Regulatory reference

The 33 documents that matter, put in order.

The post-quantum transition does not come from a single instrument. It comes from a stack of regulations, transpositions, roadmaps and standards. They are all here, grouped by how directly they apply to you, each with a note on what it actually means.

Last reviewed 20 July 2026
How they fit together

Few of them bind you directly. The rest set the expectation.

It is easy to get lost in the list. In practice only a handful of these create a legal obligation for an organisation in Romania: NIS2, through OUG 155/2024, DORA for financial services, GDPR for personal data, and, contractually, standards such as ISO 27001 and PCI DSS.

The rest do not bind on their own. But the roadmaps and guidance — the European one from 2025, the DNSC roadmap of May 2026, the ENISA guidance — are what fix the dates and the interpretation. When a supervisor assesses whether your measures meet the state of the art, that is where they look.

The technical standards become relevant later, at implementation: which algorithms, which hybrid schemes, which migration methodology.

What binds you

Direct legal or contractual force. If you fall within scope, these are not optional.

What guides you

Roadmaps, guidance, official positions. They set the dates and the interpretation supervisors measure against.

Technical reference

Standards, specifications, methodologies. They matter once you move to implementation.

Group 1

What binds you

Instruments with direct legal or contractual force over organisations in Romania. If you fall within their scope, these are not optional.

DNSC May 2026 PQC Roadmap ("Tranziția la criptografia post-cuantică. Foaie de parcurs pentru infrastructurile civile românești")

Recommendation · national roadmap
Romania · DNSC·26 May 2026

Romania's national roadmap. Sets the EU-aligned milestones: cryptographic asset inventory by end-2026, high-risk systems migrated by 2030, full transition by 2035. Formally a recommendation, but DNSC measures against these dates.

Open the document →

OUG 155/2024 (Romanian NIS2 transposition)

Binding · national law
Romania · Government·31 December 2024

Romania's transposition of NIS2. The primary citation for any Romanian NIS2 obligation. Establishes DNSC as competent authority and mirrors the EU fine ceilings (€10M / 2% of turnover).

Open the document →

DORA RTS — Commission Delegated Regulation (EU) 2024/1774

Binding · EU regulation, directly applicable
EU · Commission·2024 (in force with DORA from Jan 2025)

The regulatory technical standard for ICT risk management under DORA. This is where the crypto-agility requirement sits, along with the explicit obligation to update cryptographic technology in line with cryptanalytic developments.

Open the document →

DORA — Regulation (EU) 2022/2554

Binding · EU regulation
EU · Parliament & Council·14 December 2022 (applicable 17 January 2025)

Articles 6, 8, 9 and 28 are the cryptographically relevant ones. Article 9 covers cryptographic controls; Article 28 covers third-party risk — the basis for any supply-chain discussion.

Open the document →

NIS2 Directive (EU) 2022/2555

Binding · EU directive (needs transposition)
EU · Parliament & Council·14 December 2022

Article 21(2)(h) is the cryptography requirement; Article 21(1) carries the 'state of the art' language. Article 7 concerns national strategies. Applied in Romania through OUG 155/2024.

Open the document →

GDPR — Regulation (EU) 2016/679

Binding · EU regulation, directly applicable
EU · Parliament & Council·April 2016 (applicable May 2018)

Article 32 ('Security of processing') requires state-of-the-art technical measures. An independent legal hook, separate from NIS2 and DORA — particularly relevant for personal data with a long confidentiality life.

Open the document →

Commission Implementing Regulation (EU) 2024/2690

Binding · EU regulation, directly applicable
EU · Commission·November 2024

Directly enforceable cryptography requirements (Section 9) for the listed digital service providers. Cascades outward through procurement clauses into other sectors.

Open the document →

Cyber Resilience Act — Regulation (EU) 2024/2847

Binding · EU regulation
EU · Parliament & Council·October 2024 (applicable from 11 December 2027)

Requires products to support security updates across their lifetime — the Commission and ENISA tie this to PQC upgradability. Annex I holds the design obligations. Fines up to €15M / 2.5% of turnover.

Open the document →

DORA RTS — Commission Delegated Regulation (EU) 2024/1773

Binding · EU regulation
EU · Commission·2024

The DORA technical standard on ICT third-party risk. Read alongside Article 28: PQC roadmap requirements have to be passed down to ICT suppliers.

Open the document →

eIDAS 2.0 — Regulation (EU) 2024/1183

Binding · EU regulation
EU · Parliament & Council·April 2024

Establishes the EU Digital Identity Wallet framework and revises trust services. The ETSI TS 119 series is being updated with PQC migration paths.

Open the document →

DNSC Order 1/2025

Binding · secondary legislation
Romania · DNSC·20 August 2025

The registration and notification procedure under OUG 155/2024. Operational rather than PQC-specific, but part of the framework Romanian entities have to meet.

Open the document →

DNSC Order 2/2025

Binding · secondary legislation
Romania · DNSC·20 August 2025

The methodology for assessing service disruption and assigning entity risk levels under OUG 155/2024. Operational rather than PQC-specific.

Open the document →

ISO/IEC 27001:2022

International standard · binding if certified
International · ISO/IEC·October 2022

Control A.8.24 (cryptography) is increasingly read by auditors as requiring PQC readiness. The 2026–27 audit cycles will probe this.

Open the document →

PCI DSS v4.0

Standard · contractually binding
Industry · PCI SSC·Effective March 2025

Includes quantum-readiness expectations within the cryptography requirements. Becomes contractually mandatory through the card schemes.

Open the document →
Group 2

What guides you

Roadmaps, guidance and official positions. Not binding in themselves, but they set the dates and the interpretation supervisors measure against.

EU Coordinated PQC Implementation Roadmap

Recommendation · coordination document
EU · NIS Cooperation Group·June 2025

The document that fixes the European dates: national transitions beginning end-2026, critical infrastructure migrated by 2030, broad transition complete by 2035. Also sets out the risk-based prioritisation model.

Open the document →

NIST IR 8547 — Transition to Post-Quantum Cryptography Standards

Recommendation · binding on US federal
US · NIST·November 2024 (initial public draft)

The US migration schedule: legacy public-key algorithms deprecated after 2030, disallowed after 2035. The international benchmark other national roadmaps align to or deliberately depart from.

Open the document →

ENISA Technical Implementation Guidance on Cybersecurity Risk Management Measures

Guidance · informative, decisive in supervision
EU · ENISA·June 2025 (v1.0; living document)

170 pages. Formally a companion to Implementing Regulation 2024/2690, but used as the operational reference for NIS2 generally. The cryptography section is the essential part.

Open the document →

COM(2026) 13 final — proposed NIS2 amendment

Proposed legislation · in process
EU · Commission·20 January 2026

Proposes an Article 7(2)(k) requiring Member States to include PQC transition policies in national strategies. Recital (8) is the firmest EU statement on quantum risk so far.

Open the document →

DNSC March 2026 cryptography analysis ("Stadiul actual al criptografiei în securitatea cibernetică")

Position paper · authoritative interpretation
Romania · DNSC·20 March 2026

DNSC's interpretation of what 'state of the art' cryptography means. Covers the case for PQC, harvest-now-decrypt-later, hybrid approaches and the migration framework.

Open the document →

Commission Recommendation (EU) 2024/1101

Recommendation · non-binding
EU · Commission·11 April 2024

The Commission Recommendation that set up the coordination process. It is the legal basis for the machinery that produced the June 2025 roadmap.

Open the document →

ANSSI position papers and RGS (Référentiel Général de Sécurité)

Standard · national technical guideline
France · ANSSI·Various, ongoing

The French authority's positions on PQC. Notable for the three-phase approach: classical, then hybrid, then pure PQC. Relevant for organisations with French operations.

Open the document →

CNSA 2.0 — Commercial National Security Algorithm Suite

Standard · binding for US NSS
US · NSA·2022

Mandates PQC by 2035 for US national security systems. Globally relevant because it cascades through US federal procurement to NATO suppliers.

Open the document →
Group 3

Technical reference

The standards, specifications and methodologies you reach for at implementation time, when the conversation moves from what is required to how it is done.

BSI TR-02102 Part 1 — Cryptographic Mechanisms: Recommendations and Key Lengths

Standard · technical guideline
Germany · BSI·Annually updated

Germany's national cryptographic recommendations. The first major EU authority to require hybrid PQC. Shapes procurement requirements across regulated EU industries.

Open the document →

NIST SP 1800-38 (Volumes A, B, C)

Practice guide · informative
US · NIST NCCoE·Drafts 2023–2025

The practical companion to NIST IR 8547. Volume A is the executive summary, Volume B the methodology and architecture, Volume C the discovery and interoperability testing.

Open the document →

ETSI TS 103 744 — Quantum-safe Hybrid Key Exchanges

Technical specification · normative
EU · ETSI·Multiple versions (ongoing updates)

Specifies hybrid key exchange constructions (classical plus PQC). Used together with the NIST standards for concrete deployment patterns.

Open the document →

ETSI TR 103 619 — Migration strategies and recommendations to Quantum Safe schemes

Technical report · informative
EU · ETSI·2020

A strategic migration guide from ETSI's quantum-safe cryptography working group. Useful as a methodology reference for sequencing the phases.

Open the document →

NIST FIPS 203 — ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism)

Standard · de facto global
US · NIST·August 2024

The standardised key encapsulation mechanism. Three parameter sets (ML-KEM-512, 768, 1024).

Open the document →

NIST FIPS 204 — ML-DSA (Module-Lattice-Based Digital Signature Algorithm)

Standard · de facto global
US · NIST·August 2024

The standardised post-quantum digital signature algorithm, lattice-based.

Open the document →

NIST FIPS 205 — SLH-DSA (Stateless Hash-Based Digital Signature Algorithm)

Standard · de facto global
US · NIST·August 2024

Stateless hash-based signatures. Larger than ML-DSA, but resting on more conservative security assumptions — it relies only on the security of the hash function.

Open the document →

NIST FIPS 206 draft — HQC (Hamming Quasi-Cyclic)

Standard · draft
US · NIST·Selected March 2025; draft in progress

A backup KEM, code-based. Insurance against future cryptanalysis of ML-KEM. Still in draft.

Open the document →

ISO/IEC 27002:2022

International standard · implementation guidance
International · ISO/IEC·February 2022

Implementation guidance for the ISO 27001 controls. Used alongside it.

Open the document →

ETSI TS 119 series

Technical specification · normative
EU · ETSI·Various, being updated for PQC

The standards for qualified electronic signatures and seals. Being updated with explicit PQC migration paths.

Open the document →

IETF drafts on hybrid TLS, SSH, IPsec, X.509

Drafts · pre-standard
International · IETF·Various, ongoing

Where the real deployment patterns are defined, ahead of formal standardisation. The X25519MLKEM768 hybrid that Chrome and Cloudflare already ship comes from these drafts.

Open the document →
Post-Quantum advisory

The list is useful. The decision is another matter.

In a half-day briefing we move from the stack of documents to what actually applies to you, and to a first step your board can adopt.