PQC standards & compliance
What NIST IR 8547 actually asks you to do by 2030
Deprecation is not disallowance. Here's the timeline an auditor will hold you to, and what evidence they'll look for.
Deprecation vs disallowance
NIST IR 8547 draws a line most teams miss. Deprecated means an algorithm is still permitted but discouraged, with a countdown. Disallowed means it must not be used at all. The document sets 2030 as the point where 112-bit-strength classical algorithms (RSA-2048, ECDSA P-256) become deprecated, and 2035 as disallowance.
That two-word distinction is the whole compliance timeline. An auditor in 2031 won't fault you for having RSA in production, they'll fault you for not having a plan, an inventory, and a measurable migration rate.
What an auditor looks for
- A cryptographic inventory (CBOM) that is current, not a point-in-time spreadsheet.
- Evidence of prioritisation: which assets are being migrated first, and why.
- A migration rate you can defend, not "we'll start in 2029."
Dhiti Comply maps your CBOM to IR 8547 clause by clause and produces the evidence pack an assessor expects.
