Finland
EU roadmap Standard-takerFinland now has an active national post-quantum cryptography posture led by Traficom's National Cyber Security Centre (NCSC-FI) and its national cryptography working group. From 1 January 2026 cryptographic products entering national evaluation must use quantum-safe key establishment and quantum-safe signature algorithms, or document how the quantum risk is addressed, with hybrid post-quantum plus classical deployment strongly recommended. In March 2026 NCSC-FI published guidance for organisations on migrating to quantum-safe cryptography, covering crypto-inventory, risk assessment, crypto-agility and a step-by-step transition plan, and urged the protection of long-confidentiality data. Broader ambition is set by the Finnish Government Quantum Technology Strategy 2025 to 2035 and discussed by the state research centre VTT. Finland follows the EU coordinated roadmap for migration dates, and the gathered documents do not name specific algorithms or standard families.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | High |
| Coherence | 2.0 / 2 | High |
| Effectiveness | 2.0 / 2 | High |
| Efficiency | 2.0 / 2 | High |
| Governance | 2.0 / 2 | High |
| Impact | 2.0 / 2 | High |
Regulatory basis
- National cryptography working group requirements for national PQC product evaluations (from 1 January 2026)
- NCSC-FI guidance on migrating to quantum-safe encryption (March 2026)
- NIS2 Directive (EU) 2022/2555, Art. 21(2)(h)
- DORA, Regulation (EU) 2022/2554 (financial sector)
- Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap
- NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035)
Legal status: Binding
Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.
Standards and algorithms
No standards or algorithms specified.
Hybrid stance
Recommended
Migration timeline
- 2026National cryptography working group requires quantum-safe KEM and signatures for products entering national evaluation; hybrid strongly recommended
- 2030High-risk use cases migrated (EU coordinated roadmap)
- 2035Full migration of all systems complete (EU coordinated roadmap)
Target completion: 2035
International standards processes
- NIS Cooperation Group co-authored the EU coordinated PQC roadmap
Governmental and standards bodies
- Traficom / Kyberturvallisuuskeskus (NCSC-FI), Suomen kansallinen kryptotyöryhmä national cryptography working group; sets binding quantum-safe requirements for products entering national evaluation from 1 January 2026
- Traficom / Kyberturvallisuuskeskus (NCSC-FI) national cyber security authority; publishes PQC migration guidance for organisations
- Finnish Government (Valtioneuvosto) publishes the national Quantum Technology Strategy 2025 to 2035
- VTT Technical Research Centre of Finland state research centre, discusses quantum-safe cryptography and the need for near-term solutions
Key institutional documents
- Ohje kvanttiturvalliseen salaukseen siirtymisestä julkaistu, infotilaisuus asiantuntijoille
- Kvanttiturvallinen salaus ja PQC-siirtymä (organisaatioiden ohjesivusto)
- Suomen kansallisen kryptotyöryhmän linjaukset kansallisiin PQC-salaustuotearviointeihin 1.1.2026 alkaen
- From threat scenarios to quantum-safe cryptography: how to secure digital trust
- Finland's Quantum Technology Strategy 2025–2035
Advising on this transition, or your own sector's? Request a briefing →