Decision

    How does QCI-QS1 align with standards and regulation?

    QCI-QS1 is a voluntary readiness standard. A QCI mapping shows where its requirements can support evidence for an obligation; it does not establish legal compliance or regulator endorsement. Binding obligations come from laws and regulations such as DORA and the national laws implementing NIS2. Agency guidance and recommendations inform decisions but do not bind on their own. Each mapping must be assessed for your organization's scope.

    New to this? Read What is QCI-QS1? first. After this, continue with What evidence should an auditor expect for quantum readiness?.

    In one sentence: A mapping supports evidence; only the law and your regulator decide compliance.

    Why it matters

    Treating a mapping as compliance can leave real obligations unmet. Treating guidance as law can misdirect effort. QCI-QS1 requires an applicability register that distinguishes law, regulation, contract, binding policy, organizational policy, recommendations and drafts (QCI-2.2-01).

    Three kinds of document

    Mapping, guidance and binding obligation
    KindExampleEffect
    QCI control mappingQCI sector supplements S6 (DORA) and S7 (NIS2)Shows where QCI-QS1 evidence may support an obligation; creates no legal effect
    Agency guidance or recommendationCommission Recommendation (EU) 2024/1101; NIST IR 8547 (draft)Informs planning; not binding by itself
    Binding obligationDORA; RTS 2024/1774; national laws implementing NIS2; Public Law 117-260 for US federal agenciesApplies to those in scope, as interpreted by competent authorities

    Alignment matrix (verified rows only)

    Each row was checked against the official text on October 5, 2026. Instruments not yet verified against primary text are left out. This is not a complete list of obligations; see the Regulatory Radar for the wider tracker.

    Instruments relevant to quantum readiness and QCI mapping limits
    JurisdictionAuthorityInstrumentWho is in scopeStatusRelevant provisionDateQCI mapping sourceLimits of the mapping
    EUEuropean Parliament and CouncilRegulation (EU) 2022/2554 (DORA)Financial entities listed in Article 2Binding regulationArticle 9 (protection and prevention)Applies from Jan 17, 2025QCI-QS1-S6 v1.2Mapping supports evidence only; supervisors decide compliance
    EUEuropean CommissionDelegated Regulation (EU) 2024/1774Financial entities under DORA Title IIBinding regulationArticle 6(4): update cryptography on the basis of developments in cryptanalysisAdopted Mar 13, 2024QCI-QS1-S6 v1.2Does not name post-quantum algorithms or dates
    EUEuropean Parliament and CouncilDirective (EU) 2022/2555 (NIS2)Essential and important entities, through national lawBinding on Member States; entities bound by national transpositionArticle 21(2)(h): policies on the use of cryptography and encryptionMeasures apply from Oct 18, 2024QCI-QS1-S7 v1.2Check the national law that applies; it may differ
    EUEuropean CommissionRecommendation (EU) 2024/1101Member StatesNon-binding recommendationCoordinated PQC transition roadmapApr 11, 2024None (context only)Places no obligation on organizations
    USU.S. CongressPublic Law 117-260Federal agenciesBinding statuteSection 4: inventory and migration guidance from OMBEnacted Dec 21, 2022None (context only)Does not apply to private organizations by itself

    Editorial note

    Mappings must be assessed for your organization's scope, sector and jurisdiction. Applicability, effective dates and obligations depend on the instrument and how it applies to you. QCI does not give legal advice, and no regulator has endorsed QCI-QS1.

    What organizations should do

    1. List every obligation that applies to you in an applicability register.
    2. Label each entry as law, regulation, contract, policy, recommendation or draft.
    3. Use QCI mappings to find supporting evidence, not to conclude compliance.
    4. Confirm applicability with legal or compliance owners.
    5. Review the register at least quarterly.

    Evidence an auditor should expect

    Rows marked "QCI requirement" come from the standard. Rows marked "Editorial suggestion" are QCI's practical advice and are not requirements.

    Expected evidence
    ArtifactScopeOwnerCurrencyVerificationBasis
    Applicability registerAll external obligations and adopted profilesQuantum Risk Owner with legal and engineeringReviewed at least quarterlyCheck issuer, exact title and revision, sections, status and owner per entryQCI requirement (QCI-2.2-01)
    Impact decisions on changesEach material change in an obligation or standardQuantum Risk OwnerOn notificationCheck decision, action, owner and due dateQCI requirement (QCI-2.2-02)
    Legal applicability opinionEach binding instrumentLegal or complianceOn changeCheck jurisdiction and scopeEditorial suggestion

    How NIST or other primary authorities address it

    DORA, RTS 2024/1774 and NIS2 are EU legal acts published on EUR-Lex. Public Law 117-260 is a US statute. Commission Recommendation 2024/1101 is not binding. None of them refers to QCI-QS1.

    How QCI-QS1 addresses it

    QCI-QS1 requires organizations to track obligations and keep them distinct from recommendations and drafts. The sector supplements map QCI-QS1 requirements to specific legal provisions; those mappings are informative.

    QCI-QS1 v2.3 mappings
    RequirementClauseRelationshipPillarGate
    QCI-2.2-012.2explicit requirementP1—
    QCI-2.2-022.2explicit requirementP1—
    QCI-1.2-041.2explanatory context——

    Common mistakes

    • Saying a QCI-QS1 assessment makes you DORA or NIS2 compliant.
    • Treating a recommendation or a draft as a deadline.
    • Applying the EU directive text without checking the national law.
    • Assuming a US federal statute binds private companies.

    Questions for the board

    • Which of our quantum obligations are legally binding, and who confirmed that?

    Questions

    Does conforming to QCI-QS1 mean we comply with DORA?

    No. QCI's DORA supplement shows where QCI-QS1 evidence may support DORA obligations. Compliance is decided under DORA by competent authorities.

    Does NIS2 require post-quantum cryptography?

    Article 21(2)(h) requires policies and procedures on the use of cryptography and, where appropriate, encryption. It does not name post-quantum algorithms. Check the national law that applies to you.

    Is the EU PQC roadmap binding?

    Commission Recommendation (EU) 2024/1101 is a recommendation addressed to Member States. It does not bind organizations by itself.

    Is QCI-QS1 endorsed by any regulator?

    No. QCI-QS1 is a voluntary standard published by QCI.

    Sources

    1. Regulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), European Parliament and Council, Official Journal text; applies from January 17, 2025 (Article 64), Articles 9 and 64. Supports: Binding ICT risk management obligations for financial entities.
    2. Commission Delegated Regulation (EU) 2024/1774 (ICT risk management RTS), European Commission, Of March 13, 2024, Article 6 (encryption and cryptographic controls), paragraph 4. Supports: Policy must provide for updating cryptographic technology on the basis of developments in cryptanalysis.
    3. Directive (EU) 2022/2555 (NIS2), European Parliament and Council, Official Journal text; Member States apply measures from October 18, 2024 (Article 41), Article 21(2)(h). Supports: Policies and procedures regarding the use of cryptography and, where appropriate, encryption.
    4. Commission Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography, European Commission, Of April 11, 2024; a recommendation, not binding. Supports: Encourages Member States to coordinate a PQC transition strategy.
    5. Quantum Computing Cybersecurity Preparedness Act, Public Law 117-260, U.S. Congress, Enacted December 21, 2022, Section 4. Supports: OMB guidance requiring federal agencies to inventory quantum-vulnerable IT and plan migration.
    6. QCI-QS1-S6 EU Financial Entities (DORA) Supplement, Quantum Core Institute, v1.2, aligned to QCI-QS1 v2.3. Supports: QCI's mapping of QCI-QS1 requirements to DORA and the RTS.
    7. QCI-QS1-S7 NIS2 Supplement, Quantum Core Institute, v1.2, aligned to QCI-QS1 v2.3. Supports: QCI's mapping of QCI-QS1 requirements to NIS2 Article 21.
    8. QCI-QS1 Quantum Readiness and Post-Quantum Cryptography Governance Standard, Quantum Core Institute, Version 2.3, September 23, 2026, Clause 2.2. Supports: Applicability register.

    Back to Standards and regulation · All Knowledge Center topics

    Page history

    Published
    Not yet recorded
    Standard edition
    QCI-QS1 v2.3 (September 23, 2026)

    Cite this page

    Quantum Core Institute. (n.d.). How does QCI-QS1 align with standards and regulation?. https://quantumcoreinstitute.com/learn/standards/quantum-regulatory-alignment

    Link: https://quantumcoreinstitute.com/learn/standards/quantum-regulatory-alignment