Quantum readiness compliance
Regulators around the world are already preparing for the quantum readiness era. Understanding your obligations is the first step - QComply handles the rest.
Requirements in scope
5/27
2026 2027 2028 2029 2030 2031 2032 2033 2034 2035
United Kingdom
In scope 0 of 9
2028 Upcoming
Discovery and Planning
- Define migration goals and scope
- Complete full cryptographic discovery
- Assess supplier and infrastructure dependencies
- Publish an initial migration plan
2031 Upcoming
Priority Migration
- Complete highest-priority migration activities
- Protect critical assets first
- Refine roadmap for full transition
2035 Upcoming
Full Transition Target
- Complete migration of systems, services, and products to PQC
- Retire remaining quantum-vulnerable public-key usage in scope
European Union
In scope 1 of 7
End-2026 Due this year
Initial National Steps
- Launch national transition strategies
- Start identification, inventory, and awareness actions
- Coordinate first implementation steps across member states
Expected 2026-27 Upcoming
From Recommendation to Obligation
- Commission proposal inserts PQC transition into the NIS2 Directive as a named requirement (Article 7(2)(k))
- Once adopted and transposed, NIS2 entities carry the duty in law rather than by recommendation
End-2030 Upcoming
High-Risk Use Cases
- Transition high-risk and critical infrastructure use cases
- Scale prioritized upgrades and pilots
- Adopt PQC-by-default direction for new high-impact deployments
2035 Upcoming
Broad Completion Horizon
- Complete transition of remaining systems where feasible
- Demonstrate sustained crypto-agility and governance
United States
In scope 4 of 8
Aug 2024 Background
Standards Baseline Finalized
- NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA)
- PQC implementation and validation ecosystem accelerated
Jun 2026 Due this year
Migration Becomes Binding
- Executive Order 14412 makes the federal transition a legal obligation rather than an inventory exercise
- OMB M-26-15 replaces the M-23-02 regime with a five-phase migration timeline running to 2035
- Every agency designates a post-quantum migration lead and submits a migration plan
Dec 2026 Due this year
Contractor Rulemaking
- FAR Council to publish a proposed rule requiring covered contractors to meet the FIPS carrying PQC algorithms
- Suppliers to federal agencies should expect the requirement to reach them by contract
31 Dec 2030 Upcoming
Key Establishment
- High value assets and high impact systems use post-quantum key establishment
- Covered federal contractors meet the same standards
31 Dec 2031 Upcoming
Digital Signatures
- Post-quantum digital signatures in place across the same systems
- Remaining quantum-vulnerable public-key usage retired on the NIST IR 8547 path to 2035
Switzerland
In scope 0 of 3
2025 Background
Federal Preparation and Sector Planning
- Federal PKI guidance highlights post-quantum transition preparation
- Public-sector teams plan key-length, trust-chain, and algorithm updates
- Financial-sector action planning continues through SIF-led work
2026 Background
FINMA Guidance on Quantum Computing
- FINMA publishes Guidance 05/2026 following a survey of 60 Swiss financial institutions
- Only 8% of respondents had a specific roadmap for quantum-safe encryption
- FINMA finds action is needed on operational risk and resilience requirements
Mid-2027 Upcoming
PQC Roadmap Deadline
- FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest
- Strategy adopted by the board of directors, with an implementation plan setting out milestones and priorities
- Target dates set for complete migration and for migration of critical business processes