Categories: QUANTUM

Canada’s Quantum Deadline Isn’t 2035. If You Sell to Ottawa, It Was April 1.

CETARK | ANALYSIS | POST-QUANTUM READINESS

Published 23 July 2026 · Cetark Post-Quantum Readiness practice

Quick answer: Canada’s federal post-quantum cryptography deadline is the end of 2035, with high-priority systems due by the end of 2031. But two milestones have already passed: since April 1, 2026, federal departments must hold PQC migration plans, and every new Government of Canada contract with a digital component must include post-quantum cryptography clauses. For suppliers, the deadline is not 2035 — it is already in the contract.

Canada’s post-quantum cryptography roadmap targets the end of 2035 — and that headline has done more damage to Canadian planning than almost any other number in security this decade.

Here’s the number that actually binds you. Since April 1, 2026, every Government of Canada contract with a digital component has been required to include post-quantum cryptography clauses (Treasury Board Secretariat, SPIN, October 2025). Not a recommendation. A procurement condition, already in force.

If you sell technology to a federal department — software, cloud, managed services, hardware with a network stack — the quantum transition is not a 2035 problem you’ll get to. It is a clause in the contract you are bidding on now. This is the plain-English version of what Canada has mandated, what the United States changed in June 2026, and what both mean for Canadian enterprises, contractors, and critical-infrastructure operators.

Key facts at a glance

Canada — full migration deadline End of 2035
Canada — high-priority systems End of 2031
Canada — PQC procurement clauses In force since April 1, 2026
Canada — cryptographic inventories due April 1, 2028
US — federal key establishment December 31, 2030
US — federal digital signatures December 31, 2031
US — covered contractors (FIPS compliance) December 31, 2030
Governing documents (Canada) ITSM.40.001 (June 2025); TBS SPIN (October 9, 2025)
Governing document (US) Executive order, June 22, 2026
Core standards ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205)

 

What is post-quantum cryptography?

Post-quantum cryptography (PQC) is a set of encryption algorithms that run on ordinary computers while resisting attacks from a future quantum computer powerful enough to break RSA and elliptic-curve cryptography — the public-key cryptography securing most of the internet today.

That future machine has a name in the guidance: a cryptographically relevant quantum computer, or CRQC. Nobody has built one. That is not the point.

Why can’t Canadian organisations wait for the quantum computer to exist?

Because the attack starts before the machine does.

The threat is called harvest now, decrypt later (HNDL): an adversary copies your encrypted traffic today, stores it, and decrypts it years later once a CRQC exists. Your data’s confidentiality window, not the quantum timeline, sets your deadline. If information you transmit in 2026 must stay secret until 2040 — patient records, case files, engineering drawings, sovereign or defence data, anything with a long legal retention period — it is already exposed, and no future patch retroactively protects a copy someone else holds.

The hardware estimates keep moving toward you, which is the part planners consistently underweight. A Google Quantum AI study found that a quantum computer with roughly one million noisy qubits could break RSA-2048 in about a week — a twenty-fold reduction from the same team’s 2019 estimate (Gidney, 2025, cited in CIGI, October 2025).

The literal takeaway: the migration deadline for your data is determined by how long that data must stay confidential, not by when a quantum computer is expected to arrive.

What did Canada actually mandate, and when?

Two documents do the work, and most coverage cites only the first.

The roadmap. The Canadian Centre for Cyber Security published Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada (ITSM.40.001) in June 2025. It covers non-classified systems — those handling UNCLASSIFIED, PROTECTED A, and PROTECTED B information — and sets the milestones everyone quotes.

The enforcement instrument. The Treasury Board Secretariat’s Security Policy Implementation Notice (SPIN), effective October 9, 2025, turns the roadmap into direction under the Policy on Government Security and the Policy on Service and Digital, monitored by TBS.

The milestones, precisely:

April 1, 2026 — departments hold a migration plan, and all new contracts with a digital component must include PQC clauses (in force)

April 1, 2028 — cryptographic inventories recorded; transition work begins

End of 2031 — high-priority systems migrated

End of 2035 — remaining systems migrated

Notice what the “2035” headline obscures: the binding milestones have either passed or fall inside the next twenty months.

Why does a government deadline reach private Canadian companies?

Through procurement — the mechanism is already running.

The SPIN requires that contracts with a digital component entered into after April 1, 2026 carry clauses aligned with the Cyber Centre’s recommended contract clauses for cryptography (ITSM.00.501). Those clauses demand three things of the supplier:

■ PQC that complies with Cyber Centre-approved algorithms (ITSP.40.111)

■ Cryptographic modules certified through the Cryptographic Module Validation Program (CMVP)

Cryptographic agility — the ability to change algorithms later through configuration rather than redevelopment

That third requirement is the one most vendors underestimate. Ottawa is not only asking whether your product is quantum-safe today; it is asking whether you can change your cryptography again without rebuilding the product. A supplier who hard-codes ML-KEM in 2026 has met the letter and missed the point.And the reach extends past federal walls. Canada’s roadmap does not directly bind provinces, municipalities, banks, or utilities — a real limitation, worth stating plainly. But federally regulated financial institutions already manage quantum risk under OSFI Guideline B-13 (Global Legal Insights, February 2026), and provincial and municipal buyers routinely inherit federal clause language through funding conditions and harmonised procurement. The clause travels.

What changed in the United States in June 2026?

The US pulled its own deadline forward by four to five years — and dragged its contractors with it.

On June 22, 2026, the White House issued an executive order, Securing the Nation Against Advanced Cryptographic Attacks, replacing the 2035 horizon that had stood since National Security Memorandum 10 in 2022.

The new dates:

December 31, 2030 — federal high-value assets and high-impact systems must use PQC for key establishment

December 31, 2031 — the same systems must use PQC for digital signatures

December 31, 2030 — the deadline the FAR Council must impose on “covered contractors” to comply with NIST FIPS incorporating PQC algorithms, via a rule proposed within 180 days of the order

National security systems sit on a separate track. The Department of War published its own strategy the following day, requiring its systems to support PQC by the end of 2030 and use it by the end of 2031 (US Department of War PQC Strategy, June 23, 2026).

For a Canadian company, that matters for one reason: if you sit anywhere in a supply chain that terminates at a US federal agency, you inherit a 2030 date — regardless of what Canada’s roadmap says.

Canada vs United States: how do the post-quantum deadlines compare?

Canada United States
Full migration deadline End of 2035 System-tier based
Priority systems End of 2031 End of 2030 (key establishment)
Contractor obligation PQC clauses in federal contracts since April 1, 2026 FIPS compliance by December 31, 2030
Inventory deadline April 1, 2028 Directed under the June 2026 order
Instrument Roadmap (ITSM.40.001) + TBS SPIN Executive order

 

The short version: the US moved faster on the end date; Canada moved faster on the contract. A Canadian supplier feels Canada’s rules first, and a US federal deadline second.

──

Two governments, two timetables. Which one applies to you?

Both, if you sell to both. Neither, formally, if you sell to neither — which is exactly where the trap sits.

→ Sell to the Government of Canada → PQC clauses are in your contracts now

→ Sell into a US federal supply chain → a 2030 FIPS compliance line is coming through acquisition rules

→ Federally regulated financial institution in Canada → quantum risk already belongs in your B-13 programme → Critical infrastructure under Bill C-8’s cyber-security regime → the security baseline is rising around you regardless

→ None of the above, but you hold data that must stay confidential past 2030 → HNDL is your deadline, and no one will send you a memo about it

The standards are not the obstacle. NIST finalised the core algorithms in August 2024 — ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures — and added HQC as a backup in March 2025. The migration is an engineering and inventory problem now, not a research one. Deployment is already past theory: more than two-thirds of browser traffic to Cloudflare’s network is protected with post-quantum encryption (Cloudflare, June 2026).

What should Canadian organisations do first?

Find your cryptography. Everything else waits on it.

Every roadmap on both sides of the border puts the same task first, because it is the one that takes longest and the one nobody has budgeted. You cannot migrate what you cannot see, and most organisations discover their real cryptographic footprint only when they go looking: hard-coded algorithms in legacy applications, expired-vendor appliances, certificates nobody owns, embedded crypto in operational technology that was never inventoried because it was never considered IT.

Three moves that follow directly from the published guidance:

  1. Build the cryptographic inventory now. Canada’s own timeline gives departments until April 2028 to record algorithms, protocols, vendors, versions, dependencies, and contract expiry dates. If the federal government needs two years for this, your estimate is probably wrong too.
  2. Classify data by confidentiality lifespan, not by system. The systems to migrate first are the ones carrying data that must stay secret longest — Canada’s guidance points specifically at information in transit over public network zones as the priority HNDL exposure.
  3. Demand cryptographic agility in what you buy and build. It’s in the federal clause for a reason. The organisations that will migrate again in 2035 without pain are the ones that make algorithm changes a configuration decision today.

Post-quantum readiness is one of the four capabilities Cetark is built around, and our position here is not theoretical: with operations across Canada, the United States, Singapore, Estonia, and India, we sit inside several of these regimes at once, and inherit their clauses the same way our clients do. The work that closes this gap is unglamorous — discovery, inventory, prioritisation by data lifespan, and enough operational discipline to keep the answers current as systems change. For Canadian organisations working out which of these deadlines is theirs, and what to do in the next twelve months rather than the next decade, that is the conversation we’re having every week.

Cetark. Constant Vigilance. Relentless Defence.

Frequently asked questions

What is Canada’s post-quantum cryptography deadline? Canada’s federal deadline is the end of 2035 for full migration, and the end of 2031 for high-priority systems. Two earlier milestones already passed: since April 1, 2026, departments must hold PQC migration plans and all new federal contracts with a digital component must include PQC clauses.

Does Canada’s PQC roadmap apply to private companies? Not directly. It binds federal departments and their non-classified systems. It reaches private companies through procurement: since April 1, 2026, federal contracts with a digital component must include PQC clauses requiring approved algorithms, CMVP-certified modules, and cryptographic agility.

Is post-quantum cryptography mandatory in Canada? Yes for federal departments, and yes in practice for their suppliers. The Treasury Board SPIN, effective October 9, 2025, makes PQC migration mandatory direction for departments and requires PQC clauses in new contracts with a digital component from April 1, 2026.

What is the US post-quantum deadline for federal contractors? December 31, 2030. The executive order of June 22, 2026 directs the FAR Council to require covered contractors to comply with NIST FIPS incorporating post-quantum algorithms by that date. Federal agencies must adopt PQC for key establishment by end of 2030 and signatures by end of 2031.

What is harvest now, decrypt later? Harvest now, decrypt later is an attack where an adversary copies encrypted data today and stores it until a quantum computer can break the encryption, then decrypts it. Data with a long confidentiality requirement is already at risk today, regardless of when quantum computers arrive.

What are the NIST post-quantum cryptography standards? NIST finalised three standards in August 2024: ML-KEM (FIPS 203) for key establishment, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. HQC was selected in March 2025 as a backup key-establishment algorithm.

What is cryptographic agility? Cryptographic agility is the ability to change cryptographic algorithms through configuration rather than redevelopment. Canada’s federal contract clauses require it, because organisations that hard-code today’s algorithms will face the same migration problem again at the next standards change.

Does Canada have a quantum-safe requirement for banks? There is no PQC-specific mandate for Canadian banks. Federally regulated financial institutions are expected to manage quantum risk within their technology and cyber risk programmes under OSFI Guideline B-13, rather than under the federal roadmap, which binds government departments only.

What should an organisation do first about post-quantum migration? Build a cryptographic inventory. Identify where public-key cryptography is used across systems, applications, network services, and operational technology, recording algorithms, vendors, versions, and contract expiry dates. Both roadmaps place inventory before migration.

Sources and further reading:

→ Canadian Centre for Cyber Security — Roadmap for the Migration to Post-Quantum Cryptography for the Government of Canada (ITSM.40.001), June 2025: https://www.cyber.gc.ca/en/guidance/roadmap-migration-post-quantum-cryptography-government-canada-itsm40001

→ Treasury Board of Canada Secretariat — Migrating the Government of Canada to Post-Quantum Cryptography: Security Policy Implementation Notice, effective 9 October 2025: https://www.canada.ca/en/government/system/digital-government/policies-standards/spin/migrating-government-canada-post-quantum-cryptography.html

→ Cyber Centre — Recommended contract clauses for cryptography (ITSM.00.501): https://www.cyber.gc.ca/en/guidance/recommended-contract-clauses-cryptography-itsm00501

→ Cyber Centre — Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information (ITSP.40.111): https://www.cyber.gc.ca/en/guidance/cryptographic-algorithms-unclassified-protected-protected-b-information-itsp40111

→ Cyber Centre — Guidance on becoming cryptographically agile (ITSAP.40.018): https://www.cyber.gc.ca/en/guidance/guidance-becoming-cryptographically-agile-itsap40018

→ The White House — Securing the Nation Against Advanced Cryptographic Attacks, 22 June 2026: https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/

→ NIST — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA), August 2024; HQC selected March 2025

→ CIGI — Canada’s Migration to Post-Quantum Cryptography, October 2025 (citing Gidney, Google Quantum AI, 2025): https://www.cigionline.org/documents/3579/PQC.indd_revised_of0tjcX.pdf

→ Cloudflare — post-quantum adoption data, June 2026: https://blog.cloudflare.com/post-quantum-eo-2026/

 

Cetark

Share
Published by
Cetark

Recent Posts

The Lifecycle of Stolen Data from Data Breach to Sale

When data is stolen in a breach, it embarks on a journey through the criminal…

2 years ago

Global Space Threats: The Rise of Counterspace Capabilities

The 2024 Space Threat Assessment, published by the Center for Strategic and International Studies (CSIS), highlights…

2 years ago

Fortifying Industrial Control Systems: Strategic Defense Enhancing ICS Security with Network Segmentation and Isolation

Enhancing the security of industrial control systems (ICS) is critical, and executing network segmentation and…

2 years ago

Upgrading Cybersecurity: A Close Look at the NIST Cybersecurity Framework 2.0

Concerned about how the NIST Cybersecurity Framework 2.0 will change your approach to cybersecurity? The…

2 years ago

Smart Cybersecurity: Exploring the Role of AI and Machine Learning in Enhancing Continuous Threat Exposure Management (CTEM)

How do AI and machine learning redefine the role of AI and machine learning in…

2 years ago

Phishing 101: Essential Tips to Identify and Protect Against Cyber Scams

What exactly is phishing, and how can you recognize and prevent it? Our Phishing 101…

2 years ago