Global Post-Quantum Regulatory Matrix
Understanding what is legally binding versus what is supervisory guidance is essential for risk officers and legal counsels. Overclaiming regulatory mandates creates cynicism; underestimating supervisory discovery expectations leads to audit findings.
| Jurisdiction / Body | Key Instrument | Binding Status | Key Milestones | Scope & Impact |
|---|---|---|---|---|
| G7 Cyber Expert Group | Financial Sector PQC Roadmap (13 Jan 2026) | Supervisory Guidance | 2026: Discovery 2030–2032: Critical systems |
Co-chaired by US Treasury & Bank of England. Sets international coordination principles for cross-border banking. Cites BIS Project Leap. |
| United States | Executive Order 14412 (June 2026) / OMB M-26-15 | Binding on Federal & Contractors | 2030: Key establishment (HVAs) 2031: Digital signatures End 2030: Contractors |
Requires High-Value Assets (HVAs) and federal contractors processing covered financial data to transition to FIPS 203/204 algorithms. |
| Hong Kong (HKMA) | Quantum Preparedness Index (July 2026) | Supervisory Baseline Index | July 2026: Baseline (2.3/10) 2030: Target full readiness |
First comprehensive central bank preparedness index benchmarking authorized institutions across governance, inventory, and agility. |
| Israel (Bank of Israel) | Supervisor of Banks Directive | Binding Central Bank Directive | January 2026: Roadmaps submitted | Required all commercial banking corporations to submit board-approved quantum preparedness and algorithm replacement roadmaps. |
| NIST CMVP | FIPS 140-2 Deprecation | Binding Technical Standard | 21 Sep 2026: Historical List | All remaining FIPS 140-2 cryptographic modules moved to Historical list. Banking HSMs must validate to FIPS 140-3. |
| European Union | DORA (Art. 9 and its RTS on ICT risk management) & CRA | Statutory Law | End 2026: Member-state plans 2030: High-risk systems |
Mandates cryptographic agility, supply-chain CBOM transparency, and threat-led penetration testing (TLPT). |
| United Kingdom | NCSC Quantum Readiness Guidelines | National Cyber Strategy Guidance | 2028: Discovery / CBOM 2031: Critical infrastructure 2035: Legacy phase-out |
Establishes phased discovery and migration timelines for systemic payment utilities and critical national infrastructure. |
| Singapore (MAS) | MAS Technology Risk Management & Quantum Advisory | Supervisory Advisory | 2026: Cryptographic asset review | Recommends dual-key encapsulation mechanisms for financial market infrastructures and SWIFT cross-border gateways. |