NIST Expects Today's Public-Key Algorithms Retired by 2035
The stated horizon for withdrawing the public-key cryptography securing most of the internet overlaps directly with the service life of hardware being specified now.

NIST expects organisations to have retired the public-key algorithms securing most of the internet by 2035. Stated as a date it sounds distant. Set against hardware lifecycles it is not, and that comparison is the useful way to read it.
A smart meter, an industrial sensor or a building controller specified in 2026 will commonly still be installed in 2036. Devices in that class routinely outlast the companies that installed them and the staff who chose them. So a product being designed now will very likely still be running when the algorithms it shipped with are formally deprecated, and the question is whether it can be brought forward or whether it becomes a known-weak endpoint somebody has to work around.
That makes crypto-agility the specific property worth designing for rather than any particular algorithm. Being able to change algorithms in the field — enough flash to hold a larger implementation, an update path whose own signature can be upgraded, and no algorithm identifiers hardcoded into a protocol that both ends must agree on — is what separates a device that can follow the transition from one that is frozen at manufacture. None of that requires choosing the winning algorithm today, which is fortunate, because the point of agility is not having to.
Source: NIST NCCoE