✅ The FIPS 140-2 → Historical transition happened Monday, September 21, 2026. Every active FIPS 140-2 certificate is now on the CMVP Historical list. For federal agencies and FedRAMP-authorized services: new procurement must cite a FIPS 140-3 certificate. Existing deployments using FIPS 140-2 modules on existing systems continue to function — this is a new-purchase restriction, not a retire-everything mandate.
⏰ Next major deadline: January 1, 2027 — 98 days away. NSA CNSA 2.0 requires that new national security system acquisitions initiated after January 1, 2027 support post-quantum algorithms. This applies to national security systems — NSS operators and their vendors should be confirming PQC capability roadmaps now, not in December.
Block 1 — Situation Update
📍 Where We Stand — The Week After the FIPS 140-2 Transition
The FIPS 140-2 Historical transition on September 21, 2026 was the single most concrete cryptographic compliance deadline of the year — and it passed. Here is what actually changed and what didn't.
What changed: The CMVP placed all active FIPS 140-2 certificates on the Historical list. For U.S. federal agencies, FedRAMP-authorized cloud service providers, HIPAA-covered entities relying on FIPS 140-2 for safe harbor decisions, and DoD/CMMC assessments — new procurement documentation submitted after September 21 must cite a FIPS 140-3 certificate number. Proposals, contracts, and system security plans referencing only a FIPS 140-2 certificate number are no longer compliant for new acquisitions.
What didn't change: Existing systems using FIPS 140-2 validated modules do not need to be immediately decommissioned or replaced. The Historical designation allows continued use in existing deployments — it restricts new purchases, not ongoing operations. An organization that deployed a FIPS 140-2 validated HSM two years ago does not need to swap it out this week. But when that HSM reaches end-of-life and requires replacement, the replacement must carry a FIPS 140-3 certificate.
The harder constraint most organizations missed: The FIPS 140-3 validation process now averages 542–590 days for the CMVP-controlled portion alone — roughly 2 to 3 years end-to-end. Any vendor not already in the CMVP validation pipeline will not have a new FIPS 140-3 certificate in time for the next round of federal procurement cycles. Organizations selecting new cryptographic vendors should be asking suppliers not whether they plan to pursue FIPS 140-3 validation, but what their CMVP queue entry date is.
Block 2 — Regulatory and Standards Timeline
🗓 Key Dates — Post-Transition View
Aug 13, 2024Past
NIST PQC Standards Finalized — FIPS 203 · 204 · 205
ML-KEM (key encapsulation), ML-DSA (digital signatures), SLH-DSA (stateless hash signatures) finalized. These are the algorithms organizations must migrate toward. All three are in the CMVP validation pipeline for module vendors.
Sep 21, 2026✓ Completed
FIPS 140-2 → Historical (CMVP) — NEW PROCUREMENT GATE
All FIPS 140-2 certificates moved to Historical status. New federal procurement, FedRAMP submissions, HIPAA safe harbor documentation, and CMMC assessments must now reference FIPS 140-3 certificates. Existing deployments continue to operate.
Jan 1, 202798 Days
NSA CNSA 2.0 — New NSS Acquisitions Must Support PQC
New National Security System acquisitions initiated after January 1, 2027 must support post-quantum algorithms from the CNSA 2.0 suite. NSS operators and their vendors need confirmed PQC capability roadmaps now. This is the next hard compliance gate for defense and intelligence supply chains.
~2030~1,280 Days
NIST IR 8547 — RSA and ECDH/ECDSA Deprecated in New Systems
NIST IR 8547 establishes 2030 as the deprecation date for RSA, ECDH, and ECDSA in new systems — meaning these algorithms should not be used in new deployments. Organizations with 3-5 year technology refresh cycles need to begin PQC migration planning now to hit this target in existing infrastructure. "Harvest Now, Decrypt Later" attacks make this earlier than it feels.
Jan 1, 2030~1,196 Days
NSA CNSA 2.0 — Preferred Algorithms for All New NSS Development
CNSA 2.0 PQC algorithms become the preferred choice for all new national security system development — not just supported but actively preferred over classical alternatives.
~2035~3,200 Days
NIST IR 8547 — RSA and ECDH/ECDSA Disallowed
RSA and elliptic curve algorithms disallowed entirely in FIPS-compliant applications. Any system still using classical public-key cryptography at this point will be non-compliant. This is the hard deadline but the migration work must be largely complete well before it — cryptographic migrations historically take 7-10 years end-to-end.
Block 3 — Algorithm and Standards Status
🔐 NIST PQC Algorithm Standards — Current Status
| Standard | Algorithm | Purpose | Status | Operational Note |
| FIPS 203 | ML-KEM (Kyber) | Key Encapsulation / Key Exchange | ✅ Finalized Aug 13, 2024 | Primary post-quantum key exchange algorithm. Already adopted in browser TLS — 57.4% of connections carry a hybrid ML-KEM key share (Cloudflare, early 2026). |
| FIPS 204 | ML-DSA (Dilithium) | Digital Signatures | ✅ Finalized Aug 13, 2024 | Primary post-quantum digital signature algorithm. Required for code signing, certificate issuance, and authentication in CNSA 2.0 compliant systems. |
| FIPS 205 | SLH-DSA (SPHINCS+) | Stateless Hash-Based Signatures | ✅ Finalized Aug 13, 2024 | Hash-based signature scheme — conservative security assumptions, larger signatures. Recommended for high-assurance scenarios where algorithm diversity is required. |
| FIPS 206 | FN-DSA (FALCON) | Digital Signatures | 🔄 Expected late 2026 | Compact lattice-based signatures — smaller than ML-DSA, relevant for bandwidth-constrained environments. Standardization in final stages. |
57.4%
of browser-initiated TLS connections carried a hybrid ML-KEM key share as of early 2026 (Cloudflare data). Browsers are already ahead of most enterprises on PQC deployment — while the average organization is still in the planning phase, their users' browsers are already negotiating post-quantum key exchange for HTTPS traffic. The gap between browser adoption and enterprise backend readiness is the 2026-2030 migration priority.
Block 4 — The Present-Day Risk
⚠ Harvest Now, Decrypt Later — Why 2030 Is Not Far Enough Away
The most common misread of the post-quantum timeline is treating it as a future problem. The harvest is happening now. Nation-state adversaries — specifically those with the resources and patience to play a decade-long intelligence game — are collecting encrypted traffic today with the explicit intention of decrypting it when cryptographically relevant quantum computers (CRQCs) become available.
This matters specifically for data with a long confidentiality shelf life: diplomatic communications, defense acquisition plans, long-term infrastructure designs, medical records, financial instruments, and any information whose value persists beyond 5-10 years. If that data is encrypted with RSA or ECDH today and a CRQC arrives in 2033, the adversary's 2026 harvest becomes 2033's intelligence windfall.
Recent research from Google Quantum AI has indicated that the quantum resources required to break widely used cryptography may be significantly lower than previous estimates, which has compressed already tight migration timelines. The practical implication: organizations protecting long-lived sensitive data should be treating PQC migration as a current operational priority, not a 2029 planning item.
The 2026 NQIRA legislation (National Quantum Initiative Reauthorization Act) formalized this urgency at the federal level — empowering NIST, NSF, NASA, and OSTP to advance real-world quantum capabilities and international cooperation. The legislation signals that the U.S. government is treating quantum readiness as an operational matter, not a research program.
Block 5 — This Week's Practical Checklist: Post-FIPS 140-2 Actions
✅ Post-Transition Actions for This Week
📋
Audit your CMVP certificate inventory. Pull your organization's list of FIPS-validated modules and identify which carry only FIPS 140-2 certificates vs. FIPS 140-3 certificates. The CMVP certificate database is searchable at
csrc.nist.gov/projects/cryptographic-module-validation-program. Any module showing only a 140-2 certificate is now in Historical status — flag it for replacement in your next procurement cycle.
📋
Update procurement templates and vendor questionnaires. Any RFP, RFQ, or vendor security questionnaire that asks for "FIPS 140-2 validation" needs to be updated to require "FIPS 140-3 validation." This is administrative but important — procurement documents referencing only FIPS 140-2 are now technically non-compliant for new federal acquisitions and will create audit findings.
📋
Ask your cryptographic vendors for their CMVP queue entry date. The FIPS 140-3 validation process takes 2-3 years end-to-end. If a vendor says they "plan to pursue FIPS 140-3 validation," the next question is when they entered the CMVP queue. A vendor who entered the queue in early 2026 may have a certificate by 2028-2029. A vendor starting today will not. Your long-term vendor selection for cryptographic infrastructure should account for this timeline.
👁
For NSS operators: begin January 1, 2027 CNSA 2.0 preparation now. 98 days is not enough time to retroactively build PQC algorithm support into a contract or acquisition that hasn't started. New national security system acquisitions initiated after January 1, 2027 must support CNSA 2.0 post-quantum algorithms — confirm with your acquisition teams that any contract actions planned for Q1 2027 include this requirement.
✅
Benchmark: EnQuanta QuantaCrypt (CMVP #5312) — currently the first and only FIPS 140-3 validated cryptographic module carrying all three NIST PQC algorithms (ML-KEM, ML-DSA, SLH-DSA). When evaluating new cryptographic modules, use this as a benchmark for what "fully PQC-capable FIPS 140-3 module" means in practice. Vendors claiming PQC readiness without a validated module are offering a roadmap, not a product.
👁
If your organization handles long-lived sensitive data: assess your HNDL exposure. Identify data categories in your environment whose confidentiality must be protected beyond 5-10 years. For each: identify the encryption algorithm protecting it in transit and at rest. Any RSA or ECDH-protected data in this category is harvest-now-decrypt-later exposed today. Prioritize PQC migration for this data above all other categories.
Block 6 — This Week's Log
📰 Notable Developments — Week of September 23, 2026
Sep 21, 2026FIPS 140-2 → Historical transition complete. All active FIPS 140-2 CMVP certificates moved to Historical status. New federal procurement must cite FIPS 140-3. Existing deployments unaffected operationally.
Sep 2026Browser ML-KEM adoption at 57.4%. Cloudflare telemetry confirmed that by early 2026, 57.4% of browser-initiated TLS connections carried a hybrid ML-KEM key share — demonstrating that the web's encryption layer is already transitioning to post-quantum hybrid key exchange ahead of most enterprise backends. The enterprise-to-browser gap is the defining migration challenge of 2026-2030.
2026NQIRA signed into law. The National Quantum Initiative Reauthorization Act formally empowers NIST (quantum measurement/sensing), NSF (multidisciplinary research), NASA (quantum communications and space-based quantum tech), and OSTP (international quantum cooperation strategy) to advance real-world quantum capabilities. Signals federal treatment of quantum readiness as operational, not theoretical.
OngoingGoogle Quantum AI research suggests lower-than-expected resource requirements to break classical cryptography. Updated estimates compress previously assumed migration timelines. Organizations using 2023-era quantum threat timeline assumptions should revisit their PQC roadmap planning horizons.
WatchingFIPS 206 (FN-DSA / FALCON) standardization in final stages. Expected late 2026. Compact lattice-based signatures relevant for bandwidth-constrained and embedded environments. Monitor NIST CSRC for publication date.
Watching47-day TLS certificate maximum. CA/Browser Forum has been advancing a proposal to reduce TLS certificate maximum validity from 398 days to 47 days — increasing crypto-agility pressure on certificate management infrastructure. Automation (ACME protocol, certificate lifecycle management platforms) becomes essential, not optional, if this passes. Monitor CA/Browser Forum ballots.