Pillar D: Quantum Technologies & CybersecurityD4

Quantum-Safe Compliance

NSA CNSA 2.0, NIST FIPS 203/204/205, OMB M-23-02, ETSI QSC, quantum readiness.

Part of Pillar D: Quantum Technologies & Cybersecurity · Quantum Technologies & Cybersecurity groups the disciplines that share methods, tools, and threat models with Quantum-Safe Compliance.

What is Quantum-Safe Compliance?

Quantum-safe compliance is emerging as a distinct regulatory and standards domain as governments and industry bodies set concrete timelines for post-quantum migration. The United States is leading with aggressive mandates: NSA's CNSA 2.0 advisory requires National Security Systems to adopt quantum-resistant algorithms by 2030 for software/firmware signing and by 2033 for most other uses. OMB Memorandum M-23-02 directs federal agencies to inventory their cryptographic systems and submit migration plans.

NIST has finalized the foundational technical standards — FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA) — providing the algorithms organizations must adopt. The Cryptographic Module Validation Program (CMVP) is updating FIPS 140-3 validation to include post-quantum algorithms, which will drive adoption across regulated industries. In Europe, ETSI's Quantum-Safe Cryptography (QSC) working group and the French ANSSI have published their own guidance and timelines.

For organizations, quantum-safe compliance requires a structured approach: conducting a cryptographic inventory to identify all public-key dependencies, prioritizing migration based on data sensitivity and system lifespan, building crypto agility into procurement requirements, and establishing governance processes to track migration progress against regulatory deadlines. The compliance burden is front-loaded — the inventory and planning phase is the most resource-intensive, but delaying makes the eventual migration more expensive and risky.

Why it matters

Government mandates with hard deadlines are turning quantum-safe migration from optional future planning into a compliance requirement. Organizations that ignore CNSA 2.0 and OMB M-23-02 timelines will face regulatory consequences and procurement exclusion.

Quantum-safe compliance translates the technical requirements of post-quantum cryptography into governance, risk management, and audit frameworks that CISOs, compliance teams, and government contractors must operationalize.

Key topics

NSA CNSA 2.0 algorithm suite and migration timelines
NIST FIPS 203, 204, 205 standards
OMB Memorandum M-23-02 requirements
FIPS 140-3 validation for PQC modules
ETSI QSC guidance and European frameworks
Cryptographic inventory and discovery tools
Migration planning and prioritization frameworks
Crypto agility in procurement and contract language
Quantum readiness maturity models
Third-party and supply chain PQC compliance

People shaping this field

Researchers and practitioners worth following in this space.

NIST PQC project lead, architect of FIPS 203/204/205 standardization

Former NSA Cybersecurity Director, drove CNSA 2.0 rollout

NIST NCCoE lead on PQC migration practice guide

Curated resources

Authoritative sources we ground Quantum-Safe Compliance questions in — frameworks, research, guides, and tools.

Roles where this matters

Career paths where this domain shows up as core or recommended.

📋GRC / Compliance AnalystRecommended

Manage risk, ensure regulatory compliance, and build governance frameworks. Where security meets business strategy.

👑CISO / Security LeaderRecommended

Lead security strategy, communicate risk to the board, and build security programs. Executive-level cybersecurity leadership.

Quantum Security SpecialistCore

Prepare for the post-quantum era. Understand quantum threats and lead cryptographic migration efforts.

Certifications that signal this domain

Credentials whose blueprint meaningfully covers this domain. Core means centrally covered; also touched means present in the blueprint but not the primary focus.

Also touched

NIST PQC migration trainingProfessional·NIST / vendorsOfficial page →

NIST / vendor PQC migration training (emerging credentials)

Crypto inventory, algorithm selection (ML-KEM/ML-DSA/SLH-DSA), migration planning.

Browse all certifications → — pick a cert on the interactive map to highlight every domain it covers.

More in Quantum Technologies & Cybersecurity

Drill Quantum-Safe Compliance with adaptive difficulty

40 questions available. Skip what you know, focus where you're weak, and watch your rating move.