Skip to content

The EU Post-Quantum Cryptography Roadmap: Deadlines and What They Mean for Critical Infrastructure

For most of the last few years, “the EU is moving toward post-quantum cryptography” was a directional statement, not a deadline.

That changed with the Commission’s Recommendation on a Coordinated Implementation Roadmap for the transition to post-quantum cryptography, and it changed further in January 2026, when the Commission proposed writing post-quantum cryptography directly into the text of NIS2. What used to be “eventually” now has three dates attached to it: 2026, 2030, and 2035.

For the sectors NIS2 already regulates, an increasingly direct legal basis behind them.

If your organization operates energy, transport, banking, health, water, or digital infrastructure anywhere in the EU, those three dates are the calendar your quantum-safe migration is now being measured against, whether or not your own internal roadmap has caught up.

What the Roadmap Actually Is

The roadmap traces back to Commission Recommendation (EU) 2024/1101, adopted on 11 April 2024, which asked Member States to coordinate their transition to post-quantum cryptography rather than migrate independently and risk a fragmented, incompatible patchwork across the single market.

The Recommendation tasked the NIS Cooperation Group ,who coordinates cybersecurity policy among Member States, with standing up a dedicated PQC workstream to turn that ask into an actual plan.

That workstream published the Coordinated Implementation Roadmap in June 2025: a concrete timeline with three milestone dates, aimed primarily at Member States and the operators of critical and high-risk infrastructure within their borders. It’s worth being precise about its legal weight at that point: a Recommendation is soft law. It doesn’t, on its own, create an enforceable obligation the way a Regulation or a Directive does.

But then came the update.

In January 2026, the Commission proposed amending NIS2 itself — via COM (2026) 13 — to add a new Article 7(2)(k), explicitly requiring Member States to include post-quantum cryptography transition policy in their national cybersecurity strategies.

The same proposal expands NIS2’s own scope, formally bringing European Digital Identity Wallet providers, European Business Wallet providers, and submarine data cable operators into the directive as essential entities.

Once that amendment is adopted, the roadmap’s soft-law milestones stop being a recommendation an organization can quietly deprioritize. It turns into a timeline against which a binding directive is measured. 

The Three Deadlines

Milestone What's due
By 31 December 2026 Member States complete national PQC implementation plans: stakeholder identification, cryptographic dependency mapping, quantum-risk analysis, supply-chain assessment, and cryptographic inventories (increasingly expected in a standardized format such as a Cryptographic Bill of Materials). Pilot projects begin for high- and medium-risk use cases.
By 31 December 2030 PQC transition is fully completed for high-risk use cases; the systems and sectors judged most exposed to harvest-now-decrypt-later and most consequential if compromised. Crypto-agility becomes a default expectation for new products, aligned with the Cyber Resilience Act: anything with a service life extending past 2030 is expected to be upgradable to quantum-safe algorithms without a hardware refresh.
By 31 December 2035 Migration is completed for medium-risk use causes and substantially completed for low-risk use cases wherever technically and economically feasible.

Three things about this structure are worth noting. First, the 2026 milestone is almost entirely about knowing what you have, focusing on inventory and risk analysis but not deploying anything yet.

Second, the 2030 milestone is the one with teeth: it’s the date by which the highest-risk systems must be quantum-safe, not just planned for.

Third, the roadmap bakes crypto-agility into the 2030 milestone directly, rather than treating it as a nice-to-have. This lines up with the Cyber Resilience Act’s own approach to products with long service lives, and with the plain operational reality that no organization can be confident today’s chosen algorithm is the one it will still be running in 2035.

Who Counts as “Critical Infrastructure” Here

The roadmap doesn’t invent its own sector list but leans on NIS2’s, which is considerably broader than “critical infrastructure” often means in casual usage.

NIS2 covers energy, transport, banking and financial market infrastructure, health, drinking water and wastewater, digital infrastructure, providers of public electronic communications networks and services, digital services, public administration, and space.

It also defines as important entities certain sectors including postal and courier services, waste management, chemicals, food, and critical manufacturing.

The January 2026 NIS2 amendment adds European Digital Identity Wallet providers, European Business Wallet providers, and submarine data cable operators to that list as essential entities in their own right, a direct acknowledgment that the infrastructure carrying and authenticating Europe’s data is itself now treated as critical.

If your organization already has NIS2 obligations, the PQC roadmap isn’t a separate, optional initiative sitting next to your NIS2 compliance program. It’s increasingly the specific cryptographic content of that program’s 2026, 2030, and 2035 checkpoints. Given how broadly the directive reaches, a large share of mid-sized and large operators across the EU need to act.

Why 2030 Is the Deadline That Actually Bites for Network Operators

Inventories and national strategies matter, but 2030 is where the roadmap starts asking for evidence rather than plans. And for network infrastructure specifically, the 2030 deadline interacts with a risk that doesn’t wait politely for a compliance calendar: harvest-now-decrypt-later.

Data intercepted on a network link today, like a data-center interconnect, a backbone connection, a cross-border financial or government link, can be stored now and decrypted retroactively once a cryptographically relevant quantum computer exists.

For any of it with a confidentiality lifetime longer than the gap between now and 2030 (which describes most of what governments, banks, energy operators, and healthcare systems consider sensitive), the roadmap’s 2030 milestone isn’t really the deadline that matters. The actual deadline is whenever that data crosses an unprotected link, and 2030 is simply when regulators start checking whether you got there in time.

That’s also why network-layer encryption is where most organizations can move fastest against this timeline. It protects data in transit independent of the application or device generating it, which means it doesn’t wait on every piece of legacy IT, OT, or embedded equipment in a critical-infrastructure environment to individually support post-quantum cryptography.

The process of upgrading hardcoded or vendor-locked systems, may not finish by 2030 at all, if it ever finishes.

Three Regulations, One Calendar

NIS2 isn’t the only EU instrument converging on this timeline but it’s the broadest one. For anyone whose compliance picture spans more than one of these, it’s worth seeing them side by side, because they’re increasingly describing the same underlying expectation from different regulatory angles:

Regulation Who is covers Cryptography requirement  Status
NIS2 Directive Broad critical-infrastructure sectors; national transposition deadline 17 Oct 2024 General risk-management measures; Jan 2026 proposal (COM(2026) 13) would add explicit PQC policy requirement (Art. 7(2)(k)) Proposal, not yet adopted
DORA EU financial entities — banks, insurers, investment firms, payment/crypto-asset providers, market infrastructures Binding since 17 Jan 2025; RTS (Del. Reg. (EU) 2024/1774) requires encrypted data in transit and a documented plan to update crypto as cryptanalysis evolves (Art. 6(4)) Already binding law
Cyber Resilience Act Manufacturers of hardware/software products sold in the EU Security-by-design and crypto-agility for products with extended service life; referenced by the roadmap's 2030 milestone Adopted; phased through 2027

The pattern across all three is the same: cryptographic agility is becoming the specific, checkable thing regulators expect an organization to demonstrate their ability to not just deploy an algorithm but keep deploying future ones as they evolve.

What to Do Before the End of 2026

The 2026 milestone is closer than it looks, and it’s the one every later deadline depends on — you can’t hit 2030 without having done the 2026 work first.

  1. Complete a cryptographic inventory now, covering network links as well as applications — which algorithms are in use, where, and on what hardware, ideally in a standardized format your compliance team can hand to an auditor.
  2. Map which of your links carry data with a confidentiality lifetime that outlasts 2030 — this is the harvest-now-decrypt-later exposure the 2030 deadline is ultimately trying to close, and it's the fastest way to rank your own migration priorities.
  3. Identify hardcoded or fixed-function encryption infrastructure — appliances or systems that would need a hardware refresh, not a software update, to adopt a new algorithm, since the roadmap's 2030 milestone assumes crypto-agility as the default, not the exception.
  4. Pilot hybrid and post-quantum modes on a subset of links, matching the roadmap's own 2026 expectation of pilot projects for high- and medium-risk use cases, rather than waiting for a single organization-wide cutover.
  5. Track which of NIS2, DORA, and the CRA apply to your organization, and align your internal milestones to the earliest deadline among them rather than treating each regulation calendar separately.

When You’re Ready to Meet the 2030 Deadline

SSH’s NQX applies quantum-safe, wire-speed encryption (up to 100 Gbps) at Layer 2 and Layer 3 to exactly the network links this roadmap is asking critical-infrastructure operators to secure by 2030 — deployed transparently, with a software-defined crypto engine built for the crypto-agility the roadmap already assumes.