← All countries

Norway

NIST bloc Standard-taker

Norway's post-quantum posture is led by the National Security Authority (NSM). NSM runs a national quantum-migration programme and, in its Cryptographic Recommendations 2025 published in March 2025, advises organisations to build a cryptographic inventory, adopt cryptographic agility and create a plan to migrate to quantum-resistant cryptography as soon as possible. Its guidance is aimed at system owners handling sensitive information in telecom, finance, health, energy and petroleum, and it names today's RSA, ECDH, ECDSA and Diffie-Hellman as the algorithms that quantum computers will break. NSM has opened a Centre for Applied Cryptology to strengthen the country's quantum-safe preparedness. The financial supervisor, Finanstilsynet, has now joined the picture: its 2025 risk and vulnerability analysis warns of a steal data today, decrypt later threat and recommends that financial firms adopt quantum-safe encryption and related hardware. None of these documents set a dated migration deadline.

Governance credibility

Governance credibility for NorwayA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 2.0 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Norway, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2Medium
Coherence2.0 / 2Medium
Effectiveness2.0 / 2Medium
Efficiency2.0 / 2Medium
Governance2.0 / 2Medium
Impact2.0 / 2Medium

Regulatory basis

  • Cryptographic Security Regulation (Forskrift om kryptosikkerhet, 2018, no. 2055) under the National Security Act (sikkerhetsloven) national Binding law
  • Digital Security Act (Digitalsikkerhetsloven), implementing the NIS Directive (EU) 2016/1148, in force 1 October 2025 national Binding law
  • NSM quantum migration programme and Cryptographic Recommendations national Guidance

Binding law governs Norway's cryptographic and cyber posture: under the Security Act and its Cryptographic Security Regulation, NSM approves the cryptographic systems that protect classified information, and the Digital Security Act imposes cyber-risk duties on essential and digital service providers. Neither instrument mandates post-quantum cryptography specifically; the PQC content sits in NSM's quantum migration programme and Cryptographic Recommendations, which advise organisations to plan and carry out migration to quantum-resistant cryptography but attach no legal obligation. As an EEA state, Norway has adopted the NIS1 framework as national law and tracks NIS2 for future incorporation.

Standards and algorithms

Standard families
NIST FIPS 203, FIPS 204, FIPS 205
Algorithms
ML-KEM-768, ML-KEM-1024, ML-DSA-65, ML-DSA-87, SLH-DSA (NSM-recommended); RSA, ECDH, ECDSA, Diffie-Hellman named as quantum-vulnerable

Hybrid stance

Recommended

Migration timeline

today
2017
2025
2025
20252036
  1. 2017NSM thematic report on quantum-resistant cryptography sets out the quantum threat to public-key schemes
  2. 2025NSM Cryptographic Recommendations 2025 advise a cryptographic inventory, cryptographic agility and a plan to migrate to quantum-resistant cryptography as soon as possible
  3. 2025Finanstilsynet ROS 2025 recommends financial firms adopt quantum-safe encryption and related hardware

Target completion: None stated

Governmental and standards bodies

  • NSM Norwegian National Security Authority, runs the quantum migration programme and issues cryptographic recommendations
  • Finanstilsynet Norwegian Financial Supervisory Authority, its 2025 risk and vulnerability analysis recommends financial firms adopt quantum-safe encryption
  • Research Council of Norway Funds quantum computing strategy work referencing post-quantum cryptography

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →