DNSC May 2026 PQC Roadmap ("Tranziția la criptografia post-cuantică. Foaie de parcurs pentru infrastructurile civile românești")
Recommendation · national roadmap
Romania · DNSC·26 May 2026
Romania's national roadmap. Sets the EU-aligned milestones: cryptographic asset inventory by end-2026, high-risk systems migrated by 2030, full transition by 2035. Formally a recommendation, but DNSC measures against these dates.
Open the document →
OUG 155/2024 (Romanian NIS2 transposition)
Binding · national law
Romania · Government·31 December 2024
Romania's transposition of NIS2. The primary citation for any Romanian NIS2 obligation. Establishes DNSC as competent authority and mirrors the EU fine ceilings (€10M / 2% of turnover).
Open the document →
DORA RTS — Commission Delegated Regulation (EU) 2024/1774
Binding · EU regulation, directly applicable
EU · Commission·2024 (in force with DORA from Jan 2025)
The regulatory technical standard for ICT risk management under DORA. This is where the crypto-agility requirement sits, along with the explicit obligation to update cryptographic technology in line with cryptanalytic developments.
Open the document →
DORA — Regulation (EU) 2022/2554
Binding · EU regulation
EU · Parliament & Council·14 December 2022 (applicable 17 January 2025)
Articles 6, 8, 9 and 28 are the cryptographically relevant ones. Article 9 covers cryptographic controls; Article 28 covers third-party risk — the basis for any supply-chain discussion.
Open the document →
NIS2 Directive (EU) 2022/2555
Binding · EU directive (needs transposition)
EU · Parliament & Council·14 December 2022
Article 21(2)(h) is the cryptography requirement; Article 21(1) carries the 'state of the art' language. Article 7 concerns national strategies. Applied in Romania through OUG 155/2024.
Open the document →
GDPR — Regulation (EU) 2016/679
Binding · EU regulation, directly applicable
EU · Parliament & Council·April 2016 (applicable May 2018)
Article 32 ('Security of processing') requires state-of-the-art technical measures. An independent legal hook, separate from NIS2 and DORA — particularly relevant for personal data with a long confidentiality life.
Open the document →
Commission Implementing Regulation (EU) 2024/2690
Binding · EU regulation, directly applicable
EU · Commission·November 2024
Directly enforceable cryptography requirements (Section 9) for the listed digital service providers. Cascades outward through procurement clauses into other sectors.
Open the document →
Cyber Resilience Act — Regulation (EU) 2024/2847
Binding · EU regulation
EU · Parliament & Council·October 2024 (applicable from 11 December 2027)
Requires products to support security updates across their lifetime — the Commission and ENISA tie this to PQC upgradability. Annex I holds the design obligations. Fines up to €15M / 2.5% of turnover.
Open the document →
DORA RTS — Commission Delegated Regulation (EU) 2024/1773
Binding · EU regulation
EU · Commission·2024
The DORA technical standard on ICT third-party risk. Read alongside Article 28: PQC roadmap requirements have to be passed down to ICT suppliers.
Open the document →
eIDAS 2.0 — Regulation (EU) 2024/1183
Binding · EU regulation
EU · Parliament & Council·April 2024
Establishes the EU Digital Identity Wallet framework and revises trust services. The ETSI TS 119 series is being updated with PQC migration paths.
Open the document →
DNSC Order 1/2025
Binding · secondary legislation
Romania · DNSC·20 August 2025
The registration and notification procedure under OUG 155/2024. Operational rather than PQC-specific, but part of the framework Romanian entities have to meet.
Open the document →
DNSC Order 2/2025
Binding · secondary legislation
Romania · DNSC·20 August 2025
The methodology for assessing service disruption and assigning entity risk levels under OUG 155/2024. Operational rather than PQC-specific.
Open the document →
ISO/IEC 27001:2022
International standard · binding if certified
International · ISO/IEC·October 2022
Control A.8.24 (cryptography) is increasingly read by auditors as requiring PQC readiness. The 2026–27 audit cycles will probe this.
Open the document →
PCI DSS v4.0
Standard · contractually binding
Industry · PCI SSC·Effective March 2025
Includes quantum-readiness expectations within the cryptography requirements. Becomes contractually mandatory through the card schemes.
Open the document →