Reference Source

NIST cryptographic algorithm deprecation schedule: what is approved, deprecated, and disallowed, and when

Per-algorithm status under NIST guidance for the post-quantum cryptographic transition. Each record is one algorithm or key-length configuration with its current approval status (approved, acceptable, deprecated, restricted, disallowed, legacy use), the date at which the status changes, and the recommended replacement. Drawn from three NIST publications: IR 8547 (post-quantum transition timeline), SP 800-131A Rev 2 (current algorithm status rules) and Rev 3 draft (upcoming changes), and FIPS 203/204/205 (the post-quantum replacement standards). The key deadlines: quantum-vulnerable public-key algorithms (RSA, ECDSA, ECDH, finite-field DH) deprecated after 2030, disallowed after 2035; SHA-1 and 224-bit hashes deprecated through 2030, disallowed thereafter. AES-256 and SHA-2/SHA-3 are NOT on the deprecation schedule. Answers 'when is RSA deprecated?', 'is AES-256 affected by the post-quantum transition?', 'what replaces ECDSA?', and 'what is the current NIST status of 3DES?'

Records22
Sources4
Verified
Review by
LicenceUS government publication — public domain

The data

AlgorithmPurposeCurrent statusPlanned statusReplacementSource document
224-bit hash functionshashingAcceptableScheduled for retirement (SP 800-131A Rev 3 draft)SHA-256 or higherSP 800-131A Rev 3 draft (via EncryptionConsulting summary)
AES-256encryptionApprovedNo change plannedN/AIR 8547 (not on deprecation schedule, per EncryptionConsulting summary)
Classical algorithms below 112-bit security strengthall cryptographic purposesDisallowedNo change planned (already disallowed under Rev 2)Algorithms meeting minimum 112-bit security strengthSP 800-131A Rev 2 (March 2019)
DSA (signature generation)digital signatureDeprecatedDisallowed (SP 800-131A Rev 3 draft proposes retirement)ML-DSA (FIPS 204)SP 800-131A Rev 3 draft (via EncryptionConsulting summary)
ECB modeencryptionAcceptableDisallowed (SP 800-131A Rev 3 draft proposes retirement)CBC, CTR, GCM, or other approved modesSP 800-131A Rev 3 draft (via EncryptionConsulting summary)
ECDHkey establishmentApprovedDeprecated after 2030, Disallowed after 2035ML-KEM (FIPS 203)IR 8547, Section 3 (via EncryptionConsulting summary)
ECDSAdigital signatureApprovedDeprecated after 2030, Disallowed after 2035ML-DSA (FIPS 204)IR 8547, Section 3 (via EncryptionConsulting summary)
EdDSAdigital signatureApprovedDeprecated after 2030, Disallowed after 2035ML-DSA (FIPS 204)IR 8547, Section 3 (via EncryptionConsulting summary)
Falcondigital signatureSelected for standardizationPending FIPS standardN/APQC project page
Finite-field Diffie-Hellmankey establishmentApprovedDeprecated after 2030, Disallowed after 2035ML-KEM (FIPS 203)IR 8547, Section 3 (via EncryptionConsulting summary)
HQCkey establishmentSelected for standardizationPending FIPS standardN/APQC project page (selected March 2025)
ML-DSA (FIPS 204)digital signatureApprovedNo change plannedN/AFIPS 204 (August 2024)
ML-KEM (FIPS 203)key establishmentApprovedNo change plannedN/AFIPS 203 (August 2024)
Quantum-vulnerable public-key algorithms (general)digital signature and key establishmentApprovedDeprecated after 2030, Disallowed after 2035Post-quantum standards (FIPS 203, 204, 205)IR 8547 (Initial Public Draft, November 12, 2024)
RSA key transportkey establishmentApprovedDeprecated after 2030, Disallowed after 2035ML-KEM (FIPS 203)IR 8547, Section 3 (via EncryptionConsulting summary)
RSA PKCS#1 v1.5 (signatures)digital signatureApprovedDeprecated after 2030, Disallowed after 2035ML-DSA (FIPS 204)IR 8547, Section 3 (via EncryptionConsulting summary)
RSA-PSSdigital signatureApprovedDeprecated after 2030, Disallowed after 2035ML-DSA (FIPS 204)IR 8547, Section 3 (via EncryptionConsulting summary)
RSA (signatures)digital signatureApprovedDeprecated after 2030, Disallowed after 2035ML-DSA (FIPS 204)IR 8547, Section 3 (via EncryptionConsulting summary)
SHA-1hashingDeprecatedDisallowed (SP 800-131A Rev 3 draft proposes retirement)SHA-2 or SHA-3SP 800-131A Rev 2 / Rev 3 draft (via EncryptionConsulting summary)
SHA-2 familyhashingApprovedNo change plannedN/AIR 8547 (not on deprecation schedule, per EncryptionConsulting summary)
SHA-3 familyhashingApprovedNo change plannedN/AIR 8547 (not on deprecation schedule, per EncryptionConsulting summary)
SLH-DSA (FIPS 205)digital signatureApprovedNo change plannedN/AFIPS 205 (August 2024)

Where this came from

Every record above links the page it was taken from and quotes the sentence that states it. These are the 4 sources this dataset was assembled from.

Machine-readable

22 records. last verified against source . due for re-check by .

Licence. US government publication — public domain