← All countries

Finland

EU roadmap Standard-taker

Finland now has an active national post-quantum cryptography posture led by Traficom's National Cyber Security Centre (NCSC-FI) and its national cryptography working group. From 1 January 2026 cryptographic products entering national evaluation must use quantum-safe key establishment and quantum-safe signature algorithms, or document how the quantum risk is addressed, with hybrid post-quantum plus classical deployment strongly recommended. In March 2026 NCSC-FI published guidance for organisations on migrating to quantum-safe cryptography, covering crypto-inventory, risk assessment, crypto-agility and a step-by-step transition plan, and urged the protection of long-confidentiality data. Broader ambition is set by the Finnish Government Quantum Technology Strategy 2025 to 2035 and discussed by the state research centre VTT. Finland follows the EU coordinated roadmap for migration dates, and the gathered documents do not name specific algorithms or standard families.

Governance credibility

Governance credibility for FinlandA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 2.0 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Finland, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness2.0 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • National cryptography working group requirements for national PQC product evaluations (from 1 January 2026) National Binding law
  • NCSC-FI guidance on migrating to quantum-safe encryption (March 2026) National Guidance
  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

No standards or algorithms specified.

Hybrid stance

Recommended

Migration timeline

today
2026
2030
2035
20252036
  1. 2026National cryptography working group requires quantum-safe KEM and signatures for products entering national evaluation; hybrid strongly recommended
  2. 2030High-risk use cases migrated (EU coordinated roadmap)
  3. 2035Full migration of all systems complete (EU coordinated roadmap)

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap

Governmental and standards bodies

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →