NIST Draft Sets Different 2030 and 2035 Deadlines for RSA-2048 vs RSA-3072
A widely repeated claim that all RSA and elliptic-curve algorithms are deprecated by 2030 is only partially accurate, according to NIST IR 8547, an initial public draft on post-quantum cryptographic transitions. The draft distinguishes between algorithms by security strength: those at 112-bit security, such as RSA-2048, face deprecation after 2030 and disablement after 2035, while stronger algorithms like RSA-3072 and P-256 at 128-bit security are only disallowed after 2035 with no 2030 deprecation. The terms 'deprecated' and 'disallowed' carry distinct meanings — deprecated permits continued use with acknowledged risk, whereas disallowed is a hard stop. Because NIST IR 8547 remains a draft, all proposed dates are subject to change before final publication. Misreading the document by flattening both categories into a single 2030 ban risks misdirected compliance efforts and unnecessary infrastructure overhauls.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.

Discussion (0)
Log in to join the discussion and vote.
Log in