The 2026 Compliance Lens
DORA has applied since 17 January 2025, so financial institutions are now operating—not merely preparing— under its ICT-risk and resilience framework. DORA does not mandate post-quantum cryptography or name specific PQC algorithms. The connection is operational: cryptographic deprecation, HSM or PKI replacement, protocol change and supplier migration can all affect availability, integrity, testing and third-party risk. The EU’s separate PQC roadmap adds a strategic policy signal. The professional approach is therefore to embed quantum-readiness evidence into established DORA governance without misrepresenting PQC as a direct DORA requirement.
DORA changes the governance context
DORA requires financial entities to manage ICT risk and operational resilience through structured governance, testing, incident management and third-party oversight. It is not a post-quantum cryptography regulation. However, the operating model it creates is highly relevant to PQC transition because cryptographic dependencies sit inside the same critical services, ICT assets and suppliers that financial institutions must already govern.
Cryptographic change can become an operational-resilience event
If an algorithm, implementation or trust service must be retired faster than planned, the challenge is not only technical. Banks and insurers may need to coordinate HSMs, PKI, APIs, payment interfaces, customer channels, cloud providers and software suppliers within constrained change windows. The capacity to identify dependencies, test migration patterns and execute controlled change is therefore part of resilience.
Third parties may define the critical path
Financial services rely heavily on ICT providers, packaged software, cloud services and specialised cryptographic hardware. A firm may be internally prepared but still unable to migrate a critical service until a supplier supports the required mechanisms. PQC readiness should therefore be added to supplier assurance, architecture standards, procurement requirements and exit / substitution planning where relevant.
Evidence matters as much as intention
A defensible transition programme should show what the organisation knows, what it has prioritised and how decisions are governed. Useful evidence includes cryptographic inventories, risk assessments, migration plans, architecture decisions, supplier commitments, test results, exceptions and management reporting. This evidence can support the same governance discipline expected in broader ICT-risk management.
The practical next step
Financial institutions do not need to invent a separate quantum governance universe. They can embed cryptographic agility into existing DORA-aligned processes: ICT asset management, risk assessment, change management, resilience testing, supplier governance and board reporting. The result is a transition capability that is more durable than a one-time technology upgrade.
Key Takeaway
QSD perspective: Integrate cryptographic discovery and PQC transition into your existing ICT-risk and operational-resilience governance, with supplier readiness treated as a first-class dependency.