Activities Are EU cybersecurity rules pointing towards post-quantum cryptography?

Are EU cybersecurity rules pointing towards post-quantum cryptography?

Articles

September 11, 2026

The transition to post-quantum cryptography is usually discussed as a technological challenge. But organisations preparing for the quantum era also need to consider another dimension: how cybersecurity regulation may influence when and how they are expected to act.

Quantum computers capable of breaking widely used public-key cryptography are not yet available at the necessary scale. However, the risks already matter today. Sensitive encrypted information may need to remain secure for many years, while attackers can collect it now and attempt to decrypt it once sufficient quantum capabilities become available.

This raises an important question: even if EU legislation does not currently impose a general obligation to use post-quantum cryptography, are existing cybersecurity requirements already moving organisations in that direction?

This question is explored in a new article by Krzysztof Garstka and Charlotte Gerbehaye from Timelex, a POSEIDON partner contributing legal and regulatory expertise to the project. Their analysis examines the relationship between PQC and key elements of the EU cybersecurity framework, particularly the NIS2 Directive and the Cyber Resilience Act (CRA).

We recommend reading the full article on the Timelex website for a detailed legal perspective on how these developments may influence future PQC adoption.

What are the main takeaways?

The authors begin with two risks showing why the quantum threat cannot be treated only as a distant problem: Harvest Now, Decrypt Later, where encrypted information collected today may be decrypted in the future, and Trust Now, Forge Later, concerning signatures or certificates that could potentially be forged once suitable quantum capabilities emerge.

The article stresses that neither NIS2 nor the Cyber Resilience Act currently introduces a general obligation to implement PQC. However, both contain broader cybersecurity requirements that may become increasingly relevant as quantum-resistant technologies mature.

NIS2 requires essential and important entities to address cryptography and encryption within cybersecurity risk management, while the CRA requires appropriate protection of data using state-of-the-art mechanisms. The regulatory direction is becoming even clearer in the European Commission’s proposed revision of NIS2, which explicitly refers to migration to PQC and the European milestones of 2030 for critical use cases and 2035 for medium- and low-level use cases.

The main conclusion is therefore not that organisations are already legally required to migrate. Rather, the regulatory environment is evolving alongside the technological threat, strengthening the case for treating post-quantum readiness as part of long-term cybersecurity planning.

Why this matters for POSEIDON

This regulatory perspective complements the technological work carried out within POSEIDON, which focuses on practical post-quantum and hybrid cryptographic solutions for digital identities and the protection of sensitive data.

Migration to post-quantum security will depend on more than selecting new algorithms. Organisations will also need to understand when migration is necessary, what requirements influence their decisions and how technological solutions fit within the evolving European regulatory landscape.

The Timelex article adds this important legal perspective to the wider work of POSEIDON and shows why preparation for the quantum era needs to combine technology, implementation planning, policy and regulation.

Read the full analysis by Krzysztof Garstka and Charlotte Gerbehaye on the Timelex website.

Krzysztof Garstka
Timelex

Charlotte Gerbehaye
Timelex

POSEIDON Logo
Securing European Digital Identities with Post-Quantum Solutions
Cookies & Privacy Policies Funded by the European Union
Copyright © 2026. All rights reserved.

Subscribe to our newsletter

Stay informed by following us on LinkedIn and subscribing to our newsletter.
Privacy*
Funded by the European Union. Views and opinions expressed are however those of the author(s) only and do not necessarily reflect those of the European Union or the European Cybersecurity Competence Centre. Neither the European Union nor the European Cybersecurity Competence Centre can be held responsible for them.