The Quantum Resilience Paradox
Cryptographic primitives are the meta-trust layer.
The regulation Europe wrote to make its banks resilient is the same regulation that compiles their attack surface for a foreign state. DORA, NIS2, GDPR and MiCA require European institutions to produce vulnerability maps, ICT concentration registers and incident reports. Most of that documentation is stored on infrastructure subject to harvest-now-decrypt-later collection. When quantum computing breaks current encryption, a foreign state holds a complete operational playbook against European critical infrastructure that European regulators required the institutions to produce.
Papers 1 and 6 left out time. The quantum transition will retroactively compromise everything ever encrypted under current primitives and collected during transit. Europe is mandating post-quantum migration by 2030 on infrastructure it does not control. The migration is a once-in-a-generation alignment opportunity. Miss it, and the dependency locks in for another generation.
The Ask
The ask is mechanical.
For the financial sector, the European Supervisory Authorities (EBA, ESMA, EIOPA) designate sovereign-stack infrastructure (full seven-layer, Paper 2) as the only DORA-compliant configuration for ICT risk management documentation, third-party concentration analyses, business continuity plans, and incident reports.
Approximately five thousand DORA-regulated entities migrate before 2030, on the same timeline the post-quantum migration already requires.
For critical infrastructure, NIS2 essential and important entities (operators of energy, transport, banking, healthcare, water, digital infrastructure, public administration) compile equivalent documentation under their own resilience mandates.
The NIS Cooperation Group should designate sovereign-stack as the NIS2-compliant configuration on the same timeline.
Tens of thousands of European entities sit under NIS2; the mechanism is identical to DORA’s.
For public procurement, EU and member-state government data (health records, election systems, judicial work, classified policy work, defence procurement) sits on the same Position 4 infrastructure as DORA filings.
The European Commission’s own Microsoft 365 use was found incompatible with EU data protection law in March 2024.
The Cloud and AI Development Act, currently in draft, should require seven-layer sovereign for any public-sector contract above DORA-equivalent thresholds, on the same 2030 deadline. The deadline is not a separate political negotiation; it is the deadline already mandated by the EU’s PQC Roadmap for critical systems. The constitutional (Paper 7) and procurement-mandate (Paper 8) arguments are later in the series.
AI Act risk assessments, MiCA resilience reporting, and GDPR records of processing follow the same pattern.
Compliance documentation across regulated regimes compiles vulnerabilities on infrastructure that becomes readable when quantum arrives. The fix is identical across all regimes: sovereign-stack designation as the compliant configuration.
The Flywheel
Approximately fifteen thousand European institutions plus twenty-seven member-state public procurement budgets migrate to sovereign-stack infrastructure simultaneously. That is anchor customer demand on a scale Europe has not produced before.
The European cloud providers exist. OVHcloud, Hetzner, STACKIT, Proximus, and Outscale operate at production scale today. None of them currently absorbs the workload that this migration would generate.
That absence is the missing demand signal that the rest of this series documents.
The mechanics of how anchor customer demand converts into investable European supply are in Paper 8. The historical precedents (Airbus airline-customer commitments, Galileo mandated adoption, the CIA’s six hundred million dollar contract that built AWS into a viable enterprise platform) are in Paper 25.
The catalyst is the quantum migration deadline. It forces a procurement transition that has to happen anyway. The transition pays for itself by funding the European cloud capacity that the rest of the series argues Europe needs.
Without the quantum deadline, sovereign-stack migration competes for political attention with cheaper short-term priorities and loses.
With the deadline, the migration is a compliance obligation that has to happen anyway. The marginal cost of building sovereign rather than upgrading someone else’s infrastructure will never be lower than during this transition.
The Permanent Archive
The argument that sovereign migration matters has two components: what the archive contains today, and what happens to that archive when the encryption breaks.
The encrypted traffic transiting US-jurisdiction infrastructure is intercepted at the cable level under PRISM and UPSTREAM, and stored.
The full intelligence-cooperation argument is in Paper 19; the legal-and-extralegal access argument is in Paper 1. What makes this different is permanence: the archive does not disappear when the geopolitical relationship changes. It accumulates, and it waits.
When quantum computing breaks the encryption, every weakness mapped for European regulators becomes readable by the foreign government that controls the infrastructure. Consider what that archive contains for European institutions.
Their own vulnerability assessments.
Under DORA alone, European banks have produced thousands of pages of compliance documentation mapping their third-party provider dependencies, their concentration risks, their exit strategies, and their resilience testing results.
NIS2 incident reports map weaknesses across critical infrastructure. AI Act risk assessments document model vulnerabilities.
MiCA resilience reporting catalogues operational dependencies of crypto-asset service providers. GDPR records of processing reveal the data flows of every European organisation. Each is a different category of regulator-mandated self-disclosure. Each is being filed onto the infrastructure those filings warn about.
European monetary policy. The ECB’s interest rate decisions move trillions in European assets. If pre-announcement deliberations, draft communications between Governing Council members, or preparatory analyses transited US-jurisdiction infrastructure at any point, the archive contains the most market-moving information in European finance.
The settlement infrastructure itself. The Canton Network (Paper 13) processes European institutional finance through Super Validators, including US-jurisdiction entities, that already hold the encrypted data. They do not need to intercept anything. They need to wait.
The plan to escape all of this. European Commission officials drafting the Cloud and AI Development Act almost certainly used US-provided collaboration tools to write it. Sovereign technology investment proposals were circulated on US-provided platforms. The infrastructure dependency compromises the strategy for ending the infrastructure dependency.
The exposure is total and permanent.
Bulk collection programmes operate at the infrastructure level, capturing traffic indiscriminately. Quantum computing makes the entire archive searchable in a single event.
You cannot un-send a communication. The data already collected cannot be retroactively re-encrypted. The access that was exercised cannot be undone.
The only variable any European organisation controls is when the archive stops growing.
The EU’s own regulatory language acknowledges this reality. The PQC Recommendation explicitly names harvest-now-decrypt-later attacks as “likely occurring already now.”[1] The urgency is about stopping the collection.
The Infrastructure Contradiction
The European Union is framing post-quantum migration as a legal obligation.
The Commission published its PQC Recommendation in April 2024, establishing post-quantum cryptography as a requirement for “appropriate technical measures” under GDPR.[2] The NIS Cooperation Group’s Coordinated Implementation Roadmap (June 2025) sets hard deadlines.
National strategies by end of 2026, critical systems migrated by 2030, everything else by 2035.[3] DORA and NIS2 already require quantum-resistant cryptography. Eighteen member states have urged migration by 2030. Europol created the Quantum Safe Financial Forum to coordinate the transition. This is serious, well-structured regulatory activity.
But there is a structural problem that no amount of regulation can solve on its own.
Post-quantum migration requires new key generation, new Hardware Security Modules, new certificate infrastructure, new cipher suites, new key management procedures.
Whoever runs the cryptographic infrastructure (key generation, HSMs, certificate authority) knows the keys, has access to the key material, and can issue, revoke, or replace certificates. For European organisations at Position 4, that infrastructure is operated by US-jurisdiction providers. AWS manages your HSMs. Azure generates your keys. Google Cloud operates your certificate lifecycle.
The migration path runs through infrastructure controlled by entities subject to a foreign government’s legal jurisdiction, and that government can compel disclosure of anything within the provider’s “possession, custody, or control.”[4]
So post-quantum migration on US-controlled infrastructure means the provider generates your new quantum-resistant keys, stores them in HSMs they operate, and can still be compelled to hand over everything.
The encryption gets stronger against external attackers. Against the provider itself, or the government that has jurisdiction over that provider, nothing changes. You have upgraded the locks. The landlord still has a copy of every key.
Sovereignty is inherited downward through the stack (Paper 2). An organisation’s actual sovereignty rating is determined by the weakest link: hardware, operating system, hypervisor, key management, certificate authority, DNS, update mechanism. Tick five of seven and the two missed are the ones that get exploited. The permanent archive does not care which layer leaked.
The result is compliance theatre at the quantum layer.
The institution ticks the DORA box and the NIS2 box. The board presentation shows green across the quantum readiness column. The encryption is stronger against every actor that does not have access to the master keys, except the provider and the government with jurisdiction over the provider.
And every allied intelligence service that the US chooses to share signals intelligence with (Paper 19) still does, by extension. The migration protects European data against everyone except the US, the provider, and the allies the US chooses to share with. Jurisdiction and sovereignty position are unchanged.
The 2030 deadline itself is ambitious.
Anyone who has managed a TLS version upgrade in an enterprise environment knows that changing cryptographic primitives across critical infrastructure is measured in years.
TLS 1.2 was standardised in 2008; major cloud providers did not complete deprecation of its predecessors until 2024.
That was sixteen years for a simpler migration within the same protocol family.[5] The post-quantum migration touches every layer of the stack. For financial institutions under DORA, energy companies under NIS2, healthcare systems processing patient data under GDPR, the 2030 target is ambitious to the point of unrealism.
If migration takes longer than the regulation assumes, and it will, the permanent archive grows for every additional year of delay.
The Sovereign Migration
The post-quantum transition forces a choice that Europe has been deferring for twenty years. The cryptographic infrastructure has to change regardless. The question is whether Europe changes it on someone else’s infrastructure or on its own.
Migrate cryptography on the same US-controlled infrastructure: upgrade the cipher suites, deploy post-quantum algorithms on AWS Frankfurt and Azure West Europe, tick the compliance box.
The power relationship is identical. The archive remains accessible to the entity that controls the master keys. You have bought the lock-in at exactly the moment when you could have purchased the exit.
Migrate to sovereign-stack infrastructure on the timeline the regulation already mandates.
National strategies by end of 2026 (already required); sovereign-stack classification of the full diagnostic by 2027; critical government data legislated onto sovereign infrastructure by 2028; full DORA-regulated, NIS2-essential, and critical public-procurement migration by 2030 (the NIS Cooperation Group’s mandated deadline for critical systems); all remaining systems by 2035; complete sovereign capability before quantum decryption becomes viable between 2035 and 2040.
The deadlines are not separate; they are the deadlines already in the PQC Roadmap.
Each phase creates the demand that funds the next. The intervention is legislative, the returns commercial, the deadline set by physics.
The single most critical action any European organisation at Position 4 can take is to move to an EU-jurisdiction provider immediately.
Move now, while the migration machinery is being built and the regulatory window is open.
This action moves an institution from Position 4 to Position 1 or 2 without requiring new cryptographic architecture, only a decision to treat infrastructure sovereignty as urgent rather than optional. It closes the legal and extralegal channels and stops the permanent archive growing on foreign infrastructure. From the day of migration, the bleeding stops.
Once that foundation is in place, privacy-preserving cryptographic architectures (zero-knowledge proofs, threshold encryption, fully homomorphic encryption) can be layered on top.
Data that enters this architecture never exists in a compromisable form. There is no archive to build because there is nothing to archive. The assessment framework for these architectures is in the appendix.
The sovereign migration is expensive, disruptive, and complex. It is exactly the kind of undertaking that European organisations have been avoiding by staying at Position 4 and calling it sovereignty.
Every successful European sovereignty project started with someone placing an order.
Airbus, Galileo, the euro: each was an order with a delivery date and a penalty clause.
The regulatory framework exists: DORA, NIS2, the PQC Roadmap, CADA in draft. What is missing is the strategic decision to treat the quantum transition as a sovereignty opportunity rather than a compliance exercise.
Conclusion
The dimension the foundation deliberately left out was time. Earlier papers mapped where Europe stands (Paper 1) and how it got there (Paper 6); this is what the quantum transition does to both.
DORA was the resilience regulation. It compiled Europe’s vulnerability map. The map sits on US-jurisdiction infrastructure. The encryption that protects it has a known expiry date.
The pattern is structural. The regulation that required the maps and the regulation that requires their post-quantum migration are the same regulation. The sovereignty question is whether the migration runs on the infrastructure those maps warned about, or off it.
The post-quantum migration is a compliance obligation under DORA, NIS2, and GDPR, and the same logic extends to AI Act, MiCA, eIDAS, and public procurement.
The cryptographic infrastructure must change regardless. Building it sovereign rather than upgrading someone else’s will never cost less than during this transition.
And the migration, taken across all regulated regimes, is the anchor customer demand that finally makes European sovereign cloud investable.
DORA writes the vulnerabilities. Quantum reads them.
Stop feeding the archive. Move now. Or be read later.
Appendix: Assessment Framework for Privacy-Preserving Cryptographic Architectures
The privacy-preserving cryptographic technologies above could change the sovereignty equation. They also introduce new trust assumptions.
The permanent archive is a lesson in what happens when trust assumptions go unexamined. A vulnerability in a zero-knowledge proving system could go undetected for longer, with consequences measured in permanent data exposure.[6]
The temptation under time pressure is to adopt the first alternative that promises mathematical sovereignty. The urgency is real. But urgency without rigour produces the same compliance theatre this series has documented.
The following six questions determine whether the architecture you replace it with actually eliminates the vulnerability or merely moves it to a different layer.
| # | Question | What It Catches | Who Can Assess |
| 1 | Governance and upgrade path: who controls changes to the proving system, where are they incorporated, and can they push a compromised update? | Institutional trust re-entering through the governance layer. Jurisdictional exposure of the development entity. | Assessable in-house with public information |
| 2 | Foundational trust event: does the system require an initialisation event that, if compromised, permanently undermines all subsequent security? What is that event and how is it verified? | One-time events that permanently compromise the system if subverted. Key generation ceremonies, root key establishment, initial trust anchors. | Assessable in-house from protocol documentation |
| 3 | Soundness guarantees: computational or statistical soundness? What is the security parameter and under what conditions does it hold? | Theoretical weakness in the proof system. Whether the verifier can be fooled. | Requires cryptographic literacy: security architect or specialist consultancy |
| 4 | Implementation verification: does the system’s implementation match its specification? Has this been independently verified through formal methods, audit, or both? | Logic errors where the system behaves correctly according to flawed specifications. Divergence between what is claimed and what is implemented. | Requires specialist cryptographic auditors |
| 5 | Implementation integrity: side-channel resistance, randomness quality, supply chain dependencies, timing attack surface. | Sound mathematics implemented in broken software. The xz utils class of vulnerability. | Requires specialist security engineers for cryptographic implementations |
| 6 | Cryptographic shelf life: are the underlying hardness assumptions quantum-resistant? If not, is there a credible migration path? | Whether the system survives the quantum transition or needs to be replaced. | High-level assessment in-house; deeper analysis requires expertise |
The most common failure these questions catch is institutional trust disguised as mathematical trust.
This framework is diagnostic. Any vendor that cannot answer all six deserves the same scepticism this series applies to sovereignty claims that depend on untested trust assumptions.
Specialist cryptographic auditors are scarce.
A European register of assessed cryptographic architectures, maintained by ENISA and Europol, would let organisations reference verified assessments rather than commissioning redundant audits.
The six questions become the assessment standard. The register becomes the procurement shortlist.
ENISA and Europol’s Quantum Safe Financial Forum provide the coordination machinery. What remains is the decision to use it.
[1] Recital (8) of the EU PQC Recommendation names harvest-now-decrypt-later attacks as ‘likely occurring already now’ and references ‘planned deprecation of certain algorithm implementations and full disallowance of current public-key cryptographic algorithms’. Commission Recommendation (EU) 2024/1101 of 11 April 2024.
[2] Commission Recommendation (EU) 2024/1101 of 11 April 2024 on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography.
[3] The NIS Cooperation Group’s Coordinated Implementation Roadmap (23 June 2025) sets milestones of end-2026 for national strategies, end-2030 for critical system migration and 2035 for remaining systems. DORA (Regulation (EU) 2022/2554, applicable 17 January 2025) requires encryption policies that account for ‘quantum advancements’. NIS2 (Directive (EU) 2022/2555, applicable 14 October 2024) requires state-of-the-art cryptographic controls.
[4] 18 U.S.C. §2713 (CLOUD Act): the obligation to disclose data attaches to data within a provider’s “possession, custody, or control” regardless of where the data is stored. As of 2025, three US cloud providers (AWS, Microsoft Azure, Google Cloud) held approximately seventy per cent of the European market for cloud infrastructure services.
[5] TLS 1.2 was published in August 2008. Cloud provider deprecation of TLS 1.0 and 1.1 ran 16 to 18 years (AWS February 2024 to Google Cloud March 2026), a migration within a single cryptographic family. Production-ready HSM support for NIST post-quantum algorithms only began arriving in mid-2025 (Thales Luna v7.9, Utimaco Quantum Protect, both NIST CMVP validated). The CEPS Quantum Task Force (December 2025) found 4 per cent of surveyed European organisations had defined a quantum strategy.
[6] In February 2019, the Zcash team disclosed CVE-2019-7167, a vulnerability in the Sprout zk-SNARK proving system that would have allowed unlimited undetected counterfeiting of ZEC tokens. The vulnerability existed for just under a year before being discovered during an internal cryptograp
Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →