← All countries

Canada

NIST bloc Standard-taker

Canada's transition is led by the Canadian Centre for Cyber Security, which has published a roadmap for migrating Government of Canada non-classified IT systems to post-quantum cryptography, with the Treasury Board Secretariat issuing the matching policy implementation notice. The Cyber Centre's cryptographic algorithms standard now names the NIST-standardised post-quantum algorithms ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures as the baseline for the migration, and its recommended procurement contract clauses require cryptographic modules to support post-quantum cryptography by the end of 2026. High-priority government systems are to be migrated by 2031 and the remainder by 2035. The Cyber Centre aligns with the NIST standardisation process, having reviewed the NIST candidate algorithms.

Governance credibility

Governance credibility for CanadaA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Canada, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness1.5 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • Treasury Board Security Policy Implementation Notice: Migrating the Government of Canada to Post-Quantum Cryptography (2025) national Binding (market access)
  • Canadian Centre for Cyber Security cryptographic algorithms standard ITSP.40.111 (Version 5, 2026) national Guidance
  • Canadian Centre for Cyber Security Recommended Contract Clauses for Cryptography ITSM.00.501 (2025) national Guidance
  • Canadian Centre for Cyber Security roadmap ITSM.40.001 and guidance ITSAP.00.017 national Guidance

Federal departments only: the Treasury Board Security Policy Implementation Notice, effective 9 October 2025 under the Policy on Government Security and the Policy on Service and Digital, requires Government of Canada systems that use cryptography to migrate to post-quantum cryptography, with a high-level migration plan due by April 2026, high-priority systems migrated by the end of 2031 and all remaining systems by 2035. The Cyber Centre roadmap (ITSM.40.001) and quantum-threat guidance (ITSAP.00.017) set the recommended method and align to the NIST standards. There is no economy-wide mandate on private organisations.

Standards and algorithms

Standard families
NIST-standardised post-quantum cryptography algorithms (per Cyber Centre ITSP.40.111)
Algorithms
ML-KEM, ML-DSA, SLH-DSA

Hybrid stance

None stated

Migration timeline

today
2026
2031
2035
20252036
  1. 2026Cryptographic modules in new procurements to support post-quantum cryptography for key establishment and digital signatures (Cyber Centre contract clauses ITSM.00.501)
  2. 2031High-priority Government of Canada systems migrated to post-quantum cryptography
  3. 2035Remaining Government of Canada systems migrated to post-quantum cryptography

Target completion: 2035

Governmental and standards bodies

  • CCCS Canadian Centre for Cyber Security, publishes the migration roadmap (ITSM.40.001), the approved cryptographic algorithms standard (ITSP.40.111) naming ML-KEM, ML-DSA and SLH-DSA, the recommended cryptography contract clauses (ITSM.00.501) and quantum-threat guidance, and reviewed the NIST PQC candidates
  • TBS Treasury Board Secretariat, issues the policy implementation notice requiring migration of government systems
  • ISED Innovation, Science and Economic Development Canada, National Quantum Strategy roadmap and national quantum-readiness best practices
  • SSC Shared Services Canada, campaign material on quantum computing and cybersecurity
  • NRC National Research Council, Quantum Safe Technologies Initiative supporting testing and integration of post-quantum cryptography

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →