← All countries

Sweden

EU roadmap Standard-taker

Sweden's transition is steered by the National Cyber Security Centre, hosted by the National Defence Radio Establishment (FRA), which has issued national recommendations setting out how organisations should carry out the move to quantum-safe cryptography. The recommendations now fix recommended timepoints, with the general transition to be completed by the end of 2035 and information that must stay protected for ten years or more to be migrated by the end of 2030, and they name the NIST FIPS 203, FIPS 204 and FIPS 205 standards as the algorithms to adopt. FRA frames the change around the harvest-now-decrypt-later threat and says Swedish authorities will lead the transition over the coming years. The recommendations are framed in relation to NIS2 and the Swedish cybersecurity act, and Parliament has welcomed the European approach to promoting the transition.

Governance credibility

Governance credibility for SwedenA six-axis reading out of two: Relevance 2.0 / 2, Coherence 2.0 / 2, Effectiveness 1.5 / 2, Efficiency 2.0 / 2, Governance 2.0 / 2, Impact 2.0 / 2.RelCohEffEff.GovImp
Governance credibility scores for Sweden, each out of two. Hover or focus a row to highlight its axis.
CriterionScoreConfidence
Relevance2.0 / 2High
Coherence2.0 / 2High
Effectiveness1.5 / 2High
Efficiency2.0 / 2High
Governance2.0 / 2High
Impact2.0 / 2High

Regulatory basis

  • NCSC Sweden national recommendations and recommended timepoints (Tidpunkter) for the transition to quantum-safe cryptography National Guidance
  • NIS2 Directive (EU) 2022/2555, Art. 21(2)(h) EU Binding law
  • DORA, Regulation (EU) 2022/2554 (financial sector) EU Binding law
  • Commission Recommendation (EU) 2024/1101 on a coordinated PQC roadmap EU Soft law
  • NIS Cooperation Group Coordinated Implementation Roadmap (2026/2030/2035) EU Soft law

Essential and important entities must use state-of-the-art cryptography under NIS2, transposed into national law, and financial entities face equivalent duties under DORA; neither yet names post-quantum algorithms specifically. Migration follows the EU coordinated roadmap, with high-risk use cases targeted for 2030 and full migration by 2035, which is encouraged rather than mandated.

Standards and algorithms

Standard families
NIST FIPS 203, FIPS 204, FIPS 205
Algorithms
ML-KEM, ML-DSA, SLH-DSA

Hybrid stance

None stated

Migration timeline

today
2030
2035
20252036
  1. 2030Information needing protection for ten years or more migrated to quantum-safe cryptography
  2. 2035General transition to quantum-safe cryptography completed

Target completion: 2035

International standards processes

  • NIS Cooperation Group co-authored the EU coordinated PQC roadmap

Governmental and standards bodies

  • NCSC Sweden National Cyber Security Centre, issues national recommendations and recommended timepoints for the transition to quantum-safe cryptography and names the NIST FIPS algorithms
  • FRA National Defence Radio Establishment, hosts the NCSC and presents on the transition, framing the harvest-now-decrypt-later threat
  • Riksdagen Swedish Parliament, fact memos welcoming the EU quantum strategy and digital-infrastructure approach
  • Government of Sweden identifies the transition to quantum-safe cryptography as part of strengthening Europe's cybersecurity

Key institutional documents

Advising on this transition, or your own sector's? Request a briefing →