Bairo GonzalezLeandro · Martinez

In the world · Science · 23 June 2025

Post-quantum migration: the 2030 and 2035 deadlines

The US and EU have set dates: algorithms like RSA are phased out between 2030 and 2035, and high-risk uses must migrate by the end of 2030. What it takes.

bairogonzalez.com team, drawing on Bairo's story · Published

Replacing the cryptography that protects digital life now has a calendar. Under the NIST draft published in November 2024, the most widely used public-key algorithms today, such as RSA and elliptic curves, become deprecated after 2030 and disallowed after 2035 in systems that follow U.S. rules. On June 23, 2025, the European Union published its roadmap: each country must have a strategy by the end of 2026, and high-risk uses must migrate to post-quantum cryptography by the end of 2030.

What happened

After publishing the post-quantum standards in August 2024, NIST put document IR 8547, on the transition, out for comment. Its central table is simple. Signatures and key exchanges using RSA and elliptic curves at the 112-bit security level become deprecated after 2030. All of them, at any level, become disallowed after 2035. The year 2035 comes from the White House's National Security Memorandum 10, which set that date as the goal for mitigating quantum risk in federal systems.

In Europe, the member states' cybersecurity cooperation group published the coordinated roadmap, presented by the European Commission as the first high-level document on the subject addressed to the bloc's countries. It calls for three steps: launch national strategies and pilots by the end of 2026; migrate high-risk cases as soon as possible, by the end of 2030 at the latest; and complete the transition of medium-risk cases by 2035. The text notes that the United Kingdom has also adopted 2035 as its target.

CSO Online, reporting on NIST's calendar, recorded analysts' warning: well-resourced governments may get there first, which is why companies need to move faster than the official deadlines suggest.

Why it matters

A 2035 deadline seems far off, but it is not. Replacing cryptography means touching servers, applications, cards, certificates, industrial equipment and supplier contracts. Large organizations take years just to find out where the old cryptography is.

There is also the risk that does not wait for deadlines: data copied today can be opened tomorrow. That is why the European roadmap says that, when confidentiality must last many years, the transition should be completed as soon as possible, and by the end of 2030 at the latest.

For Brazilian companies that sell to Europe or connect to U.S. systems, these calendars end up becoming practical requirements from clients and partners.

In Bairo's view

For Bairo, a deadline announced ten years in advance is a rare gift. He learned in his own life that problems rarely give notice before they arrive. In his reading, those who start protecting themselves early are not afraid; they have time.

That is the benefit he proposes with qrqbits: that ordinary people, and not just large companies, have access to post-quantum protection for their own files, images, audio and texts. The mechanism is proprietary and not public. The promise is the result: what is intimate stays protected after 2030 as well.

He always keeps things separate. Post-quantum is the mathematics of protection. The 1420, which names the project he founded, is another order of idea: a symbol of silence and listening, the hydrogen's 21 cm yardstick. No one transmits on 1420 MHz.

Where this meets the ecosystem

qrqbits is the protection layer Bairo proposes for the other fronts. At CEASA Bank, an agribusiness financial platform, the planned digital vault keeps harvest documents, invoices and contracts. On the BTZ Chain, records need to remain verifiable for many years. In both cases, the 2030 and 2035 calendars are the design horizon.

Sources

Read also