Quantum Risk & Compliance Frameworks
Quantum computing doesn't just create new threats—it reshapes existing compliance obligations. Understand how quantum risk intersects with the frameworks your organization already follows.
8 Frameworks, One Quantum Reality
Each compliance framework has unique quantum exposure. Here's how quantum threats impact your regulatory posture.
SOC 2
Trust Services Criteria for service organizations covering security, availability, processing integrity, confidentiality, and privacy.
Quantum Impact
SOC 2 Trust Services Criteria require encryption controls that quantum computers will render obsolete. Organizations must demonstrate quantum-aware encryption governance to maintain attestation.
Key Risk Areas
- Encryption controls failing quantum-resistant standards
- Key management practices lacking PQC readiness
- Auditors increasingly requesting quantum preparedness evidence
ISO 27001
International standard for information security management systems (ISMS) with Annex A controls.
Quantum Impact
ISO 27001 Annex A cryptographic controls (A.10) require organizations to maintain effective encryption. Quantum threats necessitate updating cryptographic policies and risk assessments within the ISMS framework.
Key Risk Areas
- Annex A.10 cryptographic controls becoming insufficient
- Risk assessment methodology not accounting for quantum threats
- Certification audits flagging lack of PQC transition planning
HIPAA
Health Insurance Portability and Accountability Act protecting sensitive patient health information (PHI).
Quantum Impact
HIPAA's Security Rule mandates encryption for PHI at rest and in transit. Patient records with 50+ year retention requirements are already vulnerable to harvest-now-decrypt-later attacks.
Key Risk Areas
- PHI with decades-long sensitivity exposed to HNDL
- Encryption standards for ePHI becoming quantum-vulnerable
- Breach notification obligations expanding with quantum threats
CMMC
Cybersecurity Maturity Model Certification for Department of Defense contractors.
Quantum Impact
CMMC requires FIPS-validated cryptographic modules. As NIST transitions to PQC standards, defense contractors must align with quantum-safe cryptographic requirements to maintain contract eligibility.
Key Risk Areas
- CUI protection requiring quantum-resistant encryption
- FIPS module updates lagging behind PQC standards
- Supply chain quantum vulnerability cascading through tiers
FedRAMP
Federal Risk and Authorization Management Program for cloud service providers to the U.S. government.
Quantum Impact
FedRAMP-authorized cloud services must comply with evolving NIST cryptographic standards. Quantum readiness is becoming a prerequisite for authorization and continuous monitoring requirements.
Key Risk Areas
- Authorization baselines requiring PQC algorithm adoption
- Continuous monitoring needing quantum threat indicators
- 3PAO assessments beginning to evaluate quantum readiness
PCI DSS
Payment Card Industry Data Security Standard for organizations handling cardholder data.
Quantum Impact
PCI DSS v4.0 strengthens cryptographic requirements. Payment data protected by RSA/ECC is quantum-vulnerable, requiring proactive migration planning for transaction security and stored cardholder data.
Key Risk Areas
- Payment transaction encryption quantum-vulnerable
- Stored cardholder data at HNDL risk
- PCI SSC expected to issue PQC guidance imminently
GDPR / CCPA
General Data Protection Regulation (EU) and California Consumer Privacy Act protecting personal data.
Quantum Impact
Data protection regulations require 'appropriate technical measures' including encryption. Quantum threats redefine what constitutes 'appropriate,' potentially creating retroactive compliance gaps for archived personal data.
Key Risk Areas
- 'State of the art' encryption standard evolving to include PQC
- Right to erasure complicated by HNDL-exposed data
- Cross-border data transfers needing quantum-safe encryption
SWIFT CSP
SWIFT Customer Security Programme for financial institutions using the SWIFT network.
Quantum Impact
SWIFT CSP mandatory controls require strong encryption for financial messaging. Quantum threats to transaction integrity and authentication could compromise the global financial messaging ecosystem.
Key Risk Areas
- Financial message authentication quantum-vulnerable
- Transaction integrity controls needing PQC upgrade
- Correspondent banking security dependent on quantum-safe protocols
DORA
Digital Operational Resilience Act — EU regulation for ICT risk management in financial entities.
Quantum Impact
DORA mandates comprehensive ICT risk management, resilience testing, and third-party oversight for EU financial entities. Quantum threats to cryptographic infrastructure create new ICT risk vectors that must be identified, managed, and tested under DORA's operational resilience framework.
Key Risk Areas
- ICT risk management frameworks not accounting for quantum cryptographic threats
- Digital operational resilience testing lacking quantum threat scenarios
- Third-party ICT service provider contracts missing PQC migration requirements
NIS2
Network and Information Security Directive 2 — EU cybersecurity obligations for essential and important entities.
Quantum Impact
NIS2 requires essential and important entities to implement 'state of the art' cybersecurity risk management measures. As PQC becomes the benchmark for encryption, NIS2-regulated entities must demonstrate quantum-aware governance and incident response capabilities.
Key Risk Areas
- 'State of the art' cybersecurity measures evolving to require PQC readiness
- Supply chain security assessments lacking quantum vulnerability analysis
- Incident reporting obligations expanding to cover quantum-related breaches
EU AI Act
EU Artificial Intelligence Act — risk-based regulation for AI systems deployed in the European Union.
Quantum Impact
High-risk AI systems under the EU AI Act require cryptographic integrity for data protection, model security, and audit trails. Quantum threats to these cryptographic foundations could compromise AI system trustworthiness and regulatory compliance.
Key Risk Areas
- AI model integrity protections relying on quantum-vulnerable signatures
- Training data confidentiality exposed to HNDL harvesting
- Conformity assessment documentation requiring quantum-safe audit trails
eIDAS 2.0
EU regulation on electronic identification, authentication, and trust services including the EU Digital Identity Wallet.
Quantum Impact
eIDAS 2.0 underpins digital identity, electronic signatures, and trust services across the EU. Quantum threats to signature algorithms and certificate infrastructure could invalidate legally binding electronic transactions and identity verification at scale.
Key Risk Areas
- Qualified electronic signatures becoming quantum-vulnerable
- Trust service provider certificates requiring PQC algorithm migration
- EU Digital Identity Wallet cryptographic architecture needing quantum resilience
Compliance Readiness Matrix
How each Q-Risk dimension maps to your compliance obligations
| Framework | Cryptographic Exposure | Governance Readiness | Technical Preparedness | Strategic Alignment | Operational Resilience | Urgency |
|---|---|---|---|---|---|---|
| SOC 2 | — | — | — | High | ||
| ISO 27001 | — | — | — | High | ||
| HIPAA | — | — | — | Critical | ||
| CMMC | — | — | — | Critical | ||
| FedRAMP | — | — | — | High | ||
| PCI DSS | — | — | — | High | ||
| GDPR/CCPA | — | — | — | Moderate | ||
| SWIFT CSP | — | — | — | High | ||
| DORA | — | — | High | |||
| NIS2 | — | — | High | |||
| EU AI Act | — | — | — | Moderate | ||
| eIDAS 2.0 | — | — | High |
Latest Compliance Insights
Expert analysis on quantum computing's impact on regulatory compliance
The NIST 2024 PQC Deadline: What It Actually Requires
NIST published FIPS 203, 204, and 205 in August 2024. Here is what auditors, regulators, and boards now expect — and the controls you need before your next audit cycle.
Harvest Now, Decrypt Later: What Every CTO Needs to Know in 2025
HNDL is no longer a 2030 problem — it is a 2025 audit finding. A practical breakdown of how to inventory exposed data and brief your board.
DORA and Cryptographic Agility: What EU Financial Institutions Must Document by 2026
The Digital Operational Resilience Act treats cryptography as an operational risk. Here is what your DORA filings must include — and what auditors will check first.
Related Resources
What is HNDL?
Understand the harvest-now-decrypt-later threat referenced across compliance frameworks
Q-Risk Score
See how Q-Risk dimensions map to your compliance obligations
Quantum Glossary
Definitions for SOC 2, ISO 27001, HIPAA, and more
Start Your Assessment
Get a compliance alignment report with your Q-Risk Score