Quantum-Safe Encryption and EU Regulatory Compliance

How the key regulations treat encryption

EU regulation does not name specific cryptography technologies. What it requires is encryption that is appropriate to the risk and reflects the state of the art. For data that must stay confidential into the 2030s, the “harvest now, decrypt later” threat is what makes quantum-safe encryption the risk-appropriate, state-of-the-art choice today.
 

RegulationWho it coversWhat it says on encryption
GDPR Art. 32Any organisation processing personal data of people in the EUNames encryption explicitly as an example of an appropriate technical measure, on a risk-based standard. Encrypted data that is breached may reduce notification impact, as it stays unintelligible. Penalties up to €20m or 4% of global turnover.
NIS2 Dir. 2022/2555Essential & important entities, 18 sectors incl. financial infrastructureEntities must apply appropriate, risk-based cryptography and encryption, taking the state of the art into account. Management bears personal liability for failures.
DORA Reg. 2022/2554Financial entities and their ICT service providersMost directly relevant. Sensitive data must be protected at rest and in transit, in secure and insecure environments. Systems used to exchange data with counterparties, regulators and service providers must meet DORA security standards — the quantum-safe networks use case.
Related instruments — the EU AI Act, the Cyber Resilience Act (CRA) and ISO/IEC 27001 — rely on the same underlying controls: access control, encrypted data handling, logging and audit trails.

The compliance argument for quantum-safe encryption

shield purple

The law requires encryption “appropriate to the risk.”

The relevant risk for financial data is its confidentiality lifetime — often 7 to 15+ years.

gear blue

The threat horizon is inside that lifetime.

The German BSI works on the hypothesis that a cryptographically relevant quantum computer arrives in the early 2030s, and sets PQC migration deadlines of 2030 for critical infrastructure and 2032 for all other organisations. This aligns with the EU's coordinated roadmap, which targets critical-infrastructure migration by 2030.

network orange

Harvest today. Decrypt tomorrow.

Data encrypted with today’s classical methods can be intercepted and stored now, then decrypted and misused in the future. For information requiring long-term confidentiality, relying solely on classical encryption is becoming increasingly difficult to justify as a risk-appropriate security strategy.

hook pink

Quantum-safe encryption is the state-of-the-art response.

A hybrid approach — combining QKD and PQC keys through a standardised key derivation function — keeps the link secure even if one method is later broken (defence in depth).

Quantum Optics Jena GmbH

Don’t be shy – give it a try