Explain, with its dates, the EU coordinated roadmap in its own wording ("high-risk use cases", not "critical financial infrastructure"), keeping the distinction correct
Justify why DORA (risk-based, gives no date) and the G7 CEG (a non-binding 2035 target) have a different regulatory shape from the EU roadmap and CNSA 2.0
In the previous lesson you saw the US’s binding (EO 14412, CNSA 2.0) and advisory (IR 8547) documents. This lesson shows three different regulatory shapes on the EU and global side: concrete dates but indirect (the EU roadmap), binding but with no date (DORA), and dated but explicitly non-binding (the G7 CEG).
The EU coordinated roadmap: concrete dates, in its own wording
The Coordinated Implementation Roadmap published by the EU’s NIS Cooperation Group (v1.1, 11 June 2025) contains three milestones: member states publish national roadmaps by 31 December 2026SOURCED, the PQC transition of “high-risk use cases” is completed by 31 December 2030SOURCED, and medium and low-risk use cases are completed by 2035SOURCED. There is a subtlety to note here: the document’s own wording is “high-risk use cases”, not “critical financial infrastructure”; it is a correct inference that the financial sector falls within that scope (the roadmap references DORA separately), but it is not a verbatim quote of the document’s own sentence. When presenting these dates to an architect, rather than saying “the EU roadmap says 2030 for the financial sector”, it is more accurate to say “the EU roadmap says 2030 for ‘high-risk use cases’, and finance falls within that scope”.
DORA: no date, but a discipline
DORA (Digital Operational Resilience Act) is the EU financial regulation in force since January 2025, but the cryptography clause of its own ICT risk management RTS (Delegated Regulation 2024/1774) does not give a date. The document’s own Recital 9 is clear: “Given the rapid technological developments in the field of cryptographic techniques, financial entities… should remain abreast of relevant developments in cryptanalysis and consider leading practices and standards.” So instead of a fixed date, DORA asks for continuous, risk-based vigilance; a regulatory approach categorically different from the concrete dates of EO 14412 or the EU roadmap. The right answer to a bank asking “when does DORA tell us to do it”: “it gives no specific date, but it obliges us to keep our cryptography policy current and to follow leading practices.”
G7 CEG: dated, but explicitly non-binding
The roadmap published on 13 January 2026 by the G7 Cyber Expert Group (co-chaired by the US Treasury and the Bank of England) names 2035SOURCED as a general target for the financial sector; it recommends building crypto inventories, identifying the most sensitive systems, planning transitions and testing PQC technology. But the document itself describes this date explicitly as non-binding and open to change with the development of quantum technology. That is a third level of certainty, between the EU roadmap (not binding, but from an official EU body and aimed at member states) and EO 14412 (fully binding); presenting all three to an auditor with the same certainty would be an indefensible overclaim.
Update, October 2026
Two more signals since this lesson was written, neither changing the frames above. On 3 September 2026 the G7 Cybersecurity Working Group, a different G7 group from the CEG, published a call to action urging governments and organizations to start the PQC transition as soon as possible, without setting new dates. On 5 October 2026 the Dutch cabinet sent a government-wide quantum strategy to parliament; according to a secondary summary of the strategy document, it sets milestones for central government of high-risk systems migrated by end of 2030 and medium-risk by end of 2035, in line with the EU roadmap’s dates. Sources are on the news desk.
Numbers to know
EU NIS Cooperation Group Roadmap (v1.1, 11 June 2025): national roadmaps by 31 December 2026, 'high-risk use cases' by 31 December 2030 (which includes finance covered by DORA, though that is not the roadmap's own sentence), medium and low-risk use cases by 2035
DORA (RTS in force since 17 January 2025) does NOT give a single PQC date; its own wording is risk-based and flexible: 'remain abreast of relevant developments in cryptanalysis'
G7 CEG (13 January 2026, co-chaired by the US Treasury and the Bank of England): names 2035 as a general target for the financial sector, but its own text states explicitly that it is non-binding and may change with the development of quantum technology
Lab: Check the EU roadmap's own wording
[not run] This is a primary source verification exercise, not a runnable command
# Open the roadmap page on digital-strategy.ec.europa.eu (and the linked PDF) and search for 'high-risk use cases'
Recorded output
You will see that the document says 'high-risk use cases', not 'critical financial infrastructure', and mentions DORA separately as a reference
At the table
How to say this in a bank meeting.
To an executive
The EU, the US and the G7 each have a different regulatory shape: the EU has concrete dates, DORA has none (it only says 'stay current'), and the G7 has a date but it is explicitly non-binding. Mixing these differences up and presenting them all with the same certainty is indefensible in an audit.
To an architect
Summarizing DORA as 'move to PQC by 2030' is wrong; DORA's RTS (Recital 9) only asks entities to follow developments in cryptanalysis and consider leading practices, with no specific date. The EU NIS Cooperation Group's roadmap (a separate document) gives concrete dates and indirectly covers DORA-regulated entities, but it is not DORA itself.
Objection
“"Doesn't DORA give us a PQC date of 2030? If not, there's no need to hurry."”
Answer
DORA itself gives no date, that's right; but that does not mean there is no regulatory pressure. The EU NIS Cooperation Group's separate roadmap (31 December 2030, for high-risk use cases) covers DORA-regulated entities; the G7 CEG's 2035 target (although non-binding) shapes industry norms. The defence 'DORA gives no date' means ignoring these other two documents.
G7 Cyber Expert Group (co-chaired by the US Treasury and the Bank of England), 2026. The source of the 2035 target the G7 proposes for the financial sector, explicitly stated as non-binding in its own text
whole document / 10 min
Checkpoint
Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.
01Recall
What does the EU roadmap's own wording say, and where does the phrase 'critical financial infrastructure' come from?
Model answer
The EU roadmap's own wording is 'high-risk use cases', not 'critical financial infrastructure'. It is a correct inference that the financial sector falls within that scope (the roadmap references DORA separately), but that phrase is not a verbatim quote from the document.
02Recall
Why does DORA not give a PQC date, and what does it ask for instead?
Model answer
Instead of a fixed date, Recital 9 of DORA's RTS asks financial entities to continuously follow developments in cryptanalysis and consider leading practices; a risk-based, flexible approach.
03Scenario
An architect says 'DORA requires PQC by 2030.' How do you correct this claim using DORA's real text?
Model answer
That is wrong; DORA's own RTS (Recital 9) gives no date, only asks entities to follow developments in cryptanalysis and consider leading practices. The 2030 date comes not from DORA but from a separate document, the EU NIS Cooperation Group roadmap (for 'high-risk use cases'); it indirectly covers DORA-regulated entities, but DORA itself does not state that date.
A complete answer includes
Your score: 0/2
04Hostile
An auditor asks 'Is the G7's 2035 target binding?' Answer using the G7 CEG's own text.
Model answer
No, it is not binding. The G7 Cyber Expert Group's roadmap names 2035 as a general target for the financial sector, but the document itself states explicitly that the date is non-binding and may change with the development of quantum technology; a different level of certainty from EO 14412's fully binding dates.
A complete answer includes
Your score: 0/3
Project linkContributes to the EU/global side of the regulatory timeline sections of Projects 3 and 4; a template for presenting the status differences between DORA, the EU roadmap and the G7 correctly.