Post-quantum regulations are turning a distant cybersecurity threat into concrete deadlines. Although governments are clustering around 2030, differences in scope leave multinational organizations facing multiple migration paths.
Post-quantum regulations converge on 2030 but split on scope
Post-quantum regulations are turning a distant cybersecurity threat into concrete deadlines. Although governments are clustering around 2030, differences in scope leave multinational organizations facing multiple migration paths.
SiliconANGLE
Publisher
Sep 17, 2026 at 6:15 PM UTC · 3 min read

Australia is pursuing complete migration, while Scandinavian and Baltic countries are generally following European Union timelines for roadmaps and high-risk systems, according to Naomi Wynn (pictured, right), chief executive officer of National Energy Public Key Infrastructure (NEPKI), and Jostein Stokkan (center), product manager of service offerings at Atea Norge AS. In the United States, Executive Order 14412 requires federal agencies to name post-quantum cryptography migration leads and transition high-value assets and high-impact systems to PQC for key establishment by Dec. 31, 2030.
“When it comes to PQC, we’re actually leading the charge in terms of a regulatory sense,” Wynn said. “The Australian Signals Directorate and the Australian Cyber Security Centre have requested full PQC compliance and complete migration by 2030.”
Wynn and Stokkan spoke with Dean Coclin (left), senior director and digital trust specialist at DigiCert Inc., at DigiCert’s World Quantum Readiness Day, during an exclusive broadcast on theCUBE, SiliconANGLE Media’s livestreaming studio. They discussed how regional mandates are shaping migration priorities and accountability. (* Disclosure below.)
Article Intelligence
Topics
Related Coverage
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
