The EU's Post-Quantum Cryptography Roadmap: What It Means for CNI Hiring

The EU has set a 2030 deadline for critical infrastructure to transition to post-quantum cryptography. The talent pipeline is years behind the regulatory timeline, and the harvest now, decrypt later threat means the data risk is already present.

Regulations & Compliance
Skills & Talent Gaps
Hiring Strategy
July 30, 2026
5
minutes
← Back to Insights

On 23 June 2025, the European Commission and EU Member States published a coordinated roadmap for transitioning to post-quantum cryptography. It is the clearest signal yet that quantum-safe security is no longer theoretical. It is policy.

The timeline is aggressive. All Member States should begin transitioning to PQC by the end of 2026. Critical infrastructure must complete its transition by 2030. Medium-risk systems get until 2035. After those dates, quantum-vulnerable algorithms should no longer be used independently. A formal Quantum Act is expected to be tabled in mid-2026, creating a binding legal framework across the bloc.

The US issued its own post-quantum executive order in early 2026. The direction of travel is global and irreversible.

For UK CNI organisations, the question is no longer whether to act. It is whether you have the people to act in time.

The threat is already here

The most cited justification for urgency is “harvest now, decrypt later.” Adversaries are already intercepting and storing encrypted data. The encryption protecting that data today will not survive the arrival of fault-tolerant quantum computers. When those machines mature, every piece of harvested data becomes readable.

This is not a future risk. It is a present one. Sensitive data transmitted today across energy networks, water systems, transport infrastructure and telecommunications is being collected now. The decryption may come in three years. It may come in seven. But the interception is happening today.

That reality collapses the timeline. Organisations that wait for the Quantum Act to become binding law will already be years behind. The data they should have been protecting will already be compromised.

A new category of hire

Post-quantum cryptography is not a simple upgrade. It requires rethinking how encryption is implemented across entire systems. New algorithms behave differently. Key sizes change. Performance characteristics shift. Legacy integrations break.

This creates demand for a type of professional that barely existed five years ago. Cryptography specialists who understand lattice-based and hash-based schemes. Quantum-aware security architects who can plan migration paths across complex operational technology environments. Compliance leads who understand both the mathematics and the regulatory landscape.

These are not roles you fill by rewriting an existing job description. They require a specific intersection of deep technical knowledge and practical infrastructure experience. The people who can do this work are not sitting in applicant tracking systems waiting to be found.

The talent pipeline is years behind

Here is the core problem. The regulatory timeline assumes a workforce that does not yet exist at scale.

There are pockets of expertise in academia, in government agencies, in a small number of specialist consultancies. But the volume of qualified professionals is nowhere near what CNI sectors will need to meet a 2030 deadline. The talent pipeline is years behind the regulatory timeline.

Universities are only now beginning to integrate PQC into cyber security curricula. Professional certifications have not caught up. Most practising security architects have limited exposure to post-quantum concepts. The market is being asked to deliver something it has not yet been trained to produce.

This is a workforce planning problem as much as a technology one.

What CNI organisations should do now

Waiting is the most expensive option. Every quarter of delay narrows the available talent pool further and increases competition for the small number of qualified candidates.

Organisations that move early will have three advantages. First, they will secure talent before demand peaks and salaries escalate. Second, they will build internal capability that compounds over time. Third, they will be positioned to meet regulatory deadlines without relying on last-minute contractor surges that inflate costs and introduce risk.

Practical steps include mapping your current cryptographic estate to identify quantum-vulnerable systems. Appointing a senior leader accountable for PQC transition. Building a recruitment strategy that targets the specific skill sets required, not generic cyber security profiles.

The hire you need is not another SOC analyst. It is someone who can sit between your CISO, your engineering teams and your regulators, and translate a complex mathematical transition into a deliverable programme of work.

The regulatory window is closing

The EU roadmap is a planning document. The Quantum Act will be a legal obligation. The gap between the two is the window in which smart organisations build capability.

UK CNI operators are not directly bound by EU regulation. But supply chain dependencies, cross-border data flows and the broader direction of international standards mean that alignment is not optional. Ignoring the EU timeline does not insulate you from its consequences.

The organisations that treat this as a 2030 problem will arrive at 2030 without the people, the processes or the technical foundations to comply. The ones that treat it as a 2025 hiring challenge will be ready.

The data being intercepted today does not care about your implementation timeline.

LC
Laurence Connor
Operations Director, Foundations Search
Share this article

Trusted by security leaders at

Datacor logoNomios logoBritish Airways logoForvis Mazars logoEquinix logoJamf logo

Talk To Our Founder

Book a Call

Gyles Whitnall

"I can't recommend Gyles and the team at Foundations enough. We struggled to find a suitable candidate for 5 months, Foundations found 3 perfect candidates in 24 hours."

Manager of EMEA & APAC Network Engineering, Equinix