EU: NIS2, DORA, The Cyber Resilience Act And The 2030 PQC Roadmap
The EU has binding cryptography duties in NIS2, DORA and the Cyber Resilience Act, and non-binding post-quantum dates of 2026, 2030 and 2035. Here is how they fit together as of October 2026.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
The European Union has no single law that orders organisations to move to post-quantum cryptography. What it has instead is a set of binding rules that already require a cryptography policy, an encryption approach based on risk, and a way to keep cryptography current, plus a coordinated roadmap that attaches dates to the quantum transition without making them law.
This article sets out that structure as of October 2026: which instruments are binding, who they apply to, and where the post-quantum dates come from. It is general information, not legal advice. For the detail of DORA’s encryption articles, see Cryptography Compliance, and for the AI Act, see AI Governance And Regulation. The global overview compares the EU with other regions.
How The EU Rules Stack Up
The easiest way to read EU cyber rules is as horizontal law that covers many sectors, sector law that sits on top for finance, and guidance that sets the quantum timetable.
- Post-Quantum Roadmap And FAQ (Guidance)First steps and national roadmaps by end 2026, high-risk use cases by end 2030, medium-risk by end 2035. Member States and NIS2 entities are the audience.
- DORA And RTS 2024/1774 (Binding, Financial Sector)Encryption policy, key lifecycle, certificate register, and updates in response to cryptanalysis.
- Cyber Resilience Act (Binding, Products)State of the art protection of data confidentiality for products with digital elements.
- NIS2 And Implementing Regulation 2024/2690 (Binding, Essential And Important Entities)Policies on cryptography and, where appropriate, encryption. Detailed rules for digital and ICT providers.
NIS2: A Cryptography Policy For Every In-Scope Entity
The NIS2 Directive lists the cybersecurity risk management measures that essential and important entities must take. One of them, in Article 21(2)(h), is to have policies and procedures on how cryptography, and where appropriate encryption, is used. Member States had to transpose the Directive by 17 October 2024.1 Status: Binding, through national law.
For one group of entities the requirement is spelled out in more detail. Commission Implementing Regulation (EU) 2024/2690 applies to digital infrastructure and ICT providers, such as DNS and cloud providers, data centres, content delivery networks, managed and managed security service providers, online marketplaces, search engines, social networks and trust service providers. Section 9 of its Annex asks for a cryptography policy, choices of algorithms and cipher strength that follow a cryptographic agility approach where appropriate, a full key lifecycle, and periodic review against the state of the art.2 Status: Binding for those entities only.
Transposition has been slow. The Commission sent formal notices to 23 Member States in November 2024 and reasoned opinions to 19 in May 2025, and in July 2026 referred Ireland, Spain, France and the Netherlands to the Court of Justice, asking for financial penalties.3 On 20 January 2026 the Commission also proposed amendments to NIS2 (COM(2026) 13), which would clarify scope, definitions and jurisdiction and give ENISA a role in supporting the supervision of cross-border entities.4 Status: Draft.
The NIS Cooperation Group’s FAQ of 15 April 2026 connects NIS2 to quantum risk. Its baseline is aimed at entities within the scope of NIS2: they should, at a minimum, build an inventory of their cryptographic assets and map the dependencies between them. It encourages every other organisation to take the same steps, and to bring in its supply chain and analyse its quantum risk as part of that work.5 Status: Guidance.
DORA: The Closest Thing To A Quantum Clause
The Digital Operational Resilience Act (DORA) has applied to EU financial entities since 17 January 2025. Its ICT risk management standard, Delegated Regulation (EU) 2024/1774, requires an encryption and cryptographic controls policy (Article 6) and full key lifecycle management with a register of certificates and certificate-storing devices, at least for ICT assets that support critical or important functions (Article 7).6 These articles apply to entities under the full ICT risk framework. Status: Binding.
Article 6(4) is the provision quantum readiness work hangs on. It requires the policy to provide for updating or changing cryptography when developments in cryptanalysis call for it, and for mitigation and monitoring where that cannot be done. Article 6(4) does not use the word quantum, though recital 9 of the same regulation refers to threats from quantum advances, and a working quantum attack would be exactly such a development. The Cryptography Compliance group covers these articles paragraph by paragraph.
Supervisors are signalling that more is coming. In a July 2026 letter to banks on AI-enabled cyber threats, the ECB said adoption of post-quantum cryptography must start now and that it would address quantum risk in a separate letter, which had not been published as of October 2026.7 Status: Supervisory. The European Banking Authority’s 2027 work programme includes analysis of quantum computing risks.8 Status: Announcement (a work plan), so treat it as a signal rather than a rule.
The Cyber Resilience Act: Products Next
The Cyber Resilience Act (Regulation (EU) 2024/2847) sets security requirements for products with digital elements. Under Annex I, manufacturers must keep the data that their products store, send or process confidential. The example the annex gives is encryption that uses current best practice, both for data held on the product and for data moving across a network.9 Status: Binding.
Its dates are staggered. The Article 14 reporting obligations for actively exploited vulnerabilities and severe incidents have applied since 11 September 2026, and the main obligations, including Annex I, apply from 11 December 2027.9 For software and hardware vendors selling into the EU, “state of the art” encryption becomes a design question to settle well before then.
The Post-Quantum Roadmap: Dates Without A Law
The quantum dates come from a Commission Recommendation of 11 April 2024 and the Coordinated Implementation Roadmap that Member States produced through the NIS Cooperation Group. Version 1.1 of the roadmap asks Member States to take first steps, set initial national roadmaps and start planning and pilots by the end of 2026, to complete high-risk use cases by the end of 2030, and to complete medium-risk use cases by the end of 2035, with low-risk ones as far as feasible.10 Status: Guidance.
- In effect
European Union · European Commission Binding
Encryption policy, key lifecycle and certificate register rules apply through DORA from this date: the policy must provide for updating cryptography based on developments in cryptanalysis, and a register of certificates and certificate-storing devices must be kept up to date, at least for ICT assets supporting critical or important functions. The RTS itself entered into force on 15 July 2024.
- In effect
European Union · European Parliament and Council Binding
Manufacturer reporting obligations in Article 14 apply.
- Upcoming
European Union · NIS Cooperation Group Guidance
All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.
- Upcoming
European Union · European Parliament and Council Binding
Main obligations apply, including the Annex I requirement to protect data confidentiality, for example by encrypting data at rest or in transit with state of the art mechanisms.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for high-risk use cases.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for medium-risk use cases, and for low-risk use cases as far as feasible.
A Brief Word On AI
The AI Act is the EU’s horizontal AI law. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the Annex III high-risk obligations to 2 December 2027 and the product-linked Annex I obligations to 2 August 2028.11 Status: Binding. The AI Governance And Regulation group explains the full timeline, and AI Regulation At A Glance compares it with other regions.
Footnotes
-
European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Articles 21(2)(h) and 41(1), 14 December 2022. eur-lex.europa.eu ↩
-
European Commission, Implementing Regulation (EU) 2024/2690, Article 1 and Annex section 9, 17 October 2024. eur-lex.europa.eu ↩
-
European Commission, “Commission refers Ireland, Spain, France and the Netherlands to the Court of Justice for failing to transpose the rules on cybersecurity”, IP/26/1499, 8 July 2026. ec.europa.eu ↩
-
European Commission, proposal amending Directive (EU) 2022/2555, COM(2026) 13 final, 20 January 2026. eur-lex.europa.eu ↩
-
NIS Cooperation Group, “EU Roadmap on PQC: Frequently Asked Questions”, section 7.4, 15 April 2026. ec.europa.eu ↩
-
European Commission, Delegated Regulation (EU) 2024/1774, Articles 6 and 7, 13 March 2024. eur-lex.europa.eu ↩
-
European Central Bank, letter to banks on AI-enabled cybersecurity threats (SSM-2026-0301), 7 July 2026. bankingsupervision.europa.eu ↩
-
European Banking Authority, Work Programme 2027 (EBA/REP/2026/18), September 2026. eba.europa.eu ↩
-
European Parliament and Council, Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71(2) and Annex I Part I, 23 October 2024. eur-lex.europa.eu ↩ ↩2
-
NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, Part 1, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩
-
European Parliament and Council, Regulation (EU) 2026/1744 (Digital Omnibus on AI), 8 July 2026. eur-lex.europa.eu ↩
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.