Post-Quantum Cryptography Rules Converge on 2030, but Nations Diverge on Requirements
Governments worldwide are establishing 2030 as a target year for post-quantum cryptography migration, yet varying regulatory scopes are forcing multinational organizations to navigate divergent compliance pathways.

Post-quantum cryptography regulations are converting what once seemed a distant security concern into firm compliance deadlines. While many nations are aligning around 2030 as a target, the breadth and depth of these mandates differ significantly, compelling global enterprises to prepare for multiple distinct migration strategies.
Australia is mandating comprehensive migration across all systems, whereas countries in Scandinavia and the Baltic region are largely adhering to European Union timelines focused on roadmaps and critical infrastructure, according to Naomi Wynn, chief executive officer of National Energy Public Key Infrastructure (NEPKI), and Jostein Stokkan, product manager of service offerings at Atea Norge AS. The United States has taken its own approach through Executive Order 14412, which directs federal agencies to designate post-quantum cryptography migration leads and move high-value and high-impact systems to PQC for key establishment by December 31, 2030.
When it comes to PQC, we're actually leading the charge in terms of a regulatory sense. The Australian Signals Directorate and the Australian Cyber Security Centre have requested full PQC compliance and complete migration by 2030.
Naomi Wynn, CEO of NEPKI
Wynn and Stokkan shared their perspectives with Dean Coclin, senior director and digital trust specialist at DigiCert Inc., during DigiCert's World Quantum Readiness Day, in remarks broadcast on theCUBE, SiliconANGLE Media's livestreaming platform. The discussion centered on how regional mandates are reshaping migration priorities and establishing accountability frameworks.
Standards divergence adds layers to migration complexity
Beyond regulatory deadlines, nations are adopting distinct post-quantum standards, introducing additional layers of complexity for organizations operating across borders. Companies may find themselves needing to support multiple algorithm sets and evolving requirements depending on jurisdiction, Stokkan noted.
I think [different standards] will affect [PQC]. But if we can help organizations to become more crypto agile, to be able to adapt to different types of encryption as they become important or just change, I think everything will be smoother and easier for all parties.
Jostein Stokkan, product manager at Atea Norge AS
Even as regulatory pressure intensifies migration timelines, organizations remain uncertain about key implementation details. This lack of clarity is expected to influence the trajectory of future migration efforts, according to Wynn.
There is no one-size-fits-all; there is no template. But I'm hoping that by this time next year … we are seeing improved guidance as well in terms of what expectations are, what is good enough [and] what will actually meet the requirements.
Naomi Wynn, CEO of NEPKI


