New Zealand
NIST bloc Standard-takerNew Zealand's technical guidance comes through the New Zealand Information Security Manual, maintained by the National Cyber Security Centre within the GCSB. Section 2.4 of the manual advises government agencies to inventory their cryptographically protected assets and begin planning migration to post-quantum cryptographic standards, pointing to the NIST post-quantum work as the reference. In February 2026 this was reinforced at strategy level for the first time: New Zealand's Cyber Security Strategy 2026-2030, published by the Department of the Prime Minister and Cabinet, warns that quantum computing could render current encryption methods obsolete within the strategy's timeframe and commits the GCSB to refresh its Cryptographic Products Management Infrastructure so that government ICT is prepared for a post-quantum world. The posture remains preparatory and advisory rather than a binding migration mandate, and no completion date or specific algorithm set has been published.
Governance credibility
| Criterion | Score | Confidence |
|---|---|---|
| Relevance | 2.0 / 2 | Medium |
| Coherence | 1.5 / 2 | Medium |
| Effectiveness | 2.0 / 2 | Medium |
| Efficiency | 2.0 / 2 | Medium |
| Governance | 2.0 / 2 | Medium |
| Impact | 2.0 / 2 | Medium |
Regulatory basis
- Protective Security Requirements (PSR) mandatory requirements
- New Zealand Information Security Manual (NZISM) post-quantum preparation guidance (Section 2.4)
- New Zealand's Cyber Security Strategy 2026-2030 (post-quantum commitment)
Legal status: Binding
Government agencies covered by the Protective Security Requirements (a Cabinet direction binding on public service departments and other mandated agencies, not a statute) must manage information security in line with the PSR's mandatory requirements and report annually on compliance. The post-quantum element is advisory only: NZISM Section 2.4 directs agencies to inventory cryptographically protected assets and plan migration to post-quantum standards referencing the NIST work, and compliance with the NZISM is not required as a matter of law. No obligation falls on the wider economy.
Standards and algorithms
No standards or algorithms specified.
Hybrid stance
None stated
Migration timeline
- 2026National Cyber Security Strategy commits GCSB to refresh its Cryptographic Products Management Infrastructure for a post-quantum world, within the 2026-2030 strategy period
Target completion: None stated
Governmental and standards bodies
- NCSC / GCSB National Cyber Security Centre within the Government Communications Security Bureau, maintains the NZISM and its post-quantum preparation guidance; the GCSB is tasked by the 2026-2030 strategy with refreshing its Cryptographic Products Management Infrastructure
- DPMC Department of the Prime Minister and Cabinet, author of New Zealand's Cyber Security Strategy 2026-2030, the first national-strategy-level acknowledgement of the post-quantum transition
Key institutional documents
Advising on this transition, or your own sector's? Request a briefing →