Policy and regulation

Powered by QiC Solutions

AnalysisAI

Policy and regulation · Quantum-Safe

Spanish Parliament report calls for faster migration to post-quantum cryptography

A Spanish parliamentary panel on cyber threats urges an immediate cryptographic inventory and a gradual, hybrid migration, but sets no deadlines.

Redacción · · 4 min

Key points

  • A subcommittee of Spain's Joint Committee on National Security considers quantum computing the most serious emerging technological risk in the medium term.
  • It recommends starting the cryptographic inventory now and a gradual, hybrid migration, following NIST and Spain's National Cryptologic Centre.
  • It sets no deadlines, responsibilities or budget: the reference timetable is still the European roadmap of 2026, 2030 and 2035.

The Subcommittee on threats in cyberspace in the age of artificial intelligence (AI) and quantum computing, set up within the Joint Committee on National Security of the Spanish Congress and Senate, approved its report on 24 February 2026. The Official Journal of the Cortes Generales, Spain’s Parliament, published it on 27 March. The report devotes a section to the «quantum threat» and recommends speeding up the transition to post-quantum cryptography (PQC).

The report contributes no measurements of its own. According to its methodology, it is based exclusively on expert testimony given to the Subcommittee in closed sessions with no official record, and it contains no verbatim quotations. The work took place between October 2024 and February 2026.

What it says about the quantum threat

The report describes quantum computing as «the most serious emerging technological risk in the medium term». What it records from the experts who appeared:

  • Several warned that, before 2030, enough capability could be reached to break the cryptographic algorithms that protect communications, critical data and transactions today.
  • States and criminal groups are already following a strategy of storing encrypted data now in order to decrypt it in the future (store now, decrypt later).
  • The technology renewal cycle in critical infrastructure is 6 to 10 years, so much of what is installed today will still be in service when the threat materialises.
  • NIST has already published its post-quantum cryptography standards, but their adoption in Spain is in its infancy.
  • Almost all agreed that Spain and Europe lag behind other countries in adopting post-quantum strategies.

The report also asks for an explicit distinction between PQC, which it describes as a solution that can be generalised and is compatible with current infrastructure, and quantum key distribution (QKD), which requires specific hardware and is aimed at highly critical links. It regards them as complementary.

What it recommends

  • Starting «immediately» to identify the systems and services that use asymmetric cryptography, giving priority to those that protect sensitive information or critical infrastructure.
  • Working from a complete inventory of the cryptographic systems, protocols and algorithms in use, both for data at rest and for communications.
  • Planning an orderly, gradual and hybrid migration, with classical and post-quantum algorithms coexisting for a time, following NIST standards and the recommendations of the National Cryptologic Centre (CCN), Spain’s authority on information security in the public sector.
  • Taking a crypto-agility approach: inventory, prioritisation and selection of algorithms, interoperability testing between vendors and progressive deployment.
  • Increasing the material and staff resources of the bodies responsible for cybersecurity, especially the CCN.

Note · what this report does not say

The «before 2030» date is a warning from some of the experts, not a conclusion backed by data: the report itself acknowledges that no cryptographically relevant quantum computer is yet known to exist. Nor does it set deadlines, responsibilities or a budget for the migration.

What changes for decision-makers

For a CISO or an architect, the report adds no obligations: it is a set of recommendations from a parliamentary subcommittee. Its value lies elsewhere. It puts on record, with the backing of the parliamentary groups in both chambers, that the migration to PQC is a national security priority and that the starting point is the cryptographic inventory.

The operational timetable has to be found elsewhere. The European Union’s coordinated roadmap for the transition to PQC, published in June 2025, asks all Member States to have an initial national roadmap by the end of 2026, to have migrated high-risk use cases by the end of 2030 and to complete the transition for everything feasible by 2035. The Spanish Parliament’s report does not mention that timetable.

The method it proposes does match the European one: inventory, prioritise by risk and migrate in a hybrid way. The reference algorithms are those that NIST standardised on 13 August 2024 in FIPS 203, FIPS 204 and FIPS 205.

One clarification: the report defines Q-Day as «the day quantum computing becomes commercial». For encryption, what matters is not whether commercial quantum computers exist, but whether there is one capable of breaking the public-key cryptography in use.

Keep reading