Canada
NIST bloc Standard-takerCanada's transition is led by the Canadian Centre for Cyber Security, which has published a roadmap for migrating Government of Canada non-classified IT systems to post-quantum cryptography, with the Treasury Board Secretariat issuing the matching policy implementation notice. The Cyber Centre's cryptographic algorithms standard now names the NIST-standardised post-quantum algorithms ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures as the baseline for the migration, and its recommended procurement contract clauses require cryptographic modules to support post-quantum cryptography by the end of 2026. High-priority government systems are to be migrated by 2031 and the remainder by 2035. The Cyber Centre aligns with the NIST standardisation process, having reviewed the NIST candidate algorithms.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | High |
| Coherence | 2.0 / 2 | High |
| Effectiveness | 1.5 / 2 | High |
| Efficiency | 2.0 / 2 | High |
| Governance | 2.0 / 2 | High |
| Impact | 2.0 / 2 | High |
Regulatory basis
- Treasury Board Security Policy Implementation Notice: Migrating the Government of Canada to Post-Quantum Cryptography (2025)
- Canadian Centre for Cyber Security cryptographic algorithms standard ITSP.40.111 (Version 5, 2026)
- Canadian Centre for Cyber Security Recommended Contract Clauses for Cryptography ITSM.00.501 (2025)
- Canadian Centre for Cyber Security roadmap ITSM.40.001 and guidance ITSAP.00.017
Legal status: Binding
Federal departments only: the Treasury Board Security Policy Implementation Notice, effective 9 October 2025 under the Policy on Government Security and the Policy on Service and Digital, requires Government of Canada systems that use cryptography to migrate to post-quantum cryptography, with a high-level migration plan due by April 2026, high-priority systems migrated by the end of 2031 and all remaining systems by 2035. The Cyber Centre roadmap (ITSM.40.001) and quantum-threat guidance (ITSAP.00.017) set the recommended method and align to the NIST standards. There is no economy-wide mandate on private organisations.
Standards and algorithms
- Standard families
- NIST-standardised post-quantum cryptography algorithms (per Cyber Centre ITSP.40.111)
- Algorithms
- ML-KEM, ML-DSA, SLH-DSA
Hybrid stance
None stated
Migration timeline
- 2026Cryptographic modules in new procurements to support post-quantum cryptography for key establishment and digital signatures (Cyber Centre contract clauses ITSM.00.501)
- 2031High-priority Government of Canada systems migrated to post-quantum cryptography
- 2035Remaining Government of Canada systems migrated to post-quantum cryptography
Target completion: 2035
Governmental and standards bodies
- CCCS Canadian Centre for Cyber Security, publishes the migration roadmap (ITSM.40.001), the approved cryptographic algorithms standard (ITSP.40.111) naming ML-KEM, ML-DSA and SLH-DSA, the recommended cryptography contract clauses (ITSM.00.501) and quantum-threat guidance, and reviewed the NIST PQC candidates
- TBS Treasury Board Secretariat, issues the policy implementation notice requiring migration of government systems
- ISED Innovation, Science and Economic Development Canada, National Quantum Strategy roadmap and national quantum-readiness best practices
- SSC Shared Services Canada, campaign material on quantum computing and cybersecurity
- NRC National Research Council, Quantum Safe Technologies Initiative supporting testing and integration of post-quantum cryptography
Key institutional documents
- Cryptographic algorithms for UNCLASSIFIED, PROTECTED A, and PROTECTED B information (ITSP.40.111)
- Recommended Contract Clauses for Cryptography (ITSM.00.501)
- Cryptography and quantum computing (technical advisory services)
- Quantum Safe Technologies Initiative
- Canadian National Quantum-Readiness: Best Practices
- National Quantum Strategy Roadmap: Quantum communication and post-quantum cryptography
- Looking ahead: Quantum computing and cybersecurity
- Migration to post-quantum cryptography for the Government of Canada (policy implementation notice)
- GC Migration to Post-Quantum Cryptography (PQC) - Course CRY102S
- Cyber Centre's summary review of final candidates for NIST Post-Quantum Cryptography standards
- Preparing your organization for the quantum threat to cryptography (ITSAP.00.017)
- Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)
Advising on this transition, or your own sector's? Request a briefing →