The Quantum Deadline Stopped Being Hypothetical
Every major cybersecurity framework points the same direction: know what cryptography you have, prove you control it, and be ready to change it. Post-quantum cryptography (PQC) is where that direction finally gets a deadline, which makes post-quantum readiness in manufacturing an operational priority rather than a research topic.
The shift is a call for clarity, not alarm. The algorithms protecting your certificates, keys, and signed firmware today will not protect them forever, and regulators have now written down when that transition needs to happen. This guide covers the dates, why they arrive sooner than they appear, and how quantum-safe readiness maps to controls you can build today.
Why Manufacturing Is Now One of the Most Exposed Sectors
Manufacturing has moved from a relatively insulated industry to one of the most exposed sectors for cryptographic risk. Industry 4.0 and IT/OT convergence connected programmable logic controllers (PLCs), sensors, and industrial control systems that once sat isolated on the factory floor.
That connectivity widened the cryptographic attack surface at the same time the rules governing cryptography grew more specific. Every connected device now depends on certificates, keys, and algorithms that regulators expect you to inventory, govern, and eventually migrate.
The Timeline, Written Down
The post-quantum transition is no longer general guidance. Across the United States and beyond, technical recommendations have hardened into policy with named dates.
From Technical Guidance to Federal Policy
In August 2024, NIST finalized its first three post-quantum standards: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA). NIST’s transition report, draft NIST IR 8547, proposes deprecating RSA and elliptic curve cryptography after 2030 and disallowing them after 2035.
On June 22, 2026, Executive Order 14412 (“Securing the Nation Against Advanced Cryptographic Attacks”) turned that guidance into policy. It directs an accelerated national migration led by OMB and the National Cyber Director, directs OMB to issue guidance requiring agencies to transition all high value assets and high impact systems to PQC for key establishment by December 31, 2030 and for digital signatures by December 31, 2031, excludes national security systems, and directs NIST to run a migration pilot on a subset of its own systems, to be completed by December 31, 2027.
Two days later, OMB issued Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography.” It lays out a five-phase schedule running through 2035 prioritized key establishment migration in 2028 to 2030, signature migration in 2031, and remaining systems by 2035. It requires agency migration plans within 120 days, and points agencies toward a centralized cryptographic bill of materials (CBOM) as a live view of cryptographic posture.
The Non-US Clock Runs in Parallel
Outside the United States, a parallel clock is running. The EU Coordinated Implementation Roadmap (published by the NIS Cooperation Group in June 2025, following Commission Recommendation (EU) 2024/1101) recommends that national transition strategies and cryptographic inventories start by the end of 2026, high risk use cases transition by the end of 2030, and remaining systems transition by the end of 2035. It is a recommendation to Member States rather than directly binding law.
NIS2 already sets a baseline: Article 21(2)(h) requires in-scope entities to have policies and procedures on the use of cryptography and, where appropriate, encryption. On January 20, 2026, the Commission published COM(2026) 13, a proposed amending directive adding Article 7(2)(k), which would require Member States to include PQC transition policies in their national cybersecurity strategies. That proposal is still in the ordinary legislative procedure and the obligation sits on Member States, so treat it as direction of travel.
The Cyber Resilience Act (Regulation (EU) 2024/2847) adds product-level requirements. Its Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents applied from September 11, 2026 (a 24-hour early warning and a 72-hour full notification, and a final report, all via the ENISA Single Reporting Platform). Its Annex I essential requirements apply from December 11, 2027, and include a software bill of materials (SBOM) in a commonly used machine-readable format covering at least top-level dependencies, protection of data at rest and in transit using state of the art mechanisms, and a support period of, as a rule, at least five years.
The Two Provisions That Matter Most for Manufacturers
Two provisions carry the most weight for manufacturers. First, the FAR Council is directed to publish a proposed rule requiring covered contractors to comply by December 31, 2030 with NIST’s FIPS, including those incorporating PQC algorithms, and a separate proposed rule requiring contractor vulnerability disclosure policies that cover cryptographic vulnerabilities. Once finalized, these rules push the obligation directly into the supply chain.
Second, CISA (with NIST) is to publish minimum elements for a CBOM, a machine-readable inventory of cryptographic assets (certificates, keys, algorithms, and libraries) in any hardware or software element. The CBOM is expected to follow the SBOM trajectory, moving from a procurement requirement to a standard commercial expectation.
Why the Dates Are Closer Than They Look
A 2030 or 2035 target can feel comfortably distant. For manufacturers, three realities pull those dates much closer.
Long-Lived Assets Outlive Today’s Algorithms
Industrial control systems and embedded devices routinely run 15 to 25 years or more. A PLC commissioned this year will still be running when RSA and ECC are disallowed, so equipment shipping today must be planned for a cryptographic world that does not yet exist on the factory floor.
Jetzt ernten, später entschlüsseln
Proprietary process data and control-plane traffic encrypted today can be captured now and decrypted once quantum capability arrives. The sensitivity horizon of the data, not the arrival of a quantum computer, sets the real deadline. If information needs to stay confidential for a decade, its clock has already started.
Procurement Moves Faster Than Regulation
Federal buyers, critical infrastructure operators, and prime contractors will ask suppliers for PQC migration plans and cryptographic inventories before any rule formally requires it. Procurement questionnaires tend to outrun regulation, so the practical deadline is the day a major customer asks, not the day a mandate takes effect.
One Foundation Satisfies Many Frameworks
The frameworks look different on the surface, but they converge on one foundation. The CRA’s cryptographic component visibility, IEC 62443’s algorithm inventory requirements, NIS2’s cryptography policy mandate, and SP 800-82’s key lifecycle documentation all point to the same underlying capability that the CBOM formalizes.
That convergence is good news. A single, well-governed cryptographic inventory answers these requirements at once: build the foundation once, and satisfy many frameworks with the same work.
How PQC Readiness Maps to Cryptographic Controls
Post-quantum readiness in manufacturing becomes concrete when you map it to specific cryptographic controls. Four control areas cover most of the work.
Kryptografisches Inventar und CBOM-Bereitschaft
Start by discovering and inventorying certificates, keys, algorithms, and embedded cryptographic libraries across IT, OT, and product firmware. This inventory is the raw material for a CBOM and the prerequisite for every decision that follows.
Bewertung der Anfälligkeit gegenüber Quantencomputern
Next, analyze the cryptography you discovered against the approved algorithms (FIPS 203, 204, and 205) and the NIST IR 8547 deprecation schedule. Prioritize remediation by data sensitivity and asset lifespan so the longest-lived, most sensitive systems move first.
PQC-Capable Certificate Issuance and Crypto-Agility
Then build the ability to issue certificates using NIST-standardized PQC algorithms, including hybrid certificates for staged migration. Crypto-agility means you can rotate, reissue, and re-key at fleet scale rather than one certificate at a time.
PQC-konforme Code- und Firmware-Signierung
Finally, sign firmware and software with quantum-resistant algorithms across the full support period. For products that ship into the field for years, signing has to stay valid and updatable long after the device leaves the factory.
Questions to Gauge Your Exposure
Use these questions as a self-assessment of your current post-quantum readiness:
- Do you have a complete cryptographic inventory across IT, OT, and shipped products, including inherited dependencies?
- Have you classified quantum vulnerability against the NIST deprecation schedule, ranked by data sensitivity and asset lifespan?
- Is there a named owner, a documented migration plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates?
- Do you have compensating controls or replacement plans for long-lived devices that cannot be re-keyed in the field?
- Could you produce a CBOM today if a federal customer asked for one?
- Do you know the PQC posture of your suppliers, whose cryptography becomes your exposure?
What to Do Now
Readiness is an ongoing capability, not a one-time project. A practical, non-alarmist starting sequence looks like this:
- Verschaffen Sie sich einen Überblick über kryptografische Ressourcen in den Bereichen IT und OT.
- Assess that cryptography against current and near-term requirements.
- Automate certificate and key lifecycle management before gaps become outages.
- Begin evaluating quantum vulnerability for long-lived systems and intellectual property.
Each step builds on the last and delivers value before the deprecation dates arrive.
Wie Keyfactor helfen Keyfactor
Keyfactor maps directly to the four control areas above. For cryptographic inventory and CBOM readiness, Keyfactor Command and AgileSec discover and inventory certificates, keys, algorithms, and embedded cryptographic libraries across IT, OT, and product firmware.
For quantum vulnerability assessment, AgileSec analyzes discovered cryptography against the approved algorithms (FIPS 203, 204, and 205) and the NIST IR 8547 deprecation schedule, prioritizing by data sensitivity and asset lifespan. For PQC-capable certificate issuance, EJBCA issues certificates using NIST-standardized PQC algorithms, and Command with EJBCA delivers the crypto-agility to rotate, reissue, and re-key at fleet scale. For PQC-ready code and firmware signing, SignServer and Signum sign firmware and software with quantum-resistant algorithms across the full support period.
Together these products position Keyfactor as a single system of record, the Trust Control Plane, that makes PQC readiness repeatable across long-lived manufacturing fleets. From one platform you can observe, analyze, provision, orchestrate, and govern every cryptographic asset and machine identity across IT, OT, and shipped products.
A Program, Not a Project
Post-quantum readiness is a program, not a project. The governance foundation you build now becomes a competitive advantage: organizations with mature crypto visibility and lifecycle management move faster through vendor security assessments, respond better to audits, and recover faster from certificate expirations and algorithm changes.
The dates are written down, and the shift is a call for clarity, not alarm. Start with cryptographic visibility, and the rest of the program has somewhere solid to stand.
See how Keyfactor helps you build post-quantum readiness across your long-lived manufacturing fleets. Request a Demo.
Got Post-Quantum Readiness Questions? We’ve Got Answers.
When do RSA and ECC stop being allowed?
Under draft NIST IR 8547, RSA and elliptic curve cryptography at 112-bit security strength are deprecated after 2030, meaning continued use requires accepted risk, and disallowed after 2035. For federal high value assets and high impact systems, EO 14412 sets earlier fixed dates: key establishment by December 31, 2030 and digital signatures by December 31, 2031.
What is Executive Order 14412, and does it apply to manufacturers?
EO 14412 is a June 2026 order that converts NIST post-quantum guidance into federal policy. Manufacturers are not audited under it directly, but its procurement provisions push PQC-aligned requirements into federal supply chains by the end of 2030. The execution detail sits in OMB Memorandum M-26-15.
What is a CBOM?
A CBOM is a machine-readable inventory of cryptographic assets (certificates, keys, algorithms, and libraries) inside any hardware or software element. CISA and NIST are set to publish minimum elements for it. It is expected to follow the same path the SBOM took, from procurement requirement to standard commercial expectation.
Why act before quantum computers exist?
Because of harvest now, decrypt later: data encrypted today can be captured now and decrypted once quantum capability arrives. The sensitivity horizon of your data sets the real deadline, not the arrival date of a quantum computer. If information must stay confidential for years, its clock is already running.
How does PQC readiness relate to the CRA, IEC 62443, and NIS2?
These frameworks converge on the same cryptographic inventory foundation that the CBOM formalizes. Build that foundation once, and you can help satisfy all of them with the same work. That is why a single inventory is such a high-leverage first step.
What is the first step toward PQC readiness?
Visibility is the first step: inventory every certificate, key, algorithm, and cryptographic library across IT and OT. Without a complete inventory, you cannot assess exposure or plan a migration. Everything else in the program builds on it.
What should a PQC migration plan include?
A migration plan should have a named owner, a documented plan, and a timeline aligned to the 2030 deprecation and 2035 disallowance dates. It should also address long-lived assets that cannot be re-keyed in the field and account for your suppliers’ PQC posture. Compensating controls or replacement plans cover the devices you cannot update remotely.
Do we need to worry about our suppliers’ cryptography?
Yes, because inherited cryptography becomes your exposure. The CRA takes the same approach to vulnerabilities. From December 11, 2027, manufacturers must exercise due diligence on integrated third-party components and report vulnerabilities they identify to the entity maintaining the component.