top of page

Europe’s Post-Quantum Readiness 2026: New EU-27 Assessment Reveals Major Differences in PQC Preparedness

  • Writer: Brian Couzens
    Brian Couzens
  • 2 days ago
  • 4 min read

SITG-Consulting has published Europe’s Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27, an independent assessment of the publicly verifiable state of post-quantum cryptography readiness across all 27 European Union Member States.

The research asks a question that is becoming increasingly important for governments, regulators, financial institutions, critical infrastructure operators and organisations operating across European borders:


How ready is Europe to execute the transition to post-quantum cryptography?

The answer is not uniform.

Our assessment finds substantial differences in the publicly verifiable evidence of national post-quantum migration readiness across the EU-27.

Some Member States have established significant elements of the machinery required to support cryptographic transition. Others demonstrate partial preparation. In several jurisdictions, however, we found limited publicly verifiable evidence of an executable national migration programme.

This matters because post-quantum migration is not simply a cryptography project.

It is becoming an issue of European digital resilience.


What does the EU-27 post-quantum readiness assessment examine?

The SITG-Consulting assessment goes beyond asking whether governments recognise the future threat posed to existing public-key cryptography by sufficiently capable quantum computers.

Recognition is not migration readiness.

The research examines publicly available evidence of the practical capabilities required to move from policy intent towards implementation.

These include:

  • national post-quantum strategy and policy direction;

  • cryptographic discovery and inventory activity;

  • implementation and technical guidance;

  • testing, pilots and experimentation;

  • procurement mechanisms;

  • governance and institutional responsibility;

  • migration timelines; and

  • evidence of execution.

Every EU Member State is assessed against a common evidence framework, providing a comparable view of publicly demonstrable readiness across the European Union.

The evidence cut-off for the assessment is 3 August 2026.


What did the assessment find?

The central finding is straightforward:

Europe has established significant policy direction on post-quantum transition, but national readiness to execute that transition remains materially uneven.

The existence of European-level direction does not automatically create national implementation capability.

A government may recognise post-quantum cryptography as a strategic issue without yet having established the discovery processes, cryptographic inventories, procurement requirements, technical guidance, governance structures and implementation programmes necessary to migrate complex public and private infrastructure.

That distinction between awareness and executable readiness is central to the report.


Why does uneven PQC readiness across Europe matter?

Cryptographic dependencies do not stop at national borders.

European financial markets, payment systems, telecommunications networks, digital identity services, government platforms, cloud infrastructure, critical infrastructure and multinational supply chains depend upon interconnected systems operating across multiple jurisdictions.

A post-quantum transition progressing at materially different speeds therefore creates a wider resilience question.

An organisation may strengthen its own cryptographic environment while remaining dependent upon counterparties, suppliers, infrastructure providers or public systems operating under different migration timelines.

The issue is consequently larger than whether individual Member States have published post-quantum strategies.

Europe must ultimately consider whether interconnected systems can transition without significant gaps emerging between jurisdictions, sectors and supply chains.


Does a low readiness assessment mean a country is doing nothing?

No.

This distinction is important.

Europe’s Post-Quantum Readiness 2026 is an empirical assessment of the publicly verifiable evidence available at the stated cut-off date.

Where evidence could not be identified, the report does not claim that no activity exists.

Government agencies, security organisations and critical infrastructure operators may undertake work that is classified, restricted or simply not publicly documented.

The assessment therefore measures what can be independently demonstrated from the public record.

This also makes the research open to challenge.

If authoritative public evidence exists that materially changes a finding or national classification, SITG-Consulting welcomes that evidence and will review it.


Why did SITG-Consulting undertake this research?

SITG-Consulting specialises in post-quantum cryptographic transition, cryptographic risk, governance, regulatory readiness and the organisational implications of large-scale cryptographic transformation.

Our work increasingly indicates that the difficult part of post-quantum migration is not simply selecting new cryptographic algorithms.

Organisations must understand where cryptography exists, what it protects, which systems and third parties depend upon it, who owns the resulting risk, how migration decisions will be governed and how transition can occur without damaging interoperability or operational resilience.

At national and European scale, those questions become considerably more complex.

We undertook this research to establish a common empirical baseline against which European progress can be examined.

Rather than asking whether Europe understands the quantum threat, the assessment asks whether the publicly observable machinery required to manage the transition is being established.


Who should read the report?

The assessment is relevant to national cybersecurity authorities, EU institutions, financial regulators, banks, insurers, telecommunications providers, critical infrastructure operators, technology suppliers, policymakers, boards, risk professionals, cryptographic specialists and organisations with significant European operations or supply-chain dependencies.

It should also be relevant to organisations currently developing their own post-quantum migration programmes.

National readiness and enterprise readiness cannot be considered entirely separately. Regulatory expectations, procurement requirements, technical standards, infrastructure dependencies and supplier capabilities will increasingly influence how organisations execute their own cryptographic transition.


Read Europe’s Post-Quantum Readiness 2026

The complete report, Europe’s Post-Quantum Readiness 2026: An Empirical Assessment of the EU-27, by Brian Couzens of SITG-Consulting, is published as an open-access research output.


Read or download the full report:


The report contains the complete EU-27 assessment, methodology, evidence base and country-level findings.


SITG-Consulting welcomes substantive scrutiny of the research and authoritative evidence capable of strengthening or correcting the public record.

For organisations seeking to understand the implications of post-quantum transition for cryptographic risk, governance, operational resilience and migration readiness, SITG-Consulting is also available for independent strategic discussion and analysis.

 
 
 

Comments


bottom of page