CRYPTOGRAPHY COMPLIANCE / ADVANCED

EU Cryptography Rules Beyond DORA: The Recommendation, Roadmap, NIS2 And CRA

The EU has no single post-quantum law. Instead, a Commission Recommendation, a Member State roadmap, NIS2 and the Cyber Resilience Act each play a part. Here is how they fit together.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Financial entities in the EU have a clear cryptography rule in the DORA technical standards. Everyone else has to piece the picture together from several instruments. Some are binding law that mentions encryption only in general terms. Others are detailed post-quantum plans that carry no legal force.

This article sets out the main EU instruments as of October 2026, explains which are binding and which are guidance, and shows how they relate to DORA. It assumes some familiarity with EU legislative terms.

The Overall Structure

It helps to think of the EU approach in three layers.

  1. Policy Coordination (Non-Binding)Commission Recommendation (EU) 2024/1101, the NIS Cooperation Group roadmap of June 2025 and its April 2026 FAQ. These set the post-quantum timeline and first steps.
  2. Horizontal Law (Binding)The NIS2 Directive, which requires cryptography policies from essential and important entities, and the Cyber Resilience Act, which requires products with digital elements to protect data confidentiality.
  3. Sector Law (Binding)DORA and Delegated Regulation (EU) 2024/1774 for financial entities, which take the place of the NIS2 risk management rules for those firms.
How the main EU instruments on cryptography relate to each other, as of October 2026.

The post-quantum dates live in the top layer. The legal obligations live in the lower two, and their binding articles do not name quantum computing, although recital 9 of the DORA technical standard recognises quantum-related cryptographic risks.1 Connecting them is a matter of interpretation, which this article points out where it happens.

The Recommendation And The Roadmap

On 11 April 2024 the European Commission adopted Recommendation (EU) 2024/1101 on a coordinated implementation roadmap for the transition to post-quantum cryptography.2 A recommendation is not binding. It invited Member States to form a sub-group of the NIS Cooperation Group, the body that brings national cybersecurity authorities together under NIS2, and to produce a roadmap within two years.

They moved faster than that. Partners from 18 Member States had already issued a joint statement in November 2024 recommending that the most sensitive uses be protected against store now, decrypt later attacks by the end of 2030 at the latest.3 The roadmap itself, version 1.1, was published on 23 June 2025.4 Its timeline has three milestones:

  • By 31 December 2026: all Member States have implemented the first steps, set initial national transition roadmaps and started planning and pilots for high-risk and medium-risk use cases.
  • By 31 December 2030: the next steps are implemented, high-risk use cases have completed the transition, and quantum-safe software and firmware upgrades are enabled by default.
  • By 31 December 2035: medium-risk use cases are complete, and low-risk use cases are complete as far as feasible.

The roadmap also says that, for high-risk use cases, quantum-vulnerable public-key mechanisms should not be used on their own after the end of 2030, and recommends standardised hybrid schemes that combine classical and post-quantum algorithms where feasible.4

In April 2026 the NIS Cooperation Group published an FAQ on the roadmap. It says that, at a minimum, entities in scope of NIS2 should create an inventory of cryptographic assets and dependency maps, involve their supply chain and perform a quantum risk analysis, and it encourages all organisations to do the same.5 It also makes clear that an inventory does not need to be finished before planning starts.

NIS2: A Cryptography Policy Requirement

The NIS2 Directive, (EU) 2022/2555, is binding, but as a directive it works through national laws. Member States had to adopt their transposing measures by 17 October 2024 and apply them from 18 October 2024.6

Article 21(2) lists the minimum cybersecurity risk management measures that essential and important entities must take. Point (h) covers policies and procedures on the use of cryptography and, where appropriate, encryption.6 The text does not specify algorithms or dates. In the author’s view, a cryptography policy that ignored a threat the EU’s own roadmap treats as urgent would be hard to defend, but that is an interpretation, not a stated rule.

For certain digital infrastructure and digital service providers listed in Article 21(5), the Commission was required to adopt implementing acts with more technical detail by 17 October 2024.6 It did so in Implementing Regulation (EU) 2024/2690 of 17 October 2024, which covers DNS service providers, top-level domain registries, cloud computing, data centre and content delivery network providers, managed and managed security service providers, online marketplaces, search engines, social networking platforms and trust service providers.7

For those providers, section 9 of its annex turns point (h) into specific duties. They need a cryptography policy based on their asset classification and risk assessment that sets the type and strength of protection for data at rest and in transit, the protocols and algorithms they approve (following, where appropriate, a crypto-agility approach, meaning systems can switch algorithms without major rework) and their approach to key management across the key lifecycle. They must also review the policy at planned intervals, taking the state of the art in cryptography into account.7 Other NIS2 entities are not bound by that annex, though they may find it a useful reference.

The Cyber Resilience Act: Encryption In Products

The Cyber Resilience Act (CRA), Regulation (EU) 2024/2847, sets cybersecurity requirements for products with digital elements sold in the EU. Annex I, Part I, point (2)(e) requires such products, based on their risk assessment and where applicable, to protect the confidentiality of stored, transmitted or otherwise processed data, for example by encrypting relevant data at rest or in transit “by state of the art mechanisms”.8

The CRA was published on 20 November 2024 and entered into force on 10 December 2024. It applies in stages: the rules on conformity assessment bodies from 11 June 2026, manufacturers’ reporting obligations under Article 14 from 11 September 2026, and the rest, including the Annex I requirements, from 11 December 2027.8

What counts as state of the art moves over time. The NIS Cooperation Group’s FAQ states that post-quantum cryptography is necessary to protect CRA products from quantum threats.5 That is guidance, but it signals how authorities may read the requirement as the 2027 date approaches.

Where DORA Fits

NIS2 treats DORA as a sector-specific act for financial entities. Under Article 4 of NIS2 and its recitals, DORA’s ICT risk management and incident reporting rules apply to those firms instead of the matching NIS2 provisions.6 For a bank or insurer, the binding cryptography rules are therefore Articles 6 and 7 of Delegated Regulation (EU) 2024/1774, covered in a separate article in this section. The roadmap and FAQ still apply as guidance, and a financial firm that also manufactures software products may fall under the CRA.

  1. In effect

    European Union · European Parliament and Council Binding

    Manufacturer reporting obligations in Article 14 apply.

    Cyber Resilience Act, Regulation (EU) 2024/2847, Article 71(2). Applies to manufacturers of products with digital elements on the EU market. Source · Explainer · Verified 7 Oct 2026

  2. Upcoming

    European Union · NIS Cooperation Group Guidance

    All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 1. Applies to EU Member States. Source · Verified 7 Oct 2026

  3. Upcoming

    European Union · European Parliament and Council Binding

    Main obligations apply, including the Annex I requirement to protect data confidentiality, for example by encrypting data at rest or in transit with state of the art mechanisms.

    Cyber Resilience Act, Regulation (EU) 2024/2847, Article 71(2) and Annex I. Applies to manufacturers, importers and distributors of products with digital elements on the EU market. Source · Explainer · Verified 7 Oct 2026

  4. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for high-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 2. Applies to EU Member States. Source · Verified 7 Oct 2026

  5. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1). Applies to EU Member States. Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

Footnotes

  1. European Commission, “Commission Delegated Regulation (EU) 2024/1774”, recital 9, 13 March 2024. eur-lex.europa.eu ↩

  2. European Commission, “Commission Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography”, 11 April 2024. eur-lex.europa.eu ↩

  3. Partners from 18 EU Member States, “Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography”, 27 November 2024. bsi.bund.de ↩

  4. NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩ ↩2

  5. NIS Cooperation Group, “EU Roadmap on PQC: Frequently Asked Questions”, 15 April 2026. ec.europa.eu ↩ ↩2

  6. European Parliament and Council, “Directive (EU) 2022/2555 (NIS2 Directive)”, Articles 4, 21 and 41, 14 December 2022. eur-lex.europa.eu ↩ ↩2 ↩3 ↩4

  7. European Commission, “Commission Implementing Regulation (EU) 2024/2690”, Article 1 and Annex section 9, 17 October 2024. eur-lex.europa.eu ↩ ↩2

  8. European Parliament and Council, “Regulation (EU) 2024/2847 (Cyber Resilience Act)”, Article 71 and Annex I, 23 October 2024. eur-lex.europa.eu ↩ ↩2

  9. EUR-Lex, “Regulation (EU) 2024/2847: document information”, consulted 7 October 2026. eur-lex.europa.eu ↩

  10. European Commission, “Proposal for a Regulation on public contracts and concessions (Public Procurement Act)”, COM(2026) 590 final, 9 September 2026. eur-lex.europa.eu ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.