Common EU timeline: first steps and national roadmaps by end of 2026, high-risk systems migrated by end of 2030, medium-risk by end of 2035.
At a glance
| Type | Official guidance |
|---|---|
| Jurisdiction | EU |
| Who it applies to | EU Member States, and through them operators of critical and high-risk use cases; a de facto reference for the private sector. |
Key dates
- First steps implemented (including cryptographic inventory), national PQC roadmaps in place, planning and pilots started for high- and medium-risk use cases.
- High-risk use cases migrated; quantum-safe software and firmware upgrades enabled by default; quantum-vulnerable public key no longer used stand-alone for high-risk cases.
- Medium-risk use cases migrated; low-risk as much as feasible.
Sources
- A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (v1.1) · European Commission / NIS Cooperation Group (guidance)
Catalog version 2026-09-28. Every position links to its primary source; draft documents are labelled as such.