Quantum Security & PQC

Dutch Quantum Strategy Says Prepare for Q-Day Around 2030. Medium-Risk Systems Have Until 2035.

October 5, 2026 – The Dutch cabinet sent parliament a government-wide quantum strategy that sets dated post-quantum cryptography (PQC) migration targets for central-government organizations, aiming to complete the migration of high-risk use cases by the end of 2030 and of medium-risk use cases by the end of 2035. The cabinet expects a quantum computer capable of breaking today’s public-key cryptography between 2029 and 2035. The strategy cites advice from the General Intelligence and Security Service (AIVD) to prepare for one as early as around 2030.

Minister of Economic Affairs and Climate Heleen Herbert and State Secretary for Digital Economy and Sovereignty Willemijn Aerdts sent the 73-page Rijksbrede Quantumstrategie to the House of Representatives on behalf of nine ministries, the government said in a statement. The strategy specifies no new allocation for the migration. Its actions are to be paid for from the ministries’ existing budgets in the first instance. “If sufficient resources are not found, the ambitions will be adjusted,” the strategy states.

The cabinet’s stated aim is for the Netherlands to be “a technological leader in quantum technology, while being strategically autonomous and resilient” by 2035. The strategy follows a February report in which the Netherlands Court of Audit found that 71% of the central-government organizations it surveyed had not begun preparing for the threat quantum computers pose to their encryption.

The strategy is written in Dutch with an English management summary. Quotations from the Dutch text are my AI’s translations.

A PQC Timetable for Central Government

The strategy’s security chapter sets out a migration timetable that the cabinet said follows the European Union’s Coordinated Implementation Roadmap for the transition to PQC, published in June 2025. Central government “strives to” keep to that schedule, the strategy says, and the timetable can be adjusted or accelerated as the risk and threat picture changes. Organizations with a lower risk appetite may migrate faster, and the government’s Quantumveilige Cryptografie NL program (QvC NL) will recalibrate the timetable every year.

Some milestones apply to each central-government organization and others to central government as a whole:

  • End of 2026: quantum risk included in each organization’s risk-management process, and an organization-level cryptography policy in line with the government-wide cryptography policy framework.
  • End of 2027: account taken of the harvest now, decrypt later (HNDL) scenario, with mitigations where needed; a PQC migration plan, at least in draft, with practical trials for high- and medium-risk use cases prepared or under way; measures for mature cryptographic asset management; and the staff and resources needed for migration identified and included in budgets.
  • End of 2028: the ability to set requirements for quantum-safe cryptography in procurement and tenders, and written guidelines and policy to steer essential businesses on PQC migration.
  • End of 2030: migration completed for high-risk use cases; software and firmware using quantum-safe cryptography by default; test facilities in use to assess the impact of migration; and, at European level, standardized use of quantum-safe cryptography and agreement on which cryptographic standards will no longer be used.
  • End of 2035: migration completed for medium-risk use cases, and for low-risk use cases “as far as possible.”

The Ministry of the Interior and Kingdom Relations will coordinate the timetable across government and will explore a PQC expertise hub with the economic affairs ministry. An organization may deviate from the national timetable because of sector regulation or international agreements such as NATO commitments, the strategy says.

The strategy cites the PQC Migration Handbook published by the AIVD, the research organization TNO and Centrum Wiskunde & Informatica (CWI), the national research institute for mathematics and computer science. Citing the handbook, the strategy says migration will take a central-government organization at least eight years, because preconditions must be in place before technical work can begin.

The strategy also ties the migration to the Cyberbeveiligingswet (Cbw), the Dutch law implementing the EU’s NIS2 directive. The Cbw took effect on August 15, 2026 and applies to more than 8,000 organizations. Article 13 of its implementing decree, the Cyberbeveiligingsbesluit, requires essential and important entities to have a written cryptography policy and to apply it demonstrably. Each entity must also name who is responsible for implementing cryptography and for key management. The strategy says organizations can use the Cbw to take steps toward quantum-safe cryptography.

The Strategy’s Q-Day Window

A quantum computer able to break current, mainly asymmetric, cryptography is expected between 2029 and 2035, the cabinet wrote. The strategy calls that moment “Q-day” and says the exact date is not yet certain. The AIVD advises organizations to take measures in case such a computer is available as early as around 2030, and the strategy attributes the same advice to the Dutch Authority for Digital Infrastructure (RDI).

“For the protection of sensitive information, even a small chance of that scenario is reason enough to take appropriate measures,” the strategy states.

Alongside HNDL, the strategy names a forgery risk it calls “harvest now, forge later” (HNFL), in which data intercepted now is forged once the technology allows. Systems with long lifetimes, such as weapons systems, infrastructure and medical equipment, are especially exposed because they cannot be migrated to quantum-safe standards easily or quickly, according to the document.

QKD Kept Out of Government Information Security

The Netherlands currently relies on PQC to protect itself against the quantum computer threat, the strategy states, describing PQC as standardized and usable in existing infrastructure. Central government does not use quantum key distribution (QKD) for information security, in line with a cabinet position on the technology.

The strategy cites a January 2024 position paper in which the French and German cybersecurity agencies ANSSI and BSI, the Netherlands National Communications Security Agency (part of the AIVD) and the Swedish Armed Forces set out objections to QKD. The strategy lists limitations that include the need to use PQC for authentication and the limited possibility of end-to-end security. The position paper itself describes two ways to authenticate QKD’s classical channel: pre-shared symmetric keys or post-quantum signatures. The cabinet does not expect the objections to be resolved in the short or medium term.

The strategy also says QKD “does not yet meet the security requirements that have been set.” Its starting principle as of 2026 is that quantum pilots involving central government take place in separate environments without existing production assets or data. Several government services gained practical experience with measurement-device-independent QKD in the OCINed project under the EU’s EuroQCI program, and a Dutch optical ground station is being built for QKD demonstrations with the European Space Agency’s Eagle-1 mission, according to the strategy.

A Police and Intelligence Use Case for a CRQC

In a use-case box in the security chapter, the cabinet described breaking asymmetric encryption as an opportunity for police, forensic institutes and intelligence and security services, for example in analyzing encrypted communications within criminal networks or between terrorists preparing an attack. More of that traffic now runs through apps with end-to-end encryption, the strategy notes.

The strategy compared targeted decryption “in exceptional situations” to the breaking of the Enigma cipher machine in the Second World War and to the dismantling of the EncroChat criminal communications network by French and Dutch police.

“The impact of deciphering encrypted criminal communication is linked to the speed of the migration to PQC,” the strategy reads, adding that PQC “cannot be cracked by a quantum computer.” Police, forensic institutes and intelligence services therefore need “relatively fast access to a quantum computer,” it says, so that “an optimal return can be achieved on the investments required for a cryptographically relevant quantum computer.”

Funding From Existing Budgets

The actions in the strategy are either already under way or will be fitted within the existing resources of the ministries involved, according to its final chapter. Some of them are explorations that may show a need for additional funding later. Any budgetary consequences will be absorbed in existing departmental budgets first, and the ambitions will be adjusted if sufficient resources cannot be found.

In its February report, the Court of Audit wrote that the concrete content and budget of the then-forthcoming strategy were unknown.

The euro amounts the strategy does contain relate to research and investment instruments. They include an expansion of the Deep Tech Fund, run by the economic affairs ministry and the state investment company Invest-NL, to €610 million; €3.3 billion for a new National Investment Institution confirmed in the 2027 budget; and a €4.5 million research call on security and resilience in a quantum age that the research council NWO opened with the Ministry of Defence in July 2026. The government’s statement said €614.9 million had been made available to the National Growth Fund program Quantum Delta NL in recent years.

Economic and International Measures

The cabinet will explore acting as a launching customer for quantum technology, for example by buying a quantum computer for research, in line with the coalition agreement’s ambition to build a quantum computer in the Netherlands. Three challenge-based calls built on government use cases will be set up through the Innovation Impact Challenge instrument of the Netherlands Enterprise Agency. The government’s statement links the launching-customer role to a new National Agency for Disruptive Innovation, which the strategy says is being set up. The strategy notes that none of the world’s twelve quantum unicorns is based in the Netherlands.

The Netherlands chairs NATO’s Transatlantic Quantum Community from May 2026 to May 2027, and the foreign and economic affairs ministries will host at least two minilateral quantum meetings across 2027 and 2028. The cabinet will report to parliament on the strategy’s progress every year from 2027.

My Analysis

The Netherlands has given its central government a PQC timetable that ends on the EU’s dates and told each organization to find the money in its own budget. I think the structure of the timetable and the QKD position are right. The funding clause and the police use case are the weak parts. The police case also compares targeted decryption with the EncroChat takedown, which did not involve a cryptanalytic break.

The EU Roadmap, Applied at Home by One of Its Authors

In November 2024, France, Germany and the Netherlands invited the other EU member states to join a PQC work stream in the EU’s NIS Cooperation Group, which the three countries co-chaired while it drafted the June 2025 roadmap. The Dutch timetable keeps that roadmap’s three dates, end-2026, end-2030 and end-2035, and adds national checkpoints at the end of 2027 and the end of 2028. For how the Dutch dates compare with other countries’ deadlines, see the Global PQC Migration Clock.

The completion dates match the EU’s, but the first planning step does not. The EU roadmap expects planning and pilots for high- and medium-risk use cases to have started by the end of 2026. The Dutch timetable sets no planning or pilot requirement for 2026, and its end-2026 milestone covers only risk management and cryptography policy. Its first planning requirement, a migration plan at least in draft plus trials for high- and medium-risk use cases, is due at the end of 2027. The EU milestone is addressed to member states and the Dutch one to individual organizations, so the two do not compare one to one. But the Dutch timetable does not require central-government organizations to have planning under way by the EU’s end-2026 date.

The end-2027 checkpoint requires the most. By then each organization needs a migration plan at least in draft, trials for its high- and medium-risk use cases, measures for mature cryptographic asset management, and a budgeted estimate of the staff and money its migration requires.

These are policy targets rather than statutory deadlines. The cabinet wrote that central government “strives to” keep to them, and QvC NL reviews them every year. The strategy allows the timetable to be adjusted or accelerated as the threat changes, and sector rules or NATO agreements can justify a different pace for a given organization. Those are sensible provisions for a nine-year schedule, and under them the government can revise the dates in either direction.

Three Years Between the Planning Checkpoint and the High-Risk Target

By the strategy’s own sources, the 2030 target is tight. Citing the PQC Migration Handbook, the strategy says a central-government migration will take at least eight years. The Court of Audit found in February that 71% of the central-government organizations it surveyed had not started. The new timetable asks for measures toward mature cryptographic asset management by the end of 2027 and completed migration of high-risk use cases by the end of 2030.

An organization that reaches the planning checkpoint only at the end of 2027 will have three years left before the high-risk target. The strategy contains no instruction to wait that long, and some trials may already be under way. An eight-year estimate for a whole migration also does not rule out finishing a smaller high-risk wave first. Whether three years is enough depends on product availability, replacement cycles, testing and vendor dependencies. It also depends on a cryptographic inventory good enough to find where vulnerable algorithms run, including inside products the organization cannot inspect. Discovery and the mitigation of known urgent exposures can run in parallel, but an organization cannot migrate a system it has not found.

The cabinet expects a CRQC between 2029 and 2035 and tells organizations to prepare for one around 2030. Medium-risk use cases have until the end of 2035. Data that an organization classifies as medium risk can therefore travel under quantum-vulnerable key exchange for several years inside the window the strategy itself names. The 2035 date is a target for finishing migration, and it offers no safety to anything labeled medium risk in the meantime. Organizations will need to revisit their classifications as the threat changes and, where necessary, bring forward protection for secrets that must stay confidential for many years. The end-2027 HNDL checkpoint works the same way: ciphertext captured before an organization mitigates stays exposed whatever it migrates later. The strategy does not define the risk classes itself, and the EU roadmap’s criteria include how long data must stay confidential.

The Q-Day Window and the AIVD’s Probability Estimates

For its 2029–2035 window, the strategy cites the EU roadmap and an Ars Technica report on two resource-estimate papers released on March 30, 2026. The Google-led paper, published in PRX Quantum in August, estimates that Shor’s algorithm against 256-bit elliptic-curve cryptography could run with at most 1,200 logical qubits. Under the paper’s assumptions of a superconducting architecture with planar connectivity and a physical error rate of 10⁻³, it would finish in minutes on fewer than half a million physical qubits. That is roughly a tenfold reduction in spacetime volume against the best earlier published estimate, as I wrote at the time. Organizations have more reason to prepare early when the estimated machine is smaller. A resource estimate does not include a date for when such a machine will be built.

The strategy writes that a CRQC “is expected” between 2029 and 2035. The AIVD brochure it cites for the 2030 planning advice reports expert estimates of a 5–14% chance that a CRQC exists in 2029, rising to 19–34% for 2034, and concludes that for sensitive information a small chance is reason enough to act. Those probabilities justify preparing for an early arrival. They do not make 2029–2035 the expected window, and the strategy does not explain how it turned one into the other.

The cabinet does not need the window to justify its timetable. It wrote that even a small chance of a CRQC is reason enough to protect sensitive information, which is the AIVD’s own argument, and I agree with it. Once a government sets migration deadlines, its organizations plan against them, and a Q-Day forecast that is off by a few years does not change what they have to deliver in 2027.

No Budget Line for the Migration

In February the Court of Audit wrote that the strategy’s budget was unknown. The strategy’s final chapter specifies no dedicated new allocation for the migration: departments are to absorb the work within existing budgets in the first instance, and later explorations may show a need for additional funding. None of the euro amounts in the document is assigned to PQC migration, and the security chapter has no euro figure at all. The strategy gives no estimate of what the migration will cost.

Under the end-2027 checkpoint, each organization has to work out the staff and money it needs for its migration and include them in its budget. Each ministry and agency therefore decides what its migration gets, against its other priorities. The funding clause, under which “the ambitions will be adjusted” if the money is not found, covers the whole strategy and does not exempt the migration timetable. The central support named in the security chapter is coordination by the Interior ministry, the existing QvC NL program, and an expertise hub that has yet to be explored.

PQC migration costs money long before any algorithm changes. Inventory, dependency mapping, vendor engagement and testing all take staff time, and a single large migration program can run to more than 120,000 tasks. Boards fund obligations, not threats, and ministries work the same way. The strategy gives each organization dated targets and, in the same document, says the ambitions will be adjusted if the money is not found. A target with that clause attached is easier to defer than an obligation.

Police and Intelligence Access to a CRQC

The use-case box is candid, and it gives parliament an explicit use case to debate. It is not a procurement program: it names no provider, budget, date, access arrangement or new legal power.

The EncroChat comparison does not fit. The strategy sets “the targeted breaking of such encryption” next to the dismantling of EncroChat, but that operation relied on an implant, not on a cryptanalytic break of the messaging algorithms. In 2020 the French Gendarmerie uploaded the implant to EncroChat handsets as a software update, and it extracted communications from the compromised devices. PQC does not protect plaintext on a compromised endpoint, so that kind of access bypasses the cryptography whichever algorithms are in use, although each exploit depends on the target product.

Signal added post-quantum key agreement in 2023 with PQXDH, which combines classical and post-quantum key establishment, and added a post-quantum ratchet in 2025 with SPQR. Apple moved iMessage to its hybrid PQ3 protocol in 2024. For conversations between updated clients, breaking the classical component alone does not recover the session keys while the post-quantum algorithms stay unbroken. PQC is designed to resist known quantum attacks, a weaker guarantee than the strategy’s “cannot be cracked by a quantum computer.” Potential targets for a police CRQC would include archived traffic from before those upgrades and services that remain quantum-vulnerable. Decrypting stored ciphertext once a CRQC exists is the same technique as the HNDL attack that the cabinet asks central-government organizations to defend against.

The strategy does not say how police would get access to a CRQC: through domestic procurement, shared infrastructure, a commercial provider or an international partnership. The only quantum computer purchase it mentions is one for research, which the cabinet will explore. A CRQC would not distinguish criminal targets from government ones. Any Dutch system still using a vulnerable public-key scheme would be exposed to whoever holds such a machine and has captured the relevant traffic, and under the timetable, Dutch medium-risk systems have until 2035. The strategy does not say how the government would weigh the police interest in targets that have not migrated against its defensive interest in finishing the migration, or what oversight would apply.

QKD Stays in Research and Pilots

I agree with the QKD section. The cabinet keeps QKD out of government information security for now, and I find its reasons persuasive for critical systems today. It keeps taking part in QKD work through EuroQCI, the OCINed project and the Eagle-1 ground station, and the joint position paper concludes that research on QKD “should be continued.” QKD will always need an authenticated classical channel, and over long distances its reliance on trusted nodes rules out end-to-end security for now. A country that stops investing would lose the expertise and industrial base it would need if those limits are overcome, or if a post-quantum algorithm fails and a second line of defense is needed. The Dutch government keeps that option through its QKD work, and its starting principle is that pilots involving central government take place in separate environments without production assets or data.

What Vendors and NIS2 Entities Should Expect

By the end of 2028, central-government organizations are due to be able to set quantum-safe requirements in purchasing and tenders, and the end-2030 target is for software and firmware to use quantum-safe cryptography by default. The actual conditions will depend on each procurement. Suppliers to Dutch central government should be ready before the end of 2028 to show a dated migration roadmap, supported configurations and upgrade commitments.

The firmware target also bears on forgery, which the strategy calls “harvest now, forge later” and which I have written about as Trust Now, Forge Later. To forge a signature, an attacker with a CRQC needs no intercepted ciphertext, only the public verification key and a verifier that still accepts the vulnerable algorithm. A forged update signature could let malicious code pass signature checks on devices that trust the key, subject to their other update controls. Weapons systems, infrastructure and medical equipment, the strategy’s own examples of systems with long lifetimes, are among the hardest to update after deployment.

Essential and important entities under the Cbw already have a legal duty, under Article 13 of the Cyberbeveiligingsbesluit, to maintain a written cryptography policy, and central-government organizations are due to write PQC guidelines for essential businesses by the end of 2028. The strategy sets no PQC dates for businesses, and its milestones for central government do not apply to them as compliance deadlines. The EU roadmap does set the end of 2030 for high-risk use cases, including in critical infrastructure, as I discussed in my analysis of NIS2, DORA and the EU roadmap. Cbw entities can fold quantum risk into the risk management they already owe and track the 2028 guidance as it appears.

The End-2026 Checkpoint and the First Progress Report

The first checkpoint was less than three months away when the strategy was published. By the end of 2026, central-government organizations are due to have quantum risk in their risk-management processes and their own cryptography policies, and in February the Court of Audit found that most of those it surveyed had not started preparing. The cabinet will report progress to parliament every year from 2027. I will look in the first report for the number of organizations that met the end-2026 checkpoint. Once the end-2027 staff and budget estimates are due, parliament should also see a consolidated cost and funding picture for the 2030 target, and without one it cannot judge whether the timetable has the resources it needs.

From the author

Marin Ivezic

I am the Founder of Applied Quantum (AppliedQuantum.com), a research-driven consulting firm empowering organizations to seize quantum opportunities and proactively defend against quantum threats. A former quantum entrepreneur, I’ve previously served as a Fortune Global 500 CISO, CTO, Big 4 partner, and leader at Accenture and IBM. Throughout my career, I’ve specialized in managing emerging tech risks, building and leading innovation labs focused on quantum security, AI security, and cyber-kinetic risks for global corporations, governments, and defense agencies. I regularly share insights on quantum technologies and emerging-tech cybersecurity at PostQuantum.com. I also founded and teach at Quantum Academy (QuantumAcademy.com) which trains and certifies professionals in post-quantum cryptography, quantum computing, networking and sensing.