Reference Source

RSA key transport

For RSA key transport, purpose is key establishment; current status is Approved; planned status is deprecated after 2030 and disallowed after 2035; replacement is ML-KEM (FIPS 203); source document is IR 8547, recorded from its source on 2026-08-16; source re-checked 2026-09-28.

Algorithm
RSA key transport verified
Purpose
key establishment our reading
Current status
Approved our reading
Planned status
deprecated after 2030 and disallowed after 2035 our reading
Replacement
ML-KEM (FIPS 203) our reading
Source document
IR 8547 our reading
Sourceencryptionconsulting.com
Verified
Review by
DatasetNIST cryptographic algorithm deprecation schedule: what is approved, deprecated, and disallowed, and when

Values marked our reading are our classification of what the source says — the source does not print them in those words. The quote below is the evidence for each one; judge it yourself.

What the source says

RSA key transport, elliptic-curve Diffie-Hellman (ECDH), and finite-field Diffie-Hellman. All are broken by Shor’s algorithm on a sufficiently powerful quantum computer, which is why migrating from RSA to ECC solves nothing here: both fall to the same attack. Deprecated Is Not the Same as Disallowed The practical reading: after 2030, RSA and ECDH are no longer acceptable for new deployments on US federal systems, but existing deployed systems have until 2035 to complete migration. The window between the two dates is the migration runway. Treating 2035 as the only deadline misses the point, because procurement, auditing, and cyber-insurance practices tend to tighten around the 2030 deprecation date, not the 2035 disallowance date. How Hybrid Modes Fit In IR 8547 explicitly supports hybrid cryptography during the transition. A hybrid scheme combines a classical algorithm with a post-quantum algorithm so the result stays secure unless both are broken. NIST has clarified that the 2035 disallowance of quantum-vulnerable algorithms is not intended to prohibit hybrid modes that incorporate an approved post-quantum algorithm alongside a classical one in a composite scheme.

— encryptionconsulting.com, retrieved 2026-08-16

Source

Last verified against source: . Due for re-check by . This page as Markdown · OKF bundle · full dataset as JSON.