Skip to content

47-Day Certificates Are Coming. Are You Ready?

Act Now →

EU Defines Clear Roadmap for Post Quantum Cryptography Transition by 2035 

Post Quantum Cryptography

Quick answer: The European Commission’s Coordinated Implementation Roadmap sets three deadlines for EU Member States to transition to post-quantum cryptography: initial steps and pilots by 2026, completed migration of high-risk systems by 2030, and completed migration of medium and low-risk systems by 2035. It matters because the roadmap gives organizations operating in the EU concrete dates to plan against, tied to a risk classification framework rather than a single blanket deadline. The recommended action is to build a cryptographic asset inventory now, classify systems by risk, and align pilot programs with the 2026 milestone.

Key Takeaways

  • The EU roadmap sets three milestones: initial steps and pilots by 2026, high-risk system migration complete by 2030, and medium/low-risk system migration complete by 2035.
  • High-risk systems are those protecting data requiring confidentiality for at least 10 years, or systems with significant potential impact if compromised.
  • The 2026 milestone requires cryptographic asset inventories, dependency mapping, quantum risk assessments, and stakeholder engagement to already be underway.
  • Cryptographic agility, building systems with upgrade paths to post-quantum algorithms, is a recurring requirement across all three milestones.
  • The EU timeline broadly aligns with NIST and UK NCSC guidance, which also target retiring vulnerable cryptography by 2035.

The European Commission has recently published “A Coordinated Implementation Roadmap for the Transition to Post Quantum Cryptography,” outlining a unified strategy to prepare Europe’s digital infrastructure for the challenges posed by quantum computing

This roadmap sets out clear expectations and timelines for Member States to begin and progress their migration away from vulnerable classical cryptographic algorithms toward quantum-resistant solutions. 

Three Milestones Define the Transition Timeline 

The document organizes the PQC migration into three key milestones, providing a clear framework for coordinated action across Europe: 

By 2026: Complete Initial Steps and Begin Pilots for High and Medium Risk Use Cases 

Member States are expected to initiate or update national PQC transition plans, incorporating several foundational activities:

  • Engaging relevant stakeholders including government CTOs, CISOs, cybersecurity authorities, and research institutions.
  • Developing detailed inventories of cryptographic assets using standardized formats.
  • Mapping dependencies across applications, platforms, and supply chains.
  • Conducting quantum risk assessments to prioritize systems based on vulnerability and impact.
  • Involving supply chain partners to align product and service roadmaps.
  • Launching awareness and communication programs tailored to different stakeholder groups.
  • Sharing knowledge and coordinating via EU cybersecurity groups.
  • Creating implementation plans with timelines reflecting national priorities.

By this milestone, pilots for high and medium-risk use cases should be underway, enabling practical testing of PQC solutions.

CBOM Secure

Gain complete visibility with continuous cryptographic discovery, automated inventory, and data-driven PQC remediation.

By 2030: Implement Next Steps and Finalize Transition for High-Risk Use Cases 

The roadmap anticipates that by 2030, Member States will have completed the PQC migration for all high-risk systems. Key actions include:

  • Ensuring cryptographic agility in all new products, with upgrade paths supporting post-quantum algorithms.
  • Allocating adequate resources, both budgetary and human, to sustain the transition.
  • Updating certification and regulatory frameworks to incorporate PQC standards.
  • Revising national laws and procurement policies to enforce quantum-safe cryptography.
  • Engaging with private sector stakeholders, training programs, and funding initiatives to strengthen the PQC ecosystem.
  • Participating in EU-supported testing centers and pilot projects to validate interoperability.

High-risk systems are those protecting data requiring confidentiality for at least 10 years or systems with significant potential impact if compromised.

By 2035: Complete Transition for Medium- and Low-Risk Use Cases 

The final milestone aims for the completion of the PQC transition for medium-risk use cases and as many low-risk systems as feasible. This aligns with international goals set by authorities such as NIST and the UK NCSC, which envision retiring vulnerable cryptography by this date. 

Understanding Quantum Risk and Prioritization 

The roadmap introduces a risk classification framework to guide prioritization:

  • High risk: Use cases with long-term confidentiality needs and critical impact.
  • Medium risk: Important use cases with moderate urgency.
  • Low risk: Systems with less impact or shorter confidentiality requirements.

Organizations are encouraged to integrate quantum risk analysis into existing cybersecurity risk management processes.

PQC Advisory Services

Gain post-quantum readiness with expert-led cryptographic assessment, migration strategy, and hands-on implementation aligned to NIST standards.

Key Themes for a Successful PQC Transition 

  • Cryptographic agility: Products and systems should support seamless upgrades to quantum-resistant algorithms.
  • Stakeholder collaboration: Cross-border and cross-sector cooperation is vital.
  • Regulatory alignment: Laws, certifications, and procurement must evolve to support PQC adoption.
  • Awareness and training: Tailored education initiatives should involve all organizational levels.
  • Resource planning: Budget and personnel must be dedicated to transition efforts.
  • Testing and validation: Coordinated pilot programs and interoperability testing are essential.

How Encryption Consulting Can Support Your Post Quantum Cryptography Journey 

Encryption Consulting offers specialized Post-Quantum Cryptography Advisory Services designed to help organizations assess their quantum risk, develop tailored transition strategies, and implement cryptographic agility aligned with global and EU standards. 

Our expert team assists with risk assessments, roadmap development, vendor evaluations, and proof-of-concept testing to facilitate a smooth and compliant migration to quantum-safe cryptography

Read More: https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography   

Frequently Asked Questions

What are the three milestones in the EU’s PQC transition roadmap?

By 2026, Member States should complete initial steps like cryptographic inventories and risk assessments, and begin pilots for high and medium-risk use cases. By 2030, migration should be finalized for all high-risk systems. By 2035, migration should be complete for medium-risk and as many low-risk systems as feasible.

What counts as a “high-risk” system under the EU roadmap?

Systems protecting data that requires confidentiality for at least 10 years, or systems where a compromise would have a significant impact. These are prioritized for the earliest migration deadline, 2030.

What should organizations have in place by the 2026 milestone?

A detailed inventory of cryptographic assets, dependency mapping across applications and supply chains, completed quantum risk assessments, engaged stakeholders including CISOs and supply chain partners, and pilot programs already underway for high and medium-risk use cases.

Does the EU roadmap align with NIST and UK NCSC timelines?

Yes. The 2035 target for completing the transition for medium and low-risk systems aligns with international goals set by NIST and the UK NCSC, both of which envision retiring vulnerable classical cryptography by that date.

What is cryptographic agility, and why does the roadmap emphasize it?

Cryptographic agility is the ability to upgrade cryptographic algorithms in a system without a full redesign. The roadmap requires all new products to support cryptographic agility from the 2030 milestone onward, since systems without this capability are far more expensive and slower to migrate as standards evolve.