Post-Quantum And Cyber Regulation In 2026: Who Requires What, And By When
A region by region map of cryptography and post-quantum rules as of October 2026, showing which dates are binding and which are guidance, with live countdowns.
Checked against primary sources and independently reviewed on . Sources are listed at the end.
Post-quantum dates now appear in documents from regulators, cyber agencies and governments on every continent. Read quickly, they suggest that the whole world has ordered companies to replace their cryptography by 2030 or 2035. Read carefully, the picture is narrower and more useful: a few binding rules go beyond general encryption duties, and they mostly ask private organisations for an inventory and a plan, while the later migration dates sit mostly in guidance or in rules for government systems.
This article is the starting point for the Regulations Across Regions group. It sets out the main instruments as of October 2026, labels each one by legal force, and shows the dates that are closest. The articles that follow go region by region. For the detailed wording of PCI DSS, DORA and the US federal timeline, see Cryptography Compliance. This is general information, not legal advice.
How To Read A Regulatory Date
The same year can mean very different things depending on who wrote it. A date in a binding regulation is something a supervisor can enforce. A date in national guidance is advice, however strongly worded. A date in a government strategy may bind only government departments. Every instrument in this group carries one of these labels.
The Master Table
The table below lists the instruments that matter most for cryptography and quantum readiness, as of October 2026. Dates are those stated in the source. Where nothing was found, the table says so rather than guessing.
| Jurisdiction | Instrument | Status | Applies To | Key Dates |
|---|---|---|---|---|
| Global payments | PCI DSS v4.0.1, requirements 12.3.3 and 4.2.1.1 | Binding (contractual) | Entities that store, process or transmit card data | Cipher suite and protocol inventory, viability monitoring and response plan, reviewed at least every 12 months, plus a trusted key and certificate inventory; required since 31 March 2025 |
| European Union | DORA and Delegated Regulation (EU) 2024/1774, Articles 6 and 7 | Binding | EU financial entities under the full ICT risk framework | Encryption policy, key lifecycle and certificate register since 17 January 2025 |
| European Union | NIS2 Directive, Article 21(2)(h) | Binding (through national law) | Essential and important entities | Cryptography policies; transposition was due by 17 October 2024 |
| European Union | Cyber Resilience Act, Regulation (EU) 2024/2847 | Binding | Products with digital elements | Reporting from 11 September 2026; main obligations from 11 December 2027 |
| European Union | Coordinated post-quantum roadmap, version 1.1 | Guidance | Member States | First steps and national roadmaps by end 2026; high-risk use cases by end 2030; medium-risk by end 2035 |
| Saudi Arabia | SAMA Circular 482021280 | Binding | SAMA-regulated financial institutions | Asset identification procedures by end Q4 2026; risk assessment by end Q1 2027 |
| Saudi Arabia | NCA Essential Cybersecurity Controls 2-8 with NCS-1:2020 | Binding | National entities in scope | Approved algorithms and key lengths now; no post-quantum date |
| United Arab Emirates | National Encryption Policy v1.0; Information Assurance Standard v2.1, control T3.4.4 | Binding policy for its scope; the IA post-quantum control applies based on risk assessment | Federal and emirate government entities and non-government critical information infrastructure | Inventory and transition plan required; no deadline in the text |
| UAE (ADGM) | FSRA Notice FSRA/FCCP/146/2025 and GEN 3.5.16 | Guidance (notice); Binding (GEN rule) | ADGM firms | Notice says newly released Council policies it lists are not mandatory; incident response plan required under GEN 3.5.16 from 31 January 2026 |
| Qatar, Bahrain, Oman, Kuwait | No post-quantum instrument found | Not found | Not applicable | No PQC-specific instrument was found as of October 2026 |
| United Kingdom | NCSC migration timelines | Guidance | All organisations | Discovery and plan by 2028; priority work by 2031; complete by 2035 |
| Switzerland | FINMA Guidance 05/2026 | Supervisory | Supervised institutions | Post-quantum roadmap by mid-2027 |
| United States | Executive Order 14412 and OMB M-26-15 | Binding (federal agencies) | Federal agencies (excluding national security systems); contractors through a future rule | Plans 22 October 2026; high value assets and high impact systems on post-quantum key establishment by end 2030 and signatures by end 2031; full migration by 2035 is a planning phase, not a fixed duty |
| Canada | ITSM.40.001 roadmap; OSFI quantum bulletin | Guidance | Federal departments; federally regulated financial institutions | Federal high-priority systems end 2031 and the rest end 2035 (ITSM.40.001); OSFI points to 2035 |
| Singapore | CSA Quantum-Safe Handbook | Supervisory | Critical information infrastructure owners | Plan 31 March 2027; quantum-safe procurement from 1 January 2028; done 31 December 2031 |
| Singapore | MAS statement of 28 July 2026 | Announcement | Financial institutions | Expectations with milestones promised later in 2026 |
| Hong Kong | HKMA Quantum Preparedness Index | Announcement | Banking sector | Full sector readiness aim by 2030 |
| India | National Quantum Mission roadmap | Guidance (national strategy) | Critical information infrastructure and enterprises | Critical infrastructure 2027 to 2029; enterprises 2028 to 2033 |
| Japan | FSA communication to banks of 24 June 2025 and study group report | Supervisory and Guidance | Banks and other financial institutions | Start inventory now; high-priority systems around the mid-2030s; government around 2035 (draft) |
| South Korea | Ministry of Science and ICT and KISA pilots | Announcement | Pilot sectors; the 2026 pilots include finance | No verified national deadline |
| Australia | ASD guidance in the ISM | Guidance | Government, with advice to all | Stop traditional asymmetric cryptography by end 2030 |
| G7 | Cyber Expert Group roadmap | Announcement | Financial sector (non-authoritative) | Critical systems 2030 to 2032; overall 2035 |
Sources for the rows above: PCI DSS,1 the DORA technical standard,2 NIS2,3 the Cyber Resilience Act,4 the EU roadmap,5 SAMA,6 the NCA controls and standards,7 the UAE policy,8 the UAE IA Standard,9 the ADGM notice,10 the UK NCSC,11 FINMA,12 the US executive order and OMB memorandum,13 Canada’s roadmap and OSFI bulletin,14 the Singapore handbook,15 MAS,16 the HKMA,17 India’s roadmap,18 Japan’s FSA and Cabinet Secretariat,19 South Korea’s ministry and KISA,20 ASD21 and the G7 roadmap.22 Rows saying nothing was found rest on the searches described in the Gulf article.
What The Binding Rules Actually Ask For
Several binding rules already require private organisations to have cryptography policies or to use encryption. NIS2, the Cyber Resilience Act, the Saudi NCA controls and a range of sector rules all fall into this group. Four instruments go further and require an inventory, a register or quantum planning. India’s securities regulator also lists a cryptographic inventory, as an indicative measure in its binding cyber framework, which the inventory article explains.
PCI DSS requirement 12.3.3 expects a current list of the cipher suites and protocols in use, an active watch on whether each stays safe and a written plan for reacting to cryptographic weaknesses that can be seen coming, all revisited at least every 12 months.1 The DORA technical standard requires EU financial entities under its full ICT risk framework to keep an encryption policy that allows cryptography to be updated as cryptanalysis develops, and to keep a register of certificates for at least the assets that support critical functions.2
SAMA’s August 2026 circular is the only binding instrument found that sets a near, dated post-quantum task for a whole financial sector. Saudi financial institutions must have procedures to identify and classify all cryptographic assets by the end of 2026, then complete an enterprise quantum risk assessment with action plans by the end of March 2027.6 The UAE National Encryption Policy, within its scope, requires federal and emirate government entities and non-government critical infrastructure operators to keep an inventory of public key cryptography and prepare a transition plan, but its text sets no deadline.8
None of these rules orders a full migration by a fixed date. The common demand is visibility: know where cryptography is used, judge the risk, and have a plan.
Where The 2030 And 2035 Dates Come From
The well-known later dates come mostly from national cyber agencies and government programmes. The UK NCSC advises discovery and an initial plan by 2028, the highest-priority migration by 2031 and completion by 2035.11 The EU roadmap asks Member States to take first steps and set national roadmaps by the end of 2026 and finish high-risk use cases by the end of 2030.5 Both are guidance.
The US executive order signed on 22 June 2026 is binding, but on federal agencies. It directs OMB to issue guidance requiring agencies to move high value assets and high impact systems to post-quantum key establishment by 31 December 2030 and to post-quantum signatures by 31 December 2031, and national security systems sit outside these provisions. The order also directs the FAR Council to propose, by 19 December 2026, a rule that would require covered contractors to comply with NIST’s FIPS standards, including the post-quantum ones, by 31 December 2030.13 Until such a rule is adopted, these dates bind agencies only.
Singapore sits in between. CSA’s handbook sets dated milestones for critical information infrastructure owners, including a migration plan by 31 March 2027 and completion by 31 December 2031.15 The G7 Cyber Expert Group suggests critical financial systems move in 2030 to 2032, while saying plainly that its roadmap does not set regulatory expectations.22
The Nearest Deadlines
The countdowns below show the closest dated items across the regions. The full list, including AI rules, is in the Regulatory Deadline Tracker.
- Upcoming
United States · Office of Management and Budget Binding
Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.
- Upcoming
United States · The White House Binding
The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.
- Upcoming
European Union · NIS Cooperation Group Guidance
All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.
- Upcoming
Singapore · Cyber Security Agency of Singapore Supervisory
Submit a quantum-safe migration plan to CSA.
- Upcoming
Saudi Arabia · Saudi Central Bank (SAMA) Binding
Complete a quantum risk assessment with action plans.
- Upcoming
Switzerland · FINMA Supervisory
Draw up a post-quantum cryptography roadmap.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete discovery and build an initial migration plan.
- Upcoming
European Union · NIS Cooperation Group Guidance
Complete the transition for high-risk use cases.
- Upcoming
United Kingdom · National Cyber Security Centre Guidance
Complete migration to post-quantum cryptography across systems and products.
Reading The Regions
The rest of this group follows the map. The Gulf comes first, because Saudi Arabia has the hardest financial-sector date and the UAE has the most detailed planning text in the region: see the UAE, Saudi Arabia and rest of the GCC articles. Europe, North America and Asia Pacific follow. Two cross-cutting pieces explain which regulators require a cryptographic inventory and give AI regulation at a glance.
Footnotes
-
PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirements 4.2.1.1 and 12.3.3. pcisecuritystandards.org ↩ ↩2
-
European Commission, Delegated Regulation (EU) 2024/1774, Articles 6 and 7, 13 March 2024. eur-lex.europa.eu ↩ ↩2
-
European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Articles 21(2)(h) and 41(1), 14 December 2022. eur-lex.europa.eu ↩
-
European Parliament and Council, Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71(2), 23 October 2024. eur-lex.europa.eu ↩
-
NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩ ↩2
-
Saudi Central Bank, Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩ ↩2
-
National Cybersecurity Authority, “Essential Cybersecurity Controls (ECC-2:2024)” (cdn.nca.gov.sa) and “National Cryptographic Standards (NCS-1:2020)”, July 2020. nca.gov.sa ↩
-
UAE Cyber Security Council, “National Encryption Policy v1.0”, September 2025, sections 1.2 and 6.1. csc.gov.ae ↩ ↩2
-
UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩
-
ADGM Financial Services Regulatory Authority, Notice FSRA/FCCP/146/2025, 17 October 2025. assets.adgm.com ↩
-
UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2
-
FINMA, Guidance 05/2026 “Quantum computing”, 9 July 2026. finma.ch ↩
-
The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, sections 4(b) and 6(c) (govinfo.gov); Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2
-
Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, 23 June 2025 (cyber.gc.ca); OSFI, “Quantum Readiness Phases and Timelines”, March 2026. osfi-bsif.gc.ca ↩
-
Cyber Security Agency of Singapore, GovTech and IMDA, “Quantum-Safe Handbook V1”, 16 July 2026, page 25. isomer-user-content.by.gov.sg ↩ ↩2
-
Monetary Authority of Singapore, Managing Director’s remarks at the MAS Annual Report 2025/2026 media conference, 28 July 2026. mas.gov.sg ↩
-
Government of the Hong Kong SAR, press release on the HKMA Quantum Preparedness Index, 27 July 2026. info.gov.hk ↩
-
Department of Science and Technology, Government of India, “Quantum-Safe Ecosystem in India” roadmap, May 2026. dst.gov.in ↩
-
Financial Services Agency of Japan, notes from its meeting with new-type banks, 24 June 2025 (fsa.go.jp), and study group report, 26 November 2024 (fsa.go.jp); Cabinet Secretariat of Japan, interim summary (draft), November 2025. cas.go.jp ↩
-
Korea Internet and Security Agency, notice on the briefing for the 2026 post-quantum cryptography pilot conversion projects (in Korean), 14 January 2026. kisa.or.kr ↩
-
Australian Signals Directorate, “Planning for post-quantum cryptography”, last reviewed 22 September 2025. cyber.gov.au ↩
-
G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩ ↩2
Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.