Quantum Security & PQC

Germany’s BSI Sets 2031 End Date for Classical Key Agreement in TR-02102-1

February 11, 2026 — Germany’s Federal Office for Information Security (BSI) has released version 2026-01 of its Technical Guideline TR-02102-1, “Cryptographic Mechanisms: Recommendations and Key Lengths,” and with it the first fixed end dates for classical public-key cryptography used on its own. The updated guideline recommends hybrid quantum-safe implementations, and BSI announced the change in a press release in which BSI President Claudia Plattner called the transition unavoidable.

The most striking change: classical asymmetric key agreement used on its own is no longer recommended after December 31, 2031. Classical signature mechanisms receive a slightly longer grace period, until December 31, 2035. After these dates, BSI expects classical mechanisms to run only in combination with post-quantum ones. TR-02102 is formally a recommendation. Federal requirements and regulated sectors build on it, so many German organizations treat it as binding.

The guideline recommends hybrid approaches for quantum-safe deployments, combining post-quantum algorithms with traditional methods. Its post-quantum recommendations cover ML-KEM (FIPS 203) alongside FrodoKEM and Classic McEliece for key establishment, and ML-DSA (FIPS 204), SLH-DSA (FIPS 205), XMSS and LMS for signatures.

BSI maintains its security baseline of 120 bits, though the effective strength of recommended mechanisms often exceeds this threshold. For especially sensitive data in the classified-information domain, the cut-off comes a year earlier, at the end of 2030.

The timing follows the EU’s coordinated PQC implementation roadmap, which BSI co-led with its French and Dutch counterparts. The guideline cites the store now, decrypt later threat, acknowledging that adversaries may already be harvesting encrypted data for future decryption once cryptographically relevant quantum computers emerge.

My Analysis

This update represents more than a routine revision. I see Germany positioning itself at the forefront of Europe’s quantum-safe transition, establishing concrete timelines where others offer only vague recommendations.

The 2031 deadline for key agreement mechanisms reflects the immediate threat posed by the Store Now, Decrypt Later attack vector. Data encrypted today using RSA or elliptic curve cryptography could be decrypted retroactively once quantum computers mature. By contrast, the 2035 deadline for signatures acknowledges a different threat model: signatures only become vulnerable when quantum computers actually exist, not before.

What catches my attention is BSI’s unwavering commitment to hybrid approaches. Pure post-quantum implementations remain off the table. This conservative stance makes sense given the relative newness of these algorithms and ongoing concerns about implementation security. Organizations cannot simply swap RSA for ML-KEM and call it done. They must run both in parallel, deriving keys that depend on the security of both systems.

This is the second year running that the guideline has moved. I covered the 2025-01 version a year ago. BSI has now added end dates. Germany’s concrete deadlines could pressure other EU members to establish similar timelines. I expect France’s ANSSI and other national agencies to issue comparable guidance within months.

For organizations operating in Germany or interfacing with German entities, the message is clear: post-quantum migration planning cannot wait. The 2030 deadline for high-security applications means some organizations have less than five years to complete their transitions. Given typical enterprise IT refresh cycles and the complexity of cryptographic migrations, that timeline looks aggressive but necessary.

The guideline’s emphasis on “cryptoagility” deserves particular attention. BSI repeatedly stresses that systems must support algorithm transitions without major architectural changes. This requirement goes beyond simple algorithm swapping. It demands fundamental changes to how organizations design and deploy cryptographic systems.

The broader implications extend beyond Germany’s borders. As one of Europe’s largest economies and a key player in EU digital policy, Germany’s cryptographic standards often influence broader European approaches. This update could accelerate post-quantum adoption across the EU, especially in sectors like automotive, manufacturing, and critical infrastructure where German companies hold significant market positions.

The document signals that Germany takes the quantum threat seriously enough to mandate specific actions on specific timelines. While some may argue these deadlines arrive too early given uncertainty around Q-Day timing, I view them as appropriately conservative given the stakes involved and the time required for large-scale cryptographic transitions.

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com.