Skip to main content
QuantumGenie Book a demo
Browse all 14 categories 251

Global Cryptographic Regulations Report

This report reviews global PQC standards and migration guidance while noting that it is not a comprehensive register of cryptographic regulations.
DIRECT ANSWER

This report finds that the cited primary sources describe a global transition toward post-quantum cryptography (PQC), but they do not constitute a comprehensive register of cryptographic laws or binding regulations across jurisdictions. NIST states that it released three principal PQC standards in August 2024 and urges organizations to begin migration; CISA, NSA, and NIST recommend roadmaps, inventories, risk assessments, and vendor engagement. The UK NCSC describes migration as iterative and potentially spanning years. The evidence therefore supports a readiness and standards picture—not a quantified worldwide regulatory census—and formal obligations must be verified against applicable sector and jurisdictional authorities. C1C31234

KEY TAKEAWAYS
  • The cited source set supports a standards-and-guidance synthesis, not a complete inventory of global cryptographic regulations.
  • NIST reports three principal PQC standards released as FIPS in August 2024: FIPS 203, FIPS 204, and FIPS 205.
  • CISA, NSA, and NIST recommend beginning with a quantum-readiness roadmap, cryptographic inventory, risk assessment, and supplier engagement.
  • Migration is described as iterative; PKI, IoT, and industrial-control-system protocols may mature more slowly than some confidentiality services.
  • Crypto agility is presented as the capability to replace or adapt algorithms while preserving security and ongoing operations.
  • The evidence does not establish that every recommendation is legally binding or that all jurisdictions impose the same timetable.
01

Scope, date, and evidence method

This is a dated primary-source desk review of the cited source set cited for this article. The review uses passages attributed to NIST, CISA, NSA, the UK National Cyber Security Centre (NCSC), NIST’s Cybersecurity Framework materials, NIST’s AI Risk Management Framework materials, and OWASP. The cited sources are identified as primary and authority tier 1 in the cited source set. The review compares what those passages actually say about cryptographic standards, migration, agility, inventories, dependencies, and regulatory context. It does not add external laws, country comparisons, enforcement decisions, market statistics, or legal interpretations. C535

The evidence has an important boundary. The title refers to global cryptographic regulations, but the passages primarily address PQC standards and migration guidance. One NCSC passage says organizations may need to meet regulatory requirements and that regulatory requirements can influence migration drivers; it does not enumerate those requirements. NIST CSF materials describe informative references to regulations and other content, while also stating that the CSF describes desirable outcomes and does not prescribe outcomes or how they must be achieved. Accordingly, this report distinguishes observation from inference: it observes the guidance and standards in the cited source set, and infers only that organizations should map those materials to their own legal and sector obligations. C712

123
02

Why post-quantum cryptography is now a policy concern

NIST describes quantum computers as a future threat that could eventually break many widely used cryptographic systems, while also noting that the field remains in its infancy and that major technical hurdles remain. The evidence therefore supports a future-risk framing rather than a claim that a cryptographically relevant quantum computer currently exists. NIST explains that sufficiently capable quantum computers could affect cryptography based on the difficulty of factoring large numbers. C96

The urgency is not limited to the date on which a quantum computer becomes capable. NIST and the joint CISA, NSA, and NIST fact sheet describe a “harvest now, decrypt later” concern: adversaries may collect encrypted information today and seek to decrypt it when suitable quantum capability becomes available. The joint fact sheet says data with a long secrecy lifetime may already require protection planning. This supports prioritizing information whose confidentiality must endure for many years, but the cited evidence does not quantify the volume or value of such data. C1164

NIST reports that its PQC project used a multiyear international process involving industry, academia, governments, and cryptographers. The cited overview states that 82 algorithms from 25 countries were assessed, that 15 were initially identified for further consideration, and that draft standards were released in 2023. The NIST project passage states that the principal three PQC standards were released in 2024. These figures describe the NIST selection process; they are not a measure of global adoption or regulatory coverage. C136

03

What the cited sources say about standards and regulatory signals

The NIST project passage identifies the principal standards released in August 2024 as FIPS 203, ML-KEM; FIPS 204, ML-DSA; and FIPS 205, SLH-DSA. The passage characterizes these as key-establishment and digital-signature schemes based on candidates selected through the standardization process. NIST also states that it is developing additional standards to serve as backups or alternatives. The evidence supports treating these named FIPS documents as a central reference point for planning, but it does not establish that every private organization or foreign jurisdiction is legally required to implement them. [C2]3

The joint fact sheet says many products, protocols, and services that rely on public-key algorithms such as RSA, ECDH, and ECDSA will need to be updated, replaced, or significantly altered to use quantum-resistant algorithms. It encourages organizations to prepare proactively and to engage vendors about quantum-readiness roadmaps. The NCSC similarly says planning and sequencing should be informed by the readiness of robust, standards-compliant implementations. Together, these passages indicate that implementation readiness and supplier dependency are material parts of the regulatory-readiness problem, even though they do not prescribe one global deadline. C341

NCSC states that migration drivers can include regulatory requirements and that organizations should consider the future agility of their systems. This is a regulatory signal, not a catalog of rules. The most defensible interpretation is that legal and supervisory requirements should be captured as inputs to migration planning, alongside data lifetime, system criticality, vendor commitments, and technical maturity. That interpretation is consistent with the NIST CSF’s description of profiles and supplementary references as tools for understanding, assessing, prioritizing, and communicating cybersecurity risk, rather than as a universal prescriptive code. C41

Evidence-supported elements of a quantum-readiness and regulatory-mapping program
Program elementEvidence-supported observationPractical review question
PQC standardsNIST identifies FIPS 203, FIPS 204, and FIPS 205 as principal standards released in August 2024.Which systems, products, and suppliers depend on these or successor standards?
Cryptographic inventoryCISA, NSA, and NIST recommend identifying quantum-vulnerable technology across IT and OT and engaging supply-chain vendors.Can the organization locate algorithms, certificates, protocols, libraries, firmware, and external dependencies?
Data prioritizationInventory data criticality and secrecy lifetime to support risk assessment and migration prioritization.Which information must remain confidential or retain integrity for the longest period?
Crypto agilityNIST defines agility as adapting algorithms while preserving security and ongoing operations.Can algorithms and cryptographic components be replaced without unsafe disruption?
Regulatory mappingNCSC identifies regulatory requirements as a migration driver, while NIST CSF references help inform outcomes rather than prescribe them.Which binding laws, sector rules, contracts, and supervisory expectations apply to each system?
Supplier readinessJoint guidance calls vendor engagement critical and recommends understanding update paths, configuration changes, costs, and cloud-provider roadmaps.What evidence has each critical supplier provided about PQC support, testing, timing, and residual risk?
3415
04

A practical migration governance sequence

The joint CISA, NSA, and NIST guidance recommends beginning with a quantum-readiness roadmap, inventories, risk assessments and analysis, and vendor engagement. It says the roadmap should begin with a project-management team that scopes the migration and initiates cryptographic discovery. The inventory should cover IT and operational technology (OT), include supply-chain vendors, and identify systems and assets using quantum-vulnerable cryptography. C34

The same guidance explains why discovery is difficult: organizations are often unaware of the breadth of application and functional dependencies on public-key cryptography across products, applications, and services. It recommends identifying quantum-vulnerable algorithms in network protocols and in assets on end-user systems and servers, including applications and associated libraries. NCSC adds that discovery should identify key services and applications, record data and its expected lifetime and value to an adversary, identify protection in transit and at rest, and map the systems through which data is processed. C1741

Risk assessment should connect technical exposure to business impact. The joint guidance says that an inventory of quantum-vulnerable technology and the criticality of associated data enables organizations to plan risk assessment and prioritize migration. It also says the inventory can identify data that may be targeted now and decrypted when a cryptographically relevant quantum computer becomes available. This supports a risk-based sequence, but the cited source set supplies no universal scoring model, threshold, or deadline. C124

  1. Establish accountable ownership across information technology, OT, cybersecurity, privacy, procurement, and risk management.
  2. Create and maintain a cryptographic inventory covering algorithms, protocols, certificates, applications, libraries, hardware, firmware, cloud services, and supplier dependencies where those are in scope.
  3. Classify data by secrecy lifetime, criticality, exposure, and the consequences of loss of confidentiality or integrity.
  4. Map current and target cryptographic states, including dependencies on PKI, network protocols, software and firmware signing, IoT, and industrial-control environments.
  5. Obtain vendor and cloud-provider roadmaps, expected update paths, configuration requirements, costs, testing commitments, and support assumptions.
  6. Sequence pilots, testing, deployment, certificate transition, and retirement of vulnerable components; record decisions and residual uncertainty.
  7. Map the resulting roadmap to applicable laws, regulations, contracts, sector expectations, and internal policies rather than assuming that a general framework supplies the legal answer.
41
05

Crypto agility as a regulatory-readiness capability

NIST’s CSWP 39 Update 1 defines cryptographic agility as capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware, and infrastructure while preserving security and ongoing operations. The document is identified in the cited source set as published on December 19, 2025, with updates as of June 29, 2026, and as final in its document history. This date and version status matter: organizations should preserve the version used for a decision and monitor subsequent updates rather than treating a changing technical paper as static law. C195

NCSC warns that older systems may have cryptographic services that evolved over many years in haphazard ways, making discovery and mitigation more difficult. It presents PQC migration as an opportunity to simplify the estate and reduce other cybersecurity risks. This is an operational inference, not a quantified benefit: simplification may improve manageability, but the cited evidence does not provide a reduction percentage, cost estimate, or assurance that every migration will reduce risk. [C4]1

The evidence also cautions against assuming that all components will mature together. NCSC says it will take a number of years for all protocols and global cryptographic infrastructure to become fully PQC-ready and for trusted implementations to be available. It says confidentiality services are likely to be available soonest, while certificate-based PKI, IoT, and ICS protocols may follow more slowly. The practical implication is a staged transition with explicit compatibility, testing, and residual-risk decisions. C114

06

PKI, IoT, ICS, and suppliers

NCSC says organizations may need to operate conventional and PQC systems simultaneously during a staged migration. It discusses protocols such as TLS and IKE that can negotiate specific certificates and describes an alternative involving a new PQC root of trust that cross-signs an older one. The source stresses that security implications must be assessed case by case and that a system will generally not provide quantum-secure authentication until PKI migration is complete and traditional certificates have expired or been revoked. These are implementation considerations, not a universal certificate-transition mandate. [C1]14

For industrial-control systems, NCSC says remote logins into ICS IT zones need quantum-secure authentication and that wireless field OT devices and sensors also require attention. It distinguishes confidentiality from integrity: sensor data may not always require strong confidentiality protection, but integrity may be critical because faulty readings or commands can cause ICS failures. The source identifies additional industrial-IoT obstacles, including resource constraints, lack of upgradeability, difficult service locations, embedded deployment, proprietary protocols, and protocols not yet compatible with PQC. C221

The joint fact sheet calls vendor engagement critical and recommends treating migration as an IT/OT modernization effort. It says roadmaps should address when and how commercial off-the-shelf vendors plan to deliver updates or upgrades, as well as expected migration costs. For cloud-hosted products, organizations should ask cloud providers about their quantum-readiness roadmaps and how PQC will be enabled, for example through configuration changes or application updates. [C24]14

07

How to use the frameworks without overstating them

The NIST CSF 2.0 materials describe organizational profiles as scoped views that can address an entire organization or a particular system or threat. They recommend documenting facts and assumptions, gathering policies, risk priorities, resources, business-impact information, requirements, standards, practices, tools, and roles, then analyzing gaps between current and target profiles to create an action plan. This provides a useful governance structure for cryptographic migration, but the cited CSF passage does not make PQC implementation itself a universal CSF requirement. [C25]2

The CSF materials further state that informative references map the framework’s outcomes to standards, guidelines, regulations, policies, and other content, and that implementation examples are not a comprehensive list of actions or a baseline of required controls. This distinction is essential for a regulatory report: a mapping can help an organization identify relevant obligations and evidence, but it does not by itself prove legal compliance. [C8]2

The cited source set includes NIST AI RMF and OWASP CycloneDX materials, but the cited passages do not establish a direct cryptographic-regulation requirement arising from either source. The AI RMF passage describes voluntary use and trustworthiness considerations for AI products, services, and systems. The CycloneDX passage describes an OWASP project and its vendor-neutral community context. These materials may be relevant to broader governance or software-component visibility, but this review does not infer a PQC legal obligation from them. C262

PRACTICAL SEQUENCE
  1. 01Define method
  2. 02Collect sources
  3. 03Analyze evidence
  4. 04State limits
  5. 05Draw implications
08

Conclusion

The cited evidence supports a clear direction of travel: organizations should prepare for PQC through standards-aware, risk-based, staged migration, while improving inventory, supplier visibility, PKI planning, and crypto agility. It does not support a single global regulatory timetable or a claim that general guidance is universally binding. A defensible regulatory program should therefore preserve source dates and versions, identify the jurisdictions and sectors actually in scope, map applicable obligations to a maintained cryptographic inventory, and document assumptions, exceptions, testing, and residual risk. The most important evidence gap is the absence of a jurisdiction-by-jurisdiction register of laws, rules, deadlines, and enforcement practice. C3C74125

COMMON QUESTIONS

Frequently asked questions

Does this source set prove that PQC migration is legally mandatory worldwide?

No. The cited source set shows that NIST, CISA, NSA, and NCSC provide standards and migration guidance, and that NCSC identifies regulatory requirements as a possible migration driver. It does not provide a complete global register of binding laws, sector rules, deadlines, or penalties. Organizations must conduct jurisdiction- and sector-specific legal mapping. C421

What should an organization do first?

The joint CISA, NSA, and NIST guidance recommends establishing a quantum-readiness roadmap, creating a cryptographic inventory, conducting risk assessment and analysis, and engaging vendors. Discovery should include IT, OT, applications, protocols, libraries, suppliers, and data whose secrecy must endure. C3[C17]41

Which PQC standards does the cited NIST evidence identify?

The NIST project passage identifies three principal standards released in August 2024: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA. The same passage says NIST is developing additional standards as backups or alternatives. [C2]3

Why is crypto agility relevant?

NIST defines crypto agility as the capability to replace and adapt cryptographic algorithms across protocols, applications, software, hardware, firmware, and infrastructure while preserving security and ongoing operations. It can therefore support staged response to changing standards and implementation maturity, although the evidence does not quantify its cost or benefits. C195

REFERENCES

Sources

  1. 1
    Timelines for Migration to Post-Quantum Cryptography

    UK National Cyber Security Centre · current

    Accessed July 25, 2026
  2. 2
    The NIST Cybersecurity Framework (CSF) 2.0

    National Institute of Standards and Technology · final · NIST CSWP 29

    Accessed July 25, 2026
  3. 3
    Post-Quantum Cryptography Standardization Project

    National Institute of Standards and Technology · current · NIST PQC project

    Accessed July 25, 2026
  4. 4
    Quantum-Readiness: Migration to Post-Quantum Cryptography

    CISA, NSA, and NIST · final · Joint Quantum-Readiness Fact Sheet

    Accessed July 25, 2026
  5. 5
    Considerations for Achieving Crypto Agility: Strategies and Practices

    National Institute of Standards and Technology · final · NIST CSWP 39 Update 1

    Accessed July 25, 2026
  6. 6
    What Is Post-Quantum Cryptography?

    National Institute of Standards and Technology · current · NIST PQC overview

    Accessed July 25, 2026