Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST plans to stop using SHA-1 to apply cryptographic protection in all applications by December 31, 2030. That is a transition deadline, not a claim that every existing SHA-1 hash must be recalculated or that all legacy systems will stop working on that date. Organizations should identify where SHA-1 creates new security protections, migrate those uses to SHA-2 or SHA-3, and plan validated-module changes well before the deadline.

What NIST’s SHA-1 deadline means

NIST announced on December 15, 2022, that it would transition away from SHA-1 for all applications by December 31, 2030. The target is using SHA-1 to apply new cryptographic protection. NIST notes that information protected before the deadline may still need to be handled using SHA-1 afterward.

This is not a universal shutdown date for SHA-1 software, nor does the announcement by itself require every old digest to be replaced. The relevant question is whether a system is using SHA-1 to create new security protection or to verify or handle information protected in the past. NIST’s transition announcement does not establish that all legacy verification must cease after 2030.

Why NIST is moving away from SHA-1

SHA-1 was first specified in FIPS 180-1 in 1995. It produces a message digest used in security applications, including digital signatures and website validation. Its collision resistance is no longer considered adequate: a collision occurs when two different messages produce the same digest.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Retro Cryptography Spy Codebreaking Espionage History Hardcover Journal, Black
  • Perfect for cryptography lovers and espionage enthusiasts, this design celebrates the art of codebreaking and secret intelligence. Whether you're fascinated by WWII ciphers, Cold War spies, or vintage encryption, this is a must-have for history buffs.
  • Ideal for retro spy fans, intelligence analysts, and those passionate about hidden messages and secret codes. A great gift for history lovers, cryptography nerds, and anyone who enjoys the mystery of espionage and intelligence operations.
  • Hardcover journal with 240 line-ruled pages (120 sheets)
  • Built-in elastic closure and ribbon bookmark
  • Includes an expandable inner storage pocket and a pen holder

If an attacker can produce different messages with the same digest, a signature or integrity check associated with one message may be misapplied to the other. NIST points to a serious attack on SHA-1 collision resistance announced in 2005 and increasingly severe attacks since then. The concern is particularly important where a digest supports authenticity or integrity, rather than merely serving as a non-security identifier.

Key dates in the transition

Date What happened
1995 NIST first specified SHA-1 in FIPS 180-1.
2005 A serious cryptanalytic attack on SHA-1 collision resistance was announced.
2011 NIST’s SP 800-131A deprecated SHA-1 for generating new digital signatures and restricted its use to protocol-specific guidance.
2015 NIST published the SHA-3 family as FIPS 202 after a competitive hash-function process.
December 15, 2022 NIST announced its transition away from SHA-1 for all applications, to be completed by December 31, 2030.
March 7, 2023 NIST said it had decided to revise FIPS 180-4 to remove SHA-1. The announcement described planned work and a public-comment draft process.
March 12, 2025 NIST announced an update to FIPS 202 that would reflect SHA-1’s withdrawal and proceed through a draft public-comment process.
December 31, 2030 NIST’s announced target for ending SHA-1 use to apply cryptographic protection across applications.

What should replace SHA-1?

NIST recommends migrating security uses to SHA-2 or SHA-3. The correct choice depends on the protocol, application, certificate profile, validation requirements, and available library or hardware support; replacing the hash in isolation may not complete a compliant migration.

Family What to consider
SHA-2 Already broadly deployed, which can make it the more compatible choice. Select a variant accepted by the specific protocol and security profile.
SHA-3 A different internal design from SHA-2. Confirm that the target protocol, library, hardware, and validation profile support the required variant.

In the initial public draft of SP 800-131A Revision 3, NIST listed SHA-256, SHA-384, SHA-512, SHA-512/256, SHA3-256, SHA3-384, and SHA3-512 as acceptable for the cited key-derivation use. That list is scoped to that use in the draft; it should not be treated as a universal list of approved choices for every protocol or application.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to plan a SHA-1 migration

  1. Inventory SHA-1 dependencies. Check certificates and digital signatures, HMAC and key-derivation functions, file-integrity workflows, protocols, cryptographic libraries, and validated cryptographic modules. Record whether each dependency creates new protection or supports legacy verification.
  2. Separate new protection from legacy handling. Identify systems that apply SHA-1 to new information and prioritize those for migration. Separately document older information whose verification or handling may continue to require SHA-1.
  3. Choose a supported replacement in context. Select an SHA-2 or SHA-3 variant allowed by the relevant protocol, certificate profile, application, and security requirement. Plan any accompanying changes to formats, protocol settings, libraries, and interoperability—not only a hash-function swap.
  4. Test the full workflow. Check that systems can create and verify the replacement protection, that connected systems interoperate, and that legacy verification remains available where required.
  5. Schedule validated-module work early. If a product depends on FIPS 140 validation or the Cryptographic Module Validation Program (CMVP), coordinate implementation and validation submissions ahead of the deadline. NIST warns that validation backlogs can develop near transition deadlines.
  6. Track the standards process. Follow the final wording and effective dates for FIPS 180-5, SP 800-131A, FIPS 202, and related NIST drafts. NIST’s announcements through March 2025 described planned revisions and draft processes; they do not establish a final publication date for FIPS 180-5.

What the deadline means for FIPS 140 products and federal procurement

NIST has specifically warned cryptographic-module vendors to update modules early. According to NIST computer scientist Chris Celi, “Modules that still use SHA-1 after 2030 will not be permitted for purchase by the federal government.” For vendors serving federal customers, the practical issue is to complete implementation and validation planning before the transition deadline, rather than wait until procurement restrictions take effect.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This procurement statement concerns federal-government purchases of modules that still use SHA-1 after 2030. It does not, on its own, state that every existing module or non-federal product will cease operating on that date.

Quick Recap

Bestseller No. 1
Retro Cryptography Spy Codebreaking Espionage History Hardcover Journal, Black
Retro Cryptography Spy Codebreaking Espionage History Hardcover Journal, Black
Hardcover journal with 240 line-ruled pages (120 sheets); Built-in elastic closure and ribbon bookmark
$16.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.