Europe Is Watching.
The White House does not typically move faster than Brussels on digital infrastructure policy. But on the question of post-quantum cryptography, the March 2026 US Cyber Strategy has done something the EU’s own roadmap has not yet fully achieved: it has made quantum-resistant encryption a named, non-negotiable pillar of national infrastructure modernisation — not a future consideration, but a present operational requirement sitting alongside zero trust architecture and AI-driven defence.
That shift matters far beyond Washington. For European organisations navigating their own transition, and for the growing number of enterprises operating across both jurisdictions, the policy gap between the US and EU on PQC is no longer theoretical. It is a compliance calendar problem.
What the US Strategy Actually Says
The March 2026 Cyber Strategy places post-quantum cryptography explicitly within the federal modernisation agenda. It does not merely reference it as a risk to monitor. The strategy directs agencies to treat PQC adoption as infrastructure work — budgeted, scheduled, and accountable — in the same category as cloud migration and zero trust implementation. This builds on the Quantum Computing Cybersecurity Preparedness Act and NSM-10, which set the 2035 federal readiness target, but the 2026 strategy elevates the language from compliance exercise to strategic imperative.
The practical consequence is that federal agencies and their contractors now face a layered mandate. The NIST FIPS 203, 204 and 205 standards are in place. The OMB requires annual inventories of quantum-vulnerable systems. CISA has begun formally identifying product categories where PQC-capable alternatives are considered “widely available” — a designation that is already being used to establish the prevailing standard of care in the event of a breach. And from January 2027, all new National Security System acquisitions must meet CNSA 2.0 compliance. The clock is not theoretical. It is contractual.
The European Position
The EU published its coordinated PQC implementation roadmap in June 2025, targeting quantum-resistant critical infrastructure by 2030. ENISA’s guidance reinforces that timeline and connects PQC requirements to the Cyber Resilience Act’s risk assessment framework, meaning that for products sold into the EU market, quantum risk is now a product security consideration, not just an enterprise IT concern.
On the surface, this appears more aggressive than the US civilian timeline. The 2030 deadline for critical infrastructure is stricter than the US federal 2035 target. But the EU roadmap has a structural complication the US mandate currently avoids: implementation is fragmented across member states, and national agencies — BSI in Germany, ANSSI in France, NCSC equivalents elsewhere — have produced their own guidance with meaningful differences. BSI and ANSSI, for example, diverge on hybrid cryptography. BSI permits and recommends it as a transitional measure. ANSSI strongly recommends it for the short and medium term. The US CNSA 2.0, by contrast, discourages hybridisation in favour of direct migration. For a multinational deploying across both jurisdictions, these are not minor technical footnotes. They affect architecture decisions, procurement choices, and vendor qualification.
The Real Gap Is Execution, Not Intent
Both the US and EU now have intent on paper. What neither has solved is the execution problem at organisational level. Most enterprises handling sensitive data have not completed a cryptographic inventory. Many do not know which of their vendors have started one. The systems most at risk — legacy infrastructure with long deployment cycles, embedded OT platforms, HSMs that cannot run the new NIST algorithms at acceptable performance — are also the systems with the longest lead times for replacement.
The cyber insurance market has begun to notice. Underwriters in 2026 are incorporating quantum readiness into renewal questionnaires. This is the quiet mechanism by which policy intent converts into operational pressure for the private sector. When your insurer asks whether you have a PQC migration plan with defined ownership and timelines, the answer “we are monitoring the situation” is no longer acceptable.
What This Means for European Organisations Specifically
The US mandate creates an indirect compliance obligation for European companies in several ways. If you supply to the US federal government or its contractors, you are now inside the procurement requirements. If you hold data on US persons or operate infrastructure with US counterparties, the standard of care question extends across the Atlantic. And if you are seeking to attract US institutional capital or partnerships, quantum readiness is increasingly a due diligence item.
The 2030 EU deadline also contains a practical trap. Cryptographic transitions at enterprise scale typically take three to five years when accounting for inventory, architecture decisions, vendor coordination, testing, and validation. An organisation that begins serious work in 2027 or 2028 is not on track for 2030. It is already late.
The policy signal from Washington in March 2026 was not aimed at European boardrooms. But the message travels. PQC is no longer a future-state discussion. It is a present-tense infrastructure programme, and the organisations that treat it as such will spend the next decade managing a transition rather than a crisis.





Leave a Reply