Risk analysis
Treat harvest-now-decrypt-later exposure and long-lived sensitive data as cryptographic risk inputs, not only future technology concerns.
NIS2 makes cryptography, supplier security and cybersecurity risk management board-level operational issues. Post-quantum cryptography belongs in that risk conversation wherever long-lived sensitive data, public-key encryption or digital signatures matter.
Treat harvest-now-decrypt-later exposure and long-lived sensitive data as cryptographic risk inputs, not only future technology concerns.
Ask cloud, CDN, identity, signing and managed service providers for PQC roadmaps and evidence where they operate cryptography.
Build crypto-agility into acquisition, development and maintenance so algorithms and libraries can change without redesign.
Document where encryption, key exchange, signatures and certificate chains depend on quantum-vulnerable public-key algorithms.
NIS2 is not a post-quantum cryptography standard. It is a cybersecurity governance and risk-management framework. PQC becomes relevant because cryptography and encryption policies cannot ignore a known future break in widely deployed public-key algorithms.
The immediate task is not to replace every certificate. The useful task is to create evidence: what cryptography is used, who owns it, what suppliers operate it, how long the protected data must remain secure and where migration blockers exist.
This is also where NIS2 supplier security matters. Many organisations do not directly control their CDN, identity provider, trust service, API gateway, managed service provider or signing platform. PQC planning needs supplier answers early.
Endpoints, protocols, certificates, key stores, signing workflows, algorithms, owners and suppliers.
TLS 1.3 status, downgrade exposure, security headers and observable hybrid key exchange signals.
Provider PQC roadmaps, supported algorithms, planned dates, contractual evidence and operational dependencies.
Risk-ranked systems, pilot candidates, compatibility blockers and owners for remediation.
NIS2 requires risk-management measures that include cryptography and, where appropriate, encryption. It does not name a single PQC algorithm, but organisations with long-lived sensitive data should include PQC migration in cryptographic risk planning.
The strongest connections are risk analysis, supply chain security, secure acquisition and maintenance, asset management, access control, secured communications and cryptography or encryption policies.
No. A scan is evidence for public endpoint posture only. NIS2 readiness also depends on governance, policies, incident handling, supplier controls, internal systems and national implementation requirements.
Run a free scan for a public endpoint, save the result and use it as one evidence input for a broader NIS2 cryptography and supplier-risk review.
A PQC guide is more useful when it is attached to current evidence. Create a free account, add a public domain now or later, and keep a repeatable baseline for TLS, security headers and visible post-quantum readiness.
Prefer to scan first? Open the free quantum security scanner.