REGULATIONS ACROSS REGIONS / BEGINNER

Post-Quantum And Cyber Regulation In 2026: Who Requires What, And By When

A region by region map of cryptography and post-quantum rules as of October 2026, showing which dates are binding and which are guidance, with live countdowns.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Post-quantum dates now appear in documents from regulators, cyber agencies and governments on every continent. Read quickly, they suggest that the whole world has ordered companies to replace their cryptography by 2030 or 2035. Read carefully, the picture is narrower and more useful: a few binding rules go beyond general encryption duties, and they mostly ask private organisations for an inventory and a plan, while the later migration dates sit mostly in guidance or in rules for government systems.

This article is the starting point for the Regulations Across Regions group. It sets out the main instruments as of October 2026, labels each one by legal force, and shows the dates that are closest. The articles that follow go region by region. For the detailed wording of PCI DSS, DORA and the US federal timeline, see Cryptography Compliance. This is general information, not legal advice.

How To Read A Regulatory Date

The same year can mean very different things depending on who wrote it. A date in a binding regulation is something a supervisor can enforce. A date in national guidance is advice, however strongly worded. A date in a government strategy may bind only government departments. Every instrument in this group carries one of these labels.

The Master Table

The table below lists the instruments that matter most for cryptography and quantum readiness, as of October 2026. Dates are those stated in the source. Where nothing was found, the table says so rather than guessing.

JurisdictionInstrumentStatusApplies ToKey Dates
Global paymentsPCI DSS v4.0.1, requirements 12.3.3 and 4.2.1.1Binding (contractual)Entities that store, process or transmit card dataCipher suite and protocol inventory, viability monitoring and response plan, reviewed at least every 12 months, plus a trusted key and certificate inventory; required since 31 March 2025
European UnionDORA and Delegated Regulation (EU) 2024/1774, Articles 6 and 7BindingEU financial entities under the full ICT risk frameworkEncryption policy, key lifecycle and certificate register since 17 January 2025
European UnionNIS2 Directive, Article 21(2)(h)Binding (through national law)Essential and important entitiesCryptography policies; transposition was due by 17 October 2024
European UnionCyber Resilience Act, Regulation (EU) 2024/2847BindingProducts with digital elementsReporting from 11 September 2026; main obligations from 11 December 2027
European UnionCoordinated post-quantum roadmap, version 1.1GuidanceMember StatesFirst steps and national roadmaps by end 2026; high-risk use cases by end 2030; medium-risk by end 2035
Saudi ArabiaSAMA Circular 482021280BindingSAMA-regulated financial institutionsAsset identification procedures by end Q4 2026; risk assessment by end Q1 2027
Saudi ArabiaNCA Essential Cybersecurity Controls 2-8 with NCS-1:2020BindingNational entities in scopeApproved algorithms and key lengths now; no post-quantum date
United Arab EmiratesNational Encryption Policy v1.0; Information Assurance Standard v2.1, control T3.4.4Binding policy for its scope; the IA post-quantum control applies based on risk assessmentFederal and emirate government entities and non-government critical information infrastructureInventory and transition plan required; no deadline in the text
UAE (ADGM)FSRA Notice FSRA/FCCP/146/2025 and GEN 3.5.16Guidance (notice); Binding (GEN rule)ADGM firmsNotice says newly released Council policies it lists are not mandatory; incident response plan required under GEN 3.5.16 from 31 January 2026
Qatar, Bahrain, Oman, KuwaitNo post-quantum instrument foundNot foundNot applicableNo PQC-specific instrument was found as of October 2026
United KingdomNCSC migration timelinesGuidanceAll organisationsDiscovery and plan by 2028; priority work by 2031; complete by 2035
SwitzerlandFINMA Guidance 05/2026SupervisorySupervised institutionsPost-quantum roadmap by mid-2027
United StatesExecutive Order 14412 and OMB M-26-15Binding (federal agencies)Federal agencies (excluding national security systems); contractors through a future rulePlans 22 October 2026; high value assets and high impact systems on post-quantum key establishment by end 2030 and signatures by end 2031; full migration by 2035 is a planning phase, not a fixed duty
CanadaITSM.40.001 roadmap; OSFI quantum bulletinGuidanceFederal departments; federally regulated financial institutionsFederal high-priority systems end 2031 and the rest end 2035 (ITSM.40.001); OSFI points to 2035
SingaporeCSA Quantum-Safe HandbookSupervisoryCritical information infrastructure ownersPlan 31 March 2027; quantum-safe procurement from 1 January 2028; done 31 December 2031
SingaporeMAS statement of 28 July 2026AnnouncementFinancial institutionsExpectations with milestones promised later in 2026
Hong KongHKMA Quantum Preparedness IndexAnnouncementBanking sectorFull sector readiness aim by 2030
IndiaNational Quantum Mission roadmapGuidance (national strategy)Critical information infrastructure and enterprisesCritical infrastructure 2027 to 2029; enterprises 2028 to 2033
JapanFSA communication to banks of 24 June 2025 and study group reportSupervisory and GuidanceBanks and other financial institutionsStart inventory now; high-priority systems around the mid-2030s; government around 2035 (draft)
South KoreaMinistry of Science and ICT and KISA pilotsAnnouncementPilot sectors; the 2026 pilots include financeNo verified national deadline
AustraliaASD guidance in the ISMGuidanceGovernment, with advice to allStop traditional asymmetric cryptography by end 2030
G7Cyber Expert Group roadmapAnnouncementFinancial sector (non-authoritative)Critical systems 2030 to 2032; overall 2035
Cryptography and post-quantum instruments by jurisdiction, as of October 2026. Sources are in the footnotes and in each regional article.

Sources for the rows above: PCI DSS,1 the DORA technical standard,2 NIS2,3 the Cyber Resilience Act,4 the EU roadmap,5 SAMA,6 the NCA controls and standards,7 the UAE policy,8 the UAE IA Standard,9 the ADGM notice,10 the UK NCSC,11 FINMA,12 the US executive order and OMB memorandum,13 Canada’s roadmap and OSFI bulletin,14 the Singapore handbook,15 MAS,16 the HKMA,17 India’s roadmap,18 Japan’s FSA and Cabinet Secretariat,19 South Korea’s ministry and KISA,20 ASD21 and the G7 roadmap.22 Rows saying nothing was found rest on the searches described in the Gulf article.

What The Binding Rules Actually Ask For

Several binding rules already require private organisations to have cryptography policies or to use encryption. NIS2, the Cyber Resilience Act, the Saudi NCA controls and a range of sector rules all fall into this group. Four instruments go further and require an inventory, a register or quantum planning. India’s securities regulator also lists a cryptographic inventory, as an indicative measure in its binding cyber framework, which the inventory article explains.

PCI DSS requirement 12.3.3 expects a current list of the cipher suites and protocols in use, an active watch on whether each stays safe and a written plan for reacting to cryptographic weaknesses that can be seen coming, all revisited at least every 12 months.1 The DORA technical standard requires EU financial entities under its full ICT risk framework to keep an encryption policy that allows cryptography to be updated as cryptanalysis develops, and to keep a register of certificates for at least the assets that support critical functions.2

SAMA’s August 2026 circular is the only binding instrument found that sets a near, dated post-quantum task for a whole financial sector. Saudi financial institutions must have procedures to identify and classify all cryptographic assets by the end of 2026, then complete an enterprise quantum risk assessment with action plans by the end of March 2027.6 The UAE National Encryption Policy, within its scope, requires federal and emirate government entities and non-government critical infrastructure operators to keep an inventory of public key cryptography and prepare a transition plan, but its text sets no deadline.8

None of these rules orders a full migration by a fixed date. The common demand is visibility: know where cryptography is used, judge the risk, and have a plan.

Where The 2030 And 2035 Dates Come From

The well-known later dates come mostly from national cyber agencies and government programmes. The UK NCSC advises discovery and an initial plan by 2028, the highest-priority migration by 2031 and completion by 2035.11 The EU roadmap asks Member States to take first steps and set national roadmaps by the end of 2026 and finish high-risk use cases by the end of 2030.5 Both are guidance.

The US executive order signed on 22 June 2026 is binding, but on federal agencies. It directs OMB to issue guidance requiring agencies to move high value assets and high impact systems to post-quantum key establishment by 31 December 2030 and to post-quantum signatures by 31 December 2031, and national security systems sit outside these provisions. The order also directs the FAR Council to propose, by 19 December 2026, a rule that would require covered contractors to comply with NIST’s FIPS standards, including the post-quantum ones, by 31 December 2030.13 Until such a rule is adopted, these dates bind agencies only.

Singapore sits in between. CSA’s handbook sets dated milestones for critical information infrastructure owners, including a migration plan by 31 March 2027 and completion by 31 December 2031.15 The G7 Cyber Expert Group suggests critical financial systems move in 2030 to 2032, while saying plainly that its roadmap does not set regulatory expectations.22

The Nearest Deadlines

The countdowns below show the closest dated items across the regions. The full list, including AI rules, is in the Regulatory Deadline Tracker.

  1. Upcoming

    United States · Office of Management and Budget Binding

    Submit a post-quantum cryptography migration plan to OMB and the Office of the National Cyber Director, no later than 120 days after the memorandum. The date shown is calculated by us as 120 days after 24 June 2026; the memorandum gives only the number of days.

    OMB Memorandum M-26-15, Execution of the Migration to Post-Quantum Cryptography (24 June 2026). Applies to US federal civilian agencies (excluding national security systems). Source · Explainer · Verified 7 Oct 2026

  2. Upcoming

    United States · The White House Binding

    The FAR Council must publish, within 180 days of the order, a proposed rule that would require covered federal contractors to comply with NIST FIPS, including post-quantum algorithms, by 31 December 2030. The date shown is calculated by us as 180 days after 22 June 2026.

    Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, section 6(c). Applies to FAR Council; the contractor rule itself will be a proposal until finalised. Source · Explainer · Verified 7 Oct 2026

  3. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Ensure procedures identify and classify all cryptographic assets accurately and comprehensively.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  4. Upcoming

    European Union · NIS Cooperation Group Guidance

    All Member States have implemented at least the First Steps, set initial national transition roadmaps, and started transition planning and pilots for high-risk and medium-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 1. Applies to EU Member States. Source · Verified 7 Oct 2026

  5. Upcoming

    Singapore · Cyber Security Agency of Singapore Supervisory

    Submit a quantum-safe migration plan to CSA.

    CSA Quantum-Safe Handbook (16 July 2026). Applies to critical information infrastructure owners. Source · Verified 7 Oct 2026

  6. Upcoming

    Saudi Arabia · Saudi Central Bank (SAMA) Binding

    Complete a quantum risk assessment with action plans.

    Circular 482021280 on quantum computing risks. Applies to SAMA-regulated financial institutions. Source · Verified 7 Oct 2026

  7. Upcoming

    Switzerland · FINMA Supervisory

    Draw up a post-quantum cryptography roadmap.

    FINMA Guidance 05/2026. Applies to FINMA-supervised institutions (recommendation). Source · Verified 7 Oct 2026

  8. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete discovery and build an initial migration plan.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations, especially critical national infrastructure. Source · Verified 7 Oct 2026

  9. Upcoming

    European Union · NIS Cooperation Group Guidance

    Complete the transition for high-risk use cases.

    Coordinated Implementation Roadmap for the transition to post-quantum cryptography (version 1.1), Milestone 2. Applies to EU Member States. Source · Verified 7 Oct 2026

  10. Upcoming

    United Kingdom · National Cyber Security Centre Guidance

    Complete migration to post-quantum cryptography across systems and products.

    Timelines for migration to post-quantum cryptography. Applies to UK organisations. Source · Verified 7 Oct 2026

The nearest cryptography and post-quantum dates across regions. Check each label: only some are binding, and several apply only to governments or specific sectors.

Reading The Regions

The rest of this group follows the map. The Gulf comes first, because Saudi Arabia has the hardest financial-sector date and the UAE has the most detailed planning text in the region: see the UAE, Saudi Arabia and rest of the GCC articles. Europe, North America and Asia Pacific follow. Two cross-cutting pieces explain which regulators require a cryptographic inventory and give AI regulation at a glance.

Footnotes

  1. PCI Security Standards Council, “Payment Card Industry Data Security Standard: Requirements and Testing Procedures”, version 4.0.1, June 2024, requirements 4.2.1.1 and 12.3.3. pcisecuritystandards.org ↩ ↩2

  2. European Commission, Delegated Regulation (EU) 2024/1774, Articles 6 and 7, 13 March 2024. eur-lex.europa.eu ↩ ↩2

  3. European Parliament and Council, Directive (EU) 2022/2555 (NIS2), Articles 21(2)(h) and 41(1), 14 December 2022. eur-lex.europa.eu ↩

  4. European Parliament and Council, Regulation (EU) 2024/2847 (Cyber Resilience Act), Article 71(2), 23 October 2024. eur-lex.europa.eu ↩

  5. NIS Cooperation Group, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”, version 1.1, dated 11 June 2025 and published 23 June 2025. ec.europa.eu ↩ ↩2

  6. Saudi Central Bank, Circular 482021280, “Enhancement of Operational Resilience to Address Quantum Computing Risks”, 27 August 2026. rulebook.sama.gov.sa ↩ ↩2

  7. National Cybersecurity Authority, “Essential Cybersecurity Controls (ECC-2:2024)” (cdn.nca.gov.sa) and “National Cryptographic Standards (NCS-1:2020)”, July 2020. nca.gov.sa ↩

  8. UAE Cyber Security Council, “National Encryption Policy v1.0”, September 2025, sections 1.2 and 6.1. csc.gov.ae ↩ ↩2

  9. UAE Cyber Security Council, “UAE Information Assurance Standard”, version 2.1, November 2025, sections 2.1 and 3.4, control T3.4.4. csc.gov.ae ↩

  10. ADGM Financial Services Regulatory Authority, Notice FSRA/FCCP/146/2025, 17 October 2025. assets.adgm.com ↩

  11. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩ ↩2

  12. FINMA, Guidance 05/2026 “Quantum computing”, 9 July 2026. finma.ch ↩

  13. The White House, Executive Order 14412, “Securing the Nation Against Advanced Cryptographic Attacks”, 22 June 2026, sections 4(b) and 6(c) (govinfo.gov); Office of Management and Budget, Memorandum M-26-15, “Execution of the Migration to Post-Quantum Cryptography”, 24 June 2026. whitehouse.gov ↩ ↩2

  14. Canadian Centre for Cyber Security, “Roadmap for the migration to post-quantum cryptography for the Government of Canada (ITSM.40.001)”, 23 June 2025 (cyber.gc.ca); OSFI, “Quantum Readiness Phases and Timelines”, March 2026. osfi-bsif.gc.ca ↩

  15. Cyber Security Agency of Singapore, GovTech and IMDA, “Quantum-Safe Handbook V1”, 16 July 2026, page 25. isomer-user-content.by.gov.sg ↩ ↩2

  16. Monetary Authority of Singapore, Managing Director’s remarks at the MAS Annual Report 2025/2026 media conference, 28 July 2026. mas.gov.sg ↩

  17. Government of the Hong Kong SAR, press release on the HKMA Quantum Preparedness Index, 27 July 2026. info.gov.hk ↩

  18. Department of Science and Technology, Government of India, “Quantum-Safe Ecosystem in India” roadmap, May 2026. dst.gov.in ↩

  19. Financial Services Agency of Japan, notes from its meeting with new-type banks, 24 June 2025 (fsa.go.jp), and study group report, 26 November 2024 (fsa.go.jp); Cabinet Secretariat of Japan, interim summary (draft), November 2025. cas.go.jp ↩

  20. Korea Internet and Security Agency, notice on the briefing for the 2026 post-quantum cryptography pilot conversion projects (in Korean), 14 January 2026. kisa.or.kr ↩

  21. Australian Signals Directorate, “Planning for post-quantum cryptography”, last reviewed 22 September 2025. cyber.gov.au ↩

  22. G7 Cyber Expert Group, “Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector”, January 2026. home.treasury.gov ↩ ↩2

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.