Lithuania
EU roadmap Standard-takerLithuania now has a national direction for post-quantum cryptography. In 2026 the Government approved a national transition plan, prepared and coordinated by the Ministry of National Defence with the National Cyber Security Centre, that sets staged deadlines for cybersecurity entities: a cryptographic inventory by 2027, post-quantum or hybrid protection in high-risk systems by 2031, and a move to post-quantum-only cryptography from 2036. The Ministry recommends hybrid deployment that combines classical and post-quantum algorithms during the transition, and the work is run through a National Post-Quantum Cryptography Coordination Working Group. Lithuania frames this national effort alongside the EU coordinated roadmap rather than as a departure from it, and its guidance continues to direct organisations to begin with a cryptographic inventory.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | High |
| Coherence | 2.0 / 2 | High |
| Effectiveness | 2.0 / 2 | High |
| Efficiency | 2.0 / 2 | High |
| Governance | 2.0 / 2 | High |
| Impact | 2.0 / 2 | High |
Regulatory basis
- Government-approved national post-quantum cryptography transition plan (2026)
- NIS2 Directive (EU) 2022/2555, Art. 21(2)(h)
- DORA, Regulation (EU) 2022/2554 (financial sector)
- Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap
- NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035)
Legal status: Binding
Lithuania's Government has approved a national post-quantum cryptography transition plan that sets staged deadlines for cybersecurity entities: a cryptographic inventory by 2027, post-quantum or hybrid cryptography in high-risk systems by 2031, and post-quantum-only cryptography from 2036. The Ministry of National Defence recommends hybrid deployment during the transition. These national obligations sit alongside the EU framework, under which essential and important entities must use state-of-the-art cryptography under NIS2 as transposed into national law and financial entities face equivalent duties under DORA; neither EU instrument yet names post-quantum algorithms specifically.
Standards and algorithms
No standards or algorithms specified.
Hybrid stance
Recommended
Migration timeline
- 2027National plan: cryptographic inventory to be completed
- 2031National plan: post-quantum or hybrid cryptography in high-risk systems
- 2036National plan: transition to post-quantum-only cryptography
Target completion: Phased (no fixed end)
International standards processes
- NIS Cooperation Group co-authored the EU coordinated PQC roadmap and its PQC working group roadmap referenced in the 2025 national status report
Governmental and standards bodies
- NKSC National Cyber Security Centre of Lithuania, sets national guidance on post-quantum cryptography and the cryptographic inventory
- KAM (Ministry of National Defence) Ministry of National Defence, prepared and coordinates the Government-approved national post-quantum cryptography transition plan
- National PQC Coordination Working Group national working group coordinating Lithuania's post-quantum cryptography transition
Key institutional documents
- Artėja kvantinių kompiuterių era: kaip verslas turi apsaugoti savo duomenis nuo naujos kartos kibernetinių grėsmių (The quantum computing era is approaching: how business must protect its data)
- Nacionalinė kibernetinio saugumo būklės ataskaita 2025 (National Cybersecurity Status Report 2025)
- Ilgalaikiam saugumui – postkvantinė kriptografija: Vyriausybė patvirtino kryptį
- Postkvantinė kriptografija (Post-quantum cryptography)
- Ilgalaikiam saugumui – postkvantinė kriptografija: Vyriausybė patvirtino kryptį (For long-term security – post-quantum cryptography: Government approves the direction)
- Overview of the cybersecurity status in Lithuania: key information
- CTAC 2024 Yearly Report
- Guidelines for cryptography use inventory
- Digital Europe Programme calls (info day presentation)
- Post-quantum cryptography
- Quantum computing threats to current cryptography: reality or hype (post-quantum cryptography presentation)
Advising on this transition, or your own sector's? Request a briefing →