How does quantum computing intersect with compliance?
Most major data-protection regulations already require organizations to protect personal and sensitive data using appropriate, up-to-date security measures, and quantum computing quietly raises what "appropriate" means. As post-quantum standards become the accepted baseline for strong cryptography, continuing to rely solely on algorithms known to be quantum-vulnerable will increasingly look like a failure of due care. Compliance frameworks rarely name specific algorithms, but their language of "state of the art," "reasonable security," and "appropriate technical measures" is exactly where the quantum threat lands.
For regulated enterprises, this reframes post-quantum migration from an optional IT modernization into a governance and, ultimately, a legal obligation. The question a board will eventually ask is not "is quantum interesting?" but "are we still meeting our duty of care if we knowingly protect regulated data with cryptography we know will be broken?"
Which regulations are most affected?
The frameworks that demand strong, current data protection are the ones quantum readiness touches first, and the ones protecting long-lived personal data feel it most acutely. Four frameworks stand out. GDPR governs EU personal data and requires "state of the art" security for long-lived personal data. HIPAA governs US health data and requires decades-long confidentiality of medical records. PCI DSS governs payment card data and mandates strong cryptography for cardholder data. And DORA governs the EU financial sector, requiring operational resilience that includes cryptographic risk.
Health and financial data are especially exposed because their confidentiality requirements stretch across decades: a long data shelf-life in Mosca-inequality terms. Medical records must stay private for a patient's lifetime; financial and legal records carry multi-decade obligations. That means harvest-now-decrypt-later already threatens today's records under these regimes, because data collected now will still require protection long after a quantum computer could plausibly decrypt it.
Does any regulation require post-quantum cryptography yet?
Broad commercial regulations generally do not yet mandate specific post-quantum algorithms, and it is important to be precise about that. But the direction of travel is unmistakable. Government mandates like CNSA 2.0 set firm dates for national-security systems, and those requirements cascade outward through contractors, suppliers, and their suppliers. Sector regulators and standards bodies are increasingly signaling that quantum readiness will become an expectation, not a bonus.
The prudent reading is that "reasonable security" and "state of the art" will soon be understood to include quantum-safe cryptography, and that regulators will look unfavorably on organizations that knew about the threat, had standardized solutions available, and did nothing. Enterprises that wait for an explicit, dated mandate will find themselves migrating under deadline pressure rather than on their own schedule, which is both riskier and more expensive.
What does quantum-ready compliance look like in practice?
It looks like evidence. Regulators and auditors increasingly expect organizations not just to be secure, but to demonstrate that they understand their risk and are managing it deliberately. For quantum readiness, that means maintaining a cryptographic bill of materials so you can show what cryptography you run; classifying data by sensitivity and lifespan so you can show you understand where the risk concentrates; having a documented migration roadmap toward NIST standards; and being able to prove progress against it on demand.
The ability to produce this evidence is what separates a defensible posture from a hopeful one. In a post-incident or audit scenario, "we were planning to look into it" is a very different answer from "here is our cryptographic inventory, our data classification, our roadmap, and our progress to date." The second is compliance; the first is exposure.
How should compliance teams start?
Begin by mapping which regulated data you hold has the longest confidentiality requirements, then connect that data to the cryptography currently protecting it. Treat quantum readiness as an extension of your existing data-protection obligations rather than a separate initiative: it draws on the same inventory, classification, and governance capabilities you already use for privacy and security compliance. The overlap is substantial: the data mapping GDPR requires, the record-retention rules HIPAA imposes, and the cryptographic requirements in PCI DSS all feed directly into a quantum-readiness program.
The enterprises that fold PQC into their compliance programs now will meet future mandates as a formality rather than a fire drill, and will be able to answer the board's inevitable question with evidence instead of anxiety.



