Author

Comisia Europeană

1 reading card from 1 book · 2024.

1 card

  1. Recomandarea (UE) 2024/1101 privind o foaie de parcurs coordonată de punere în aplicare a tranziției la criptografia post-cuantică · 2024

    A control that produces its own evidence is audited once and reported into several frameworks.

    Three lines are already visible. First: evidence collects itself. A control described as prose and checked once a year is replaced by a control expressed as an executable rule that produces the record that it worked; the auditor reads a history, not a screenshot. Second: the supply chain. Controls 5.19-5.23 of Annex A and Article 21(2)(d) of NIS2 ask the same thing — know what your suppliers risk, and write it into the contract. The threat landscape published in 2025 by the European cybersecurity agency analysed 4,875 incidents between July 2024 and June 2025, with phishing the dominant intrusion vector, in 60% of cases. Third: post-quantum cryptography. The coordinated roadmap of June 2025 asks that the transition start by the end of 2026 and that critical infrastructures migrate no later than the end of 2030, onto the algorithms standardised in August 2024 by the American institute of standards and technology.

    Member States should consider migrating their current digital infrastructures and services for public administrations and other critical infrastructures to Post-Quantum Cryptography as soon as possible, inducing a fundamental shift in cryptographic algorithms, protocols and systems.

    Open the card