Article content
In briefShow moreShow lessThe survey, held from 11 August to 29 September 2025, received 97 submissions.
- The survey, held from 11 August to 29 September 2025, received 97 submissions.
- The FAQ addresses quantum-risk estimation, prioritisation, hybrid approaches, milestones and national roadmaps.
- The roadmap coordinates EU action but is not a directly binding Norwegian deadline.
What was published
On 2 September 2026, the NIS Cooperation Group published feedback from its public survey on the “Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography”. The survey ran from 11 August to 29 September 2025 and received 97 submissions. Of those respondents, 73 provided an overall rating of the document or comments on its content.
What respondents found useful
Respondents highlighted clear timelines and milestones, actionable steps, a risk-based approach, alignment with global best practice and consistent deadlines. Hybrid approaches and crypto-agility were also considered useful. The feedback therefore supports a transition capable of accommodating both emerging post-quantum mechanisms and systems that cannot be replaced immediately.
The FAQ
Sixty-three respondents identified areas requiring clarification. In response, the NIS Cooperation Group developed an FAQ on quantum-risk estimation, milestones, prioritisation, hybrid schemes, the EU’s role and national roadmaps. It is a clarifying coordination document connected to the roadmap, not a new regulation or an independent source of mandatory duties.
Read the milestones precisely
The Commission’s roadmap material says Member States, supported by the Commission, issued a timeline to begin using post-quantum cryptography. The plan points to starting the transition by the end of 2026 and moving high-risk uses to quantum-resistant solutions by 2030. Those milestones express coordinated policy direction and implementation expectations; they do not automatically create an identical legal deadline for every organisation.
Security implications
Organisations should inventory cryptographic use, classify information by required confidentiality lifetime and assess supplier dependencies. Hybrid configurations can support staged migration, while crypto-agility enables changes to algorithms, certificates and protocols without extensive redesign. Testing should cover performance, interoperability, key management, signature validation and recovery procedures.
EU and Norway
This was an EU coordination roadmap and consultation result, not a directly binding Norwegian deadline. Norway’s EEA relationship does not turn EU coordination milestones into Norwegian law or an automatic national commencement date. Norwegian organisations should align migration with NSM advice, sector requirements, contractual obligations and the confidentiality risk of long-lived information.
Sources
European Commission: “EU Roadmap on Post-Quantum Cryptography – survey feedback,” 2 September 2026.
NIS Cooperation Group: “Coordinated roadmap for transition to post-quantum cryptography,” 23 June 2025.
For discussion
Which systems should your organisation prioritise if the EU milestones guide planning while Norwegian requirements and internal risk assessments determine actual implementation?


