Cookie Preferences

    We use cookies to ensure our website functions properly and to improve your experience. Essential cookies are always active. You can choose to enable other categories below. Review our cookie policy

    Regulatory Intelligence

    Think Earlier.

    The quantum problem starts before the quantum computer arrives.

    Quantum Compliance: Requirements, Frameworks & Deadlines

    Quantum compliance means proving your cryptography meets current and emerging regulatory expectations as NIST post-quantum standards take effect. This page maps which frameworks require quantum readiness, what evidence auditors expect, and the deadlines that matter.

    What Is Quantum Compliance?

    Quantum compliance is the set of regulatory obligations that follow from quantum computing's ability to break widely used public-key cryptography (RSA, ECC, Diffie-Hellman). No major framework yet says "use post-quantum cryptography" verbatim, but the obligations already exist in the language regulators use today: encryption must be "appropriate," "state of the art," and effective against "current and emerging threats."

    Three developments turned this from theory into audit scope. First, NIST finalized its post-quantum cryptography standards (FIPS 203, 204, and 205) in August 2024, creating an approved migration target. Second, NIST IR 8547 deprecates classical algorithms from 2030 and disallows them by 2035, giving auditors concrete dates to test against. Third, harvest-now-decrypt-later attacks mean data encrypted today with long confidentiality lifetimes is already exposed, which puts quantum readiness inside existing breach, retention, and risk-assessment duties.

    In practice, auditors now expect three artifacts: a cryptographic inventory covering applications, vendors, and certificates; a documented PQC migration plan with owners and dates; and governance evidence that quantum risk is assessed and reported at board level. The QCI-QS1 standard defines how to produce that evidence, and the Q-Risk Score measures your posture across the five dimensions regulators probe.

    12 Frameworks, One Quantum Reality

    Each compliance framework has unique quantum exposure. Here's how quantum threats impact your regulatory posture.

    SOC 2

    High Urgency

    Trust Services Criteria for service organizations covering security, availability, processing integrity, confidentiality, and privacy.

    Quantum Impact

    SOC 2 Trust Services Criteria require encryption controls that quantum computers will render obsolete. Organizations must demonstrate quantum-aware encryption governance to maintain attestation.

    Key Risk Areas

    • Encryption controls failing quantum-resistant standards
    • Key management practices lacking PQC readiness
    • Auditors increasingly requesting quantum preparedness evidence
    Q-Risk Dimensions:
    Cryptographic Exposure
    Governance Readiness

    ISO 27001

    High Urgency

    International standard for information security management systems (ISMS) with Annex A controls.

    Quantum Impact

    ISO 27001 Annex A cryptographic controls (A.10) require organizations to maintain effective encryption. Quantum threats necessitate updating cryptographic policies and risk assessments within the ISMS framework.

    Key Risk Areas

    • Annex A.10 cryptographic controls becoming insufficient
    • Risk assessment methodology not accounting for quantum threats
    • Certification audits flagging lack of PQC transition planning
    Q-Risk Dimensions:
    Governance Readiness
    Technical Preparedness

    HIPAA

    Critical Urgency

    Health Insurance Portability and Accountability Act protecting sensitive patient health information (PHI).

    Quantum Impact

    HIPAA's Security Rule mandates encryption for PHI at rest and in transit. Patient records with 50+ year retention requirements are already vulnerable to harvest-now-decrypt-later attacks.

    Key Risk Areas

    • PHI with decades-long sensitivity exposed to HNDL
    • Encryption standards for ePHI becoming quantum-vulnerable
    • Breach notification obligations expanding with quantum threats
    Q-Risk Dimensions:
    Cryptographic Exposure
    Operational Resilience

    CMMC

    Critical Urgency

    Cybersecurity Maturity Model Certification for Department of Defense contractors.

    Quantum Impact

    CMMC requires FIPS-validated cryptographic modules. As NIST transitions to PQC standards, defense contractors must align with quantum-safe cryptographic requirements to maintain contract eligibility.

    Key Risk Areas

    • CUI protection requiring quantum-resistant encryption
    • FIPS module updates lagging behind PQC standards
    • Supply chain quantum vulnerability cascading through tiers
    Q-Risk Dimensions:
    Technical Preparedness
    Cryptographic Exposure

    FedRAMP

    High Urgency

    Federal Risk and Authorization Management Program for cloud service providers to the U.S. government.

    Quantum Impact

    FedRAMP-authorized cloud services must comply with evolving NIST cryptographic standards. Quantum readiness is becoming a prerequisite for authorization and continuous monitoring requirements.

    Key Risk Areas

    • Authorization baselines requiring PQC algorithm adoption
    • Continuous monitoring needing quantum threat indicators
    • 3PAO assessments beginning to evaluate quantum readiness
    Q-Risk Dimensions:
    Technical Preparedness
    Governance Readiness

    PCI DSS

    High Urgency

    Payment Card Industry Data Security Standard for organizations handling cardholder data.

    Quantum Impact

    PCI DSS v4.0 strengthens cryptographic requirements. Payment data protected by RSA/ECC is quantum-vulnerable, requiring proactive migration planning for transaction security and stored cardholder data.

    Key Risk Areas

    • Payment transaction encryption quantum-vulnerable
    • Stored cardholder data at HNDL risk
    • PCI SSC expected to issue PQC guidance imminently
    Q-Risk Dimensions:
    Cryptographic Exposure
    Operational Resilience

    GDPR / CCPA

    Moderate Urgency

    General Data Protection Regulation (EU) and California Consumer Privacy Act protecting personal data.

    Quantum Impact

    Data protection regulations require 'appropriate technical measures' including encryption. Quantum threats redefine what constitutes 'appropriate,' potentially creating retroactive compliance gaps for archived personal data.

    Key Risk Areas

    • 'State of the art' encryption standard evolving to include PQC
    • Right to erasure complicated by HNDL-exposed data
    • Cross-border data transfers needing quantum-safe encryption
    Q-Risk Dimensions:
    Governance Readiness
    Cryptographic Exposure

    SWIFT CSP

    High Urgency

    SWIFT Customer Security Programme for financial institutions using the SWIFT network.

    Quantum Impact

    SWIFT CSP mandatory controls require strong encryption for financial messaging. Quantum threats to transaction integrity and authentication could compromise the global financial messaging ecosystem.

    Key Risk Areas

    • Financial message authentication quantum-vulnerable
    • Transaction integrity controls needing PQC upgrade
    • Correspondent banking security dependent on quantum-safe protocols
    Q-Risk Dimensions:
    Cryptographic Exposure
    Operational Resilience

    DORA

    High Urgency

    Digital Operational Resilience Act: EU regulation for ICT risk management in financial entities.

    Quantum Impact

    DORA mandates comprehensive ICT risk management, resilience testing, and third-party oversight for EU financial entities. Quantum threats to cryptographic infrastructure create new ICT risk vectors that must be identified, managed, and tested under DORA's operational resilience framework.

    Key Risk Areas

    • ICT risk management frameworks not accounting for quantum cryptographic threats
    • Digital operational resilience testing lacking quantum threat scenarios
    • Third-party ICT service provider contracts missing PQC migration requirements
    Q-Risk Dimensions:
    Cryptographic Exposure
    Operational Resilience
    Technical Preparedness

    NIS2

    High Urgency

    Network and Information Security Directive 2: EU cybersecurity obligations for essential and important entities.

    Quantum Impact

    NIS2 requires essential and important entities to implement 'state of the art' cybersecurity risk management measures. As PQC becomes the benchmark for encryption, NIS2-regulated entities must demonstrate quantum-aware governance and incident response capabilities.

    Key Risk Areas

    • 'State of the art' cybersecurity measures evolving to require PQC readiness
    • Supply chain security assessments lacking quantum vulnerability analysis
    • Incident reporting obligations expanding to cover quantum-related breaches
    Q-Risk Dimensions:
    Governance Readiness
    Cryptographic Exposure
    Operational Resilience

    EU AI Act

    Moderate Urgency

    EU Artificial Intelligence Act, risk-based regulation for AI systems deployed in the European Union.

    Quantum Impact

    High-risk AI systems under the EU AI Act require cryptographic integrity for data protection, model security, and audit trails. Quantum threats to these cryptographic foundations could compromise AI system trustworthiness and regulatory compliance.

    Key Risk Areas

    • AI model integrity protections relying on quantum-vulnerable signatures
    • Training data confidentiality exposed to HNDL harvesting
    • Conformity assessment documentation requiring quantum-safe audit trails
    Q-Risk Dimensions:
    Technical Preparedness
    Cryptographic Exposure

    eIDAS 2.0

    High Urgency

    EU regulation on electronic identification, authentication, and trust services including the EU Digital Identity Wallet.

    Quantum Impact

    eIDAS 2.0 underpins digital identity, electronic signatures, and trust services across the EU. Quantum threats to signature algorithms and certificate infrastructure could invalidate legally binding electronic transactions and identity verification at scale.

    Key Risk Areas

    • Qualified electronic signatures becoming quantum-vulnerable
    • Trust service provider certificates requiring PQC algorithm migration
    • EU Digital Identity Wallet cryptographic architecture needing quantum resilience
    Q-Risk Dimensions:
    Cryptographic Exposure
    Technical Preparedness
    Operational Resilience

    EU Requirements: DORA, NIS2, eIDAS 2.0 and the Coordinated PQC Roadmap

    European supervisors were the first to turn quantum exposure into an examinable obligation. None of these instruments names "post-quantum cryptography" as a separate control; each reaches it through existing duties on ICT risk, state-of-the-art security and trust-service assurance.

    DORA: quantum exposure is an ICT risk

    DORA requires EU financial entities to identify, classify and document ICT risk, test operational resilience, and oversee third-party dependencies. Cryptography with a known expiry date is an identified ICT risk: long-lived encrypted data, certificate and key management, and vendor cryptographic dependencies all belong in the ICT risk register and in resilience testing scenarios. Supervisors ask what you knew, when you recorded it, and what your remediation plan is.

    NIS2: "state of the art" moves to PQC

    NIS2 obliges essential and important entities to apply state-of-the-art risk management measures, including policies on cryptography and encryption. As NIST's standardised algorithms and the EU Coordinated Implementation Roadmap for PQC become the reference point, classical-only cryptography becomes progressively harder to defend as state of the art, and management bodies carry personal accountability for the gap.

    eIDAS 2.0 and the EU Digital Identity Wallet

    Wallet providers, qualified trust service providers and relying parties depend on signature and device-binding cryptography with a lifetime measured in decades. Certification under the eIDAS 2.0 regime therefore reaches cryptographic agility directly: the ability to change algorithms without re-architecting the service.

    The dates that drive EU examinations

    The EU Coordinated PQC Roadmap sets the expectation that member states begin migration planning immediately, with high-risk use cases transitioned by 2030 and the broader estate by 2035. NIST deprecates RSA-2048 and ECC-256 by 2030 and disallows them by 2035. Those dates are what turn a 2026 audit conversation about quantum readiness from a hypothetical into a finding.

    Evidence that satisfies an EU examiner

    A cryptographic inventory, a data-lifetime analysis identifying harvest-now-decrypt-later exposure, a board-approved migration roadmap with owners and dates, third-party cryptographic attestations, and a governance record showing the decision was taken deliberately. QCI²-QS1 and its DORA (S6), NIS2 (S7) and eIDAS 2.0 wallet (S8) supplements specify each artefact, and the Q-Risk Score measures how much of it you can produce today.

    How QCI-QS1 Maps to the Frameworks Examiners Cite

    Examiners do not ask for "quantum compliance." They ask whether existing obligations were met. Each obligation below maps to a QCI²-QS1 deliverable; the sector and regional supplements carry the framework-specific detail.

    DORA and the QASI inventory

    QRAF's governance artifacts, QASI inventory entries feeding the ICT risk register, and the Vendor Roadmap Request Pack satisfy DORA's ICT risk documentation and third-party oversight duties directly. The DORA supplement (QCI-QS1-S6) maps each requirement to DORA's five-pillar ICT risk framework, including the Register of Information certificate requirements and the vendor exception register structure DORA requires when systems cannot be migrated.

    NIS2 and the board record

    NIS2 holds management bodies personally accountable for cybersecurity measures. The Board Briefing Insert (QCI-QS1 Section 8) produces the quarterly oversight record, and QASI inventory coverage demonstrates a cryptography policy that meets the state-of-the-art bar as PQC becomes the reference point. The NIS2 supplement (QCI-QS1-S7) covers essential and important entities in detail.

    HIPAA and the risk analysis

    HIPAA's Security Rule does not name post-quantum cryptography; it requires a thorough risk analysis and "reasonable and appropriate" encryption of ePHI. QASI captures ePHI systems with long retention periods, and the Q-Risk Score's Cryptographic Exposure pillar measures harvest-now-decrypt-later exposure in the terms a HIPAA risk analysis already uses. A documented inventory and migration plan is the answer to the examiner's question.

    SOC 2 and ISO 27001 and the audit evidence

    Both frameworks assess whether cryptographic controls are current and whether risk assessments account for emerging threats. The Q-Risk Score produces dated, auditable evidence of quantum due diligence mapped to the same controls auditors test, and QCI-QS1's conformance clause distinguishes self-assessed from externally validated scores, so an auditor knows exactly what the number represents.

    Compliance Readiness Matrix

    How each Q-Risk dimension maps to your compliance obligations

    FrameworkCryptographic ExposureGovernance ReadinessTechnical PreparednessStrategic AlignmentOperational ResilienceUrgency
    SOC 2
    High
    ISO 27001
    High
    HIPAA
    Critical
    CMMC
    Critical
    FedRAMP
    High
    PCI DSS
    High
    GDPR/CCPA
    Moderate
    SWIFT CSP
    High
    DORA
    High
    NIS2
    High
    EU AI Act
    Moderate
    eIDAS 2.0
    High

    Quantum Compliance FAQ

    Does HIPAA require post-quantum cryptography?

    Not yet explicitly, but HIPAA's Security Rule mandates 'reasonable and appropriate' encryption safeguards. As quantum computing advances, PQC will become the standard for protecting PHI. Organizations should begin cryptographic inventory and PQC migration planning now to maintain compliance.

    When will SOC 2 audits include quantum risk?

    SOC 2 auditors are already beginning to ask about quantum preparedness as part of encryption control assessments. While not yet a formal requirement, the Trust Services Criteria's emphasis on current and emerging threats means quantum risk questions will become standard within 2 to 3 years. Proactive organizations are documenting quantum readiness now.

    How does quantum computing affect ISO 27001 compliance?

    ISO 27001 Annex A controls for cryptography (A.10) will need updating as quantum computers render current algorithms vulnerable. Organizations should integrate quantum risk into their ISMS risk assessment process and begin planning for post-quantum cryptographic transitions to maintain certification.

    What compliance frameworks are most affected by quantum computing?

    All frameworks relying on cryptographic controls are affected. SOC 2, HIPAA, PCI DSS, and CMMC face the highest urgency due to explicit encryption requirements. ISO 27001, FedRAMP, GDPR/CCPA, DORA, NIS2, and SWIFT CSP also require quantum-aware updates to risk assessments and data protection controls.

    How does the Q-Risk Score map to compliance frameworks?

    The Q-Risk Score's five dimensions (Cryptographic Exposure, Governance Readiness, Technical Preparedness, Strategic Alignment, and Operational Resilience) map directly to controls across the major frameworks. This provides auditable evidence of quantum due diligence aligned with existing regulatory obligations.

    Map Your Compliance to Quantum Readiness

    Get your Q-Risk Score and receive a compliance alignment report showing exactly how your quantum posture maps to each framework.