Why international businesses in the EU must prepare for post-quantum cybersecurity risks
Quantum computing has long been considered a distant technological development. Recent advances, however, indicate that practical applications may arrive much sooner than previously expected. This raises a critical question for international companies operating in the EU or Germany: will today’s encryption methods still be considered secure in the coming years? This question is no longer purely technical — it is increasingly relevant from a regulatory compliance perspective under frameworks such as NIS‑2, DORA and the Cyber Resilience Act (CRA).
The emerging quantum threat
Many widely used encryption methods rely on mathematical problems that are practically unsolvable for classical computers. Powerful quantum computers could fundamentally challenge this assumption. In this context, the term “Q‑Day” is often used to describe the point in time when quantum computers are capable of breaking established cryptographic algorithms. Importantly, the risk does not begin at Q‑Day. Already today, attackers may intercept and store encrypted data with the intention of decrypting it in the future once more powerful technologies become available (“harvest now, decrypt later”). This is particularly relevant for data requiring long-term confidentiality, such as trade secrets, sensitive business information, or security-critical data.
State of the art as a moving target
EU cybersecurity frameworks require companies to implement “appropriate technical and organizational measures,” including robust encryption. The benchmark for these obligations is the “state of the art,” which is inherently dynamic. Under NIS 2, companies must regularly reassess whether their cybersecurity measures remain adequate in light of foreseeable technological developments. This includes evaluating the resilience of existing cryptographic mechanisms against emerging threats such as quantum computing. The CRA extends similar requirements to manufacturers of products with digital elements. These must ensure cybersecurity throughout the expected lifecycle of their products. For long-lived products, this implies that cryptographic methods must be adaptable or replaceable over time. A documented risk assessment is central to this requirement, taking into account product lifecycle, sensitivity of processed data, current cryptographic methods, their potential vulnerabilities, and technical update capabilities.
Practical implications for international companies
Post-quantum cryptography should already be integrated into enterprise risk management. Companies operating in or targeting the EU market should systematically identify and document their use of cryptographic technologies, the data sensitivity and required protection level, assess system lifecycles, and evaluate whether future migration or updates are technically feasible.
For manufacturers and technology providers, this has direct implications for product design, technical documentation, vulnerability management, and contractual frameworks within supply chains. Organizations falling within the scope of NIS 2 should extend their cybersecurity strategies to explicitly include quantum resilience considerations.
We support you in assessing the regulatory implications of cryptography and security concepts, evaluating post-quantum risks, defining necessary measures, and establishing audit-proof cybersecurity documentation.
back