Post-Quantum And Cyber Regulation In 2026: Who Requires What, And By When
A region by region map of cryptography and post-quantum rules as of October 2026, showing which dates are binding and which are guidance, with live countdowns.
Cryptography, cybersecurity and AI rules region by region, from the UAE and Saudi Arabia to the EU, UK, US and Asia Pacific.
A region by region map of cryptography and post-quantum rules as of October 2026, showing which dates are binding and which are guidance, with live countdowns.
A cryptographic inventory is binding in a few places and recommended almost everywhere else. Here is who requires one, what each expects it to contain, and where a CBOM is named.
The UAE has a detailed national encryption policy with a post-quantum section, but it binds a defined set of entities and sets no migration date. Here is who is in scope as of October 2026.
SAMA's August 2026 circular gives Saudi financial institutions dated quantum duties, built on years of binding NCA and SAMA cryptography controls. Here is what applies and when, as of October 2026.
As of October 2026, no post-quantum instrument and no binding AI law were found in Qatar, Bahrain, Oman or Kuwait. Here is what still applies, which AI policies exist, and what to watch.
The EU has binding cryptography duties in NIS2, DORA and the Cyber Resilience Act, and non-binding post-quantum dates of 2026, 2030 and 2035. Here is how they fit together as of October 2026.
Neither the UK nor Switzerland has a binding post-quantum rule as of October 2026. The UK relies on NCSC dates; FINMA recommends a roadmap by mid-2027. Here is what each expects.
US post-quantum deadlines bind federal agencies and soon contractors. Private firms face sector encryption and disclosure rules instead. A map of who is bound by what, as of October 2026.
Canada pairs a dated post-quantum roadmap for federal systems with OSFI guidelines for banks and insurers. Here is what is binding, what is guidance, and which dates matter, as of October 2026.
Singapore has dated quantum-safe milestones for critical infrastructure and promised milestones for financial institutions. Hong Kong has measured its banks and set a 2030 aim. The position as of October 2026.
India's binding rules already demand strong cryptography and name post-quantum risk, while the dated migration milestones sit in a national roadmap. What applies, and what is still under study, as of October 2026.
Japan's FSA has asked banks to start post-quantum work now, South Korea leads on AI law, and Australia has the earliest government cryptography date of the three. How the three compare, as of October 2026.
PCI DSS v4.0.1 already requires the building blocks of quantum readiness, but neither PCI SSC nor EMVCo has set a quantum requirement. Here is what applies worldwide as of October 2026.
A one-page comparison of AI rules by region as of October 2026, separating binding laws from guidance, with the next dates to watch and links to deeper reading.