Quantum-Safe Encryption and EU Regulatory Compliance
How the key regulations treat encryption
EU regulation does not name specific cryptography technologies. What it requires is encryption that is appropriate to the risk and reflects the state of the art. For data that must stay confidential into the 2030s, the “harvest now, decrypt later” threat is what makes quantum-safe encryption the risk-appropriate, state-of-the-art choice today.
| Regulation | Who it covers | What it says on encryption |
|---|---|---|
| GDPR Art. 32 | Any organisation processing personal data of people in the EU | Names encryption explicitly as an example of an appropriate technical measure, on a risk-based standard. Encrypted data that is breached may reduce notification impact, as it stays unintelligible. Penalties up to €20m or 4% of global turnover. |
| NIS2 Dir. 2022/2555 | Essential & important entities, 18 sectors incl. financial infrastructure | Entities must apply appropriate, risk-based cryptography and encryption, taking the state of the art into account. Management bears personal liability for failures. |
| DORA Reg. 2022/2554 | Financial entities and their ICT service providers | Most directly relevant. Sensitive data must be protected at rest and in transit, in secure and insecure environments. Systems used to exchange data with counterparties, regulators and service providers must meet DORA security standards — the quantum-safe networks use case. |
Related instruments — the EU AI Act, the Cyber Resilience Act (CRA) and ISO/IEC 27001 — rely on the same underlying controls: access control, encrypted data handling, logging and audit trails.
The compliance argument for quantum-safe encryption
