
Updates

Articles

The transition to post-quantum cryptography is usually discussed as a technological challenge. But organisations preparing for the quantum era also need to consider another dimension: how cybersecurity regulation may influence when and how they are expected to act.
Quantum computers capable of breaking widely used public-key cryptography are not yet available at the necessary scale. However, the risks already matter today. Sensitive encrypted information may need to remain secure for many years, while attackers can collect it now and attempt to decrypt it once sufficient quantum capabilities become available.
This raises an important question: even if EU legislation does not currently impose a general obligation to use post-quantum cryptography, are existing cybersecurity requirements already moving organisations in that direction?
This question is explored in a new article by Krzysztof Garstka and Charlotte Gerbehaye from Timelex, a POSEIDON partner contributing legal and regulatory expertise to the project. Their analysis examines the relationship between PQC and key elements of the EU cybersecurity framework, particularly the NIS2 Directive and the Cyber Resilience Act (CRA).
We recommend reading the full article on the Timelex website for a detailed legal perspective on how these developments may influence future PQC adoption.
The authors begin with two risks showing why the quantum threat cannot be treated only as a distant problem: Harvest Now, Decrypt Later, where encrypted information collected today may be decrypted in the future, and Trust Now, Forge Later, concerning signatures or certificates that could potentially be forged once suitable quantum capabilities emerge.
The article stresses that neither NIS2 nor the Cyber Resilience Act currently introduces a general obligation to implement PQC. However, both contain broader cybersecurity requirements that may become increasingly relevant as quantum-resistant technologies mature.
NIS2 requires essential and important entities to address cryptography and encryption within cybersecurity risk management, while the CRA requires appropriate protection of data using state-of-the-art mechanisms. The regulatory direction is becoming even clearer in the European Commission’s proposed revision of NIS2, which explicitly refers to migration to PQC and the European milestones of 2030 for critical use cases and 2035 for medium- and low-level use cases.
The main conclusion is therefore not that organisations are already legally required to migrate. Rather, the regulatory environment is evolving alongside the technological threat, strengthening the case for treating post-quantum readiness as part of long-term cybersecurity planning.
This regulatory perspective complements the technological work carried out within POSEIDON, which focuses on practical post-quantum and hybrid cryptographic solutions for digital identities and the protection of sensitive data.
Migration to post-quantum security will depend on more than selecting new algorithms. Organisations will also need to understand when migration is necessary, what requirements influence their decisions and how technological solutions fit within the evolving European regulatory landscape.
The Timelex article adds this important legal perspective to the wider work of POSEIDON and shows why preparation for the quantum era needs to combine technology, implementation planning, policy and regulation.
Read the full analysis by Krzysztof Garstka and Charlotte Gerbehaye on the Timelex website.

Krzysztof Garstka
Timelex

Charlotte Gerbehaye
Timelex

Updates

Updates

Updates

Articles

Articles

Articles

Updates

Legislation, Updates

