Europe Nears Its First Quantum-Safe Deadline With “Limited Progress”
Europe’s first post-quantum deadline is less than four months away. The EU post-quantum cryptography policy says every Member State should have taken the roadmap’s first steps by 31 December 2026, including a national transition plan and pilots for high- and medium-risk systems.
The timetable is ambitious. Europe’s own assessment is less reassuring. In the 2026 State of the Digital Decade work, the Commission classified progress on the relevant post-quantum recommendation as “Limited progress”. It said further sector guidance depends on non-continuous expert engagement, implementation will be difficult to monitor and more work is needed to support cross-border testing and an EU ecosystem of compliant products.
This is not evidence that every Member State will miss the milestone. It is a warning that adopting a roadmap and completing the operational work are different achievements. Europe has agreed where it needs to go. Its inventory, procurement, testing and migration machinery now has to catch up.
The 2026 deadline is a policy milestone, not a blanket legal ban
The legal status matters. Commission Recommendation (EU) 2024/1101 encouraged Member States to develop a coordinated strategy for moving public administrations and critical infrastructure towards post-quantum cryptography. The NIS Cooperation Group then published its coordinated implementation roadmap in June 2025.
A Commission recommendation and the roadmap are not the same as a directly applicable regulation. They establish shared policy, milestones and expected actions, but they do not create a universal ban on classical cryptography or a single compliance duty for every European organisation.
The end-2026 milestone is nevertheless concrete. Member States should have implemented the roadmap’s first steps, established initial national transition roadmaps and started planning and pilots for high- and medium-risk use cases. The roadmap also says states should not wait until the deadline to begin later actions that will take longer.
| Target date | Roadmap milestone | What it means operationally |
|---|---|---|
| 31 December 2026 | First steps, national roadmaps and initial high- and medium-risk pilots | Governance, cryptographic discovery, prioritisation, funding and testing should already be under way |
| 31 December 2030 | High-risk use cases transitioned; medium-risk planning and pilots completed; quantum-safe software and firmware upgrades enabled by default | Long-lived sensitive systems and difficult infrastructure cannot be left until the final migration window |
| 31 December 2035 | Medium-risk transition completed and low-risk transition completed as far as feasible | The wider estate should no longer depend on vulnerable public-key cryptography without a managed exception |
“Limited progress” describes the implementation gap
The Commission’s assessment does not say that Europe has done nothing. The roadmap exists, the NIS Cooperation Group has an active work stream and several national authorities have already published detailed guidance. France, Germany and the Netherlands co-chair the work.
The gap lies between coordination and measurable delivery. The Commission said additional steps were being taken to provide more sector-specific guidance, but participation by experts was not continuous. It also identified monitoring, cross-border testing and the availability of EU-based post-quantum products as areas requiring further work.
Those are not administrative details. A national roadmap cannot reveal which public-key algorithms sit inside a hospital appliance, a border system, a payment platform or a ten-year industrial control deployment. A policy cannot rotate a certificate, replace an embedded trust anchor or force a supplier to produce an upgrade path. Delivery happens inside inventories, architectures, contracts and maintenance windows.
Stakeholders liked the dates but asked for more clarity
Newly published survey results show both support for the roadmap and demand for more operational detail. The NIS Cooperation Group’s consultation received 97 submissions. Of those, 73 respondents rated the document or commented on its contents, while 63 provided feedback on areas needing clarification.
Respondents valued the clear milestones, actionable steps, risk-based approach, alignment with global practice, hybrid approaches and crypto-agility. Their questions covered risk estimation, milestones, prioritisation, hybrid schemes, the EU’s role and the relationship with national roadmaps.
The NIS Cooperation Group published an FAQ in response and is developing a second deliverable to supplement the roadmap. The sequence is revealing: Europe has reached broad agreement on urgency, while the hard questions now concern sequencing, evidence, interoperability and ownership.
The risk is already present in long-lived data
A cryptographically relevant quantum computer does not yet exist at the scale needed to break widely deployed public-key systems. Waiting for one to appear would still be a poor risk decision.
Attackers can collect encrypted information now and retain it for later decryption. This “store now, decrypt later” or “harvest now, decrypt later” model makes the confidentiality lifetime of data as important as the predicted arrival date of a capable machine. Diplomatic material, health records, intellectual property, defence information and critical-infrastructure designs may need protection for many years.
The infrastructure has its own clock. Public-key cryptography is embedded in PKI, TLS, VPNs, code signing, firmware validation, identity, secure boot, hardware security modules, industrial systems and third-party libraries. Some assets can be updated quickly. Others have certification, safety or replacement cycles measured in years.
France, the Netherlands and Germany show what national action looks like
National guidance is beginning to turn the European timetable into specific decisions. France says post-quantum requirements will begin entering ANSSI security qualification from 2027, at least for certain product types. BlackTree’s France analysis explains why that qualification gate matters to product and procurement teams.
The Dutch NCSC and AIVD advise organisations to begin with risk analysis, a cryptographic inventory and a migration plan. Dutch guidance also translates the European dates into national preparation: a roadmap by the end of 2026, high-risk migration and plans for other systems by 2030, then broader completion by 2035.
Germany’s BSI treats crypto-agility as a design requirement rather than an optional future feature. Its guidance stresses that algorithms and parameters must be replaceable as standards, evidence and threats evolve. That is useful well beyond the quantum scenario because classical cryptographic failures also force migrations.
PQC and QKD are not interchangeable
Post-quantum cryptography uses mathematical algorithms designed to run on conventional computing platforms while resisting known quantum attacks. Quantum key distribution uses quantum effects and specialised infrastructure to exchange key material.
National authorities do not treat them as substitutes. The Dutch NCSC describes PQC as the preferred route for migration at scale. BSI and partner agencies have said QKD is not ready for general security use and may fit only specialised cases. Organisations should therefore avoid using a quantum-network project as evidence that the broader cryptographic estate has been made quantum-safe.
A proposed NIS2 change could give policy more legal weight
In January 2026, the Commission proposed targeted amendments to NIS2 that would require Member States to include policies for post-quantum migration in their national cybersecurity strategies. That change remains a legislative proposal. It should not be presented as current law.
If adopted, it would connect today’s coordinated roadmap more directly to the national strategy duties in NIS2. For now, the operational case does not depend on that outcome. Procurement cycles, data-retention periods and hard-to-replace assets are already moving towards the 2030 and 2035 windows.
The first deliverable should be an inventory
Organisations do not need to predict the exact arrival date of a cryptographically relevant quantum computer before acting. They need to know where current public-key cryptography is used, how long the protected data remains valuable and how difficult each system will be to change.
- Identify certificates, algorithms, protocols, libraries, signing services, trust stores and embedded cryptography.
- Record the confidentiality and authenticity lifetime of the data or process each dependency protects.
- Map suppliers, support periods, update mechanisms, certification constraints and replacement lead times.
- Prioritise high-risk data, long-lived systems and assets without a credible quantum-safe upgrade path.
- Require crypto-agility, standardised algorithms, hybrid options and migration evidence in procurement.
- Run interoperability and performance pilots before the most complex systems become the critical path.
Mainstream product support can help with testing, but a feature flag is not a migration programme. Windows 11 update KB5120998, for example, added a standalone ML-KEM option for TLS key exchange. That creates implementation and interoperability opportunities. It does not prove that an organisation has completed discovery, supplier assurance, rollout or risk acceptance.
Europe’s deadline is really a test of institutional time
The quantum threat is unusual because policymakers are asking organisations to act before the feared capability is visible. That makes delay easy to rationalise. It also makes the roadmap valuable: its dates force today’s budgets and contracts to account for tomorrow’s cryptographic failure.
The end of 2026 will not make Europe quantum-safe. It will show whether Member States have built enough governance and operational momentum to make the 2030 deadline credible. The Commission’s “Limited progress” verdict suggests that this first milestone should be treated as a delivery test, not a ceremonial date.
EU post-quantum cryptography questions
Is the EU roadmap legally binding on every company?
No. The roadmap and Commission Recommendation establish coordinated policy and milestones, not a blanket legal ban on classical cryptography. Sector rules, procurement requirements and national measures may create separate obligations.
What should happen by the end of 2026?
Member States should have completed the roadmap’s first steps, established initial national transition plans and begun planning and pilots for high- and medium-risk use cases.
What are the 2030 and 2035 targets?
High-risk use cases should complete transition by the end of 2030. Medium-risk systems should complete transition by the end of 2035, with low-risk systems migrated as far as feasible.
Does the proposed NIS2 amendment already apply?
No. The Commission proposed adding post-quantum migration policies to national cybersecurity strategies in January 2026. It remains a proposal and should not be described as current law.
Official sources
- Commission Recommendation (EU) 2024/1101, adopted 11 April 2024 and published in the Official Journal on 12 April 2024. No publication time was provided.
- NIS Cooperation Group coordinated implementation roadmap, published 23 June 2025. No publication time was provided. Page last updated 3 September 2026.
- European Commission post-quantum cryptography policy page, current overview last updated 3 September 2026.
- EU roadmap survey feedback, published 2 September 2026. No publication time was provided. Page last updated 3 September 2026.
- 2026 State of the Digital Decade staff working document, published in July 2026. The source classifies progress on the relevant recommendation as limited.
- COM(2026) 13 proposal for targeted NIS2 amendments, published 20 January 2026. This remains a legislative proposal.
- ANSSI post-quantum cryptography FAQ, current French guidance accessed 7 September 2026.
- Netherlands NCSC guidance on quantum-safe cryptography, current guidance accessed 7 September 2026.
- Germany BSI guidance on migration to post-quantum cryptography, current English guidance accessed 7 September 2026.
This article provides general information and does not constitute legal, procurement or cryptographic-engineering advice.
Continue the series: European National Cyber & Digital Law Series index


