Policy & Sovereignty

Eighteen EU Member States Call for Post-Quantum Migration by 2030

November 27, 2024 — Eighteen European Union member states released a joint statement on post-quantum cryptography, “Securing Tomorrow, Today,” urging public administration, critical infrastructure providers and industry to start the transition now and to protect the most sensitive use cases by the end of 2030 at the latest. France, Germany and the Netherlands initiated the statement and presented it at the European Cyber Security Meeting in Athens in September; BSI announced it in a press release on November 27.

The signatories are cybersecurity authorities from 18 EU member states, among them Czechia’s NÚKIB alongside the French, German and Dutch agencies.

The statement identifies two primary quantum threats requiring immediate attention. First, adversaries may already be collecting encrypted data today for future decryption once quantum computers become available—a scenario known as “store now, decrypt later.” Second, complex systems like public key infrastructures face lengthy migration periods that could extend beyond the arrival of quantum computers capable of breaking current encryption.

The statement grounds its urgency in the Global Risk Institute’s 2023 Quantum Threat Timeline expert survey.

The statement recommends that the most sensitive use cases be protected against these attacks as soon as possible, and by the end of 2030 at the latest.

The agencies recommend deploying post-quantum cryptography in hybrid configurations, combining traditional encryption with quantum-resistant algorithms. This approach ensures security even if one component fails.

Through the statement, France, Germany and the Netherlands invite all EU member states to join the post-quantum cryptography work stream within the NIS Cooperation Group, which the three countries lead and which is tasked with coordinating the transition across member states.

My Analysis

I’ve been tracking European PQC policy development for years, and this statement represents a watershed moment. For the first time, we have eighteen EU member states speaking with one voice about quantum threats. More importantly, they’re putting a hard deadline on the table: 2030.

Let me decode what’s actually happening here. Germany, France, and the Netherlands aren’t just random participants—they’re the technological and economic engines of the EU. When BSI, ANSSI, and the Dutch NLNCSA decide to co-chair a working group, Brussels pays attention. These agencies have the technical expertise and political influence to drive real policy changes.

The 2030 deadline deserves scrutiny. At first glance, it seems aggressive. But consider the math: we’re already closing in on 2025. That gives organizations roughly five years to inventory their cryptographic assets, develop migration plans, test hybrid implementations, and complete transitions. For a large enterprise or government agency, five years is barely adequate. For critical infrastructure operators running decades-old systems? It’s downright ambitious.

What struck me most was the statement’s emphasis on “store now, decrypt later” attacks. This isn’t theoretical anymore. Intelligence agencies and sophisticated threat actors are almost certainly harvesting encrypted data today, betting they can crack it within the next decade. If you’re transmitting data that needs to remain confidential for 10-15 years—medical records, trade secrets, diplomatic cables—you’re already vulnerable.

The expert survey they cite points the same way as my own analysis of quantum computing timelines: the probability of a CRQC within ten years is too high to ignore. These aren’t quantum computing cheerleaders or vendor representatives—they’re cryptographers and security researchers with reputations on the line.

I’m particularly encouraged by their hybrid approach recommendation. Too many organizations want to flip a switch and declare themselves “quantum-safe” overnight. That’s a recipe for disaster. Hybrid implementations let you maintain current security levels while gradually building confidence in new algorithms. It’s pragmatic engineering, not security theater.

The creation of a dedicated PQC Work Stream under the NIS Cooperation Group signals serious intent. The NIS Directive already mandates cybersecurity standards for essential services across the EU. By embedding PQC requirements into this existing framework, they’re leveraging established compliance mechanisms rather than creating new bureaucracy. Smart move.

However, I see three potential friction points ahead. First, the statement carefully avoids mandating specific algorithms or standards beyond referencing NIST. European sovereignty concerns might eventually push for EU-developed alternatives, creating fragmentation. Second, smaller member states without robust cryptographic expertise may struggle to implement these recommendations effectively. Third, the private sector—particularly SMEs—will need significant support to meet these timelines.

Reading between the lines, this statement also serves as a message to the European Commission. By presenting a united front, these eighteen nations are essentially saying: “We’re ready to move. Give us the regulatory framework and funding to make it happen.” Expect to see this translate into concrete regulatory requirements within the next 12-18 months.

For security leaders, the message is unambiguous. Stop waiting for perfect clarity on quantum timelines. Start your cryptographic inventory yesterday. Build your migration roadmap now. Test hybrid implementations in 2025. Because when eighteen EU nations collectively say “latest by the end of 2030,” that deadline has a way of becoming mandatory regulation faster than you might expect.

The statement’s underlying message is that uncertainty about quantum progress is no reason to wait. I couldn’t agree more. The quantum threat might arrive in 2035 or 2045, but migration projects starting in 2030 won’t finish until 2035 at the earliest. Do the math.

This joint statement marks the end of the “wait and see” phase of European PQC policy. We’re now firmly in the “plan and execute” phase. Organizations that haven’t started their quantum risk assessments are already behind the curve. Those waiting for regulatory mandates before acting just got their clearest signal yet: the mandates are coming, and 2030 is your deadline.

From the author

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com. I also founded and teach at Quantum Academy (QuantumAcademy.com) which trains and certifies professionals in post-quantum cryptography, quantum computing, networking and sensing.