3.5 Critical Infrastructure
PQC requirements for critical infrastructure1) operators.
Definition
Critical infrastructures are organizations and facilities of significant importance to the community, whose failure would have dramatic consequences.
Sectors According to NIS2
The NIS2 Directive2) defines the following sectors:
Essential Entities:
Energy (Electricity, Gas, Oil)
Transport (Air, Rail, Water, Road)
Banking
Financial Market Infrastructures
Healthcare
Drinking Water
Digital Infrastructure
Important Entities:
Special Requirements
Early PQC migration (before 2030)
Documentation obligations
Incident reporting requirements (within 24h)
Regular audits
Risk management according to ENISA
3) guidelines
"Harvest Now, Decrypt Later" Risk
Especially critical for critical infrastructure4):
BSI Recommendations
The Federal Office for Information Security5) recommends:
Immediate inventory of cryptography
Prioritization by data sensitivity
Hybrid solutions as transitional measure
At least FIPS 203/204/205 compliant algorithms
Sources