EU compliance guide

NIS2 and Post-Quantum Cryptography

NIS2 makes cryptography, supplier security and cybersecurity risk management board-level operational issues. Post-quantum cryptography belongs in that risk conversation wherever long-lived sensitive data, public-key encryption or digital signatures matter.

Updated: 19 June 2026|13 min read

Risk analysis

Treat harvest-now-decrypt-later exposure and long-lived sensitive data as cryptographic risk inputs, not only future technology concerns.

Supply chain security

Ask cloud, CDN, identity, signing and managed service providers for PQC roadmaps and evidence where they operate cryptography.

Secure development

Build crypto-agility into acquisition, development and maintenance so algorithms and libraries can change without redesign.

Cryptography policy

Document where encryption, key exchange, signatures and certificate chains depend on quantum-vulnerable public-key algorithms.

Why NIS2 Teams Should Track PQC

NIS2 is not a post-quantum cryptography standard. It is a cybersecurity governance and risk-management framework. PQC becomes relevant because cryptography and encryption policies cannot ignore a known future break in widely deployed public-key algorithms.

The immediate task is not to replace every certificate. The useful task is to create evidence: what cryptography is used, who owns it, what suppliers operate it, how long the protected data must remain secure and where migration blockers exist.

This is also where NIS2 supplier security matters. Many organisations do not directly control their CDN, identity provider, trust service, API gateway, managed service provider or signing platform. PQC planning needs supplier answers early.

NIS2 to PQC Roadmap

1. Scope

  • -Identify whether the organisation, service or supplier relationship is in scope under national NIS2 implementation.
  • -List network and information systems that handle regulated or long-lived sensitive data.
  • -Identify public endpoints, APIs, VPNs, certificates, identity systems and signing workflows.

2. Evidence

  • -Run external TLS scans for public services and save repeatable results.
  • -Record which suppliers operate cryptographic controls and what evidence they can provide.
  • -Map risks to policy, asset management, access control and supplier-security records.

3. Migration

  • -Prioritise systems by data lifetime, exposure and operational dependency.
  • -Pilot hybrid ML-KEM transport where provider support is already mature.
  • -Plan ML-DSA or SLH-DSA signature migration separately for software, documents and device identity.

Evidence to Keep

Cryptographic inventory

Endpoints, protocols, certificates, key stores, signing workflows, algorithms, owners and suppliers.

Public endpoint scans

TLS 1.3 status, downgrade exposure, security headers and observable hybrid key exchange signals.

Supplier responses

Provider PQC roadmaps, supported algorithms, planned dates, contractual evidence and operational dependencies.

Migration backlog

Risk-ranked systems, pilot candidates, compatibility blockers and owners for remediation.

Primary References

NIS2 and PQC FAQ

Does NIS2 explicitly require post-quantum cryptography?

NIS2 requires risk-management measures that include cryptography and, where appropriate, encryption. It does not name a single PQC algorithm, but organisations with long-lived sensitive data should include PQC migration in cryptographic risk planning.

Which NIS2 areas connect most directly to PQC?

The strongest connections are risk analysis, supply chain security, secure acquisition and maintenance, asset management, access control, secured communications and cryptography or encryption policies.

Can an external website scan prove NIS2 compliance?

No. A scan is evidence for public endpoint posture only. NIS2 readiness also depends on governance, policies, incident handling, supplier controls, internal systems and national implementation requirements.

Start With Observable Evidence

Run a free scan for a public endpoint, save the result and use it as one evidence input for a broader NIS2 cryptography and supplier-risk review.

Free readiness account

Keep This Guide Connected to a Real Website Scan

A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.

No cardStart the free evidence path without a paid plan.
Saved scanKeep the public endpoint result after the browser session.
Rescan laterRerun after TLS, header or provider changes.

Prefer to scan first? Open the free quantum security scanner.

Create Your Free Account

Start with Google, Microsoft or a one-time email code. You can add a domain now if you want the scanner to run after signup, but it is not required.

No cardNo passwordFree saved scan
Add a domain to scan after signup (optional)

Leave this blank to create the account first and scan later.

or use email code

No card or password is needed. The free account can keep scan evidence for rescans and badge qualification when you add a public domain.