CRYPTOGRAPHY COMPLIANCE / BEGINNER

Why Regulators Now Care About Your Cryptography

Cryptography used to be an engineering detail. Payment standards, financial supervisors and governments now ask for evidence about it. Here is why, and what kinds of rules exist.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Choosing an encryption algorithm has traditionally been treated as an engineering decision, made by developers and product vendors and reviewed, if at all, as a technical detail. That is changing. Over the last few years, payment card standards, EU financial rules, central banks and national governments have started to ask organisations to show which cryptography they use, where it runs and how they plan to change it. The Monetary Authority of Singapore published its quantum advisory in February 2024, a new payment card requirement became mandatory in March 2025, and several supervisors and governments followed with dated expectations in 2026.

This article explains what is driving that shift, the different kinds of rules you will meet, and the one request that almost all of them share. The rest of this section looks at each framework in more detail.

The Problem Regulators Are Responding To

Most secure connections and digital signatures rely on public-key algorithms such as RSA and elliptic curve cryptography. These are the algorithms that let two parties agree a secret key over an open network and let software prove who signed it. A large enough quantum computer, often called a cryptographically relevant quantum computer, could break those algorithms. The US Office of Management and Budget put the current position plainly in June 2026: such a machine “is not yet known to exist”, but steady progress could produce one within the coming decade.1

The timing matters less than you might expect, because of a tactic known as harvest now, decrypt later. An attacker can record encrypted traffic today and decrypt it once the capability exists. The G7 Cyber Expert Group, which advises G7 finance ministers and central bank governors, notes that under this scenario data can be at risk long before a quantum computer of that size appears.2

Migration is also slow. Cryptography sits inside applications, network devices, hardware security modules, vendor products and partner connections. Replacing it means finding it first, then testing, buying and rolling out alternatives. Regulators have concluded that organisations which wait for certainty will not finish in time.

Why Cryptography Became An Audit Topic

Three things turned this from a research topic into a compliance one.

First, standards caught up. The US National Institute of Standards and Technology (NIST), whose cryptographic standards are used well beyond the US, published its main post-quantum standards for key establishment and digital signatures in August 2024. Organisations now have approved replacements to plan towards.3

Second, existing rules already contained hooks. The Payment Card Industry Data Security Standard (PCI DSS) expects an organisation to keep a current list of the cipher suites and protocols it relies on, watch whether they stay safe, plan for weaknesses it can see coming, and revisit all of this at least once every 12 months. That requirement has been mandatory since 31 March 2025.4 The EU’s Digital Operational Resilience Act (DORA) applies technical standards that require financial entities to keep an encryption policy that allows cryptography to be updated as cryptanalysis develops.5 DORA’s binding articles do not name quantum computing, although recital 9 of the technical standard recognises quantum-related cryptographic risks,6 and the PCI DSS requirement is written in general terms, but both give auditors a reason to ask about it.

Third, newer instruments name the quantum threat directly. The Saudi Central Bank (SAMA) issued a circular in August 2026 requiring supervised institutions to make their procedures for identifying and classifying all cryptographic assets accurate and comprehensive by the end of 2026.7 In the US, a June 2026 executive order directed the budget office to set dates for federal systems to move to post-quantum key establishment and signatures, and the office’s memorandum turned those dates into a phased plan.1

Binding Rules, Supervisory Expectations And Guidance

Not every document carries the same weight, and treating guidance as law (or law as guidance) leads to poor decisions. It helps to sort the instruments into layers.

  1. Law And Binding RegulationLegally enforceable. Examples: DORA and its ICT risk technical standards for EU financial entities, the SAMA quantum circular, US executive orders and OMB memoranda for federal agencies.
  2. Contractual StandardsBinding through contracts with card brands and acquirers rather than by statute. Example: PCI DSS.
  3. Supervisory ExpectationsIssued by a regulator to the firms it supervises. Not always legally binding, but ignored at your own risk. Examples: the MAS quantum advisory in Singapore and FINMA Guidance 05/2026 in Switzerland.
  4. National Guidance And RoadmapsRecommended timelines from cyber agencies and governments. Examples: UK NCSC migration timelines and the EU coordinated roadmap.
  5. Non-Binding StatementsShared reference points from international groups. Example: the G7 Cyber Expert Group roadmap, which states that it sets no regulatory expectations.
How much weight each kind of instrument carries, from strongest at the top. Examples are as of October 2026.

The label tells you who can enforce it and what happens if you fall short. A missed PCI DSS requirement shows up in your assessment report. A missed SAMA deadline is a supervisory matter. A missed NCSC milestone has no direct penalty, though it may shape what your regulator expects next.

The Common Thread: Know What You Have

Read the instruments side by side and one request repeats. Before any migration date, almost every framework asks you to find and record the cryptography you depend on, usually alongside a risk assessment.

The Monetary Authority of Singapore advises financial institutions to keep an inventory that records each algorithm and key length, who owns it, and which system uses it.8 The UK National Cyber Security Centre asks organisations to complete discovery and an initial plan by 2028.9 Swiss supervisor FINMA starts with a risk analysis of business processes, which it expects to produce a comprehensive inventory that is kept up to date.10 The US migration memo for federal agencies opens with a discovery phase in 2026 and 2027.1

That is useful news. Work done once, if it is recorded well, can answer several regulators at the same time. The last article in this section shows how one inventory maps to several frameworks.

Deadlines Already In Play

Some of these dates have passed and others are close. The countdowns below update in your browser.

  1. In effect

    European Union · European Commission Binding

    Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.

    Delegated Regulation (EU) 2024/1774 (DORA ICT risk RTS), Articles 6 and 7. Applies to EU financial entities under the full DORA ICT risk framework. Source · Verified 7 Oct 2026

  2. In effect

    Global payments · PCI Security Standards Council Binding

    Keep documentation of the cryptographic cipher suites and protocols in use, with a current inventory of what each does and where it runs, active tracking of whether each remains safe and a plan for reacting to foreseeable cryptographic weaknesses, and review it at least once every 12 months. Treated as a best practice until this date and required since.

    PCI DSS v4.0.1, requirement 12.3.3. Applies to entities in scope of PCI DSS (contractual standard), for all cipher suites and protocols used to meet PCI DSS requirements. Source · Verified 7 Oct 2026

  3. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  4. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  5. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  6. Upcoming

    United States · The White House and Office of Management and Budget Binding

    OMB guidance issued under the order must require agencies to move all high value assets and high impact systems to post-quantum key establishment by this date. M-26-15 plans this as its 2028 to 2030 migration phase.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks (22 June 2026), section 4(b)(ii), through OMB guidance including Memorandum M-26-15. Applies to US federal agencies (national security systems excluded). Source · Explainer · Verified 7 Oct 2026

Countdowns run to the end of each deadline date (UTC) and are calculated in your browser. "Binding" means legally or contractually required; other labels describe supervisory expectations, guidance, drafts or announcements. Always check the source for the current text.

Footnotes

  1. US Office of Management and Budget, “M-26-15: Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2 ↩3

  2. G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩

  3. Partners from 18 EU Member States, “Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography”, 27 November 2024. bsi.bund.de ↩

  4. PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirement 12.3.3. pcisecuritystandards.org ↩

  5. European Commission, “Commission Delegated Regulation (EU) 2024/1774”, Article 6, 13 March 2024. eur-lex.europa.eu ↩

  6. European Commission, “Commission Delegated Regulation (EU) 2024/1774”, recital 9, 13 March 2024. eur-lex.europa.eu ↩

  7. Saudi Central Bank, “Circular 482021280: Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩

  8. Monetary Authority of Singapore, “MAS/TCRS/2024/01: Advisory on Addressing the Cybersecurity Risks Associated with Quantum”, 20 February 2024. mas.gov.sg ↩

  9. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

  10. FINMA, “FINMA Guidance 05/2026: Quantum computing”, 9 July 2026. finma.ch ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.