Tools

Last updated: June 22, 2026

Practical resources for security teams navigating the post-quantum transition. Use these tools to assess your readiness, compare algorithms, track key dates, and understand your regulatory obligations.

PQC migration checklist

A phased readiness checklist for enterprise cryptography migration. Work through the four phases to assess where your organisation stands.

Phase 1 — Discovery & inventory

Phase 2 — Assessment & planning

Phase 3 — Implementation

Phase 4 — Governance & compliance


NIST post-quantum algorithm comparison

The four NIST-standardised post-quantum algorithms compared by type, security level, key and signature sizes, and recommended use case.

Key encapsulation mechanisms (KEM)

AlgorithmStandardSecurity levelPublic keyCiphertextRecommended for
ML-KEM-512FIPS 203Level 1 (AES-128)800 B768 BConstrained environments
ML-KEM-768FIPS 203Level 3 (AES-192)1184 B1088 BGeneral enterprise use
ML-KEM-1024FIPS 203Level 5 (AES-256)1568 B1568 BHighest-sensitivity applications

Digital signature algorithms

AlgorithmStandardLevelPublic keySignatureRecommended for
ML-DSA-44FIPS 20421312 B2420 BLower-security applications
ML-DSA-65FIPS 20431952 B3309 BGeneral enterprise use
ML-DSA-87FIPS 20452592 B4627 BHigh-assurance applications
SLH-DSA-128sFIPS 205132 B7856 BRoot CAs, conservative deployments
SLH-DSA-192fFIPS 205348 B35664 BLong-term signatures, fast variant
FN-DSA-512FIPS 2061897 B666 BIoT and bandwidth-constrained systems
FN-DSA-1024FIPS 20651793 B1280 BHigh-security small-signature applications

Classical vs. post-quantum: size comparison

AlgorithmTypePublic keySignature / ciphertextQuantum resistant
RSA-2048Classical256 B256 BNo
ECDSA P-256Classical64 B64 BNo
X25519 (ECDH)Classical32 B32 BNo
ML-KEM-768Post-quantum1184 B1088 BYes
ML-DSA-65Post-quantum1952 B3309 BYes

For most enterprise deployments, start with ML-KEM-768 for key exchange and ML-DSA-65 for signatures. These are the Level 3 parameter sets, equivalent to AES-192 security, and are the ones referenced in most current implementation guidance from NIST, BSI, and ETSI.


Post-quantum standards timeline

NIST PQC project milestones

YearEvent
2016NIST launches PQC standardisation project. 69 candidate algorithms submitted from research teams worldwide.
2017 to 2019Round 1 evaluation. 26 candidates advance to Round 2.
2020Round 2 complete. 15 candidates advance to Round 3.
2022NIST announces initial algorithm selections: CRYSTALS-Kyber, CRYSTALS-Dilithium, FALCON, SPHINCS+.
2023Draft standards published for public comment.
August 2024FIPS 203, 204, and 205 finalised. First official post-quantum cryptography standards published.
Late 2024FIPS 206 (FN-DSA / FALCON) finalised.
2025HQC under evaluation as an additional code-based KEM candidate.

NSA CNSA 2.0 migration deadlines

DeadlineRequirement
2025New software applications delivered to national security systems must support CNSA 2.0 algorithms.
2026New hardware delivered to national security systems must support CNSA 2.0 algorithms.
2027Legacy national security systems must have approved CNSA 2.0 migration plans in place.
2030Existing systems must use only CNSA 2.0 algorithms for new cryptographic operations.
2033All national security systems must be fully migrated to CNSA 2.0 algorithms.

European milestones

YearBodyEvent
2021ENISAPQC report for EU critical infrastructure published.
2022BSIMigration guidance recommending CRYSTALS-Kyber and Dilithium published.
2022NSACNSA 2.0 published. First government mandate with hard PQC migration deadlines.
2023ETSIISG QSC guidance on quantum-safe migration for telecoms and financial sector published.
October 2024EUNIS2 Directive becomes enforceable across 18 sectors.
August 2024NISTFIPS 203 to 205 published. Global baseline for PQC migration established.
January 2025EUDORA becomes fully applicable to EU financial entities and their critical ICT providers.
2025 to 2026EU regulatorsNIS2 and DORA supervisory guidance on PQC obligations expected from EBA, ENISA, and national authorities.
2030BSITarget date for full migration of German federal systems to post-quantum algorithms.

Regulatory reference guide

NIS2 Directive (EU 2022/2555)

NIS2 became enforceable in October 2024 across all EU member states. Article 21(2)(h) requires entities to maintain policies and procedures regarding the use of cryptography and encryption. Article 21(2)(d) addresses supply chain security, making vendor PQC readiness a legitimate third-party risk assessment dimension. Article 20 makes management bodies accountable for approving and overseeing cybersecurity measures.

National cybersecurity authorities in Germany, the Netherlands, and France have incorporated post-quantum readiness into supervisory examinations. The minimum credible evidence of compliance is a cryptographic inventory, documented HNDL risk awareness, and a migration roadmap with prioritised timelines.

DORA (EU 2022/2554)

DORA became fully applicable in January 2025 for EU financial entities and their critical ICT third-party service providers. Article 9 requires state-of-the-art encryption and cryptographic controls, a dynamic standard that evolves as the threat environment changes. Articles 28 to 30 govern third-party risk management. PQC readiness is an auditable assessment dimension for critical ICT providers. The CTPP oversight framework gives EU supervisory authorities direct scrutiny of major cloud and infrastructure providers.

eIDAS 2.0

eIDAS 2.0 governs qualified trust services including electronic signatures, seals, timestamps, and the EU Digital Identity Wallet. Qualified certificates issued today with RSA or ECDSA keys will need to be reissued as post-quantum alternatives are incorporated into ETSI qualified trust service standards. ETSI and CEN/CENELEC are actively working on post-quantum profiles for the relevant technical specifications.

Sector-specific guidance

SectorBodyStatus
Finance (EU)EBA / ECBPQC referenced in ICT supervisory expectations. Formal guidance expected 2025 to 2026.
Telecoms (EU)ETSI ISG QSCMigration guidance published. 5G security standards incorporating PQC requirements.
Government (DE)BSIFormal migration guidance published. Federal systems target date 2030.
Government (FR)ANSSIHybrid PQC deployment guidance and QKD position paper published.
Defence / Gov (US)NSA / CISACNSA 2.0 mandates with hard deadlines: 2025 (new software) through 2033 (full migration).
Healthcare (EU)ENISA / DPAsGDPR Article 32 state-of-the-art obligation increasingly relevant to special category health data.