Sitemap
Press enter or click to view image in full size

Member-only story

In the EU, Less Than Five Years To Migrate to PQC for High-Risk Areas

4 min readJul 26, 2025

--

The EU Commission now agrees with the US that the migration away from public key cryptography is with FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). Overall, ML-KEM will replace our ECDH key exchange methods, ECIES hybrid encryption and RSA OAEP encryption, while ML-DSA and SLH-DSS will replace our signature methods of RSA PSS, RSA PKCS#1 v1.5, ECDSA, and EdDSA.

Now the EU — through the NIS Cooperation Group — has mandated a deadline of 2030 for the migration of critical infrastructure (eg water, energy, health care, finance and transportation) and high-risk domains for PQC (Post Quantum Cryptography) migration. This includes a First Steps and a Next Steps approach to the migration process. The foundation of this approach comes from a report by 18 cybersecurity agencies in the EU [here]:

Press enter or click to view image in full size

In the report, it is recommended that organisations perform a quantum threat analysis for all their assets that use cryptography. From this, they need to develop a risk-oriented roadmap, which includes crypto-agility, and then plan the migration. Additionally, the report emphasises the importance of ongoing investment in PQC research and…

--

--

Prof Bill Buchanan OBE FRSE
Prof Bill Buchanan OBE FRSE

Written by Prof Bill Buchanan OBE FRSE

Professor of Cryptography. Serial innovator. Believer in fairness, justice & freedom. Based in Edinburgh. Old World Breaker. New World Creator. Building trust.