DORA · NIS2 · DNSC PQC Roadmap 2026

The regulatory clock on quantum-safe cryptography has already started.

A half-day executive briefing for Romanian banking leadership calibrated to real hardware timelines, anchored in the EU and national regulatory stack, and built to produce a defensible board-level decision.

~3 hours
Half-day, on-site or remote
Board-ready
Decision framework, not a sales pitch
Independent
No product to sell you
The regulatory forcing function

This is a compliance timeline before it is a cryptography problem.

The urgency for banks is not an abstract quantum threat date. It is a stack of EU and Romanian obligations already in force or dated, each of which touches cryptographic governance.

2024–2025
NIS2 transposed into Romanian law; DORA enters application for financial entities.
In force
May 2026
DNSC publishes the national PQC migration roadmap, setting direction for scoped entities.
Published
Dec 2026
Cryptographic inventory (CBOM) expectation for NIS2 essential and important entities.
Next deadline
2030–2035
Phased migration to post-quantum standards across high-value and long-lived systems.
Horizon
Calibrated, not alarmist

Honest threat framing is the whole point.

Most quantum messaging a bank board hears is either dismissive ("decades away") or breathless ("harvest-now, decrypt-tomorrow"). Neither helps you make a decision you can defend to a supervisor.

This briefing works from the published hardware trajectory and the peer-reviewed resource estimates, states plainly what is and is not known, and separates the regulatory obligations that are already dated from the cryptographic threat that is still on the horizon. The regulation is what creates the near-term work and the regulation is not speculative.

That calibration is deliberate. It is easier to act on a realistic picture than on a frightening one, and a realistic picture is what an audit committee can sign off against.

The workshop

A half-day briefing that ends in a decision, not a to-do list.

Roughly three hours with your leadership team. The output is a shared understanding of the obligation, the exposure, and a defensible first move captured in a short board-ready statement.

01

Regulatory map

Exactly which obligations — DORA, NIS2, the DNSC roadmap, eIDAS 2.0 — apply to your institution, and on what dates.

02

Threat calibration

What the current quantum hardware trajectory does and does not imply for RSA and ECC, from the published estimates.

03

Cryptographic surface

Where the vulnerable cryptography actually lives in a banking estate — the surface a migration has to cover.

04

Phased roadmap

A migration sequence aligned to the DNSC, EU, and NIST timelines, prioritised by risk and system longevity.

05

90-day block

The concrete first moves — inventory, ownership, governance — that a board can commit to immediately.

06

Board statement

A short written position your audit committee can adopt as its documented decision on quantum-safe readiness.

Structure

How the three hours run.

00:00

The forcing function

The regulatory stack, the dated obligations, and what "scoped entity" means for your institution specifically.

00:40

The threat, calibrated

Real hardware numbers, the peer-reviewed resource estimates, and an honest read of the timeline.

01:20

Your cryptographic surface

A structured walk through where vulnerable cryptography sits across a banking estate, and how exposure is assessed.

02:00

The migration roadmap

A phased plan aligned to DNSC, EU, and NIST timelines — sequenced by risk, not by convenience.

02:35

The 90-day commitment & board statement

Agreeing the immediate moves and drafting the position your audit committee can adopt. Open Q&A to close.

Who it's for

Built for the people who own the decision.

  • CISOs and heads of information security
  • COOs and CTOs at regulated financial entities
  • Audit-committee chairs and board risk leads
  • DORA and NIS2 compliance leads
  • QTSPs and entities in the eIDAS trust ecosystem
Why this advisor

Quantum security is the research.

Primary quantum security research
A working research practice in quantum computer security and reliability — the foundation the advisory is built on.
Published, peer-reviewed work
An IEEE conference publication on quantum hardware security and a published industry partnership on quantum security.
Presented at Black Hat
A 2024 Black Hat speaking credit — the work has been put in front of a critical security audience.
Independent by design
No product, platform, or licence to sell. The only deliverable is your decision.
The honest scope
This is an executive briefing, not a full cryptographic assessment. That boundary is deliberate.

A credible half-day gives your leadership the regulatory map, a calibrated threat picture, and a defensible first move. Where a deeper implementation assessment is the right next step, we say so plainly rather than overreaching.

Book a briefing

Put quantum-safe readiness on your board's record.

Delivered on-site in Romania or remotely, in English, with Romanian-language materials available. Tell us your institution and timeframe, and we'll confirm a date.

Request pricing / half-day briefing
  • Up to ~3 hours with your leadership team
  • Regulatory map tailored to your institution
  • Phased migration roadmap
  • Board-ready statement template
Request a date