# Post-Quantum Has a Deadline: 2030 for Keys, 2031 for Signatures

Executive Order 14412 dates post-quantum key establishment to 2030 and signatures to 2031, and 6 of the 7 official calendars land on 2030. What each one asks, how it reaches a vendor, and what already ships.

Canonical HTML: https://www.livetradingnews.com/post-quantum-has-a-deadline-2030-for-keys-2031-for-signatures
Last modified: 2026-10-05

---

By Shayne Heffernan · 2026-10-05
Tags: post-quantum cryptography, PQC, Executive Order 14412, OMB M-26-15, CNSA 2.0, NIST, FIPS 203, ML-KEM, ML-DSA, NCSC, CISA, cryptographic bill of materials, quantum computing, cybersecurity, KXCO, OpenSSL, Node.js
Signed: ML-DSA-65, anchored on Armature L1.
Nothing in this article is investment advice.

## 2 dates, and why keys come first

[Executive Order 14412](https://www.federalregister.gov/documents/2026/06/25/2026-12909/securing-the-nation-against-advanced-cryptographic-attacks), signed on 22 June 2026, gives federal high-value and high-impact systems until 31 December 2030 to use post-quantum cryptography for key establishment, and until 31 December 2031 for signatures. Section 1 gives the reason for the order of the two: adversaries are "collecting United States information now, and decrypting it later once large-scale quantum computers are operational".

That is why the key date is earlier. A forged signature needs a quantum computer on the day of the forgery. A recorded session only needs one eventually, and the recording is being made now.

The Order does not stand alone. Six of the seven official post-quantum calendars put a milestone in 2030, and the seventh has its steps in 2028 and 2031. For an engineering team the date on the plan is no longer a forecast. It is written into federal law, a federal memorandum and a procurement list, and a contract rule is due by 19 December.

## 2030 is on 6 of the 7 calendars

![Exhibit 1: the post-quantum calendars of NIST, EO 14412, OMB M-26-15, NSA CNSA 2.0, UK NCSC, the EU roadmap and the G7 Cyber Expert Group, 2024 to 2035, with 2030 on six of seven.](https://livetradingnews-media.nyc3.digitaloceanspaces.com/media/2026/09/29/cmpgg3-4b6afb70147b4d04.svg)

*Exhibit 1. Every dated milestone, read from the primary documents. Each dot is quoted from the document on its row, and the figure fails to build if the quote is not in the text.*

- **NIST:** FIPS 203, 204 and 205 were published on 13 August 2024, per [FIPS 203](https://csrc.nist.gov/pubs/fips/203/final). The [NIST IR 8547 draft](https://csrc.nist.gov/pubs/ir/8547/ipd) marks quantum-vulnerable signatures at 112 bits of security "Deprecated after 2030" and "Disallowed after 2035".
- **NSA CNSA 2.0:** software and firmware signing is to "exclusively use CNSA 2.0 by 2030", and the national security systems transition is expected to be "complete by 2035", per the [CNSA 2.0 advisory](https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF).
- **OMB M-26-15:** 5 phases, discovery 2026 to 2027, pilots 2027 to 2028, key establishment 2028 to 2030, signatures 2031 and full migration 2035, per [M-26-15](https://www.whitehouse.gov/wp-content/uploads/2026/06/M-26-15-Execution-of-the-Migration-to-Post-Quantum-Cryptography.pdf).
- **UK NCSC:** goals and discovery by 2028, the highest-priority migration by 2031, and all systems, services and products by 2035, per the [NCSC timelines](https://www.ncsc.gov.uk/guidance/pqc-migration-timelines).
- **EU:** national strategies by the end of 2026, high-risk use cases completed by 31 December 2030, and no stand-alone quantum-vulnerable public-key mechanism in medium-risk use cases after the end of 2035, per the [EU roadmap v1.1](https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography).
- **G7 Cyber Expert Group:** 2030 to 2032 for critical financial systems and 2035 as the overall target, in a statement that "does not set guidance or regulatory expectations", per the [G7 roadmap](https://home.treasury.gov/system/files/136/G7-CEG-Quantum-Roadmap.pdf).

The NCSC is the one calendar without a 2030 milestone. It runs 2028, 2031 and 2035, so its highest-priority migration lands one year after the US and EU dates for their highest-risk systems.

## How the date reaches a vendor's code

The Order binds agencies. It reaches a vendor by five routes, and each one lands on a different team.

![Exhibit 2: knowledge graph of six federal instruments, EO 14412 sections 4(b), 5(d) and 6(c), OMB M-26-15 and the CISA product list, reaching agencies, contractors and a vendor's product.](https://livetradingnews-media.nyc3.digitaloceanspaces.com/media/2026/09/29/cmpgg3-2c5942812f52dcd4.svg)

*Exhibit 2. Solid edges are quoted from the primary text and checked when the figure is built. Dashed edges are this note's reading of how the obligation travels: through the contract.*

- **The contract:** section 6(c) gives the FAR Council 180 days, to 19 December 2026, to propose a rule requiring covered contractors to comply by 31 December 2030 with NIST's FIPS, "including all applicable FIPS incorporating PQC compliant algorithms".
- **The purchase:** the [CISA product categories list](https://www.cisa.gov/resources-tools/resources/product-categories-technologies-use-post-quantum-cryptography-standards) of 23 January 2026 says organisations "should acquire only PQC-capable products when planning acquisitions" in the categories it lists.
- **The build:** [OMB M-26-15](https://www.whitehouse.gov/wp-content/uploads/2026/06/M-26-15-Execution-of-the-Migration-to-Post-Quantum-Cryptography.pdf) says development practice "must mandate the use of PQC-agile libraries for all new applications", and that "API gateways and application workloads must be configured to issue and validate PQC-signed tokens".
- **The data:** the same memorandum tells agencies to prioritise "re-encrypting long-lived sensitive data using keys protected by PQC mechanisms".
- **The inventory:** section 5(d) gives CISA 270 days, to 19 March 2027, to set the "minimum elements for a cryptographic bill of materials".

Section 6(b) adds the validation side. NIST is to "accelerate validations of cryptographic modules" under the Cryptographic Module Validation Program, the queue a module joins before it can be sold as FIPS 140-3 validated.

## The runtimes moved first

Engineers already have a model to follow, and it is the platform under their code. [OpenSSL 3.5.0](https://github.com/openssl/openssl/blob/openssl-3.5/NEWS.md), released on 8 April 2025, added "Support for PQC algorithms (ML-KEM, ML-DSA and SLH-DSA)". It also changed its default TLS keyshares "to offer X25519MLKEM768", the hybrid of X25519 and ML-KEM-768. [Node.js 24.7.0](https://nodejs.org/en/blog/release/v24.7.0), released on 27 August 2025, put ML-KEM and ML-DSA into node:crypto.

The result is measurable. On 30 September a stock Node.js client, with no options set, negotiated X25519MLKEM768 on Node 22.23.3, 24.21.0 and 26.1.0, read from Cloudflare's trace endpoint. The same client fetching livetradingnews.com and kxco.ai negotiated X25519MLKEM768 too. Forced to X25519 alone, it got X25519, which is the control that shows the reading is real.

So for TLS 1.3 between current runtimes, post-quantum key establishment is already the default wherever the server offers the hybrid group. What no runtime upgrade reaches is what the application owns: every signature it makes, every token its gateway issues, every ciphertext it has stored and every key record it keeps. That work is dated 2030 and 2031, and it is in the codebase.

## What KXCO ships for it

KXCO publishes that application layer as open source on npm under Apache-2.0. Each package below was installed from the registry and imported on 30 September, at its latest version, and each release carries a provenance attestation.

- [kxco-post-quantum](https://www.npmjs.com/package/kxco-post-quantum) 1.7.7 carries ML-KEM-768, ML-DSA-65 and SLH-DSA from FIPS 203, 204 and 205, with ML-KEM-1024 and ML-DSA-87 behind the same API, and compact JWS signed with ML-DSA for the gateway.
- It passes 1,793 NIST ACVP test vectors with 0 failed, and 225 interoperability checks against liboqs, Bouncy Castle and the Python reference implementations with 0 failed, per its [CONFORMANCE.md](https://github.com/KnightsbridgeAIQ/kxco-post-quantum/blob/main/CONFORMANCE.md).
- On Node 24 and later its maths runs in OpenSSL 3.5, the same library the runtime already uses for TLS.
- [kxco-pq-vault](https://www.npmjs.com/package/kxco-pq-vault) 1.1.7 encrypts files and payloads to one or many recipients under ML-KEM-768 and AES-256-GCM, which is the long-lived data M-26-15 says to re-encrypt.
- [kxco-pq-scan](https://www.npmjs.com/package/kxco-pq-scan) 1.1.2 reads a lockfile, names each quantum-vulnerable package and the dependency that pulled it in, and writes a CycloneDX 1.6 cryptographic bill of materials.

CNSA 2.0 asks for Level V parameters, and in FIPS 203 and FIPS 204 those are ML-KEM-1024 and ML-DSA-87, both at security category 5. In kxco-post-quantum the move from the default Category 3 to those sets is a change of import. The [companion developer note](https://www.livetradingnews.com/the-2030-post-quantum-deadline-in-code-6-changes-and-the-test-for-each) on this desk walks each change in code, with the test that proves it.

## For institutions

The cryptography is free, works offline and needs nothing from KXCO. What KXCO sells is the part that has to be operated. A hosted key registry answers, at the moment a signature is checked, whether the key is active, revoked or rotated. Live revocation confirms that a signing key is still trusted now. An on-chain timestamp is anchored on Armature L1, where the chain itself checks it. A relay submits signed intents, so the institution never holds a token or runs a node. Support comes with an SLA and a named contact. It is priced in US dollars, per seat, per year. KXCO is a software company and holds no customer assets. Write to admin@kxco.ai, or start at [kxco.ai/contact](https://kxco.ai/contact).

## What to watch

The FAR Council's proposed rule is due by 19 December 2026, 180 days after the Order. It is the first draft of the contract clause that carries the 2030 date to every covered contractor. CISA's minimum elements for a cryptographic bill of materials follow by 19 March 2027, and from then a CBOM has a required shape.

## Sources

Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, 22 June 2026, 91 FR 38483, sections 1, 4(b), 5(d) and 6(b) to 6(c). OMB M-26-15, Execution of the Migration to Post-Quantum Cryptography, 24 June 2026. CISA, Product Categories for Technologies That Use Post-Quantum Cryptography Standards, 23 January 2026.

NIST FIPS 203 and FIPS 204, August 2024. NIST IR 8547 initial public draft, November 2024. NSA CNSA 2.0 Algorithms advisory. UK NCSC, Timelines for migration to post-quantum cryptography, 20 March 2025. EU Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, v1.1, 23 June 2025. G7 Cyber Expert Group financial-sector roadmap, January 2026.

OpenSSL NEWS for 3.5.0, 8 April 2025. Node.js 24.7.0 release notes, 27 August 2025. Key exchange measured by this desk with the stock node:https client against Cloudflare's /cdn-cgi/trace endpoint, 30 September 2026 at 00:27 Bangkok time, 17:27 UTC on 29 September. npm registry, 30 September 2026.

Shayne Heffernan, Ph.D., is the founder of Live Trading News, the KnightsBridge Group, Knightsbridge Law and the KXCO.ai ecosystem spanning post-quantum cryptography, identity, attestation and enterprise ontology.

*This note is commentary. It is not legal advice. Dates are as published by each authority on the day of writing. Read the primary text before you plan against a date.*

---

This Markdown mirrors https://www.livetradingnews.com/post-quantum-has-a-deadline-2030-for-keys-2031-for-signatures. The HTML page is canonical.
Site index for AI clients: https://www.livetradingnews.com/llms.txt
