European requirements for Post-Quantum security.
The NIS2 Directive1) has been in force since October 2024 and requires „state of the art“ cryptography for critical infrastructures.
Affected sectors:
The EU Commission2) has published a coordinated roadmap3) for PQC transition:
| Deadline | Requirement |
|---|---|
| End 2025 | Cryptographic inventory |
| End 2026 | National PQC roadmaps, first pilots |
| End 2027 | New products must be PQC-capable (CRA4)) |
| End 2030 | Complete migration for high-risk |
The Digital Operational Resilience Act (DORA)5) applies since January 2025 for financial companies and requires „robust cryptographic controls“.
The General Data Protection Regulation6) requires „appropriate technical measures“ for protecting personal data - PQC is increasingly considered necessary.