Skip to main content

Envisioning is an emerging technology research institute and advisory.

LinkedInInstagramGitHub

2011 — 2026

research
  • Reports
  • Newsletter
  • Methodology
  • Origins
  • My Collection
services
  • Research Sessions
  • Signals Workspace
  • Bespoke Projects
  • Use Cases
  • Signal Scanfree
  • Readinessfree
impact
  • ANBIMAFuture of Brazilian Capital Markets
  • IEEECharting the Energy Transition
  • Horizon 2045Future of Human and Planetary Security
  • WKOTechnology Scanning for Austria
audiences
  • Innovation
  • Strategy
  • Consultants
  • Foresight
  • Associations
  • Governments
resources
  • Pricing
  • Partners
  • How We Work
  • Data Visualization
  • Multi-Model Method
  • FAQ
  • Security & Privacy
about
  • Manifesto
  • Community
  • Events
  • Support
  • Contact
  • Login
ResearchServicesPricingPartnersAbout
ResearchServicesPricingPartnersAbout
  1. Home
  2. Research
  3. Polis
  4. Post-Quantum Cryptography Migration

Post-Quantum Cryptography Migration

EU mandating all member states begin migration to quantum-resistant encryption by end of 2026 — protecting critical infrastructure against future quantum attacks
Back to PolisView interactive version

The EU issued a Post-Quantum Cryptography (PQC) roadmap in June 2025 requiring all member states to begin migrating critical infrastructure to quantum-resistant encryption by end of 2026, with completion mandated by 2030. This is the most aggressive government-mandated cryptographic migration timeline in the world.

The threat is 'harvest now, decrypt later': adversaries are already intercepting and storing encrypted communications that current quantum computers cannot break, but future quantum computers could. Financial transactions, diplomatic communications, military orders, and healthcare records encrypted today may be readable within 10-15 years. The migration must happen before quantum computers are powerful enough to break current encryption — not after.

Europe's regulatory-first approach (mandate migration timelines, then support implementation) follows the GDPR playbook. NIST standardized PQC algorithms in 2024; the EU is now forcing adoption timelines. European cryptography companies and research institutions (CWI Amsterdam, INRIA France, universities across Germany) contribute significantly to PQC algorithm development and implementation. The ENISA (EU Agency for Cybersecurity) coordinates the migration across 27 member states.

TRL
7/9Operational
Impact
4/5
Investment
5/5
Category
Software

Book a research session

Bring this signal into a focused decision sprint with analyst-led framing and synthesis.
Research Sessions