The EU Member States, supported by the European Commission, have issued a roadmap and timeline to start using post-quantum cryptography (PQC) to future-proof cyber security.
The roadmap was written by the NIS Cooperation Group and includes a set of recommendations that Member States need to implement for a synchronised transition to PQC, as well as measures to ensure that all stakeholders are well informed about the quantum threat to cryptography.
Key points from the roadmap, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, include:
- A two-phase recommendation structure: the roadmap divides actions into First Steps (to initiate the transition) and Next Steps (to follow through).
- Timeline with milestones:
- By end 2026: Member States should implement First Steps, establish national PQC transition strategies, and initiate pilots for critical use cases.
- By end 2030: high-risk use cases must have migrated to PQC.
- By 2035: transition should be largely complete for all practical systems.
- Coordinated approach: the roadmap underscores the need for EU-level coordination and national strategies, supported by the NIS Cooperation Group.
- Awareness and asset management: it recommends that stakeholders be informed of the quantum threat, incorporate it into risk management, and establish robust cryptographic asset inventories to enhance agility.
- Hybrid and standards-based migration: when shifting to PQC, the uptake of standardised hybrid solutions is advised to ensure security throughout the transition phase.
These recommendations aim to support a systematic, timely, and well-informed shift to quantum-resistant cryptography across the EU.






