Between June and September 2026, more happened in post-quantum cryptography regulation than in the previous three years combined.
The United States signed Executive Order 14412, making PQC migration a binding obligation for all federal civilian agencies and their contractors by 2030. France announced it will stop certifying security products that lack quantum-resistant encryption from 2027. Switzerland's FINMA mandated board-approved PQC strategies for all supervised financial institutions by mid-2027. Japan's CRYPTREC added ML-KEM to the national approved cipher list, clearing the path for government PQC adoption. Singapore's MAS announced formal supervisory expectations for quantum resilience by the end of the decade. The G7 Cybersecurity Working Group issued a joint call to action across all seven member nations. And NIST moved every remaining FIPS 140-2 certificate to Historical status.
Every one of these developments points back to the same requirement: know what cryptography you are running, know where it is vulnerable, and have a plan to replace it.
This article maps the complete global picture as of late September 2026. It covers the international standards that underpin everything, the country-by-country mandates and timelines, the sector-specific frameworks that most organisations actually report against, and the common thread that connects all of them.
Before examining individual countries, it is worth understanding the international standards layer. These standards do not belong to any single jurisdiction but are referenced by nearly all of them.
The foundation for everything that follows. NIST finalised three PQC algorithm standards: FIPS 203 (ML-KEM for key encapsulation), FIPS 204 (ML-DSA for digital signatures), and FIPS 205 (SLH-DSA for stateless hash-based signatures). These are the algorithms that most national frameworks now reference, though some jurisdictions recommend additional algorithms beyond the NIST suite.
On September 21, 2026, NIST moved every remaining FIPS 140-2 certificate to Historical status. This means that cryptographic modules validated only under FIPS 140-2 no longer satisfy compliance requirements for new federal systems. Organisations whose compliance posture depends on FIPS-validated modules (including those subject to HIPAA, FedRAMP, and certain state-level regulations) now need to verify that their modules hold active FIPS 140-3 certificates. The practical implication: if you do not know which FIPS-validated modules are running in your environment, the September 21 sunset may have already created a compliance gap you have not detected.
The G7 Cybersecurity Working Group published Preparing for the Post-Quantum Era: A Call to Action, co-issued by the cybersecurity agencies of all seven member nations under France's 2026 G7 presidency (led by ANSSI). The document urges governments and organisations across all sectors to adopt a phased, risk-based approach to PQC migration, beginning with identifying critical data and assets, inventorying cryptographic assets, mapping dependencies, and developing a transition plan.
ISO standardised three post-quantum key encapsulation mechanisms: ML-KEM, FrodoKEM, and Classic McEliece, as part of ISO/IEC 18033-2:2006/Amd 2:2026. This is significant because it gives the conservative algorithms recommended by BSI (Germany) and ANSSI (France) formal international standards backing, not just national recommendation status. Organisations operating across jurisdictions now have an ISO reference for algorithms that go beyond the NIST suite.
PCI DSS does not yet mandate post-quantum algorithms. However, Requirement 12.3.3 (mandatory since March 31, 2025) requires organisations to maintain a documented cryptographic inventory, assign monitoring ownership for cipher suite viability, and develop a plan for migrating away from deprecated algorithms. PCI SSC has issued no standalone PQC guidance as of September 2026, but the cryptographic inventory and migration planning requirements effectively create a PQC readiness obligation for any payment environment.
DORA applies to financial entities across more than 20 categories of EU-regulated financial services. Its ICT risk management regulatory technical standards explicitly require entities to monitor cryptographic threats "including threats from quantum advancements" and to update cryptographic technology accordingly. DORA operates in parallel with NIS2 for financial entities and creates a distinct compliance obligation for quantum risk assessment.
The Bank for International Settlements published a quantum readiness roadmap urging financial institutions to begin migration without delay, though it stopped short of setting a hard compliance date. The roadmap has informed subsequent national financial regulator actions (FINMA, HKMA, MAS, Bank of Israel).
SWIFT has not issued a formal PQC mandate as of September 2026. However, according to industry analysis, SwiftNet 8.0 is expected to be PQC-enabled by 2027, with a 15-month migration window for participating institutions. The SWIFT Customer Security Programme (CSCF) already requires cryptographic controls that will need to be updated as PQC standards are adopted.
NIST's draft Interagency Report 8547 proposes deprecating quantum-vulnerable public-key cryptography after 2030 and disallowing it entirely after 2035. While still in draft, this document signals the intended end-of-life timeline for RSA and ECC across the US federal ecosystem.
The table below summarises the current state of PQC regulation across seventeen jurisdictions. Each entry is expanded in the sections that follow.
| Jurisdiction | Authority | Key Deadline | Primary Framework | Algorithm Position | Hybrid Position |
|---|---|---|---|---|---|
| USA (Federal/NSS) | NSA, OMB, CISA | Jan 2027 (new NSS acquisitions), Dec 2030 (EO 14412 HVAs), 2035 (full) | CNSA 2.0, EO 14412, OMB M-26-15 | ML-KEM, ML-DSA only (no SLH-DSA) | Interim only; pure-PQC end state |
| USA (Financial) | Treasury | TBD | Quantum-Readiness Task Force (Aug 2026) | Per NIST | Not specified |
| EU | NIS Cooperation Group, ENISA | End 2026 (first steps), 2030 (critical systems), 2035 (full) | NIS2, DORA, EU PQC Roadmap | Per NIST + ENISA recommendations | Required (ETSI TS 103 744) |
| France | ANSSI | 2027 (certification cutoff), 2030 (purchase only quantum-safe) | ANSSI qualification | ML-KEM + FrodoKEM | Required |
| Germany | BSI | Aligned with EU 2030; classical-only KEM sunset Dec 2031 | TR-02102-1 (2026-01 revision) | ML-KEM + FrodoKEM + Classic McEliece | Mandated |
| UK | NCSC | 2028 (discovery + plans), 2031 (high-priority migration), 2035 (full) | NCSC PQC Migration Timelines | NIST suite (incl. SLH-DSA) | Single-layer preferred |
| Australia | ASD | 2030 | ISM | ML-KEM-1024 required (768 acceptable until 2030) | Not recommended |
| Canada | CSE, TBS | In development | CCSPA, CCCS PQC Roadmap (mid-2025) | NIST suite | Recommended |
| Singapore | MAS | End of decade | Supervisory expectations (late 2026) | NIST suite | QKD sandbox completed |
| Japan | CRYPTREC, NISC/NCSB, JFSA | 2035 (full); national roadmap expected May 2027 | CRYPTREC Ciphers List, Cabinet Secretariat interim report | NIST suite (ML-KEM on CRYPTREC list) | Recommended |
| India | DST | 2027 (CII foundation) | NQM Task Force | NIST suite | Not specified |
| Switzerland | FINMA | Mid-2027 (board-approved strategies) | Guidance 05/2026 | NIST suite | Not specified |
| Israel | Bank of Israel | Jan 2026 (plans submitted) | Board directive (Jan 2025) | NIST suite | Not specified |
| UAE | Cyber Security Council | Immediate (board-level plans mandatory) | National Encryption Policy | NIST suite | Not specified |
| South Korea | KISA, NIS | In development | KpqC national competition | NIST + national suite (KpqC) | Not specified |
| Saudi Arabia | NCA, SAMA | In development | NCS, NCA ECC, SAMA CSF, Pasqal/KACST partnership | NIST suite (via NCS) | Not specified |
| Malaysia | NACSA | In development | Chief Executive Directive No. 9 | Not specified | Not specified |
Algorithm and hybrid positions reflect the stated or recommended posture of each jurisdiction's primary cybersecurity authority as of September 2026.
The US has the most layered PQC mandate structure of any country. Executive Order 14412, signed on June 22, 2026, makes PQC migration a binding legal obligation for all federal civilian agencies and their contractors. The EO sets two distinct deadlines: December 31, 2030 for migrating high-value assets to post-quantum key establishment, and December 31, 2031 for post-quantum digital signatures. OMB Memorandum M-26-15 replaces the earlier M-23-02 with a five-phase timeline running to 2035. The Department of War published a department-wide PQC strategy aligned with these migration gates. For National Security Systems, NSA's CNSA 2.0 requires all new acquisitions to comply from January 1, 2027, with a full mandate by 2033-2035.
The FAR Council must publish a proposed rule on contractor PQC compliance by December 2026, which will embed quantum-safe requirements directly into federal procurement contracts.
Notably, CNSA 2.0 excludes SLH-DSA (the hash-based signature algorithm) and permits hybrid only as an interim step toward a pure-PQC end state. This puts the US at odds with European agencies on both points.
No sector-specific PQC mandate exists for private-sector financial institutions as of September 2026. However, in August 2026, the US Treasury established a Quantum-Readiness Task Force to coordinate the transition across the financial sector, with particular attention to third-party vendor risk and digital assets. Federal contractors in the financial sector now fall under EO 14412's 2030 deadline.
The EU's approach layers multiple instruments. The NIS Cooperation Group's Coordinated Implementation Roadmap (June 2025), led by France, Germany, and the Netherlands, sets three milestones: national transition plans by end of 2026, critical systems migrated by 2030, and full migration by 2035.
In early 2026, the European Commission proposed amending NIS2 to include an explicit PQC requirement, directing every member state to adopt PQC transition policies within their national cybersecurity strategies. This amendment is expected to be adopted in late 2026 or early 2027.
DORA (Regulation (EU) 2022/2554) creates parallel obligations for financial entities, with its ICT risk management RTS explicitly referencing quantum threats. ETSI TS 103 744 governs hybrid TLS within EU deployments.
ANSSI announced at France Quantum 2026 (June 2026) that it will stop certifying security products that do not include quantum-resistant encryption from 2027. By 2030, businesses should be purchasing only quantum-safe products. Since ANSSI certification is a prerequisite for use across French government agencies and critical infrastructure operators, this effectively makes PQC a procurement gate for one of Europe's largest government technology markets. ANSSI requires hybrid for any product with a long-term security claim and recommends FrodoKEM alongside ML-KEM.
BSI's Technical Guideline TR-02102-1 (revised January 2026) recommends FrodoKEM and Classic McEliece alongside the NIST selections and mandates hybrid key exchange. The guideline sunsets classical-only key agreement at the end of 2031. BSI's approach is more prescriptive than the EU anchor and reflects a conservative risk posture that prioritises algorithmic diversity as a hedge against future lattice cryptanalysis.
The NCSC published its Timelines for Migration to Post-Quantum Cryptography in March 2025, setting a three-phase roadmap: Phase 1 (by 2028) covers cryptographic discovery, inventory, and migration planning; Phase 2 (2028-2031) covers high-priority system migration; Phase 3 (2031-2035) covers full migration. The UK was the first major regulatory jurisdiction to endorse NIST's PQC algorithms after their August 2024 release. The NCSC prefers a single-layer PQC approach rather than mandating hybrid, diverging from both ANSSI and BSI on this point.
The Cross Market Operational Resilience Group (CMORG) published sector-specific PQC guidance for UK financial institutions in April 2025, aligning with NCSC and NIST recommendations.
The ASD Information Security Manual (ISM) targets a 2030 PQC mandate and specifies ML-KEM-1024 as the required algorithm (ML-KEM-768 is acceptable as an interim measure until 2030). Australia does not recommend hybrid key exchange, aligning more closely with the US pure-PQC position than the European hybrid mandate. This creates a compliance divergence for organisations operating across both jurisdictions: satisfying both simultaneously would mean running hybrid until 2030 (for European compliance) and then removing the classical component (for Australian compliance).
Canada published its PQC roadmap via the Canadian Centre for Cyber Security (CCCS) in mid-2025. The CCSPA introduces cybersecurity obligations for critical infrastructure operators that will encompass cryptographic modernisation. No hard PQC compliance date has been set, but federal departments are developing migration plans. Canada recommends hybrid key exchange.
MAS Managing Director Chia Der Jiun announced on July 28, 2026 that MAS will issue formal supervisory expectations later in 2026 to guide financial institutions' migration toward quantum resilience, with the aim of achieving quantum resilience across the financial sector before the end of the decade. Financial institutions will be expected to establish a cryptographic inventory, develop a prioritised migration plan, and build technical capabilities and governance frameworks for a quantum-safe transition. MAS previously ran a QKD sandbox with DBS, HSBC, OCBC, and UOB, publishing its technical report in September 2025.
Japan is taking a dual-track approach to the quantum transition, pursuing both PQC and quantum key distribution (QKD). CRYPTREC, the body that maintains Japan's approved cipher lists, published its Post-Quantum Cryptography Guideline in April 2025. In April 2026, PQShield delivered the external ML-KEM evaluation for CRYPTREC, supporting ML-KEM's inclusion in the CRYPTREC Ciphers List. This was the first clear signal that the Japanese government is accelerating its move toward quantum-safe security.
A formal national PQC roadmap is expected by May 2027. In the interim, the Cabinet Secretariat's National Cyber Security Bureau (NCSB, successor to NISC) concluded in a November 2025 interim report that government agencies must complete their PQC transition by 2035, aligning with US and EU timelines. The report highlights HNDL risks, recommends hybrid PQ/classical schemes, and emphasises cryptographic agility. Japan's Financial Services Agency (JFSA) has separately directed deposit-taking institutions to begin the transition. METI, MIC, NICT, and CRYPTREC are coordinating the national programme.
The DST's National Quantum Mission (NQM) Task Force report (February 2026) classifies telecommunications as critical information infrastructure with a 2027 foundation deadline. The report introduces mandatory CBOM requirements in procurement from FY 2027-28 for CII sectors. QNu Labs' QShield 2.0, launched September 2026, implements the National Cryptographic Assessment and Assurance Framework (NCAAF) as a domestic execution engine.
FINMA published Guidance 05/2026 in July 2026, requiring all supervised financial institutions to have board-approved PQC strategies in place by mid-2027. A Swiss survey found that fewer than 8% of institutions currently have a formal PQC roadmap. FINMA's guidance runs ahead of the broader EU timeline and creates an early compliance pressure point for Swiss financial entities.
The Bank of Israel wrote to every banking corporation and licensed payment provider in January 2025, requiring a quantum preparedness plan discussed by the board and submitted within one year. This was one of the earliest mandatory board-level PQC requirements issued by any financial regulator globally.
The UAE Cyber Security Council's National Encryption Policy (late 2025) requires board-level transition plans, automated cryptographic inventory, and crypto-agility as a design constraint for government entities. This was one of the earliest mandatory national-level PQC requirements anywhere.
South Korea is running a national PQC algorithm competition (KpqC) to develop domestic alternatives alongside the NIST suite. KISA and the National Intelligence Service (NIS) are developing migration guidance, but no hard compliance date has been published. Organisations operating in South Korea may need to support both NIST and KpqC algorithms, creating a dual-algorithm compliance requirement.
Saudi Arabia is positioning PQC as a national strategic priority under Vision 2030. The National Cybersecurity Authority (NCA) publishes the National Cryptographic Standards (NCS), which specify minimum cryptographic requirements for national data, systems, and networks. NCA's Essential Cybersecurity Controls (ECC) are mandatory for all government entities, semi-government organisations, and private-sector organisations operating critical national infrastructure. The SAMA Cybersecurity Framework (SAMA CSF) creates parallel obligations for financial institutions across 32 sub-domains.
While no PQC-specific compliance date has been published, the regulatory infrastructure is in place. In February 2026, Pasqal and KACST (King Abdulaziz City for Science and Technology) announced a research partnership to advance PQC in Saudi Arabia, directly supporting Vision 2030 objectives. The NCA's mandate to draft national cryptographic policies and standards, combined with SAMA's financial sector oversight and the Critical Systems Cybersecurity Controls (CSCC), creates a framework through which PQC requirements can be imposed across energy, telecommunications, finance, and government sectors as the transition progresses.
NACSA's Chief Executive Directive No. 9 establishes cybersecurity requirements for critical infrastructure operators. While PQC-specific mandates are still in development, BNM (Bank Negara Malaysia) and PDPA compliance expectations are expected to evolve toward quantum readiness as ASEAN-wide guidance develops.
Despite the divergence in algorithms, hybrid positions, and timelines, every framework on this page converges on the same sequence of practical steps. No jurisdiction says "deploy PQC first." Every single one starts with the same prerequisite:
Step 1: Build a cryptographic inventory. Before you can migrate, you need to know what you are running. This means scanning across TLS configurations, source code, APIs, SSH keys, JWT tokens, key management systems, databases, email, and embedded devices. The output is a Cryptographic Bill of Materials (CBOM) that maps every cryptographic asset, its algorithm, its key length, and its location.
Step 2: Assess quantum risk exposure. Score each asset against its vulnerability window: how long does the data need to remain confidential? Is it subject to harvest-now-decrypt-later risk? Which regulatory deadline applies first?
Step 3: Develop a migration plan. Prioritise assets by risk, map them to compliance deadlines, and build a phased migration roadmap that fits within your budget and refresh cycles.
Step 4: Build crypto-agility. Design your architecture to support algorithm replacement without a full redesign. This matters because national algorithm positions are still diverging, and an organisation operating across multiple jurisdictions may need to swap between algorithm suites.
Step 5: Monitor continuously. Migration is not a one-time event. New algorithms will be standardised, old ones may be deprecated (as NIST IR 8547 proposes for RSA and ECC), and your environment will change. Continuous cryptographic monitoring ensures your posture stays current.
The order is the same whether you are subject to CNSA 2.0, NIS2, DORA, APRA CPS 234, the ASD ISM, FINMA, SAMA, or NCA ECC. Discovery comes first. Everything else follows from that.
ExeQuantum is an ISO 27001 certified, AUKUS authorised post-quantum cryptography company. CipherScout, CipherForge, and CipherWatch cover steps 1 through 5 as an integrated platform. Learn more at exequantum.com.
For a surface-by-surface comparison of cryptographic discovery vendors, see Cryptographic Discovery Vendors Compared: Who Finds What in 2026.