KEY EXCHANGE…000
Skip to content
Blog

Compliance24 September 2026 5 min

NIS2, GDPR and post-quantum: what regulations actually say about encryption

No regulation forces you to adopt post-quantum cryptography today. But several ask you to use state-of-the-art encryption, and "state of the art" is moving.

"Is post-quantum encryption mandatory?" Not as such, not yet. But the texts that govern data security in Europe all point in the same direction, and it's worth reading what they actually say.

GDPR: encryption is named explicitly

Article 32 of the GDPR requires "appropriate technical and organisational measures" taking into account "the state of the art", and explicitly lists "the pseudonymisation and encryption of personal data" among them.

Article 34 adds a concrete benefit: after a personal data breach, you don't have to notify the people affected if the data was rendered unintelligible to unauthorised persons, for example by encryption. Encryption that a future attacker can break is a weaker argument than encryption that holds.

NIS2: a cryptography policy is required

The NIS2 directive (EU 2022/2555) widens the circle of "essential" and "important" entities subject to cybersecurity obligations. Its article 21 lists the minimum measures, including "policies and procedures regarding the use of cryptography and, where appropriate, encryption". Concretely, an entity must know what cryptography it uses and justify that it is adequate.

Where post-quantum comes in

  • NIST published its first post-quantum standards in August 2024 (FIPS 203, 204 and 205).
  • The European Commission published a recommendation in April 2024 calling on member states to coordinate their transition to post-quantum cryptography.
  • France's ANSSI recommends hybrid solutions (classical + post-quantum) during the transition.

In other words, "state of the art" now includes post-quantum algorithms. Data that must remain confidential for years is the natural starting point.

Compliance asks you to justify your cryptographic choices. "We hadn't looked into it" is getting harder to justify.

A pragmatic path

  • Document which cryptography protects which data (this is also what NIS2 expects).
  • Assess exposure with a simple model such as Mosca's inequality.
  • Start with the most sensitive, longest-lived data, using hybrid encryption.

Encryption supports compliance; it doesn't replace it. But it's one of the few measures that reduces both the risk and the consequences of a breach. This article is general information, not legal advice.

Are you exposed?

Find out in 30 seconds in our Lab.

Check my exposure →