← Back to Guidance Portal

PQC Transition Roadmap

Ensuring Quantum-Resilience for Core Signaling & Long-term Data Retention under NIS2 Article 21.

TOOL // HNDL_RISK_CALCULATOR

"Harvest Now, Decrypt Later" Risk

Calculate the risk exposure of your data assets based on their required shelf-life vs quantum development timelines.

RISK LEVEL: HIGH
REF // NIST_FIPS_STANDARDS

PQC Algorithm Kernels

ML-KEMEncryption

FIPS 203 (Kyber)

Maturity: 100%
ML-DSASignature

FIPS 204 (Dilithium)

Maturity: 95%
SLH-DSASignature

FIPS 205 (SPHINCS+)

Maturity: 85%

The PQC Migration Path

01
Inventory

Identify all systems using RSA/ECC (Diameter, N32, IPsec).

02
Agility

Implement hybrid key exchanges (RSA + ML-KEM) for backward compatibility.

03
Upgrade

Deploy Q-Safe Hardware Security Modules (HSMs) in the Signaling core.

04
Retention

Migrate encrypted storage for Lawful Interception to PQC kernels.

05
Hardening

Enforce mandatory ML-DSA signatures for firmware updates.

⚠️
Lawful Interception (LI) Impact: Long-term data retention mandates in many EU states mean that data captured today must remain secure for 10+ years. If your LI system is not using PQC-hardened storage, it is inherently vulnerable to future quantum decryption.