Think Earlier.
The quantum problem starts before the quantum computer arrives.
Quantum Compliance: Requirements, Frameworks & Deadlines
Quantum compliance means proving your cryptography meets current and emerging regulatory expectations as NIST post-quantum standards take effect. This page maps which frameworks require quantum readiness, what evidence auditors expect, and the deadlines that matter.
What Is Quantum Compliance?
Quantum compliance is the set of regulatory obligations that follow from quantum computing's ability to break widely used public-key cryptography (RSA, ECC, Diffie-Hellman). No major framework yet says "use post-quantum cryptography" verbatim, but the obligations already exist in the language regulators use today: encryption must be "appropriate," "state of the art," and effective against "current and emerging threats."
Three developments turned this from theory into audit scope. First, NIST finalized its post-quantum cryptography standards (FIPS 203, 204, and 205) in August 2024, creating an approved migration target. Second, NIST IR 8547 deprecates classical algorithms from 2030 and disallows them by 2035, giving auditors concrete dates to test against. Third, harvest-now-decrypt-later attacks mean data encrypted today with long confidentiality lifetimes is already exposed, which puts quantum readiness inside existing breach, retention, and risk-assessment duties.
In practice, auditors now expect three artifacts: a cryptographic inventory covering applications, vendors, and certificates; a documented PQC migration plan with owners and dates; and governance evidence that quantum risk is assessed and reported at board level. The QCI-QS1 standard defines how to produce that evidence, and the Q-Risk Score measures your posture across the five dimensions regulators probe.
12 Frameworks, One Quantum Reality
Each compliance framework has unique quantum exposure. Here's how quantum threats impact your regulatory posture.
SOC 2
Trust Services Criteria for service organizations covering security, availability, processing integrity, confidentiality, and privacy.
Quantum Impact
SOC 2 Trust Services Criteria require encryption controls that quantum computers will render obsolete. Organizations must demonstrate quantum-aware encryption governance to maintain attestation.
Key Risk Areas
- Encryption controls failing quantum-resistant standards
- Key management practices lacking PQC readiness
- Auditors increasingly requesting quantum preparedness evidence
ISO 27001
International standard for information security management systems (ISMS) with Annex A controls.
Quantum Impact
ISO 27001 Annex A cryptographic controls (A.10) require organizations to maintain effective encryption. Quantum threats necessitate updating cryptographic policies and risk assessments within the ISMS framework.
Key Risk Areas
- Annex A.10 cryptographic controls becoming insufficient
- Risk assessment methodology not accounting for quantum threats
- Certification audits flagging lack of PQC transition planning
HIPAA
Health Insurance Portability and Accountability Act protecting sensitive patient health information (PHI).
Quantum Impact
HIPAA's Security Rule mandates encryption for PHI at rest and in transit. Patient records with 50+ year retention requirements are already vulnerable to harvest-now-decrypt-later attacks.
Key Risk Areas
- PHI with decades-long sensitivity exposed to HNDL
- Encryption standards for ePHI becoming quantum-vulnerable
- Breach notification obligations expanding with quantum threats
CMMC
Cybersecurity Maturity Model Certification for Department of Defense contractors.
Quantum Impact
CMMC requires FIPS-validated cryptographic modules. As NIST transitions to PQC standards, defense contractors must align with quantum-safe cryptographic requirements to maintain contract eligibility.
Key Risk Areas
- CUI protection requiring quantum-resistant encryption
- FIPS module updates lagging behind PQC standards
- Supply chain quantum vulnerability cascading through tiers
FedRAMP
Federal Risk and Authorization Management Program for cloud service providers to the U.S. government.
Quantum Impact
FedRAMP-authorized cloud services must comply with evolving NIST cryptographic standards. Quantum readiness is becoming a prerequisite for authorization and continuous monitoring requirements.
Key Risk Areas
- Authorization baselines requiring PQC algorithm adoption
- Continuous monitoring needing quantum threat indicators
- 3PAO assessments beginning to evaluate quantum readiness
PCI DSS
Payment Card Industry Data Security Standard for organizations handling cardholder data.
Quantum Impact
PCI DSS v4.0 strengthens cryptographic requirements. Payment data protected by RSA/ECC is quantum-vulnerable, requiring proactive migration planning for transaction security and stored cardholder data.
Key Risk Areas
- Payment transaction encryption quantum-vulnerable
- Stored cardholder data at HNDL risk
- PCI SSC expected to issue PQC guidance imminently
GDPR / CCPA
General Data Protection Regulation (EU) and California Consumer Privacy Act protecting personal data.
Quantum Impact
Data protection regulations require 'appropriate technical measures' including encryption. Quantum threats redefine what constitutes 'appropriate,' potentially creating retroactive compliance gaps for archived personal data.
Key Risk Areas
- 'State of the art' encryption standard evolving to include PQC
- Right to erasure complicated by HNDL-exposed data
- Cross-border data transfers needing quantum-safe encryption
SWIFT CSP
SWIFT Customer Security Programme for financial institutions using the SWIFT network.
Quantum Impact
SWIFT CSP mandatory controls require strong encryption for financial messaging. Quantum threats to transaction integrity and authentication could compromise the global financial messaging ecosystem.
Key Risk Areas
- Financial message authentication quantum-vulnerable
- Transaction integrity controls needing PQC upgrade
- Correspondent banking security dependent on quantum-safe protocols
DORA
Digital Operational Resilience Act: EU regulation for ICT risk management in financial entities.
Quantum Impact
DORA mandates comprehensive ICT risk management, resilience testing, and third-party oversight for EU financial entities. Quantum threats to cryptographic infrastructure create new ICT risk vectors that must be identified, managed, and tested under DORA's operational resilience framework.
Key Risk Areas
- ICT risk management frameworks not accounting for quantum cryptographic threats
- Digital operational resilience testing lacking quantum threat scenarios
- Third-party ICT service provider contracts missing PQC migration requirements
NIS2
Network and Information Security Directive 2: EU cybersecurity obligations for essential and important entities.
Quantum Impact
NIS2 requires essential and important entities to implement 'state of the art' cybersecurity risk management measures. As PQC becomes the benchmark for encryption, NIS2-regulated entities must demonstrate quantum-aware governance and incident response capabilities.
Key Risk Areas
- 'State of the art' cybersecurity measures evolving to require PQC readiness
- Supply chain security assessments lacking quantum vulnerability analysis
- Incident reporting obligations expanding to cover quantum-related breaches
EU AI Act
EU Artificial Intelligence Act, risk-based regulation for AI systems deployed in the European Union.
Quantum Impact
High-risk AI systems under the EU AI Act require cryptographic integrity for data protection, model security, and audit trails. Quantum threats to these cryptographic foundations could compromise AI system trustworthiness and regulatory compliance.
Key Risk Areas
- AI model integrity protections relying on quantum-vulnerable signatures
- Training data confidentiality exposed to HNDL harvesting
- Conformity assessment documentation requiring quantum-safe audit trails
eIDAS 2.0
EU regulation on electronic identification, authentication, and trust services including the EU Digital Identity Wallet.
Quantum Impact
eIDAS 2.0 underpins digital identity, electronic signatures, and trust services across the EU. Quantum threats to signature algorithms and certificate infrastructure could invalidate legally binding electronic transactions and identity verification at scale.
Key Risk Areas
- Qualified electronic signatures becoming quantum-vulnerable
- Trust service provider certificates requiring PQC algorithm migration
- EU Digital Identity Wallet cryptographic architecture needing quantum resilience
EU Requirements: DORA, NIS2, eIDAS 2.0 and the Coordinated PQC Roadmap
European supervisors were the first to turn quantum exposure into an examinable obligation. None of these instruments names "post-quantum cryptography" as a separate control; each reaches it through existing duties on ICT risk, state-of-the-art security and trust-service assurance.
DORA: quantum exposure is an ICT risk
DORA requires EU financial entities to identify, classify and document ICT risk, test operational resilience, and oversee third-party dependencies. Cryptography with a known expiry date is an identified ICT risk: long-lived encrypted data, certificate and key management, and vendor cryptographic dependencies all belong in the ICT risk register and in resilience testing scenarios. Supervisors ask what you knew, when you recorded it, and what your remediation plan is.
NIS2: "state of the art" moves to PQC
NIS2 obliges essential and important entities to apply state-of-the-art risk management measures, including policies on cryptography and encryption. As NIST's standardised algorithms and the EU Coordinated Implementation Roadmap for PQC become the reference point, classical-only cryptography becomes progressively harder to defend as state of the art, and management bodies carry personal accountability for the gap.
eIDAS 2.0 and the EU Digital Identity Wallet
Wallet providers, qualified trust service providers and relying parties depend on signature and device-binding cryptography with a lifetime measured in decades. Certification under the eIDAS 2.0 regime therefore reaches cryptographic agility directly: the ability to change algorithms without re-architecting the service.
The dates that drive EU examinations
The EU Coordinated PQC Roadmap sets the expectation that member states begin migration planning immediately, with high-risk use cases transitioned by 2030 and the broader estate by 2035. NIST deprecates RSA-2048 and ECC-256 by 2030 and disallows them by 2035. Those dates are what turn a 2026 audit conversation about quantum readiness from a hypothetical into a finding.
Evidence that satisfies an EU examiner
A cryptographic inventory, a data-lifetime analysis identifying harvest-now-decrypt-later exposure, a board-approved migration roadmap with owners and dates, third-party cryptographic attestations, and a governance record showing the decision was taken deliberately. QCI²-QS1 and its DORA (S6), NIS2 (S7) and eIDAS 2.0 wallet (S8) supplements specify each artefact, and the Q-Risk Score measures how much of it you can produce today.
How QCI-QS1 Maps to the Frameworks Examiners Cite
Examiners do not ask for "quantum compliance." They ask whether existing obligations were met. Each obligation below maps to a QCI²-QS1 deliverable; the sector and regional supplements carry the framework-specific detail.
DORA and the QASI inventory
QRAF's governance artifacts, QASI inventory entries feeding the ICT risk register, and the Vendor Roadmap Request Pack satisfy DORA's ICT risk documentation and third-party oversight duties directly. The DORA supplement (QCI-QS1-S6) maps each requirement to DORA's five-pillar ICT risk framework, including the Register of Information certificate requirements and the vendor exception register structure DORA requires when systems cannot be migrated.
NIS2 and the board record
NIS2 holds management bodies personally accountable for cybersecurity measures. The Board Briefing Insert (QCI-QS1 Section 8) produces the quarterly oversight record, and QASI inventory coverage demonstrates a cryptography policy that meets the state-of-the-art bar as PQC becomes the reference point. The NIS2 supplement (QCI-QS1-S7) covers essential and important entities in detail.
HIPAA and the risk analysis
HIPAA's Security Rule does not name post-quantum cryptography; it requires a thorough risk analysis and "reasonable and appropriate" encryption of ePHI. QASI captures ePHI systems with long retention periods, and the Q-Risk Score's Cryptographic Exposure pillar measures harvest-now-decrypt-later exposure in the terms a HIPAA risk analysis already uses. A documented inventory and migration plan is the answer to the examiner's question.
SOC 2 and ISO 27001 and the audit evidence
Both frameworks assess whether cryptographic controls are current and whether risk assessments account for emerging threats. The Q-Risk Score produces dated, auditable evidence of quantum due diligence mapped to the same controls auditors test, and QCI-QS1's conformance clause distinguishes self-assessed from externally validated scores, so an auditor knows exactly what the number represents.
Compliance Readiness Matrix
How each Q-Risk dimension maps to your compliance obligations
| Framework | Cryptographic Exposure | Governance Readiness | Technical Preparedness | Strategic Alignment | Operational Resilience | Urgency |
|---|---|---|---|---|---|---|
| SOC 2 | — | — | — | High | ||
| ISO 27001 | — | — | — | High | ||
| HIPAA | — | — | — | Critical | ||
| CMMC | — | — | — | Critical | ||
| FedRAMP | — | — | — | High | ||
| PCI DSS | — | — | — | High | ||
| GDPR/CCPA | — | — | — | Moderate | ||
| SWIFT CSP | — | — | — | High | ||
| DORA | — | — | High | |||
| NIS2 | — | — | High | |||
| EU AI Act | — | — | — | Moderate | ||
| eIDAS 2.0 | — | — | High |
Quantum Compliance FAQ
Does HIPAA require post-quantum cryptography?
Not yet explicitly, but HIPAA's Security Rule mandates 'reasonable and appropriate' encryption safeguards. As quantum computing advances, PQC will become the standard for protecting PHI. Organizations should begin cryptographic inventory and PQC migration planning now to maintain compliance.
When will SOC 2 audits include quantum risk?
SOC 2 auditors are already beginning to ask about quantum preparedness as part of encryption control assessments. While not yet a formal requirement, the Trust Services Criteria's emphasis on current and emerging threats means quantum risk questions will become standard within 2 to 3 years. Proactive organizations are documenting quantum readiness now.
How does quantum computing affect ISO 27001 compliance?
ISO 27001 Annex A controls for cryptography (A.10) will need updating as quantum computers render current algorithms vulnerable. Organizations should integrate quantum risk into their ISMS risk assessment process and begin planning for post-quantum cryptographic transitions to maintain certification.
What compliance frameworks are most affected by quantum computing?
All frameworks relying on cryptographic controls are affected. SOC 2, HIPAA, PCI DSS, and CMMC face the highest urgency due to explicit encryption requirements. ISO 27001, FedRAMP, GDPR/CCPA, DORA, NIS2, and SWIFT CSP also require quantum-aware updates to risk assessments and data protection controls.
How does the Q-Risk Score map to compliance frameworks?
The Q-Risk Score's five dimensions (Cryptographic Exposure, Governance Readiness, Technical Preparedness, Strategic Alignment, and Operational Resilience) map directly to controls across the major frameworks. This provides auditable evidence of quantum due diligence aligned with existing regulatory obligations.
Latest Compliance Insights
Expert analysis on quantum computing's impact on regulatory compliance
The NIST 2024 PQC Deadline: What It Actually Requires
NIST published FIPS 203, 204, and 205 in August 2024. Here is what auditors, regulators, and boards now expect — and the controls you need before your next audit cycle.
Harvest Now, Decrypt Later: What Every CTO Needs to Know in 2025
HNDL is no longer a 2030 problem — it is a 2025 audit finding. A practical breakdown of how to inventory exposed data and brief your board.
DORA and Cryptographic Agility: What EU Financial Institutions Must Document by 2026
The Digital Operational Resilience Act treats cryptography as an operational risk. Here is what your DORA filings must include — and what auditors will check first.
Related Resources
What is HNDL?
Understand the harvest-now-decrypt-later threat referenced across compliance frameworks
Q-Risk Score
See how Q-Risk dimensions map to your compliance obligations
Quantum Glossary
Definitions for SOC 2, ISO 27001, HIPAA, and more
Start Your Assessment
Get a compliance alignment report with your Q-Risk Score