Global post-quantum cryptography rules converge on 2030, but diverge on what must change
Governments worldwide are setting 2030 as a deadline for post-quantum cryptography migration, yet varying regulatory scopes are forcing multinational organizations to navigate multiple compliance paths.

Regulatory mandates for post-quantum cryptography are converting what once seemed a far-off security challenge into binding timelines with real consequences. While many nations are aligning on 2030 as a target year, the breadth of what each jurisdiction requires differs sharply, leaving companies operating across borders to manage divergent migration strategies.
Australia is demanding a comprehensive shift to post-quantum systems, whereas nations in Scandinavia and the Baltic region largely track the European Union's approach to roadmap development and protections for critical infrastructure, according to Naomi Wynn, chief executive officer of National Energy Public Key Infrastructure (NEPKI), and Jostein Stokkan, product manager of service offerings at Atea Norge AS. The United States has issued Executive Order 14412, which directs federal agencies to designate post-quantum cryptography migration leads and move high-value and high-impact systems to PQC for key establishment no later than Dec. 31, 2030.
When it comes to PQC, we're actually leading the charge in terms of a regulatory sense. The Australian Signals Directorate and the Australian Cyber Security Centre have requested full PQC compliance and complete migration by 2030.
Naomi Wynn, chief executive officer of National Energy Public Key Infrastructure
Wynn and Stokkan shared their perspectives with Dean Coclin, senior director and digital trust specialist at DigiCert Inc., during DigiCert's World Quantum Readiness Day, in remarks broadcast on theCUBE, SiliconANGLE Media's livestreaming platform. The conversation centered on how regional mandates are reshaping migration priorities and establishing accountability measures.
Standards divergence adds another layer of complexity
Beyond the variation in regulatory deadlines, different nations are establishing distinct post-quantum standards, introducing additional challenges for organizations spanning multiple jurisdictions. Companies may find themselves needing to support shifting algorithms and evolving requirements across their operations, Stokkan noted.
I think [different standards] will affect [PQC]. But if we can help organizations to become more crypto agile, to be able to adapt to different types of encryption as they become important or just change, I think everything will be smoother and easier for all parties.
Jostein Stokkan, product manager of service offerings at Atea Norge AS
Even as regulatory pressure mounts to accelerate post-quantum migration efforts, many organizations still grapple with fundamental questions about how to execute these transitions. This lack of clarity will likely define the coming phase of implementation work, according to Wynn.
There is no one-size-fits-all; there is no template. But I'm hoping that by this time next year … we are seeing improved guidance as well in terms of what expectations are, what is good enough [and] what will actually meet the requirements.
Naomi Wynn, chief executive officer of National Energy Public Key Infrastructure