Cryptographic algorithm deprecation timeline
When does each algorithm stop being allowed? Pick an algorithm and a year to see its status under NIST SP 800-131A Rev.3 (the current draft), NSA CNSA 2.0, and BSI TR-02102-1. The dates come straight from the standards, because the widely-repeated ones are often out of date.
Status at a glance (NIST SP 800-131A Rev.3 & BSI TR-02102-1)
Deprecated = still allowed but discouraged; disallowed = not allowed for applying protection (legacy verification/decryption may continue). Rev.3 is an initial public draft; treat dates as proposed until it is final. The BSI column reflects the German BSI TR-02102-1 (v2026-01), which targets a >=120-bit security level: RSA/DH >=3000-bit, ECC >=250-bit.
| Algorithm | Through 2030 | After 2030 | BSI TR-02102-1 | Note |
|---|
The "RSA-2048 disallowed in 2035" figure is stale. That was NIST SP 800-131A
Rev.2. Rev.3 changed strategy to a single step straight to quantum-resistant algorithms, and
lists 112-bit algorithms (RSA-2048, etc.) as acceptable through 2030 then deprecated — with
no fixed disallow year announced. Many sites still quote the retired 2035 date.
BSI (Germany) is stricter on key length and has firm PQC dates. BSI TR-02102-1
(v2026-01) requires RSA and finite-field DH keys of at least 3000 bits and elliptic
curves of at least 250 bits for a >=120-bit security level, so RSA-2048 already falls
short under BSI. It recommends classic key agreement only until the end of 2031, with
migration to quantum-safe mechanisms by the end of 2030 for high-protection uses, and limits its
guidance horizon to the end of 2032.
Frequently asked questions
Sources. NIST SP 800-131A Rev.3 (initial public draft, Oct 2024) — algorithm
transition tables. NSA CNSA 2.0 — CSA (Sept 2022) and the current CNSA 2.0 & Quantum Computing FAQ (Dec 2024, v2.1) — for the
National Security Systems deadlines (mandated for use by Dec 31, 2031). Dates are reproduced from those documents; verify against the primary
source before relying on them in a design or compliance decision. BSI TR-02102-1 (v2026-01, Jan 2026) key-length minimums and PQC horizon are reproduced in the BSI column. PCI-DSS generally tracks NIST and is not reproduced here. Not legal or compliance advice.
See the PQC migration lookup →