← All countries

Italy

EU roadmap Standard-taker

Italy's posture is led by the National Cybersecurity Agency, the ACN. In 2026 the ACN updated its cryptographic functions guidelines to evaluate quantum-resistant solutions, adding post-quantum alternatives for digital signature schemes and post-quantum solutions in the TLS guidelines, with the update described as aligned to the NIST post-quantum standards published in August 2024. At the policy level Italy presented a national Strategy for Quantum Technologies in 2025, which sets migration to post-quantum cryptography as a strategic objective in line with EU recommendations and with ACN support. The Bank of Italy is active on the financial-sector side, having run post-quantum experiments in real payment systems through the BIS Project Leap and worked on a quantum-safe public key infrastructure. The Italian Parliament, the Ministry of Enterprises and Made in Italy, and the Department for Digital Transformation have all addressed post-quantum cryptography in defence, industrial and strategy documents.

Governance credibility

Governance credibility for ItalyA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Italy, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness1.5 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

Standard families
NIST PQC standards (published August 2024)

Hybrid stance

None stated

Migration timeline

today
2030
2035
20252036
  1. 2030High-risk use cases migrated
  2. 2035Full migration of all systems complete

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap

Governmental and standards bodies

  • ACN Agenzia per la Cybersicurezza Nazionale, guidance on post-quantum and quantum cryptography referencing the NIST process and EU transition material, and 2026 update of the cryptographic functions guidelines adding post-quantum alternatives for signatures and TLS aligned to the NIST PQC standards
  • Banca d'Italia Bank of Italy, post-quantum experiments in real payment systems via BIS Project Leap, a quantum-safe PKI implementation in a payment systems environment, and notices on the G7 financial-sector roadmap
  • Dipartimento per la Trasformazione Digitale Department for Digital Transformation, presented the national Strategy for Quantum Technologies setting migration to post-quantum cryptography as a strategic objective in line with EU recommendations
  • Senato Italian Senate documents covering the defence multi-year acquisition programme SMD 41/2025 including post-quantum cryptography and national PQC activities
  • Camera dei Deputati Chamber of Deputies, Defence Committee inquiry on quantum technologies for defence and security discussing post-quantum cryptography
  • MIMIT (MISE) Ministry of Enterprises and Made in Italy, report mapping Italy's quantum industrial ecosystem and addressing post-quantum cryptography for enterprises and critical digital infrastructure

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →