EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can Help
-
Lees meer over hoe organisaties hun transformatie versnellen en tegelijkertijd de cyberbeveiliging versterken.
Read more
Financial institutions cannot afford to wait for EU deadlines
In June 2025, the European Commission published a roadmap for transitioning to post-quantum encryption. Supported by ENISA and the NIS Cooperation Group, the roadmap outlines key milestones: by the end of 2026, initial national PQC transition roadmaps need to be established by all member states, including awareness campaigns, and cryptographic inventories. By 2030, critical infrastructure sectors, including finance, telecommunications, and government, should be secured with PQC. The goal is to complete PQC migration across most systems in the EU by 2035, including legacy environments where feasible. (European Commission, 2025)
Currently, Dutch financial institutions have a critical window of about five years to implement post-quantum cryptography and safeguard customers, core business operations, and sensitive data from emerging quantum threats. While this may seem like ample time, historical transitions, such as the migration from SHA-1 to SHA-256, demonstrate that it is not. Organizations should, therefore, begin immediately by conducting a comprehensive cryptographic inventory and establishing crypto-agile architectures to prepare for post-quantum deployment. The year 2026 marks the quantum inflection point. Organizations may have post quantum cryptography on their radar, but it is now crucial to start taking concrete steps. Our next article will detail how to identify quantum exposed assets and build a phased migration roadmap for your organization.