Compliance
Post-Quantum Compliance in 2026: PCI DSS 4.0, DORA, NIS2 & CNSA 2.0 Deadlines You Can't Ignore
PCI DSS 4.0 Req 12.3.3, DORA, NIS2 and CNSA 2.0 all demand a cryptographic inventory first. See the 2025-2033 deadlines and how to start free.
Post-Quantum Compliance in 2026: PCI DSS 4.0, DORA, NIS2 & CNSA 2.0 Deadlines You Can't Ignore
If you lead compliance or security in a regulated sector, the post-quantum transition stopped being a future research topic and became a present-day regulatory obligation. PCI DSS 4.0's cryptographic controls became enforceable on March 31, 2025, DORA went into effect on January 17, 2025, and the NSA's CNSA 2.0 timeline already expects you to prefer quantum-resistant algorithms in several categories by 2025 and 2026. The striking part is what nearly every one of these mandates asks for first: not a finished migration, but a documented cryptographic inventory — a list of where and how you use encryption. Most organizations don't have one yet.
Why these regulations are converging now
The standards bodies have already done their part. On August 13, 2024, NIST finalized the first post-quantum cryptography standards — FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) for hash-based signatures. (FIPS 206, the FN-DSA / Falcon standard, is still in progress in 2026, and HQC was selected in March 2025 as a backup key-encapsulation mechanism with finalization ongoing.) Once approved algorithms exist, regulators can reasonably start asking whether you have a plan to adopt them — and they have.
The driving threat is "harvest now, decrypt later" (HNDL): adversaries collect long-lived encrypted data today, intending to decrypt it once a cryptographically relevant quantum computer (CRQC) exists. Guidance from DHS, the UK's NCSC, ENISA, and Australia's ACSC is built on this premise. The Global Risk Institute's 2025 quantum threat timeline, led by Michele Mosca, puts the median expert estimate for a CRQC at roughly 2029–2032, with about a 34% probability by 2030. Mosca's theorem makes the regulatory logic concrete: if your migration time (X) plus your data's security shelf-life (Y) exceeds the time until a CRQC arrives (Z), your data is already at risk today. For a payment processor or a financial entity holding records that must stay confidential for a decade, that inequality is uncomfortable right now.
The readiness gap is the reason regulators feel the need to be explicit. A 2025 DigiCert study found that only about 5% of enterprises have quantum-safe encryption in place, even though roughly 69% recognize the risk. ISACA's 2025 research found a similar picture: only about 5% of organizations have a defined quantum strategy and roughly 95% lack a roadmap. Other 2025 surveys reported that around 81% say their crypto libraries and HSMs aren't prepared and about 91% have no formal migration roadmap. The mandates below exist to close that gap.
The four mandates, side by side
Here is the compressed view — what each framework targets, what it actually requires, and the first concrete action it forces. Note how consistently "inventory" appears in the final column.
| Mandate | Who it applies to | Key date(s) | What it requires | First action it forces | |---|---|---|---|---| | PCI DSS 4.0 — Req. 12.3.3 | Any entity that stores, processes, or transmits cardholder data | Future-dated cryptographic controls effective March 31, 2025 | A documented cryptographic inventory plus a migration plan for deprecated/weak algorithms | Build and maintain a cryptographic inventory | | DORA | EU financial entities and their critical ICT providers | In effect January 17, 2025 | ICT risk management that explicitly includes crypto-agility and post-quantum readiness | Know your cryptographic estate so you can manage and rotate it | | NIS2 | Essential & important entities across EU critical sectors | National transposition (2024–onward) | "State-of-the-art" encryption for data in transit and at rest, and readiness to upgrade | Inventory current encryption to prove it is state-of-the-art | | CNSA 2.0 | U.S. National Security Systems and their suppliers | Prefer quantum-resistant: networking equipment by 2026, software/firmware signing & web/cloud by 2025; exclusive deadlines 2030–2033; new NSS acquisitions must support CNSA 2.0 from Jan 1, 2027 | Adoption of CNSA 2.0 algorithms on a fixed schedule by asset class | Map which systems and algorithms fall under each deadline |
A few details worth keeping in front of your auditors and your board:
- PCI DSS 4.0 Requirement 12.3.3 is the most explicit. It doesn't merely encourage an inventory — it mandates a documented cryptographic inventory and a migration plan for algorithms that are deprecated or weakening. The future-dated cryptographic controls in PCI 4.0 took effect on March 31, 2025, so this is no longer a "best practice" you can defer; it is an assessable requirement.
- DORA (effective January 17, 2025) requires financial entities to manage ICT risk, and that explicitly extends to crypto-agility and post-quantum considerations. You cannot demonstrate crypto-agility — the ability to swap algorithms quickly — if you can't first say where your algorithms live.
- NIS2 pushes "state-of-the-art" encryption for data in transit and at rest, along with the readiness to upgrade it. "State-of-the-art" is a moving target, and the only way to evidence it is against a current inventory.
- CNSA 2.0 sets the hardest dates. The NSA expects organizations to prefer quantum-resistant algorithms for networking equipment (VPNs, routers) by 2026 and for software/firmware signing and web/cloud services by 2025, moving to exclusive use across categories between 2030 and 2033. From January 1, 2027, new National Security System acquisitions must support CNSA 2.0 — which flows straight down to federal contractors and defense suppliers.
If your organization touches more than one of these — say, a fintech that processes card payments in the EU, or a defense supplier that also handles regulated data — the requirements stack. The good news is that they share a foundation. Satisfy the inventory requirement once and you have the starting evidence for all four.
The first deliverable is always the same: an inventory
Read the table again and the pattern is unmistakable. PCI names it outright. DORA's crypto-agility presumes it. NIS2's "state-of-the-art" claim can't be substantiated without it. CNSA 2.0's deadlines can't be scheduled until you know which assets fall under which date. You cannot build a migration plan for cryptography you can't see.
This is also where most programs stall. The encryption in a modern enterprise is scattered across public-facing TLS endpoints, certificates with varying key algorithms and expiry dates, internal services, libraries, and HSMs. The public-facing layer — your TLS configuration, certificates, the RSA and ECC public-key algorithms protecting your traffic, and your HTTP security headers — is both the most exposed and the easiest place to get an authoritative, evidence-grade starting picture quickly. That external view is exactly the inventory PCI Req. 12.3.3 asks you to begin documenting, and it's the baseline a board wants to see before approving a migration budget.
This is why a cryptographic inventory is consistently described as the first step of any serious PQC program, not a side task. For a deeper treatment of what belongs in one, see what a cryptographic inventory is and why it anchors enterprise PQC migration. If you sell to or operate within the federal supply chain, the government contractor PQC compliance guide maps the CNSA 2.0 deadlines to contractor obligations in more detail.
See where your organization stands — run a free CipherReady readiness scan and get a cryptographic inventory of your public TLS, certificates, and algorithms in about 3 minutes.
How CipherReady gives you the starting inventory
CipherReady runs a safe, external, metadata-only readiness scan of domains you own or are authorized to assess. It inventories your public TLS certificates, TLS versions, DNS exposure, public-key algorithms (RSA and ECC), and HTTP security headers, then produces a CipherReady Readiness Score, an executive PDF report, AI-assisted summaries, and scheduled monitoring so your inventory stays current as certificates rotate and configurations change.
A few things it deliberately is not: it is not a vulnerability scanner or a penetration test. There is no exploitation, no credential use, and no intrusive testing — just the metadata visibility regulators are asking you to document. CipherReady is honest about its role: it is the first step, giving you the visibility and inventory that make a migration plan possible. Migration itself is a journey, and crypto-agility is what makes that journey survivable as standards evolve — see crypto-agility explained for how that capability underpins DORA-style requirements.
For compliance leaders, the executive PDF report does double duty: it's the evidence artifact for an assessor and the briefing document for leadership. If you need to translate the technical findings into board-level language, how to present cryptographic risk to your board of directors walks through framing the inventory, the deadlines, and the budget ask.
What to do in the next 90 days
You don't need to solve post-quantum migration this quarter. You need to be able to show that you've started, on the record, against the mandate that applies to you.
- Generate a baseline inventory of your public cryptographic footprint — TLS versions, certificates, key algorithms, and security headers across your domains.
- Map findings to your applicable mandate(s) — PCI Req. 12.3.3, DORA crypto-agility, NIS2 state-of-the-art, and/or CNSA 2.0 deadlines by asset class.
- Document a migration plan for deprecated and weakening algorithms, prioritizing long-lived data most exposed to HNDL.
- Put the inventory on a schedule so it stays current — certificates and configurations drift, and "documented" means "kept up to date."
- Brief leadership with the executive report and the Mosca's-theorem framing so the migration budget has a clear rationale.
Frequently Asked Questions
Does PCI DSS 4.0 really require a cryptographic inventory?
Yes. Requirement 12.3.3 mandates a documented cryptographic inventory along with a migration plan for algorithms that are deprecated or weakening. PCI 4.0's future-dated cryptographic controls took effect on March 31, 2025, so this is an assessable requirement, not an optional best practice.
We're an EU financial entity — what does DORA expect on cryptography?
DORA (in effect since January 17, 2025) requires you to manage ICT risk, and that explicitly includes crypto-agility and post-quantum readiness. In practice, you can't demonstrate the ability to rotate or upgrade algorithms quickly unless you first know where your cryptography is — which makes an inventory the practical starting point.
Do CNSA 2.0 deadlines affect us if we aren't the government?
They can. CNSA 2.0 applies to U.S. National Security Systems, and its requirements flow down to federal contractors and defense suppliers. The NSA expects organizations to prefer quantum-resistant algorithms in several categories by 2025 and networking equipment by 2026, and from January 1, 2027, new NSS acquisitions must support CNSA 2.0 — with exclusive-use deadlines between 2030 and 2033.
Is a CipherReady scan safe to run against our production domains?
Yes. The scan is external and metadata-only. It inventories public TLS, certificates, public-key algorithms, DNS exposure, and HTTP headers without exploitation, credentials, or intrusive testing. It is not a vulnerability scan or a pentest — it produces the visibility and documentation that compliance frameworks ask you to maintain.
Start with the inventory every mandate requires
PCI DSS 4.0, DORA, NIS2, and CNSA 2.0 disagree on scope and dates, but they agree on the first move: know your cryptography. A documented inventory is the foundation for every migration plan and the evidence your assessors and board will ask for.
Run a free CipherReady readiness scan and get a cryptographic inventory of your public TLS, certificates, and algorithms in about 3 minutes — the free plan includes 3 scans per month, so you can baseline and re-check as you go. When you're ready to monitor continuously, manage multiple domains, or generate ongoing executive reports for auditors, review the options on the pricing page. The deadlines are already in effect. The inventory is where you start.