M11 / Regulation and timelines

EU and global timelines: NIS CG, DORA, G7

PractitionerAdvisor

After this lesson you can

  • Explain, with its dates, the EU coordinated roadmap in its own wording ("high-risk use cases", not "critical financial infrastructure"), keeping the distinction correct
  • Justify why DORA (risk-based, gives no date) and the G7 CEG (a non-binding 2035 target) have a different regulatory shape from the EU roadmap and CNSA 2.0

Before thisThe US timeline: EO 14412, CNSA 2.0, IR 8547

Mental model

In the previous lesson you saw the US’s binding (EO 14412, CNSA 2.0) and advisory (IR 8547) documents. This lesson shows three different regulatory shapes on the EU and global side: concrete dates but indirect (the EU roadmap), binding but with no date (DORA), and dated but explicitly non-binding (the G7 CEG).

The EU coordinated roadmap: concrete dates, in its own wording

The Coordinated Implementation Roadmap published by the EU’s NIS Cooperation Group (v1.1, 11 June 2025) contains three milestones: member states publish national roadmaps by 31 December 2026SOURCED, the PQC transition of “high-risk use cases” is completed by 31 December 2030SOURCED, and medium and low-risk use cases are completed by 2035SOURCED. There is a subtlety to note here: the document’s own wording is “high-risk use cases”, not “critical financial infrastructure”; it is a correct inference that the financial sector falls within that scope (the roadmap references DORA separately), but it is not a verbatim quote of the document’s own sentence. When presenting these dates to an architect, rather than saying “the EU roadmap says 2030 for the financial sector”, it is more accurate to say “the EU roadmap says 2030 for ‘high-risk use cases’, and finance falls within that scope”.

DORA: no date, but a discipline

DORA (Digital Operational Resilience Act) is the EU financial regulation in force since January 2025, but the cryptography clause of its own ICT risk management RTS (Delegated Regulation 2024/1774) does not give a date. The document’s own Recital 9 is clear: “Given the rapid technological developments in the field of cryptographic techniques, financial entities… should remain abreast of relevant developments in cryptanalysis and consider leading practices and standards.” So instead of a fixed date, DORA asks for continuous, risk-based vigilance; a regulatory approach categorically different from the concrete dates of EO 14412 or the EU roadmap. The right answer to a bank asking “when does DORA tell us to do it”: “it gives no specific date, but it obliges us to keep our cryptography policy current and to follow leading practices.”

G7 CEG: dated, but explicitly non-binding

The roadmap published on 13 January 2026 by the G7 Cyber Expert Group (co-chaired by the US Treasury and the Bank of England) names 2035SOURCED as a general target for the financial sector; it recommends building crypto inventories, identifying the most sensitive systems, planning transitions and testing PQC technology. But the document itself describes this date explicitly as non-binding and open to change with the development of quantum technology. That is a third level of certainty, between the EU roadmap (not binding, but from an official EU body and aimed at member states) and EO 14412 (fully binding); presenting all three to an auditor with the same certainty would be an indefensible overclaim.

Update, October 2026

Two more signals since this lesson was written, neither changing the frames above. On 3 September 2026 the G7 Cybersecurity Working Group, a different G7 group from the CEG, published a call to action urging governments and organizations to start the PQC transition as soon as possible, without setting new dates. On 5 October 2026 the Dutch cabinet sent a government-wide quantum strategy to parliament; according to a secondary summary of the strategy document, it sets milestones for central government of high-risk systems migrated by end of 2030 and medium-risk by end of 2035, in line with the EU roadmap’s dates. Sources are on the news desk.

Numbers to know

  • EU NIS Cooperation Group Roadmap (v1.1, 11 June 2025): national roadmaps by 31 December 2026, 'high-risk use cases' by 31 December 2030 (which includes finance covered by DORA, though that is not the roadmap's own sentence), medium and low-risk use cases by 2035
  • DORA (RTS in force since 17 January 2025) does NOT give a single PQC date; its own wording is risk-based and flexible: 'remain abreast of relevant developments in cryptanalysis'
  • G7 CEG (13 January 2026, co-chaired by the US Treasury and the Bank of England): names 2035 as a general target for the financial sector, but its own text states explicitly that it is non-binding and may change with the development of quantum technology

Lab: Check the EU roadmap's own wording

[not run] This is a primary source verification exercise, not a runnable command

Requires: internet access. Check your setup

shell
# Open the roadmap page on digital-strategy.ec.europa.eu (and the linked PDF) and search for 'high-risk use cases'
Recorded output
You will see that the document says 'high-risk use cases', not 'critical financial infrastructure', and mentions DORA separately as a reference

At the table

How to say this in a bank meeting.

To an executive
The EU, the US and the G7 each have a different regulatory shape: the EU has concrete dates, DORA has none (it only says 'stay current'), and the G7 has a date but it is explicitly non-binding. Mixing these differences up and presenting them all with the same certainty is indefensible in an audit.
To an architect
Summarizing DORA as 'move to PQC by 2030' is wrong; DORA's RTS (Recital 9) only asks entities to follow developments in cryptanalysis and consider leading practices, with no specific date. The EU NIS Cooperation Group's roadmap (a separate document) gives concrete dates and indirectly covers DORA-regulated entities, but it is not DORA itself.
Objection
“"Doesn't DORA give us a PQC date of 2030? If not, there's no need to hurry."”
Answer
DORA itself gives no date, that's right; but that does not mean there is no regulatory pressure. The EU NIS Cooperation Group's separate roadmap (31 December 2030, for high-risk use cases) covers DORA-regulated entities; the G7 CEG's 2035 target (although non-binding) shapes industry norms. The defence 'DORA gives no date' means ignoring these other two documents.

Sources

Checkpoint

Answer first, then compare with the model answer and score yourself against the rubric. Saved in this browser only.

  1. 01Recall

    What does the EU roadmap's own wording say, and where does the phrase 'critical financial infrastructure' come from?

  2. 02Recall

    Why does DORA not give a PQC date, and what does it ask for instead?

  3. 03Scenario

    An architect says 'DORA requires PQC by 2030.' How do you correct this claim using DORA's real text?

  4. 04Hostile

    An auditor asks 'Is the G7's 2035 target binding?' Answer using the G7 CEG's own text.

Project linkContributes to the EU/global side of the regulatory timeline sections of Projects 3 and 4; a template for presenting the status differences between DORA, the EU roadmap and the G7 correctly.