← All countries

Lithuania

EU roadmap Standard-taker

Lithuania now has a national direction for post-quantum cryptography. In 2026 the Government approved a national transition plan, prepared and coordinated by the Ministry of National Defence with the National Cyber Security Centre, that sets staged deadlines for cybersecurity entities: a cryptographic inventory by 2027, post-quantum or hybrid protection in high-risk systems by 2031, and a move to post-quantum-only cryptography from 2036. The Ministry recommends hybrid deployment that combines classical and post-quantum algorithms during the transition, and the work is run through a National Post-Quantum Cryptography Coordination Working Group. Lithuania frames this national effort alongside the EU coordinated roadmap rather than as a departure from it, and its guidance continues to direct organisations to begin with a cryptographic inventory.

Governance credibility

Governance credibility for LithuaniaA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 2.0 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Lithuania, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness2.0 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • Government-approved national post-quantum cryptography transition plan (2026) national Binding law
  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law

Lithuania's Government has approved a national post-quantum cryptography transition plan that sets staged deadlines for cybersecurity entities: a cryptographic inventory by 2027, post-quantum or hybrid cryptography in high-risk systems by 2031, and post-quantum-only cryptography from 2036. The Ministry of National Defence recommends hybrid deployment during the transition. These national obligations sit alongside the EU framework, under which essential and important entities must use state-of-the-art cryptography under NIS2 as transposed into national law and financial entities face equivalent duties under DORA; neither EU instrument yet names post-quantum algorithms specifically.

Standards and algorithms

No standards or algorithms specified.

Hybrid stance

Recommended

Migration timeline

today
2027
2031
2036
phased →
20252036
  1. 2027National plan: cryptographic inventory to be completed
  2. 2031National plan: post-quantum or hybrid cryptography in high-risk systems
  3. 2036National plan: transition to post-quantum-only cryptography

Target completion: Phased (no fixed end)

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap and its PQC working group roadmap referenced in the 2025 national status report

Governmental and standards bodies

  • NKSC National Cyber Security Centre of Lithuania, sets national guidance on post-quantum cryptography and the cryptographic inventory
  • KAM (Ministry of National Defence) Ministry of National Defence, prepared and coordinates the Government-approved national post-quantum cryptography transition plan
  • National PQC Coordination Working Group national working group coordinating Lithuania's post-quantum cryptography transition

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →