01%
HomeProducts & SolutionsConsultingQ-TR PlatformR&DProjectsBlog & NewsAbout UsContactLegalImpressumPrivacy PolicyCookie PolicyTerms & ConditionsAccessibility StatementLanguageEnglishDeutsch
All insights
Blog & News
Regulatory Update

DORA & PQC: What Financial Institutions Need to Know Now

Why post-quantum readiness belongs inside digital operational resilience rather than in a separate research track.

PublishedFebruary 2026
AuthorQSD Editorial

The 2026 Compliance Lens

DORA has applied since 17 January 2025, so financial institutions are now operating—not merely preparing— under its ICT-risk and resilience framework. DORA does not mandate post-quantum cryptography or name specific PQC algorithms. The connection is operational: cryptographic deprecation, HSM or PKI replacement, protocol change and supplier migration can all affect availability, integrity, testing and third-party risk. The EU’s separate PQC roadmap adds a strategic policy signal. The professional approach is therefore to embed quantum-readiness evidence into established DORA governance without misrepresenting PQC as a direct DORA requirement.

DORA changes the governance context

DORA requires financial entities to manage ICT risk and operational resilience through structured governance, testing, incident management and third-party oversight. It is not a post-quantum cryptography regulation. However, the operating model it creates is highly relevant to PQC transition because cryptographic dependencies sit inside the same critical services, ICT assets and suppliers that financial institutions must already govern.

Cryptographic change can become an operational-resilience event

If an algorithm, implementation or trust service must be retired faster than planned, the challenge is not only technical. Banks and insurers may need to coordinate HSMs, PKI, APIs, payment interfaces, customer channels, cloud providers and software suppliers within constrained change windows. The capacity to identify dependencies, test migration patterns and execute controlled change is therefore part of resilience.

Third parties may define the critical path

Financial services rely heavily on ICT providers, packaged software, cloud services and specialised cryptographic hardware. A firm may be internally prepared but still unable to migrate a critical service until a supplier supports the required mechanisms. PQC readiness should therefore be added to supplier assurance, architecture standards, procurement requirements and exit / substitution planning where relevant.

Evidence matters as much as intention

A defensible transition programme should show what the organisation knows, what it has prioritised and how decisions are governed. Useful evidence includes cryptographic inventories, risk assessments, migration plans, architecture decisions, supplier commitments, test results, exceptions and management reporting. This evidence can support the same governance discipline expected in broader ICT-risk management.

The practical next step

Financial institutions do not need to invent a separate quantum governance universe. They can embed cryptographic agility into existing DORA-aligned processes: ICT asset management, risk assessment, change management, resilience testing, supplier governance and board reporting. The result is a transition capability that is more durable than a one-time technology upgrade.

Key Takeaway

QSD perspective: Integrate cryptographic discovery and PQC transition into your existing ICT-risk and operational-resilience governance, with supplier readiness treated as a first-class dependency.

Related
DORAFinancial ServicesOperational Resilience

Connect PQC readiness to your DORA operating model

Explore Regulatory & Compliance Advisory.

NIST FIPS 203NIST FIPS 204NIST FIPS 205EU NIS2DORA RegulationEU AI ActISO/IEC 27001GDPR · DSGVOHR 7535 PQC ActZero-Trust SP 800-207NIST FIPS 203NIST FIPS 204NIST FIPS 205EU NIS2DORA RegulationEU AI ActISO/IEC 27001GDPR · DSGVOHR 7535 PQC ActZero-Trust SP 800-207
Quantum-Pulse
QSD Theme · Click to play