Across cybersecurity, digital identity and post-quantum cryptography, a common pattern is beginning to emerge. Europe is moving beyond guidance and towards enforceability, reshaping the relationship between technology, trust and accountability in the process.
For much of the digital era, trust was largely treated as a matter of policy, governance and good practice. Organisations were encouraged to adopt stronger security controls, improve identity verification processes and strengthen their resilience against emerging threats. Regulators published frameworks, standards bodies developed technical guidance and industry groups promoted best practices. Progress was expected to come through voluntary adoption supported by commercial incentives and growing awareness of risk.
That model is beginning to change.
Across multiple areas of technology policy, governments and regulators are introducing mechanisms that move trust beyond aspiration and towards obligation. The result is not a single regulatory initiative but a broader shift in how digital systems are governed, monitored and assessed.
Trust Becomes Operational
Recent developments across Europe illustrate how this transition is unfolding.
In France, the Agence nationale de la sécurité des systèmes d’information (ANSSI) has begun linking security certification to the adoption of Post-Quantum Cryptography (PQC), transforming what was once viewed as a future technology challenge into a present procurement consideration. The significance of the decision lies not only in the cryptography itself but in the use of certification as a mechanism for accelerating change.
The Cyber Resilience Act (CRA) is applying similar principles to software and connected products by embedding security responsibilities throughout the product lifecycle. Organisations are increasingly expected not only to implement security controls but also to demonstrate that risks have been assessed, vulnerabilities managed and obligations fulfilled.
Meanwhile, the European Digital Identity Wallet is progressing beyond pilot programmes and technical frameworks towards operational deployment. The focus is moving away from experimentation and towards the practical realities of integrating digital credentials into everyday business processes and public services.
Viewed independently, these developments appear to address different challenges. Viewed together, they reveal a common direction of travel in which trust is becoming embedded within operational systems rather than remaining a matter of policy intent.
The Rise of Demonstrable Trust
One of the most significant aspects of this transition is the growing importance of evidence.
Historically, organisations often relied on policies, certifications or declarations to demonstrate their commitment to security and compliance. Increasingly, regulators are seeking greater visibility into how trust is maintained throughout the lifecycle of systems, products and services.
Risk assessments, audit trails, software inventories, credential validation mechanisms and incident reporting processes are becoming part of the evidence organisations use to demonstrate accountability. The question is no longer confined to whether a control exists. The question increasingly extends to whether that control can be verified, monitored and, if necessary, audited.
This trend is visible not only within the CRA but also across initiatives such as the Digital Operational Resilience Act (DORA), the Network and Information Security Directive 2 (NIS2) and emerging approaches to artificial intelligence governance. While each framework addresses different risks, they share a common emphasis on demonstrable action rather than declared intention.
Infrastructure Over Intentions
A second characteristic of this shift is the growing recognition that trust cannot depend solely on the behaviour of individual organisations. Instead, trust is increasingly being built into infrastructure, standards, certification schemes and regulatory frameworks that shape how digital systems operate.
The transition to PQC is being accelerated through certification and procurement requirements. Digital identity frameworks are being supported through legislation and governance structures. Cybersecurity obligations are being embedded within product development processes and operational lifecycles.
In each case, trust is becoming part of the environment rather than a discretionary choice.
This reflects a broader understanding that digital economies depend upon shared infrastructure and common expectations. Organisations continue to make individual decisions, but those decisions increasingly take place within frameworks that define what acceptable behaviour looks like and how compliance is measured.
The Next Phase of Digital Transformation
For many years, digital transformation focused on digitising services, automating processes and improving efficiency. Those objectives remain important, but a new layer is emerging beneath them.
As digital systems become more interconnected and more critical to economic and social activity, attention is shifting towards the mechanisms through which trust is established and maintained. Identity, cryptography, cybersecurity and governance are no longer specialist concerns operating at the edge of digital transformation. They are becoming foundational components of how digital systems function.
The result is a gradual but significant change in expectations. Organisations are increasingly required not only to operate securely and responsibly but also to demonstrate that they have done so. Evidence, accountability and enforceability are becoming integral parts of the digital environment.
A Different Kind of Future
The significance of this shift extends beyond compliance.
What is emerging is a model in which trust is increasingly supported by infrastructure, reinforced through policy and validated through evidence. The objective is not simply to encourage responsible behaviour but to create systems in which trust can be established, verified and maintained at scale.
The transition is still underway, and its final shape remains uncertain. What is becoming increasingly clear, however, is that the era in which trust could rely primarily on voluntary adoption is drawing to a close. The next phase of digital transformation will be defined not only by what technology can do, but by how effectively organisations can demonstrate that it operates securely, responsibly and in accordance with the expectations of the societies that depend upon it.
TQS Insight
The defining technology story of the next decade may not be artificial intelligence, digital identity or quantum computing in isolation. It may be the emergence of systems that make trust measurable, verifiable and enforceable across all three.
Related TQS Coverage
- France Draws a Line: No Quantum-Safe Encryption, No Certification
- The CRA Enforcement Clock Starts Ticking
- From Identity Project to Business Infrastructure





Leave a Reply