The full briefing is available via Download PDF above. What follows is the same analysis, in web form.
On 3 September 2026 the G7 Cyber Security Working Group, chaired by France’s ANSSI under the French G7 presidency and supported by the European Commission and ENISA, published Preparing for the Post-Quantum Era: A Call to Action. Its argument is that the quantum threat to cryptography has to be reframed “from a distant future problem” into a near-term one that concerns every sector, not only critical infrastructure.
That publication is the point at which the post-quantum question stopped being about physics and became about dates. Nobody has a cryptographically relevant quantum computer. Several authorities now have deadlines, and two of them apply directly to organisations operating in Switzerland and the EU.
What exactly is the threat, and why does it have a deadline?
Cryptographically relevant quantum computer (CRQC) — a fault-tolerant quantum computer large enough to run Shor’s algorithm against real key sizes, breaking RSA and elliptic-curve cryptography. None exists publicly. Germany’s federal government works on the planning hypothesis that one may exist in the early 2030s — explicitly a risk-assessment reference point, not a forecast.
Harvest now, decrypt later (HNDL), also called store-now-decrypt-later — an adversary records encrypted traffic today and decrypts it once a CRQC exists. This is why the deadline is not “whenever quantum computers arrive”. Any data whose confidentiality must outlast the CRQC is already exposed, today, at capture time.
Hybrid — combining a post-quantum algorithm with a classical one so the result holds if either component breaks. European authorities lean strongly toward it; the US NSA treats standalone PQC as sufficient.
Crypto-agility — designing systems so a cryptographic algorithm can be swapped without re-architecting. It is the property that makes the next transition cheap, and most guidance now treats it as the real deliverable.
Cryptographic inventory — the record of which algorithms, keys and certificates are used where, increasingly expressed as a Cryptographic Bill of Materials (CBOM). Every roadmap in this article depends on one, and almost nobody has one.
The deadline logic follows from HNDL and from migration duration. Even without an active adversary, public key infrastructure and long-lived devices take years to move, so the transition has to finish before the threat lands rather than when it does.
Which algorithms actually replace RSA and ECC?
NIST published the three principal standards on 13 August 2024, and they are production-ready today.
| Standard | Algorithm | Purpose |
|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | Key encapsulation — the RSA and ECDH replacement |
| FIPS 204 | ML-DSA (Dilithium) | Digital signatures, the general-purpose default |
| FIPS 205 | SLH-DSA (SPHINCS+) | Hash-based signatures, conservative backup |
FIPS 206, standardising Falcon as FN-DSA, is still in development, and HQC was selected in March 2025 as a second key-encapsulation mechanism on a roughly two-year track. The backups matter: a single algorithm family failing to cryptanalysis is precisely the scenario hybrid deployment and crypto-agility exist to survive.
The retirement schedule sits in NIST IR 8547, which proposes that quantum-vulnerable public-key algorithms — RSA, ECDSA, EdDSA, finite-field and elliptic-curve Diffie-Hellman — be deprecated after 2030 and disallowed after 2035. Worth noting for anyone quoting it in a policy document: as of this writing IR 8547 is still an initial public draft, published 12 November 2024. Its dates are nonetheless the de facto planning baseline everyone else anchors to.
What does the EU require, and when?
Two distinct layers, and conflating them is the most common mistake in this area.
The PQC layer is a recommendation. On 11 April 2024 the Commission adopted Recommendation (EU) 2024/1101 on a coordinated implementation roadmap. The resulting work stream in the NIS Cooperation Group, co-chaired by France, Germany and the Netherlands, published A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography on 23 June 2025. A Commission recommendation is not binding on private entities.
| Milestone | Date | What is expected |
|---|---|---|
| Milestone 1 | 31 December 2026 | Every Member State has a national PQC transition roadmap, has implemented the “First Steps”, and has begun pilots and high-risk migration |
| Milestone 2 | 31 December 2030 | High-risk use cases fully transitioned; quantum-safe upgrades enabled by default; “Next Steps” implemented |
| Milestone 3 | 31 December 2035 | Transition complete for as many medium- and low-risk systems as feasible |
The roadmap is explicit that for high-risk use cases, quantum-vulnerable public-key mechanisms “shall not be used stand-alone” after the end of 2030, and after the end of 2035 for medium-risk ones. Where migration happens, it recommends standardised, tested hybrid solutions.
The obligation layer is already binding. The roadmap itself points at this, describing its own measures as “no-regret” moves that support compliance with existing law:
- NIS2 (Directive (EU) 2022/2555) requires in-scope entities to adopt risk-management measures including policies on the use of cryptography, and makes management bodies liable for failures. NIS2 does not say “post-quantum”. It does say state-of-the-art cryptography and top-level risk management, which is the hook supervisors will use.
- DORA imposes equivalent ICT risk-management duties on EU financial entities.
- The Cyber Resilience Act applies to products with digital elements placed on the EU market from 11 December 2027, including confidentiality protection and — critically for PQC — the authenticity and upgradeability of software and firmware updates. A device that cannot receive a quantum-safe-signed update is a device that cannot be migrated later.
- eIDAS trust services and the Cybersecurity Act certification schemes both need PQC-aware parameters. Version 2 of the European Cybersecurity Certification Group’s Agreed Cryptographic Mechanisms (May 2025) already carries PQC algorithm recommendations for EUCC.
So the honest summary for an EU entity: no law currently names a PQC deadline for you, and the combination of NIS2 cryptography duties, the CRA’s 2027 product requirements and a 2030 political target for high-risk systems makes waiting for one an expensive strategy.
What applies in Switzerland?
Switzerland sits outside NIS2, and it is not among the 21 European states that signed Securing Tomorrow, Today. It has nonetheless produced the most concrete sectoral deadline in this article.
FINMA Guidance 05/2026, published 9 July 2026, is the instrument that matters. At the end of 2025 FINMA surveyed 60 Swiss financial institutions on quantum risk. The findings are worth reading as a benchmark:
| Finding | Figure |
|---|---|
| Institutions with a specific roadmap for quantum-safe encryption | 8% |
| Planning to draw one up within one to three years | around half |
| No decision taken yet | 43% |
| Rate crypto-agility as important or very important | 73% |
| Expect to be directly affected within seven years | around two-thirds |
| Expect RSA-2048 to be breakable within 24 hours within ten years | around two-thirds |
Source: FINMA Guidance 05/2026.
FINMA’s central recommendation: supervised institutions should have a PQC strategy adopted by the board of directors, with an implementation plan, milestones and target dates, by mid-2027 at the latest. It expects a cryptographic inventory, prioritisation of data needing long-term confidentiality or non-repudiation, explicit treatment of HNDL risk, crypto-agility as a design requirement for new systems and procurements, and early engagement with external service providers — because much of the cryptographic exposure of a Swiss bank sits in infrastructure it does not run.
Two points about its legal character. It is a supervisory communication, not new law: FINMA’s position is that Switzerland’s technology-neutral, principles-based operational-risk and resilience requirements already cover quantum risk. And “mid-2027” attaches to the roadmap, not the migration. FINMA deliberately does not set a final migration date, requiring instead that institutions set their own and state them.
Elsewhere in the Swiss federal picture:
- The NCSC / BACS published a technology brief, Quantum computers and post-quantum cryptography, on 8 December 2025, alongside an assessment that action is required. Guidance, not obligation.
- Three parliamentary items were filed in June 2026: motion 26.3628 (Juillard) for a national PQC transition roadmap, motion 26.3830 (Blunschy) to prepare federal IT for quantum-safe cryptography, and postulate 26.3831 seeking a situation report and migration plan for federal IT. The Federal Council came out in favour of a national roadmap at the start of September 2026. The motions had not completed parliamentary passage at the time of writing, so Switzerland still has no binding national roadmap — only a government now on record supporting one.
- The FOITT / BIT is already migrating the Swiss Government PKI, with certificate key lengths and signature algorithms changing across classes.
- The Cyber-Defence Campus at armasuisse has run dedicated quantum-computing monitoring since 2023.
How do the national authorities differ?
They agree on inventory-first and disagree on hybrid. If you operate across borders, the strictest applicable position is the one to build to.
| Authority | Position and dates |
|---|---|
| ANSSI (France) | The strictest in Europe. Hybridisation is mandatory, not advisory, for products seeking French security visas, on a three-phase roadmap: defence-in-depth, then post-quantum assurance with mandatory hybridisation from around 2025, then optional standalone PQC no earlier than 2030. ANSSI intends to require PQC for product qualification from 2027, and states it will not be reasonable to buy products without PQC after 2030. |
| BSI (Germany) | Recommends hybrid, publishes the reference study on quantum computer development, co-chairs the EU work stream, and anchors the “early 2030s” planning hypothesis for high-security government use. |
| NCSC (UK) | The clearest published three-phase timeline: by 2028 complete discovery and assessment and produce an initial migration plan; by 2031 complete highest-priority migrations; by 2035 finish. Aimed at large organisations and critical national infrastructure. |
| NIST and CISA (US) | FIPS 203/204/205 plus the IR 8547 deprecate-2030 / disallow-2035 schedule. A June 2026 executive order, Securing the Nation Against Advanced Cryptographic Attacks, tightened federal expectations, with reporting that internal migration targets moved from 2035 toward 2030. NSA’s CNSA 2.0 gates national-security-system acquisitions separately. |
| ACN (Italy), CSE (Canada), NCO (Japan) | Co-signatories of the G7 working group statement; ACN also publishes its own quantum-safe cryptography guidance. |
| ENISA and ECCG (EU) | Support the Commission’s roadmap and maintain the Agreed Cryptographic Mechanisms document whose version 2 adds PQC recommendations for EU certification. |
The G7 working group statement on preparing for a PQC migration — jointly published by CSE, BSI, ACN, ANSSI, CISA, NCSC with DSIT, and Japan’s NCO, in collaboration with the Commission — is the most useful cross-jurisdictional document, because it is practical rather than declaratory. Separately, the G7 Cyber Expert Group published a coordinated roadmap for the financial sector in January 2026, which is the natural companion to the FINMA guidance.
Where the deadlines actually land
| Date | What lands |
|---|---|
| 31 December 2026 | EU Member States: national PQC roadmaps and First Steps complete |
| Mid-2027 | Swiss financial institutions: board-approved PQC roadmap (FINMA) |
| 2027 | ANSSI intends to require PQC for product qualification |
| 11 December 2027 | Cyber Resilience Act applies to products on the EU market |
| 2028 | UK: discovery and assessment complete, initial migration plan |
| 2030 | EU high-risk use cases migrated; no standalone quantum-vulnerable public key; NIST deprecation; ANSSI procurement expectation |
| 2031 | UK: highest-priority migrations complete |
| 2035 | EU, UK and NIST all converge on full transition and disallowance |
The instruments are not comparable — state roadmaps, supervisory guidance, procurement gates and product regulation all behave differently — but the band is unmistakable. Planning work is due in 2026 and 2027. Migration of anything sensitive is due by 2030.
What should you do in the next ninety days?
Every roadmap above begins at the same place, and it is not cryptography.
Days 0–30, see. Establish what you actually expose. Enumerate internet-facing services and the TLS versions and certificate algorithms they present, because the G7 statement singles out internet-facing network services as the highest HNDL exposure, and PQC key establishment only exists in TLS 1.3 and later. Identify data with a confidentiality or non-repudiation requirement extending past 2030, and record the required lifetime explicitly. Name an accountable owner for the transition.
Days 31–60, inventory and prioritise. Build the cryptographic inventory outward from the asset inventory you already maintain — the G7 statement recommends exactly this starting point rather than a greenfield exercise. Consider CBOM as the format. Run a quantum risk assessment weighting potential damage, data lifespan and network accessibility; a three-level low/medium/high scheme is sufficient to sequence work. Open the supplier conversation, since a large share of your exposure sits in someone else’s product roadmap.
Days 61–90, commit. Write the roadmap with milestones and target dates, and get it approved at board level if FINMA applies to you. Put crypto-agility and PQC support into procurement criteria and contract language now, because procurement is the cheapest lever available. Pilot hybrid key establishment on something real. Map the result to the framework your supervisor will ask about — NIS2 or DORA cryptography duties, or FINMA operational-risk expectations — and set a reassessment cycle, because the standards and the dates are both still moving.
Five questions for the next board meeting
- Which of our data, if captured in transit today, would still be sensitive in 2035?
- Do we have a cryptographic inventory, and if not, when will we?
- Which internet-facing services still negotiate TLS 1.2 or below, and who owns them?
- Which of our suppliers have a published PQC roadmap, and which have gone quiet when asked?
- If FINMA, a NIS2 supervisor or a large customer asked for our PQC roadmap next quarter, what would we send?
If question two has no answer, that is the ninety-day programme.
The cryptographic inventory is a discipline of its own, and Panop does not build it for you. What Panop does address is the layer underneath every roadmap in this article: knowing what you actually expose to the internet, which of it is reachable, which supplier and cloud infrastructure sits in the path, and keeping that current as the estate changes rather than as of the last audit. That is the asset inventory the G7 statement tells you to start from, and the exposure prioritisation that decides which endpoints migrate first. See autonomous discovery, third-party risk and risk prioritisation, or book a demo.
Sources
This is an awareness briefing, not legal advice, a compliance opinion or a cryptographic assessment. Figures are reproduced as published by the cited source and were current at the publication date. Regulatory dates in this area have already moved and may move again — verify against the primary source before relying on any date here. NIST IR 8547 remains a draft.
- G7 Cyber Security Working Group and CISA — Preparing for the Post-Quantum Era: A Call to Action, 3 September 2026
- G7 Cybersecurity Working Group — Statement on preparing for a post-quantum cryptography migration, with CSE, BSI, ACN, ANSSI, CISA, NCSC and DSIT, and Japan’s NCO
- European Commission — Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography, 11 April 2024
- NIS Cooperation Group — A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, 23 June 2025
- European Parliament and Council — Directive (EU) 2022/2555 (NIS2)
- FINMA — Guidance 05/2026, quantum computing, 9 July 2026
- NCSC / BACS Switzerland — Technology brief: Quantum computers and post-quantum cryptography, 8 December 2025
- BACS — parliamentary items 26.3628, 26.3830 and 26.3831, June 2026; and inside-it.ch on the Federal Council’s support for a national roadmap, 1 September 2026
- ANSSI — PQC FAQ, views on the PQC transition (2022) and follow-up position paper (2023)
- BSI and 20 further European authorities — Securing Tomorrow, Today: Transitioning to Post-Quantum Cryptography, second version, 27 June 2025
- UK NCSC — Timelines for migration to post-quantum cryptography
- NIST — FIPS 203, FIPS 204 and FIPS 205, 13 August 2024, and IR 8547 initial public draft, 12 November 2024
- AIVD, CWI and TNO — The PQC Migration Handbook
- German Federal Government — reply on quantum threat planning assumptions, Bundestag Drucksache 20/8104