Post-quantum cryptography: the real deadline is late 2026, not 2030
5 min read
On 23 June 2025 the NIS Cooperation Group — the technical forum bringing together the cyber authorities of the member states, supported by ENISA and the Commission — published the roadmap implementing EU Recommendation 2024/1101 on the transition to post-quantum cryptography. Three deadlines, not one: end of 2026, end of 2030, end of 2035. The first seems distant until you check the calendar: five months remain. And it does not concern governments alone. Organisations operating in sectors covered by NIS2, DORA or the Cyber Resilience Act are discovering that “post-quantum” is no longer a research-lab topic: it is a line item in the next compliance audits.
The risk is already here, not on the day of the quantum computer
The point that catches out anyone hearing about this topic for the first time: the risk does not require a working quantum computer to exist. It is enough for someone to intercept and store encrypted traffic today, in order to decrypt it tomorrow once computing capacity is sufficient. ACN, the Italian national cybersecurity agency, calls it “store now, decrypt later” — also known as “harvest now, decrypt later”. For data with a short useful life — a transaction, a web session — the risk is contained. For healthcare data, multi-year contracts, intellectual property, and defence and critical-infrastructure communications, useful life is measured in decades. These are exactly the data an adversary has an incentive to store now.
The three stages of the European roadmap
The Commission set out the path with the recommendation of 11 April 2024; the NIS Cooperation Group made it operational a year later, with precise timings:
- By 31 December 2026: every member state must have a national transition roadmap, with objectives and timings, and must have started the inventory of its cryptographic assets for medium- and high-risk use cases.
- By 31 December 2030: transition completed for high-risk use cases — critical infrastructure first — and planning concluded for medium-risk ones.
- By 31 December 2035: transition concluded, as far as technically possible, for lower-risk cases too.
It is a recommendation, not a regulation: no direct penalty attaches to missing these dates. But the substance changes when it intersects with legislation that already imposes binding obligations: NIS2’s ICT risk management, DORA’s resilience testing, the Cyber Resilience Act’s security-by-design requirements. In all three, “managing cryptographic risk” falls within scope — and an algorithm that a European agency declares to have a known expiry date sooner or later becomes a risk that must be documented within those processes.
What the 2026 requirement really asks for
This is not a paperwork exercise. The NIS Cooperation Group’s guidance concretely requires:
- an inventory of the cryptographic algorithms in use — where RSA, ECC and Diffie-Hellman are used, and on which systems;
- a map of supply-chain dependencies: firmware, third-party libraries, devices that cannot be updated without the supplier;
- adoption of the crypto-agility principle: systems designed to change algorithm without rewriting the application, because the post-quantum standards (the NIST FIPS 203, 204 and 205 schemes) are already published but will continue to evolve;
- the involvement of stakeholders along the supply chain, not just the internal security department.
It is the same visibility work that NIS2 already requires of critical sectors and that the Cyber Resilience Act requires of connected-product manufacturers: knowing what runs inside your own systems, before having to act against a deadline.
Italy moves: the ACN guidelines
ACN takes part in the NIS Cooperation Group and has repeatedly published technical material on the subject, as part of measure 22 of the National Cybersecurity Strategy. In June 2026 the agency updated its guidelines on cryptographic functions, incorporating version 2.0 of the TLS document with post-quantum solutions and publishing new chapters on stream ciphers and digital signatures. For Italian organisations — especially those falling under NIS2 as operators in critical sectors, in energy, healthcare or public administration — these documents are the most direct technical reference for understanding what to expect in upcoming inspections.
Who needs to move first
Not every sector moves at the same pace. Critical infrastructure — energy, telecommunications, transport, healthcare, defence — is classified as high risk and must treat 2030 as the operational deadline, with the inventory to be started now. The financial sector, under DORA, inherits the same ICT risk-management obligation regarding its technology suppliers. Manufacturers of connected products, under the Cyber Resilience Act, will have to demonstrate that the cryptography chosen today remains defensible over the product’s life cycle — which can run to ten years.
What to do by the end of 2026
- Carry out the cryptographic inventory: which algorithms, on which systems, with what useful-life deadline for the protected data.
- Classify by risk: data with a long useful life (healthcare, defence, intellectual property, multi-year contracts) go to the top of the list.
- Map the supply chain: firmware, devices that cannot be updated remotely, third-party libraries — these are the slowest points to fix.
- Ask suppliers for crypto-agility: systems that allow the algorithm to be replaced without rewriting the application.
- Put the transition into the ICT risk-management plan already required by NIS2 or DORA: it is the same register, not a parallel requirement.
Post-quantum cryptography is not a project for 2030. It is an inventory to be opened now, because whatever is encrypted today with a vulnerable algorithm remains readable to whoever intercepts it — in due course. It is the same principle we apply to every operational trial: first map what exists, then decide what to change. Regulatory compliance works on the same logic: visibility first, compliance after.
Want to know which systems in your organisation depend on at-risk cryptography, and in what order to tackle them? Half an hour with one of our experts for the first map.