← All countries

Australia

NIST bloc Standard-contextualiser

Australia's transition is led by the Australian Signals Directorate (ASD) and its Australian Cyber Security Centre (ACSC). The Information Security Manual, mandatory for Commonwealth entities, embeds an end-of-2030 retirement of the classical asymmetric algorithms (RSA, Diffie-Hellman, ECDH, ECDSA) and approves the post-quantum algorithms ML-KEM and ML-DSA. The Manual's March 2026 update documents the move to these ASD-approved algorithms and the timelines for ceasing traditional asymmetric cryptography, one of the most compressed official timelines and a step ahead of the global 2035 horizon. Alongside this technical lead, the Department of Industry, Science and Resources frames post-quantum cryptography as a critical technology within the National Quantum Strategy, the ACSC has issued a Quantum Technology Primer series for the wider economy, and the Parliament has begun to scrutinise the transition through Senate and budget estimates.

Governance credibility

Governance credibility for AustraliaA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Australia, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2Medium
Coherence2.0 / 2Medium
Effectiveness1.5 / 2Medium
Efficiency2.0 / 2Medium
Governance2.0 / 2Medium
Impact2.0 / 2Medium

Regulatory basis

  • PSPF Policy 11 (Robust ICT systems) applying the Information Security Manual national Binding (market access)
  • Security of Critical Infrastructure Act 2018 (risk management programme) national Binding law
  • ASD/ACSC post-quantum cryptography guidance national Guidance

Non-corporate Commonwealth entities must, under PSPF Policy 11, secure their ICT systems by applying the cyber security principles and risk-based approach of the Australian Government Information Security Manual, which the PSPF makes mandatory under the Public Governance, Performance and Accountability Act 2013; responsible entities for critical infrastructure assets must also maintain a risk management programme addressing cyber and information security hazards under the Security of Critical Infrastructure Act 2018. The Information Security Manual, mandatory for these entities, embeds an end-of-2030 retirement of the classical asymmetric algorithms (RSA, Diffie-Hellman, ECDH, ECDSA) and approves the NIST post-quantum algorithms; for Commonwealth systems this makes migration to post-quantum cryptography effectively binding on a 2030 deadline, ahead of the global 2035 horizon, while the wider economy follows ASD guidance.

Standards and algorithms

Algorithms
ML-KEM, ML-DSA

Hybrid stance

None stated

Migration timeline

today
2026
2028
2030
20252036
  1. 2026Transition plan in place
  2. 2028Migration underway
  3. 2030Traditional asymmetric cryptography ceased and migration complete

Target completion: 2030

Governmental and standards bodies

  • ASD Australian Signals Directorate, national signals intelligence and cyber security authority; issues the Information Security Manual
  • ACSC Australian Cyber Security Centre within ASD; issues post-quantum planning guidance and the Quantum Technology Primer series
  • DISR Department of Industry, Science and Resources; leads the National Quantum Strategy and lists post-quantum cryptography as a critical technology in the national interest
  • Parliament of Australia parliamentary oversight of the post-quantum transition through Senate and budget estimates
  • CSIRO national science agency; research on the quantum-safe transition and post-quantum migration pathways

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →