How does QCI-QS1 align with standards and regulation?
QCI-QS1 is a voluntary readiness standard. A QCI mapping shows where its requirements can support evidence for an obligation; it does not establish legal compliance or regulator endorsement. Binding obligations come from laws and regulations such as DORA and the national laws implementing NIS2. Agency guidance and recommendations inform decisions but do not bind on their own. Each mapping must be assessed for your organization's scope.
New to this? Read What is QCI-QS1? first. After this, continue with What evidence should an auditor expect for quantum readiness?.
In one sentence: A mapping supports evidence; only the law and your regulator decide compliance.
Why it matters
Treating a mapping as compliance can leave real obligations unmet. Treating guidance as law can misdirect effort. QCI-QS1 requires an applicability register that distinguishes law, regulation, contract, binding policy, organizational policy, recommendations and drafts (QCI-2.2-01).
Three kinds of document
| Kind | Example | Effect |
|---|---|---|
| QCI control mapping | QCI sector supplements S6 (DORA) and S7 (NIS2) | Shows where QCI-QS1 evidence may support an obligation; creates no legal effect |
| Agency guidance or recommendation | Commission Recommendation (EU) 2024/1101; NIST IR 8547 (draft) | Informs planning; not binding by itself |
| Binding obligation | DORA; RTS 2024/1774; national laws implementing NIS2; Public Law 117-260 for US federal agencies | Applies to those in scope, as interpreted by competent authorities |
Alignment matrix (verified rows only)
Each row was checked against the official text on October 5, 2026. Instruments not yet verified against primary text are left out. This is not a complete list of obligations; see the Regulatory Radar for the wider tracker.
| Jurisdiction | Authority | Instrument | Who is in scope | Status | Relevant provision | Date | QCI mapping source | Limits of the mapping |
|---|---|---|---|---|---|---|---|---|
| EU | European Parliament and Council | Regulation (EU) 2022/2554 (DORA) | Financial entities listed in Article 2 | Binding regulation | Article 9 (protection and prevention) | Applies from Jan 17, 2025 | QCI-QS1-S6 v1.2 | Mapping supports evidence only; supervisors decide compliance |
| EU | European Commission | Delegated Regulation (EU) 2024/1774 | Financial entities under DORA Title II | Binding regulation | Article 6(4): update cryptography on the basis of developments in cryptanalysis | Adopted Mar 13, 2024 | QCI-QS1-S6 v1.2 | Does not name post-quantum algorithms or dates |
| EU | European Parliament and Council | Directive (EU) 2022/2555 (NIS2) | Essential and important entities, through national law | Binding on Member States; entities bound by national transposition | Article 21(2)(h): policies on the use of cryptography and encryption | Measures apply from Oct 18, 2024 | QCI-QS1-S7 v1.2 | Check the national law that applies; it may differ |
| EU | European Commission | Recommendation (EU) 2024/1101 | Member States | Non-binding recommendation | Coordinated PQC transition roadmap | Apr 11, 2024 | None (context only) | Places no obligation on organizations |
| US | U.S. Congress | Public Law 117-260 | Federal agencies | Binding statute | Section 4: inventory and migration guidance from OMB | Enacted Dec 21, 2022 | None (context only) | Does not apply to private organizations by itself |
Editorial note
Mappings must be assessed for your organization's scope, sector and jurisdiction. Applicability, effective dates and obligations depend on the instrument and how it applies to you. QCI does not give legal advice, and no regulator has endorsed QCI-QS1.
What organizations should do
- List every obligation that applies to you in an applicability register.
- Label each entry as law, regulation, contract, policy, recommendation or draft.
- Use QCI mappings to find supporting evidence, not to conclude compliance.
- Confirm applicability with legal or compliance owners.
- Review the register at least quarterly.
Evidence an auditor should expect
Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.
| Artifact | Scope | Owner | Currency | Verification | Basis |
|---|---|---|---|---|---|
| Applicability register | All external obligations and adopted profiles | Quantum Risk Owner with legal and engineering | Reviewed at least quarterly | Check issuer, exact title and revision, sections, status and owner per entry | QCI requirement (QCI-2.2-01) |
| Impact decisions on changes | Each material change in an obligation or standard | Quantum Risk Owner | On notification | Check decision, action, owner and due date | QCI requirement (QCI-2.2-02) |
| Legal applicability opinion | Each binding instrument | Legal or compliance | On change | Check jurisdiction and scope | Editorial suggestion |
How NIST or other primary authorities address it
DORA, RTS 2024/1774 and NIS2 are EU legal acts published on EUR-Lex. Public Law 117-260 is a US statute. Commission Recommendation 2024/1101 is not binding. None of them refers to QCI-QS1.
How QCI-QS1 addresses it
QCI-QS1 requires organizations to track obligations and keep them distinct from recommendations and drafts. The sector supplements map QCI-QS1 requirements to specific legal provisions; those mappings are informative.
| Requirement | Clause | Relationship | Pillar | Gate |
|---|---|---|---|---|
| QCI-2.2-01 | 2.2 | explicit requirement | P1 | — |
| QCI-2.2-02 | 2.2 | explicit requirement | P1 | — |
| QCI-1.2-04 | 1.2 | explanatory context | — | — |
Common mistakes
- Saying a QCI-QS1 assessment makes you DORA or NIS2 compliant.
- Treating a recommendation or a draft as a deadline.
- Applying the EU directive text without checking the national law.
- Assuming a US federal statute binds private companies.
Questions for the board
- Which of our quantum obligations are legally binding, and who confirmed that?
Questions
Does conforming to QCI-QS1 mean we comply with DORA?
No. QCI's DORA supplement shows where QCI-QS1 evidence may support DORA obligations. Compliance is decided under DORA by competent authorities.
Does NIS2 require post-quantum cryptography?
Article 21(2)(h) requires policies and procedures on the use of cryptography and, where appropriate, encryption. It does not name post-quantum algorithms. Check the national law that applies to you.
Is the EU PQC roadmap binding?
Commission Recommendation (EU) 2024/1101 is a recommendation addressed to Member States. It does not bind organizations by itself.
Is QCI-QS1 endorsed by any regulator?
No. QCI-QS1 is a voluntary standard published by QCI.
Sources
- Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), European Parliament and Council, Official Journal text; applies from January 17, 2025 (Article 64), Articles 9 and 64. Supports: Binding ICT risk management obligations for financial entities.
- Commission Delegated Regulation (EU) 2024/1774 (ICT risk management RTS), European Commission, Of March 13, 2024, Article 6 (encryption and cryptographic controls), paragraph 4. Supports: Policy must provide for updating cryptographic technology on the basis of developments in cryptanalysis.
- Directive (EU) 2022/2555 (NIS2), European Parliament and Council, Official Journal text; Member States apply measures from October 18, 2024 (Article 41), Article 21(2)(h). Supports: Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
- Commission Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography, European Commission, Of April 11, 2024; a recommendation, not binding. Supports: Encourages Member States to coordinate a PQC transition strategy.
- Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, U.S. Congress, Enacted December 21, 2022, Section 4. Supports: OMB guidance requiring federal agencies to inventory quantum-vulnerable IT and plan migration.
- QCI-QS1-S6 EU Financial Entities (DORA) Supplement, Quantum Core Institute, v1.2, aligned to QCI-QS1 v2.3. Supports: QCI's mapping of QCI-QS1 requirements to DORA and the RTS.
- QCI-QS1-S7 NIS2 Supplement, Quantum Core Institute, v1.2, aligned to QCI-QS1 v2.3. Supports: QCI's mapping of QCI-QS1 requirements to NIS2 Article 21.
- QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 2.2. Supports: Applicability register.
Related learning
Elsewhere
Back to Standards and regulation · All Knowledge Center topics
Page history
- Published
- Not yet recorded
- Standard edition
- QCI-QS1 v2.3 (September 23, 2026)
Cite this page
Quantum Core Institute. (n.d.). How does QCI-QS1 align with standards and regulation?. https://quantumcoreinstitute.com/learn/standards/quantum-regulatory-alignment
Link: https://quantumcoreinstitute.com/learn/standards/quantum-regulatory-alignment