The EU post-quantum roadmap: what you must have done by 2026, 2030 and 2035
In June 2025, EU Member States, supported by the European Commission, published A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. It was drafted by a dedicated post-quantum cryptography (PQC) workstream of the NIS Cooperation Group, and it answers the Commission’s Recommendation (EU) 2024/1101 of 11 April 2024, which asked Member States to agree a common strategy and timeline for moving to PQC.
The roadmap sets three dates: the end of 2026, the end of 2030 and 2035. With roughly twelve weeks left in 2026, the first one is no longer a planning question. It is a delivery question.
The three milestones
The roadmap is risk-based. Its milestones, in summary:
| By | What the roadmap expects |
|---|---|
| End of 2026 | Every Member State has started the transition: “first steps” taken, a national transition plan in place, and pilots launched for high- and medium-risk use cases. The first steps include identifying stakeholders, cryptographic asset management (inventories), dependency mapping including the supply chain, quantum risk analysis, and awareness programmes. |
| End of 2030 | High-risk use cases moved to PQC “as soon as possible, no later than” the end of 2030, with quantum-safe upgrade paths in place for the products and services involved. |
| 2035 | Medium-risk use cases transitioned. The Commission summarises the end state as moving as many systems as feasible to PQC by 2035. |
“High risk” is not a list of sectors. It is driven largely by harvest-now-decrypt-later exposure: systems protecting data that must stay confidential for many years, and systems that will take a long time to migrate. A payment platform’s long-term archive and a hospital’s patient-records exchange are likely to qualify. A marketing site will not.
Who the roadmap actually binds
Precision matters here. The roadmap is a coordination document addressed to Member States. It is not a regulation, and it creates no new legal obligation for a bank or an energy operator on its own.
In practice that distinction offers little shelter. National cybersecurity agencies and sector supervisors are the bodies that will carry the roadmap forward, and they reach regulated entities through law that already applies:
- NIS2. Article 21(2)(h) of Directive (EU) 2022/2555 requires “policies and procedures regarding the use of cryptography and, where appropriate, encryption”. For digital-infrastructure and certain digital-service entities, Implementing Regulation (EU) 2024/2690 adds detail: the cryptography policy must follow asset classification and the results of the risk assessment. More in our NIS2 Article 21 guide.
- DORA. Under Article 9 of Regulation (EU) 2022/2554 and its risk management RTS, Delegated Regulation (EU) 2024/1774, financial entities must keep a documented encryption and cryptographic controls policy. Article 6 of the RTS requires that policy to provide for updating cryptographic technology on the basis of developments in cryptanalysis. Article 7 covers key management and a register of certificates. See DORA Article 9 and the cryptographic inventory.
Once a public, EU-endorsed timeline says quantum-vulnerable cryptography in high-risk use cases should be replaced by 2030, “we were not aware of the risk” stops being a credible answer to an auditor. What NIS2 and DORA treat as an appropriate cryptography policy will increasingly be judged against that timeline.
The roadmap does not create a new obligation. It sets the date against which your existing NIS2 or DORA obligations will be read.
What the national agencies say
The two agencies EU practitioners cite most, France’s ANSSI and Germany’s BSI, agree on direction and on method: hybrid deployment during the transition.
- ANSSI describes a phased transition. Hybrid mechanisms, which combine a classical algorithm with a post-quantum one, come first. Standalone PQC becomes an option only in a later phase, which ANSSI expects no earlier than around 2030. ANSSI strongly recommends hybrid post-quantum protection for products meant to protect information over the long term, and applies the hybrid principle to signatures as well as key establishment.
- BSI also recommends using post-quantum mechanisms in combination with classical ones, and publishes its algorithm guidance in Technical Guideline TR-02102. In November 2024, BSI and partner agencies from 18 EU Member States issued a joint statement, Securing Tomorrow, Today. It called for the most sensitive use cases to be protected against “store now, decrypt later” attacks by the end of 2030 at the latest. The roadmap later set the same date.
For an enterprise, that means the 2030 target is not just “switch to ML-KEM”. It means running classical and post-quantum mechanisms side by side, which in turn depends on crypto-agility: being able to change algorithms without rewriting every application. The standards involved are covered in our FIPS 203/204/205 migration guide.
What “end of 2026” means with three months left
For a regulated enterprise, the practical reading of the 2026 milestone is simple. By 31 December, you should be able to show that you know where your quantum-vulnerable cryptography is, which of it is high risk, and what you will do first.
You do not need to have migrated anything by then. You need evidence that you have started. That evidence is the inventory, the risk classification and a prioritised plan.
A 90-day plan to reach the 2026 milestone
The sequence below fits the time left this year. It assumes a named owner (usually the CISO’s office), access to the main code repositories, and a list of internet-facing endpoints.
- Weeks 1–2: scope and stakeholders. Agree which business services are in scope. Start with the critical or important functions you already report under DORA or NIS2. Name owners in security, architecture, PKI and procurement. Ask your top suppliers for their PQC plans now, because the answers take weeks to come back.
- Weeks 2–6: inventory. Find cryptography in three places: source code (library calls, hard-coded algorithms, key sizes), X.509 certificates, and live TLS configurations. Expect surprises in legacy Java services, vendored C libraries and internal TLS that nobody has looked at in years. A cryptographic inventory built from scans beats one built from questionnaires.
- Weeks 5–8: classification. For each asset, record the algorithm, what data it protects, and how long that data must stay confidential. That last field turns a list of RSA keys into a risk register. Mark the use cases that meet the roadmap’s high-risk profile.
- Weeks 7–10: CBOM. Export the inventory as a Cryptography Bill of Materials in a standard format such as CycloneDX 1.6, so it can be versioned, compared between scans and handed to auditors. See what a CBOM looks like.
- Weeks 9–12: prioritise and report. Rank assets by quantum risk and HNDL window. Pick a first migration wave and one or two pilots, which the roadmap expects by end-2026. Write it up for the board: current exposure, the 2030 target for high-risk use cases, and the budget required.
If you are unsure where to start, our free 2-minute PQC readiness self-assessment shows where the gaps are. The CISO readiness checklist goes into more detail.
How CRYPTAGION fits
CRYPTAGION was built for this milestone. It performs static analysis of Python, JS/TS, Java, Go and C/C++, parses X.509 certificates, and scans live TLS endpoints. Each asset gets a 0–100 quantum risk score that takes HNDL exposure into account and is anchored to NIST IR 8413, BSI TR-02102-1 and CNSA 2.0. Output is a CycloneDX 1.6 CBOM, a 4-wave migration roadmap, and a board-ready PDF mapped to DORA, NIS2, the EU CRA and FIPS 203/204/205. It runs on-premises or air-gapped, so your code never leaves your perimeter.
The takeaway
The EU timeline is now fixed: start by the end of 2026, finish high-risk use cases by 2030, and complete medium-risk ones by 2035. The milestone at the end of this year is the cheapest to meet and the most embarrassing to miss, because it asks only for visibility and a plan. Use the next twelve weeks to build the inventory. Every later milestone depends on it.
Sources
- European Commission — A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (NIS Cooperation Group, June 2025)
- Commission Recommendation (EU) 2024/1101 of 11 April 2024 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography
- European Commission — Post-quantum cryptography policy page
- Directive (EU) 2022/2555 (NIS2), Article 21
- Commission Implementing Regulation (EU) 2024/2690 (NIS2 technical and methodological requirements)
- Regulation (EU) 2022/2554 (DORA), Article 9
- Commission Delegated Regulation (EU) 2024/1774 (ICT risk management RTS), Articles 6–7
- BSI et al. — Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography (joint statement, November 2024)
- BSI — Technical Guideline TR-02102 Cryptographic Mechanisms
- ANSSI — Post-quantum cryptography
- ANSSI — Follow-up position paper on post-quantum cryptography
Get your end-2026 evidence pack in place
CRYPTAGION produces the inventory, CBOM, risk scores and board report that the first EU milestone calls for, and it runs inside your perimeter.
Book a free discovery call → Or take the 2-minute readiness assessment