EU roadmap · Deadlines

The EU post-quantum roadmap: what you must have done by 2026, 2030 and 2035

Published 7 October 2026 · 7 min read · By Ali Korsi The first EU milestone falls at the end of this year. Here is what it asks for, how it connects to DORA and NIS2, and how to get there in the weeks that remain.

Lire en français

In June 2025, EU Member States, supported by the European Commission, published A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography. It was drafted by a dedicated post-quantum cryptography (PQC) workstream of the NIS Cooperation Group, and it answers the Commission’s Recommendation (EU) 2024/1101 of 11 April 2024, which asked Member States to agree a common strategy and timeline for moving to PQC.

The roadmap sets three dates: the end of 2026, the end of 2030 and 2035. With roughly twelve weeks left in 2026, the first one is no longer a planning question. It is a delivery question.

The three milestones

The roadmap is risk-based. Its milestones, in summary:

ByWhat the roadmap expects
End of 2026Every Member State has started the transition: “first steps” taken, a national transition plan in place, and pilots launched for high- and medium-risk use cases. The first steps include identifying stakeholders, cryptographic asset management (inventories), dependency mapping including the supply chain, quantum risk analysis, and awareness programmes.
End of 2030High-risk use cases moved to PQC “as soon as possible, no later than” the end of 2030, with quantum-safe upgrade paths in place for the products and services involved.
2035Medium-risk use cases transitioned. The Commission summarises the end state as moving as many systems as feasible to PQC by 2035.

“High risk” is not a list of sectors. It is driven largely by harvest-now-decrypt-later exposure: systems protecting data that must stay confidential for many years, and systems that will take a long time to migrate. A payment platform’s long-term archive and a hospital’s patient-records exchange are likely to qualify. A marketing site will not.

Who the roadmap actually binds

Precision matters here. The roadmap is a coordination document addressed to Member States. It is not a regulation, and it creates no new legal obligation for a bank or an energy operator on its own.

In practice that distinction offers little shelter. National cybersecurity agencies and sector supervisors are the bodies that will carry the roadmap forward, and they reach regulated entities through law that already applies:

Once a public, EU-endorsed timeline says quantum-vulnerable cryptography in high-risk use cases should be replaced by 2030, “we were not aware of the risk” stops being a credible answer to an auditor. What NIS2 and DORA treat as an appropriate cryptography policy will increasingly be judged against that timeline.

The roadmap does not create a new obligation. It sets the date against which your existing NIS2 or DORA obligations will be read.

What the national agencies say

The two agencies EU practitioners cite most, France’s ANSSI and Germany’s BSI, agree on direction and on method: hybrid deployment during the transition.

For an enterprise, that means the 2030 target is not just “switch to ML-KEM”. It means running classical and post-quantum mechanisms side by side, which in turn depends on crypto-agility: being able to change algorithms without rewriting every application. The standards involved are covered in our FIPS 203/204/205 migration guide.

What “end of 2026” means with three months left

For a regulated enterprise, the practical reading of the 2026 milestone is simple. By 31 December, you should be able to show that you know where your quantum-vulnerable cryptography is, which of it is high risk, and what you will do first.

You do not need to have migrated anything by then. You need evidence that you have started. That evidence is the inventory, the risk classification and a prioritised plan.

A 90-day plan to reach the 2026 milestone

The sequence below fits the time left this year. It assumes a named owner (usually the CISO’s office), access to the main code repositories, and a list of internet-facing endpoints.

  1. Weeks 1–2: scope and stakeholders. Agree which business services are in scope. Start with the critical or important functions you already report under DORA or NIS2. Name owners in security, architecture, PKI and procurement. Ask your top suppliers for their PQC plans now, because the answers take weeks to come back.
  2. Weeks 2–6: inventory. Find cryptography in three places: source code (library calls, hard-coded algorithms, key sizes), X.509 certificates, and live TLS configurations. Expect surprises in legacy Java services, vendored C libraries and internal TLS that nobody has looked at in years. A cryptographic inventory built from scans beats one built from questionnaires.
  3. Weeks 5–8: classification. For each asset, record the algorithm, what data it protects, and how long that data must stay confidential. That last field turns a list of RSA keys into a risk register. Mark the use cases that meet the roadmap’s high-risk profile.
  4. Weeks 7–10: CBOM. Export the inventory as a Cryptography Bill of Materials in a standard format such as CycloneDX 1.6, so it can be versioned, compared between scans and handed to auditors. See what a CBOM looks like.
  5. Weeks 9–12: prioritise and report. Rank assets by quantum risk and HNDL window. Pick a first migration wave and one or two pilots, which the roadmap expects by end-2026. Write it up for the board: current exposure, the 2030 target for high-risk use cases, and the budget required.
The end-2026 evidence pack: scoped inventory + per-asset risk classification + CBOM + prioritised roadmap with named pilots + a board paper that references the EU milestones.

If you are unsure where to start, our free 2-minute PQC readiness self-assessment shows where the gaps are. The CISO readiness checklist goes into more detail.

How CRYPTAGION fits

CRYPTAGION was built for this milestone. It performs static analysis of Python, JS/TS, Java, Go and C/C++, parses X.509 certificates, and scans live TLS endpoints. Each asset gets a 0–100 quantum risk score that takes HNDL exposure into account and is anchored to NIST IR 8413, BSI TR-02102-1 and CNSA 2.0. Output is a CycloneDX 1.6 CBOM, a 4-wave migration roadmap, and a board-ready PDF mapped to DORA, NIS2, the EU CRA and FIPS 203/204/205. It runs on-premises or air-gapped, so your code never leaves your perimeter.

The takeaway

The EU timeline is now fixed: start by the end of 2026, finish high-risk use cases by 2030, and complete medium-risk ones by 2035. The milestone at the end of this year is the cheapest to meet and the most embarrassing to miss, because it asks only for visibility and a plan. Use the next twelve weeks to build the inventory. Every later milestone depends on it.

Sources

Get your end-2026 evidence pack in place

CRYPTAGION produces the inventory, CBOM, risk scores and board report that the first EU milestone calls for, and it runs inside your perimeter.

Book a free discovery call → Or take the 2-minute readiness assessment

← All resources · Home