The Essentials

The European Union has set a legal timeline to protect its critical infrastructure against a threat that does not yet exist: quantum computers capable of breaking current encryption. The roadmap requires migration of the most sensitive systems to post-quantum cryptography by the end of 2030, and all remaining systems by 2035. Audits of major German companies show that a significant portion of them are already several years behind schedule. The stakes go beyond regulatory intent: actors are collecting encrypted data today that they plan to decrypt within a decade, making current inaction a deferred data breach.


A secret encrypted today can be stored for ten years, then decrypted tomorrow by a machine that does not yet exist. This mechanism, which experts call “harvest now, decrypt later,” transforms every day of inaction into accumulated vulnerability. The quantum threat is asymmetric in time: it operates in the present without revealing itself for years.

Europe understood this logic early enough to act before the rupture. The European Commission published a roadmap that requires member states and critical infrastructure operators to migrate to new cryptographic standards according to a precise timeline. This is rare. Digital regulations almost always react after crises, not before. This one is an exception, and that is precisely why it deserves close examination: not to celebrate planning, but to measure the gap between the legal timeline and the actual capacity to honor it.


The “Harvest Now, Decrypt Later” Threat Makes 2026 Inaction Retroactively Dangerous

Asymmetric cryptography protects nearly all sensitive digital communications: banking transactions, health data, diplomatic communications, industrial control systems. These protocols, notably RSA and elliptic curves, rely on a mathematical problem that classical computers cannot solve in useful time: factoring very large integers.

A sufficiently powerful quantum computer could achieve this. Shor’s algorithm, formulated in 1994, demonstrates it theoretically. But current machines still lack stable qubits and reliable error correction to achieve this. The most conservative estimates place the horizon for such a computer at 15 to 25 years or more. The 10 to 15-year horizon corresponds to the most optimistic estimates, notably those from manufacturers like IBM and Google.

This uncertainty about the deadline does not reduce the threat: it displaces it. Intelligence services, state actors, and according to Western cybersecurity agencies, certain organized criminal groups are intercepting and storing encrypted flows today. They gain nothing from them for now. But they are waiting. When the appropriate machine exists, data collected in 2024 will be readable as if it had always been.

This logic creates a partial irreversibility that few regulatory frameworks have been able to name. Intercepted data cannot be “decrypted again.” State secrets, medical files, industrial contracts: what circulates today under cryptographic protection constitutes a stock of future vulnerabilities. This is why the European Commission chose to act now rather than wait for the public demonstration of an operational quantum computer.


Concrete Obligations of the European Roadmap

The European Commission published its Recommendation on Post-Quantum Cryptography on April 11, 2024. The roadmap published by Commission services sets two structural deadlines: the end of 2030 for migration of critical infrastructure, and the end of 2035 for all remaining systems in public administration and essential operators.

These two dates are not symbolic. They are based on recommendations from the American NIST, which finalized its first post-quantum cryptography standards in August 2024 after an eight-year selection process. The selected algorithms, notably CRYSTALS-Kyber for encryption and CRYSTALS-Dilithium for digital signatures, now constitute the international reference toward which European systems must migrate.

ENISA, the EU’s cybersecurity agency, supports this migration. It has published technical guidelines to help member states assess their exposure and plan their transitions. The NIS2 and DORA directives, which came into force in 2023 and 2025 respectively, strengthen security obligations on critical operators and the financial sector, and constitute the legal framework within which cryptographic migration is situated.

This regulatory apparatus is coherent. But its legal coherence does not prejudge its effective implementation.


A Significant Portion of Major German Companies Already Lags Several Years Behind

Germany is often taken as a barometer of European industrial capacity. An audit conducted by KPMG in collaboration with the BSI, the Federal Office for Information Security Systems, surveyed a large number of major German companies on their readiness for post-quantum migration. Result: a significant portion of them estimate they are already several years behind on this project.

This lag against a 2030 deadline is theoretically recoverable. But cryptographic migration is not an ordinary IT project. It involves identifying all cryptographic assets of an organization, what is called a “crypto inventory,” then prioritizing, testing, and replacing protocols, often on systems whose code dates back decades. In the energy, transport, and finance sectors, some equipment incorporates cryptographic modules that cannot be updated without complete hardware replacement.

The lag is all the more problematic because migration cannot be done in a single step. Experts recommend a hybrid approach: temporarily maintain old protocols while deploying new ones, to guarantee compatibility and allow detection of anomalies. This hybrid phase lengthens timelines and multiplies transitory attack surfaces.

For economists studying technological regulations, such as Philippe Aghion in his work on Schumpeterian innovation, the true test of a transition policy is not its normative sophistication but its ability to trigger actual investment in affected companies. On this point, German data provide a mixed picture: major companies aware of the problem have mostly begun working. But a significant fraction of them remains in a posture of waiting that looks less like a strategy than organized procrastination.


SMEs and Local Authorities, the Blind Spot of the System

The European roadmap prioritizes critical infrastructure and major administrations. This is the perimeter where the threat is most severe and regulation most constraining. The majority of actual exposure lies elsewhere.

Industrial SMEs, territorial authorities, medium-sized hospitals, and law firms handle sensitive data daily under cryptographic protocols identical to those of large organizations. They share the same future vulnerability, but without the resources or expertise to conduct a complex migration. NIS2 extends the regulatory perimeter to more entities, but concrete obligations regarding post-quantum cryptography remain unclear for mid-sized actors.

The question of financing the transition arises here with acuity. Migration to post-quantum cryptography has direct costs: asset inventory, system updates, team training, compatibility testing. For a major bank, this cost is absorbed in the existing cybersecurity budget. For a regional hospital network or an industrial components SME, it can represent an investment without immediate visible return.

The European Union has financing instruments, Horizon Europe, the digital Europe program, but access to them requires administrative capacity that many small structures do not possess. Comparisons with other technological transitions are illuminating: during the transition to IPv6, the new-generation internet addressing protocol, mid-sized organizations were systematically the slowest, and some delays persist even today, twenty years after the first recommendations. The question of operational capacity of second-rank actors is not resolved by an ambitious legal timeline, however well-founded.


The United States Moved First, Europe Follows with Its Own Instruments

The United States laid the groundwork for the international response. The May 2022 presidential executive order on quantum cybersecurity provided strong federal impetus, and NIST delivered its final standards in August 2024 after a selection that cryptographers worldwide could observe and comment on. This transparency was decisive: it provided a credible reference that Europe could adopt without having to conduct its own algorithmic selection process.

Europe nevertheless brings a dimension that the American model does not integrate as directly: regulatory constraint on private actors. In the United States, federal agencies are subject to deadlines set by CISA and OMB, but private companies remain largely autonomous in their timelines. In Europe, NIS2 and DORA impose legal obligations on critical infrastructure operators and financial entities, with sanctions for non-compliance.

This coupling of regulation and technical standard is a structural strength of the European model, which Daron Acemoglu and Simon Johnson have analyzed in their work on the relationship between institutions and technological adoption: when rules are clear and standards available, companies invest. The mechanism is not automatic, but the combination of a legal obligation and a public technical reference reduces the uncertainty that ordinarily impedes investment.

China is developing its own post-quantum cryptographic standards, independently of the NIST process, as part of its technological sovereignty strategy. This parallelism creates a fragmentation risk: if standards diverge, information systems operating in both spaces will have to manage incompatible protocols, which multiplies transition costs and risks.


A Project That Redefines What “Anticipating” Means in Technology Policy

Post-quantum cryptography is a textbook case for anticipatory regulation. Most digital regulatory texts respond to demonstrated crises: GDPR was born from data collection scandals, NIS1 from the first major cyberattacks on critical infrastructure, DORA from systemic incidents in the financial sector. Acting before the public demonstration of a technological rupture is an exercise of a different kind.

This requires accepting a form of political discomfort: investing heavily to prevent a risk that no one can precisely date. Opponents of this type of regulation argue that we are mobilizing rare resources on a hypothetical threat while actual and immediate threats remain underfunded. The argument has some validity. Cybersecurity budgets of European public organizations remain globally insufficient relative to current attacks, which do not need a quantum computer to paralyze a hospital or power plant.

But this tension reinforces the principle of the roadmap: it underscores the necessity of additional funding, rather than a choice between two priorities. Post-quantum migration takes time because it will be urgent in ten years and the systems to be migrated are often twenty years old. The horizon of industrial policy in digital security must be longer than that of an annual budget cycle. This is precisely what the European timeline seeks to impose.

BSI and KPMG data indicate that the message is getting through unevenly. Organizations that have begun their cryptographic inventory speak of an awareness that transforms the way they think about their infrastructure: no longer as a set of functional systems, but as a stack of technical decisions each with an expiration date. This change in perspective, more than the deployment of this or that algorithm, may be the most durable thing the European roadmap produces.

For 2026, the question is whether companies falling behind will begin to accelerate, or whether they will wait for a possible extension of the deadline. Europe has set a timeline, whose compliance remains to be confirmed.


Sources

  1. European Commission, Post-Quantum Cryptography Cybersecurity Strategy: digital-strategy.ec.europa.eu
  2. NIST, Post-Quantum Cryptography Standards (FIPS 203, 204, 205), August 2024: nist.gov
  3. ENISA, Guidelines on Post-Quantum Migration: enisa.europa.eu
  4. KPMG-BSI, Audit on the Readiness of Major German Companies for Post-Quantum Cryptography (results cited via The Quantum Insider)
  5. NIS2 Directive (EU 2022/2555): eur-lex.europa.eu
  6. DORA Regulation (EU 2022/2554): eur-lex.europa.eu
  7. NIST – Official Publication FIPS 203, 204, 205 (August 2024): nist.gov
  8. Federal Register – Issuance FIPS 203, 204, 205 (August 14, 2024): federalregister.gov
  9. NIST CSRC – Official Post-Quantum Cryptography Page: csrc.nist.gov
  10. European Commission – PQC Roadmap (Official Page): digital-strategy.ec.europa.eu
  11. European Commission – PQC Recommendation Announcement (April 11, 2024): digital-strategy.ec.europa.eu
  12. ENISA – NIS2 Directive: enisa.europa.eu
  13. EIOPA – DORA (Digital Operational Resilience Act): eiopa.europa.eu
  14. BSI/KPMG – Market Survey on Cryptography and Quantum Computing (2023): bsi.bund.de
  15. Wikipedia – Shor’s Algorithm: wikipedia.org
  16. White House Archives (Biden) – NSM-10 May 2022: bidenwhitehouse.archives.gov