← All countries

Czechia

EU roadmap Standard-taker

The Czech Republic's posture is set by the National Cyber and Information Security Agency (NÚKIB), which explains the quantum threat and quantum-resistant cryptography in an appendix to its minimum requirements and sets out expectations for when post-quantum cryptography should be deployed for sensitive information of critical confidentiality in higher-risk environments. NÚKIB has updated its Minimum Requirements for Cryptographic Algorithms to add post-quantum algorithm names and parameters in line with the finalised NIST post-quantum cryptography standards, the latest edition being version 4.1 of March 2026. NÚKIB has joined the joint statement of eighteen EU member states calling for the transition to post-quantum cryptography, and now coordinates the national transition as a partner in the Horizon Europe QARC project, which develops and validates post-quantum implementation methodologies for critical state systems. The agency's portal supports quantum-resistant cryptography, its National Cyber Security Strategy 2026-2030 names post-quantum cryptography among the technologies for strengthening cyber security, and a study for the Ministry of Industry and Trade under the National Recovery Plan addresses the migration challenge. No dated national migration deadline has been published; the timeline shown is the EU coordinated roadmap.

Governance credibility

Governance credibility for CzechiaA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Czechia, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness1.5 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law
  • NÚKIB Minimum Requirements for Cryptographic Algorithms (v4.1, March 2026) national Guidance

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

Standard families
NIST post-quantum cryptography standards (finalised August 2024)

Hybrid stance

None stated

Migration timeline

today
2030
2035
20252036
  1. 2030High-risk use cases migrated
  2. 2035Full migration of all systems complete

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap
  • Joint statement 'Securing Tomorrow, Today' (18 EU member states) signatory endorsing a risk-oriented PQC migration roadmap
  • QARC (Horizon Europe / ECCC) partner coordinating the national transition to post-quantum cryptography

Governmental and standards bodies

  • NÚKIB National Cyber and Information Security Agency, national authority for cyber security
  • MPO (Ministerstvo průmyslu a obchodu) Ministry of Industry and Trade, commissioned a National Recovery Plan study on quantum technologies and post-quantum cryptography
  • ČNB Czech National Bank, central bank research on quantum-resistant signature schemes

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →