Quantum readiness compliance

Regulators around the world are already preparing for the quantum readiness era. Understanding your obligations is the first step - QComply handles the rest.

2026

Requirements in scope

5/27

2026 2029 2032 2035

United Kingdom

In scope 0 of 9
2028 Upcoming

Discovery and Planning

  • Define migration goals and scope
  • Complete full cryptographic discovery
  • Assess supplier and infrastructure dependencies
  • Publish an initial migration plan
2031 Upcoming

Priority Migration

  • Complete highest-priority migration activities
  • Protect critical assets first
  • Refine roadmap for full transition
2035 Upcoming

Full Transition Target

  • Complete migration of systems, services, and products to PQC
  • Retire remaining quantum-vulnerable public-key usage in scope

European Union

In scope 1 of 7
End-2026 Due this year

Initial National Steps

  • Launch national transition strategies
  • Start identification, inventory, and awareness actions
  • Coordinate first implementation steps across member states
Expected 2026-27 Upcoming

From Recommendation to Obligation

  • Commission proposal inserts PQC transition into the NIS2 Directive as a named requirement (Article 7(2)(k))
  • Once adopted and transposed, NIS2 entities carry the duty in law rather than by recommendation
End-2030 Upcoming

High-Risk Use Cases

  • Transition high-risk and critical infrastructure use cases
  • Scale prioritized upgrades and pilots
  • Adopt PQC-by-default direction for new high-impact deployments
2035 Upcoming

Broad Completion Horizon

  • Complete transition of remaining systems where feasible
  • Demonstrate sustained crypto-agility and governance

United States

In scope 4 of 8
Aug 2024 Background

Standards Baseline Finalized

  • NIST finalized FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA)
  • PQC implementation and validation ecosystem accelerated
Jun 2026 Due this year

Migration Becomes Binding

  • Executive Order 14412 makes the federal transition a legal obligation rather than an inventory exercise
  • OMB M-26-15 replaces the M-23-02 regime with a five-phase migration timeline running to 2035
  • Every agency designates a post-quantum migration lead and submits a migration plan
Dec 2026 Due this year

Contractor Rulemaking

  • FAR Council to publish a proposed rule requiring covered contractors to meet the FIPS carrying PQC algorithms
  • Suppliers to federal agencies should expect the requirement to reach them by contract
31 Dec 2030 Upcoming

Key Establishment

  • High value assets and high impact systems use post-quantum key establishment
  • Covered federal contractors meet the same standards
31 Dec 2031 Upcoming

Digital Signatures

  • Post-quantum digital signatures in place across the same systems
  • Remaining quantum-vulnerable public-key usage retired on the NIST IR 8547 path to 2035

Switzerland

In scope 0 of 3
2025 Background

Federal Preparation and Sector Planning

  • Federal PKI guidance highlights post-quantum transition preparation
  • Public-sector teams plan key-length, trust-chain, and algorithm updates
  • Financial-sector action planning continues through SIF-led work
2026 Background

FINMA Guidance on Quantum Computing

  • FINMA publishes Guidance 05/2026 following a survey of 60 Swiss financial institutions
  • Only 8% of respondents had a specific roadmap for quantum-safe encryption
  • FINMA finds action is needed on operational risk and resilience requirements
Mid-2027 Upcoming

PQC Roadmap Deadline

  • FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest
  • Strategy adopted by the board of directors, with an implementation plan setting out milestones and priorities
  • Target dates set for complete migration and for migration of critical business processes