Reference Source

NIST cryptographic algorithm deprecation schedule: what is approved, deprecated, and disallowed, and when

Per-algorithm status under NIST guidance for the post-quantum cryptographic transition. Each record is one algorithm or key-length configuration with its current approval status (approved, acceptable, deprecated, restricted, disallowed, legacy use), the date at which the status changes, and the recommended replacement. Drawn from three NIST publications: IR 8547 (post-quantum transition timeline), SP 800-131A Rev 2 (current algorithm status rules) and Rev 3 draft (upcoming changes), and FIPS 203/204/205 (the post-quantum replacement standards). The key deadlines: quantum-vulnerable public-key algorithms (RSA, ECDSA, ECDH, finite-field DH) deprecated after 2030, disallowed after 2035; SHA-1 and 224-bit hashes deprecated through 2030, disallowed thereafter. AES-256 and SHA-2/SHA-3 are NOT on the deprecation schedule. Answers 'when is RSA deprecated?', 'is AES-256 affected by the post-quantum transition?', 'what replaces ECDSA?', and 'what is the current NIST status of 3DES?'

Records21
Sources2
Verified
Review by
LicenceUS government publication — public domain

The data

AlgorithmPurposeCurrent statusPlanned statusReplacementSource document
224-bit hash functionshashingApprovedretirement scheduled under SP 800-131A Rev 3 draftSHA-2 or SHA-3 at 256-bit or higher outputSP 800-131A Rev 3 draft
AES-256encryptionApprovednot on the scheduleN/AIR 8547
Classical algorithms below 112-bit security strengthvariousDisallowedminimum moves from 112 bits to 128 bits at the end of 2030algorithms at 128-bit security strength or higherSP 800-131A Rev 2 / Rev 3 draft
DSA (signature generation)digital signatureDeprecatedretired under SP 800-131A Rev 3 draftECDSA, EdDSA, or ML-DSA (FIPS 204)SP 800-131A Rev 3 draft
ECB confidentiality modeencryptionApprovedretired under SP 800-131A Rev 3 draftCBC, CTR, GCM, or other approved modesSP 800-131A Rev 3 draft
ECDHkey establishmentApproveddeprecated after 2030 and disallowed after 2035ML-KEM (FIPS 203)IR 8547
ECDSAdigital signatureApproveddeprecated after 2030 and disallowed after 2035ML-DSA (FIPS 204)IR 8547
EdDSAdigital signatureApproveddeprecated after 2030 and disallowed after 2035ML-DSA (FIPS 204)IR 8547
Falcondigital signatureselected for ongoing standardizationstandardization underwayN/A (this is a future post-quantum standard)NIST PQC project
finite-field Diffie-Hellmankey establishmentApproveddeprecated after 2030 and disallowed after 2035ML-KEM (FIPS 203)IR 8547
HQCkey establishmentselected for ongoing standardizationstandardization underwayN/A (this is a future post-quantum standard)NIST PQC project
ML-DSA (FIPS 204)digital signatureApprovedpost-quantum standard, published August 2024N/A (this is the replacement)FIPS 204
ML-KEM (FIPS 203)key establishmentApprovedpost-quantum standard, published August 2024N/A (this is the replacement)FIPS 203
RSA key transportkey establishmentApproveddeprecated after 2030 and disallowed after 2035ML-KEM (FIPS 203)IR 8547
RSA PKCS#1 v1.5 (signatures)digital signatureApproveddeprecated after 2030 and disallowed after 2035ML-DSA (FIPS 204)IR 8547
RSA-PSSdigital signatureApproveddeprecated after 2030 and disallowed after 2035ML-DSA (FIPS 204)IR 8547
RSA (signatures)digital signatureApproveddeprecated after 2030 and disallowed after 2035ML-DSA (FIPS 204)IR 8547
SHA-1hashingDeprecatedretirement scheduled under SP 800-131A Rev 3 draftSHA-2 or SHA-3SP 800-131A Rev 3 draft
SHA-2 familyhashingApprovednot on the public-key scheduleN/AIR 8547
SHA-3 familyhashingApprovednot on the public-key scheduleN/AIR 8547
SLH-DSA (FIPS 205)digital signatureApprovedpost-quantum standard, published August 2024N/A (this is the replacement)FIPS 205

Where this came from

Every record above links the page it was taken from and quotes the sentence that states it. These are the 2 sources this dataset was assembled from.

Machine-readable

From your own code

Same records, same quotes, without scraping the page: refsource is on PyPI and npm. Each value comes back carrying the URL it was read from and the sentence on that page that states it — .source and .quote sit on the value itself rather than in a side channel, so the checking step is available instead of skipped.

pip install refsource
refsource lookup nist-cryptographic-algorithm-deprecation-schedule algorithm="224-bit hash functions"

npx -y refsource lookup nist-cryptographic-algorithm-deprecation-schedule algorithm="224-bit hash functions"

Set your AI assistant up to use this

Two files and no account. Put this in .mcp.json at the root of your project — Claude Code, Cursor, Windsurf, VS Code and Codex all read that file — and your assistant can look this dataset up instead of recalling it. The server is remote, keyless and read-only.

{
  "mcpServers": {
    "referencesource": {
      "type": "http",
      "url": "https://referencesource.org/mcp"
    }
  }
}

Add to Cursor · or, on the command line: claude mcp add --transport http referencesource https://referencesource.org/mcp --scope project

Then one line in the project's CLAUDE.md or AGENTS.md, so the assistant knows when to reach for it:

When a question needs "NIST cryptographic algorithm deprecation schedule: what is approved, deprecated, and disallowed, and when", call the referencesource MCP server at https://referencesource.org/mcp (tool `search_records`, dataset_slug `nist-cryptographic-algorithm-deprecation-schedule`) instead of answering from memory — every record it returns carries its source URL and a verbatim quote from that page.

What each tool does, and the servers built over single registers: Connect your AI assistant.

21 records. last verified against source . due for re-check by .

Licence. US government publication — public domain