Norway
NIST bloc Standard-takerNorway's post-quantum posture is led by the National Security Authority (NSM). NSM runs a national quantum-migration programme and, in its Cryptographic Recommendations 2025 published in March 2025, advises organisations to build a cryptographic inventory, adopt cryptographic agility and create a plan to migrate to quantum-resistant cryptography as soon as possible. Its guidance is aimed at system owners handling sensitive information in telecom, finance, health, energy and petroleum, and it names today's RSA, ECDH, ECDSA and Diffie-Hellman as the algorithms that quantum computers will break. NSM has opened a Centre for Applied Cryptology to strengthen the country's quantum-safe preparedness. The financial supervisor, Finanstilsynet, has now joined the picture: its 2025 risk and vulnerability analysis warns of a steal data today, decrypt later threat and recommends that financial firms adopt quantum-safe encryption and related hardware. None of these documents set a dated migration deadline.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | Medium |
| Coherence | 2.0 / 2 | Medium |
| Effectiveness | 2.0 / 2 | Medium |
| Efficiency | 2.0 / 2 | Medium |
| Governance | 2.0 / 2 | Medium |
| Impact | 2.0 / 2 | Medium |
Regulatory basis
- Cryptographic Security Regulation (Forskrift om kryptosikkerhet, 2018, no. 2055) under the National Security Act (sikkerhetsloven)
- Digital Security Act (Digitalsikkerhetsloven), implementing the NIS Directive (EU) 2016/1148, in force 1 October 2025
- NSM quantum migration programme and Cryptographic Recommendations
Legal status: Binding
Binding law governs Norway's cryptographic and cyber posture: under the Security Act and its Cryptographic Security Regulation, NSM approves the cryptographic systems that protect classified information, and the Digital Security Act imposes cyber-risk duties on essential and digital service providers. Neither instrument mandates post-quantum cryptography specifically; the PQC content sits in NSM's quantum migration programme and Cryptographic Recommendations, which advise organisations to plan and carry out migration to quantum-resistant cryptography but attach no legal obligation. As an EEA state, Norway has adopted the NIS1 framework as national law and tracks NIS2 for future incorporation.
Standards and algorithms
- Standard families
- NIST FIPS 203, FIPS 204, FIPS 205
- Algorithms
- ML-KEM-768, ML-KEM-1024, ML-DSA-65, ML-DSA-87, SLH-DSA (NSM-recommended); RSA, ECDH, ECDSA, Diffie-Hellman named as quantum-vulnerable
Hybrid stance
Recommended
Migration timeline
- 2017NSM thematic report on quantum-resistant cryptography sets out the quantum threat to public-key schemes
- 2025NSM Cryptographic Recommendations 2025 advise a cryptographic inventory, cryptographic agility and a plan to migrate to quantum-resistant cryptography as soon as possible
- 2025Finanstilsynet ROS 2025 recommends financial firms adopt quantum-safe encryption and related hardware
Target completion: None stated
Governmental and standards bodies
- NSM Norwegian National Security Authority, runs the quantum migration programme and issues cryptographic recommendations
- Finanstilsynet Norwegian Financial Supervisory Authority, its 2025 risk and vulnerability analysis recommends financial firms adopt quantum-safe encryption
- Research Council of Norway Funds quantum computing strategy work referencing post-quantum cryptography
Key institutional documents
- Risiko- og sårbarhetsanalyse (ROS) 2025
- NSMs kryptografiske anbefalinger (Security Conference 2025 session)
- Kryptografiske utfordringer (Security Conference 2025 session)
- NSM Temarapport: Kvanteresistent kryptografi (thematic report on quantum-resistant cryptography)
- NSM Cryptographic Recommendations 2025 (guidance document, PDF)
- Post-quantum algorithms (Security Conference 2024 session)
- Migration to post-quantum cryptography (Security Conference 2023 session)
- NSM opens Centre for Applied Cryptology
- Quantum computers challenge today's cryptographic solutions
- Cryptographic recommendations - a guidance document from NSM (Security Act guidance)
- Cryptographic Recommendations - a guidance document from NSM (English)
- Cryptographic recommendations
- Quantum migration guide (PDF) - NSM guide to quantum relocation
- Overview report for cryptographic resources and systems
- Vulnerable algorithms (quantum migration)
- Quantum migration - guide
- What is quantum migration?
- Quantum migration
Advising on this transition, or your own sector's? Request a briefing →