Desk live·
ForensicPost
Nation-state/Cryptography/File 26-0427

NIST Finalises Three Post-Quantum Standards With Migration Deadlines From September 2026

NIST finalised three post-quantum standards — ML-KEM, ML-DSA and SLH-DSA — and migration deadlines begin from September 2026. The hard part was never the algorithm selection.

Constructed geometry · not a chart of case data
TargetPublic-key cryptography estate
ActorUnattributed
D. Kennedy11 min readConfidence: high3 sources reviewed

NIST concluded an eight-year standardisation process with three finalised standards: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures and FIPS 205 (SLH-DSA) as a hash-based signature backup, with a fourth expected in 2026. Migration deadlines begin from September 2026, with government contractors facing the strictest.

Selecting Algorithms Was The Easy Part

The standardisation process was long, public and adversarial in the productive sense: candidates were attacked, several were broken, and the survivors are better understood for it.

None of that helps with the actual problem, which is that an organisation does not know where its cryptography is. Public-key cryptography sits inside TLS terminators, VPN appliances, code-signing pipelines, hardware security modules, embedded devices, database drivers, payment terminals and a great deal of software nobody has looked at in a decade.

Cryptographic Inventory Is The Deliverable Nobody Has

A migration plan begins with a list of every place a vulnerable algorithm is used, what depends on it, and who can change it. Almost no organisation can produce that list, and building it is unglamorous discovery work rather than cryptography.

The edge appliances filed at 26-0311 are a good illustration. They terminate TLS, they run vendor firmware customers cannot inspect, and a fair proportion are past support. Migrating them is not a configuration change; for some it is a procurement.

Agility Is The Durable Requirement

The lasting lesson is not that RSA needs replacing. It is that organisations discovered they could not replace an algorithm quickly, which will be true again the next time a primitive weakens.

Systems where the algorithm is a configurable parameter rather than an assumption baked into a protocol implementation will handle this migration and the one after it. That is an architectural property worth acquiring for its own sake.

How we reported this

This is a standards file compiled from published NIST material and analysis, listed below. Deadline specifics vary by sector and jurisdiction; this is not compliance advice. Corrections: corrections@forensicpost.com.

Sources
  1. NIST finalizes 2026 technical requirements for post-quantum cryptographic infrastructure migrationGopher Security
  2. Post-quantum cryptography: 2026 complete guideITECS
  3. Post-quantum cryptography deadlines 2026Ciphers Security
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary