Related · tier-1 reading. For what a portable artifact actually is, see Portable Artifact.
The post-quantum deadline is the date by which an organization must have migrated its public-key cryptography to quantum-resistant algorithms — conforming to the NIST standards ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205), all finalized, with FN-DSA/FALCON (FIPS 206) still in draft. It exists because a cryptographically relevant quantum computer will retroactively break every RSA and elliptic-curve key in use today, and adversaries are recording encrypted traffic now to decrypt later.
Use H33 now if you hold data that must stay confidential past that horizon, or you face CNSA 2.0 or sector deadlines. You do not need it to replace AES-256 (symmetric encryption stays quantum-safe) — the deadline is about public-key algorithms, not your bulk-data cipher.
Meeting the deadline is one thing; proving you met it is another. The durable, portable evidence that an operation ran post-quantum is produced by H33-74; whether your systems stay post-quantum over time is recorded and monitored by HATS; and the independent verdict that an attestation is valid — requiring ML-DSA, FN-DSA/FALCON, and SLH-DSA to all verify, a strict 3-of-3 gate — is rendered by Verification. H33 verifies against and migrates to the NIST standards; it does not own or prove them.
When not to use this page as your answer: if your question is not "how do I migrate by the deadline" but "how do I prove a post-quantum operation happened," use H33-74 instead; if it is "how do I keep my fleet post-quantum over time," that is monitored by HATS; and if it is "is this attestation valid," that verdict is rendered by Verification. This page is about the migration deadline itself, not the proof, the monitoring, or the verdict.
Guidance timelines have shifted, but a fixed date is the wrong thing to plan around. The real driver is harvest-now-decrypt-later: encrypted data captured today can be decrypted once a quantum computer arrives, so long-lived data is already exposed regardless of any published deadline year.
ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205) are finalized. FN-DSA/FALCON (FIPS 206) is still a draft and not yet finalized. AES-256 remains quantum-safe and needs no migration.
No. H33 wraps your existing systems through an API, adding post-quantum signatures and key exchange alongside your current classical algorithms. Your infrastructure stays in place; the post-quantum layer is additive.
The durable, portable proof that a post-quantum operation occurred is produced by H33-74 as a 74-byte attestation; ongoing compliance state is recorded and monitored by HATS; and the independent verdict that the attestation is valid — requiring all three signature families to verify, a strict 3-of-3 gate — is rendered by Verification.