, your VPNs and your document seals are the ones on the list.
Free · 4 minutes
Would you survive contact with a determined attacker — or an auditor?
Fourteen questions on access, patching, detection, and recovery — the basics that prevent most real incidents, and the ones most often assumed rather than verified. Banded finding on screen, full sheet by email.
- Who this is for:
- Heads of security and platform owners whose estates carry long-lived certificates, signing keys or embedded devices.
- CTOs in regulated sectors — banking, payments, healthcare — where supervisors will ask for a quantum-readiness plan before 2030.
- Anyone shipping hardware or firmware today with a service life that runs past 2030.
Why it bites
Cryptography is rarely in one place. It is in your load balancers, your service mesh, your code-signing pipeline, your database TLS, your third-party libraries and the appliances you forgot were appliances. You cannot migrate what you cannot see, and most organisations have no inventory of where RSA and ECDSA actually live. That discovery work — a cryptographic bill of materials — is the slow part, and it is why a 2030 milestone needs starting years ahead, not months.
There is a second reason to move early: harvest-now, decrypt-later. Data captured today under RSA or ECDSA can be stored and broken once a cryptographically relevant quantum computer exists. For anything with a long confidentiality horizon — health records, contracts, keys — the clock started the day it was first transmitted, not in 2030. This sits squarely in your security architecture risk picture.
The one thing to do before 2030
Build a cryptographic inventory this year and keep it current: every place you use public-key crypto, which algorithm, which key length, and how long the data or certificate it protects must stay valid. That single artefact tells you what is on the deprecation list, what has a service life crossing 2030, and where crypto-agility — the ability to swap algorithms without re-architecting — is missing. Everything downstream, from library upgrades to hardware refresh cycles, keys off it.
If you want a second pair of eyes on your crypto inventory and a migration path to post-quantum algorithms, that is the kind of review I do — see how I work. Fees are fixed and quoted up front, so the scope is clear before anything starts.
NIST IR 8547 is a roadmap, not a statute, and it began life as a draft — but the 2030 and 2035 markers are the ones supervisors and auditors are already quoting. Diarise the end of 2030. The work to be ready for it belongs in this year’s plan.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Can you trust the architecture you have?
Architecture diagrams rarely show the reality of how systems actually operate. An independent review establishes what is really there.