← All countries

Spain

EU roadmap Standard-taker

Spain's posture now runs on two tracks. INCIBE and its INCIBE-CERT carry the awareness and early-warning work, framing the quantum threat and the need for post-quantum cryptography, while the national coordination centre (NCC-ES) presents the European public-administration transition roadmap. The technical authority is the Centro Criptologico Nacional (CCN), whose CCN-STIC 221 guide of November 2025 sets out the cryptographic mechanisms it authorises, including a dedicated post-quantum chapter covering lattice-based schemes such as ML-KEM and FrodoKEM, and whose CCN-TEC 009 recommendations set out a safe transition and advise early adoption of hybrid solutions for protocols like TLS and IKEv2. Parliamentary guidance from the Cortes Generales states that the transition must begin from a complete inventory of cryptographic systems, protocols and algorithms. Spain has no published national migration deadline of its own; the dated milestones it works to are those of the EU coordinated roadmap.

Governance credibility

Governance credibility for SpainA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 2.0 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Spain, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness2.0 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law
  • CCN-STIC 221 Guia de mecanismos criptograficos autorizados por el CCN (Nov 2025) national Guidance
  • CCN-TEC 009 Recomendaciones para una transicion postcuantica segura national Guidance

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

Standard families
CCN-STIC 221 (CCN authorised cryptographic mechanisms, post-quantum chapter)
Algorithms
ML-KEM, FrodoKEM

Hybrid stance

Recommended

Migration timeline

today
2030
2035
20252036
  1. 2030High-risk use cases migrated (EU coordinated roadmap)
  2. 2035Full migration of all systems complete (EU coordinated roadmap)

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap

Governmental and standards bodies

  • INCIBE Spanish National Cybersecurity Institute, leads national cybersecurity work and hosts the national coordination centre (NCC-ES)
  • INCIBE-CERT national CERT, publishes guidance and advisories on the quantum threat and post-quantum cryptography
  • CCN (Centro Criptológico Nacional) national cryptologic authority, publishes the CCN-STIC 221 guide of authorised cryptographic mechanisms (with a post-quantum chapter) and the CCN-TEC 009 recommendations for a secure post-quantum transition
  • CCN-CERT (Centro Criptológico Nacional) national governmental CERT within the CCN, announces the CCN-STIC 221 and CCN-TEC 009 post-quantum publications
  • Congreso de los Diputados Spanish Congress, parliamentary bulletins framing the transition around a complete cryptographic inventory
  • Cortes Generales (Congreso de los Diputados) issuing body of the BOCG serie A no. 223 bulletin on the post-quantum transition
  • Oficina Nacional de Prospectiva national foresight office, trend analysis on post-quantum cryptography
  • Banco de España central bank, studies post-quantum cryptography against the store-now-decrypt-later threat and notes that a future transition requires substantial effort and advance planning

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →