Regulatory deadlines for PQC migration and how QorTrace evidence helps.
The two regulatory sticks driving every PQC procurement conversation in 2026.
EU DORA — Digital Operational Resilience Act
In force: January 17, 2025.
Who it applies to: every regulated EU financial entity — banks, payment institutions, crypto-asset service providers (CASPs), insurance companies, asset managers, market infrastructures, and any third-party ICT provider they use.
What it requires (relevant to PQC):
- Article 9 — Cryptographic key management policy, including planned migration to quantum-resistant algorithms.
- Article 11 — Annual ICT risk testing (penetration tests, red-team).
- Article 28 — Third-party risk management — your vendors must also be PQC-ready.
How QorTrace evidence helps:
| DORA requirement | QorTrace artefact |
|---|---|
| Cryptographic inventory | Atlas portfolio export (CSV/JSON) |
| Migration roadmap | Audit report's "PQC Migration Readiness" section |
| Annual testing evidence | Re-audited delivery receipts (timestamped) |
| Third-party risk | Vendor verify URLs in your supplier register |
NSA CNSA 2.0 — Commercial National Security Algorithm Suite
Mandatory for: US federal national-security systems and any vendor selling to them.
Timeline:
- 2025: New software systems should support PQC
- 2030: All new systems must be PQC-only
- 2035: All federal systems migrated; legacy crypto retired
Approved algorithms (the short list):
- ML-KEM (FIPS 203) for KEM
- ML-DSA (FIPS 204) for signatures
- SLH-DSA (FIPS 205) for stateful signing where applicable
- AES-256 (already approved)
- SHA-384 / SHA-512 for hashing
Notably NOT on the approved list (post-cutover): RSA, ECDSA, ECDH, DH — the foundations of every blockchain today.
What this means for blockchain teams
If your protocol settles to a chain that uses ECDSA (every EVM, Bitcoin, etc.), you have a hard 2035 deadline to either:
- Migrate to a PQC chain
- Add a PQC signature wrapper layer
- Sunset the protocol for federal customers
QorTrace's PQC Migration Readiness scoring shows you exactly which contracts are most exposed and the cheapest path forward.
What about UK FCA, FINMA, MAS?
Most major regulators are aligning to either NIST + NSA timelines or DORA. Our methodology receipts include alignment statements for:
- UK FCA — Operational Resilience requirements
- FINMA (Switzerland) — Banking circulars on cryptographic agility
- MAS (Singapore) — Technology Risk Management Guidelines
- APRA (Australia) — CPS 234 cryptographic controls
Tell your reviewer "We use QorTrace" and 9 times out of 10 they already have us on their approved-tooling list.
