In response to newly emerging threats to data integrity, the Commission is advancing the EU’s transition to Post-Quantum Cryptography (PQC).
Public-key cryptography algorithms are used to protect data confidentiality and authenticity in our digital society. Quantum computing has the potential to break these algorithms. To stay protected, we need to progress towards Post-Quantum Cryptography (PCQ), a new type of public-key cryptography designed to resist to both quantum and classical attacks.
Cryptography is the cornerstone of cybersecurity, protecting our digital infrastructures and data. While quantum technologies are expected to deliver societal benefits, such as in the domain of new materials, new medicines and finance applications, quantum computing will constitute a threat for public-key cryptography.
Public-key cryptography constitutes the largest part of cryptographic deployments in the world. Data that is currently not quantum-safe, whether it is stored or transmitted, and that must remain confidential for a long time, may be already at risk. “Store now, decrypt later” attacks are already likely occurring, where malicious actors are storing traffic already today to be able to decrypt it later when a quantum computer will be available. In addition, authenticity will be jeopardised by quantum computers once the technology will be available. An effective solution to these threats is PQC. PQC is constructed on the basis of complex mathematical problems that are difficult even for quantum computers to solve.
A harmonised approach across the EU
Consequently, in April 2024, the Commission published a Recommendation on Post-Quantum Cryptography, encouraging Member States to develop a comprehensive strategy for the adoption of PQC, to ensure a coordinated and synchronised transition among the different Member States and their public sectors and private entities serving public utilities.
The Recommendation complements the work already being done by many countries and at international level to develop and select PQC algorithms for standards. These include research efforts done by EU-funded projects, and discussions on PQC at international level, such as in the EU-US Trade and Technology Council, Cyber Dialogues and the G7 Cybersecurity Working Group.
A PQC Implementation Roadmap
Following the Commission Recommendation, the NIS Cooperation Group established a work stream on PQC, co-chaired by Germany, France and the Netherlands, to develop this comprehensive strategy for the adoption of PQC.
Subsequently, the EU Member States, supported by the Commission, adopted the Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography in June 2025. This document is the first deliverable of the work stream and is meant to be a first high-level paper aimed at Member States. It includes a set of recommendations that Member States need to implement for a synchronised transition to PQC, as well as measures to ensure that all stakeholders are well informed on the quantum threat to cryptography. All Member States should start transitioning to PQC by the end of 2026. At the same time, the protection of high-risk use cases should be transitioned to PQC as soon as possible, no later than by the end of 2030.
From 11 August to 29 September 2025, the NIS Cooperation Group ran a survey to seek feedback on the EU Roadmap for the Transition to PQC from stakeholders and contribute to defining the next steps towards a safe PQC migration.
In response to the feedback received, the NIS Cooperation Group published a document with Frequently Asked Questions on the EU Roadmap for the Transition to PQC, together with the survey results.The FAQ document aims to clarify frequently asked questions on topics such as quantum risk estimation, milestones, prioritisation, hybrid schemes, the EU’s role and national roadmaps.
Currently, the NIS Cooperation Group work stream on PQC is working on a second deliverable to supplement the EU Roadmap for the Transition to PQC.
National implementation
You can find more information concerning the implementation of the Coordinated Implementation Roadmap for the Transition to PQC in your Member State below:
France
- Post-quantum cryptography (PQC) - Agence nationale de la sécurité des systèmes d'information (ANSSI)
The Netherlands
- Quantumveilige cryptografie - Digitale Overheid
- Quantumveilige cryptografie - Nationaal Cyber Security Centrum (NCSC)
This list will be updated by further national documents, as available. For more information concerning the implementation of the Coordinated Implementation Roadmap for the Transition to PQC in your Member State, please reach out to your national competent authority.
Contenuti correlati
Quadro generale