← All countries

Portugal

EU roadmap Standard-taker

Portugal's activity is centred on the National Cybersecurity Centre, whose National Coordination Centre funds work on the security evaluation of post-quantum cryptography primitives and the security of post-quantum algorithm implementations, and which lists post-quantum cryptography among the priority topics for its C-DAYS 2026 conference. The posture is one of research and awareness, with no published national migration guidance, algorithm list or timeline. Portugal follows the European Union coordinated approach, under which essential and important entities must use state-of-the-art cryptography and migration is encouraged towards high-risk use cases by 2030 and full migration by 2035, but neither obligation yet names post-quantum algorithms specifically.

Governance credibility

Governance credibility for PortugalA six-axis reading out of two: Relevance 2.0 / 2, Coherence 1.5 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 1.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Portugal, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence1.5 / 2High
Effectiveness1.5 / 2High
Efficiency2.0 / 2High
Governance1.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding (market access)
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding (market access)
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

No standards or algorithms specified.

Hybrid stance

None stated

Migration timeline

today
2030
2035
20252036
  1. 2030High-risk use cases migrated
  2. 2035Full migration of all systems complete

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap

Governmental and standards bodies

  • CNCS National Cybersecurity Centre, national authority for cyber security

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →