Post-quantum cryptography for critical energy infrastructure: the BSI 2030 deadline
This article sets out the BSI deadlines for grid operators, utilities and critical infrastructure operators: what the BSI has required since February 2026, why energy infrastructure with its long life cycles is especially exposed, which NIST standards are ready, and what operators should do now. Closely related topics are the classification of AI in energy infrastructure as high-risk and the PKI in the SMGW backend, each covered in its own article. Here the focus is the quantum threat and the migration.
On 11 February 2026 the BSI set binding end dates through the updated technical guideline TR-02102: stand-alone classical asymmetric encryption should end at the end of 2030 for very high protection needs and at the end of 2031 in general, after which only hybrid operation, combining a classical and a post-quantum scheme, is permitted. For signature-only schemes the deadline is the end of 2035. The EU roadmap of June 2025 aligns with this and names energy explicitly as critical infrastructure to be migrated by the end of 2030. The algorithms are not the gap: NIST finalised FIPS 203, 204 and 205 back in August 2024. Energy infrastructure faces the quantum threat harder than many IT systems, because remote control technology and SCADA run for 15 to 30 years and, under the harvest now, decrypt later pattern, data captured today can be decrypted later. By the end of 2025 around 3.09 million smart metering systems were installed. Action lags behind awareness: 69 percent of organisations see the quantum risk, but only 5 percent have quantum-safe encryption in use. The first step is not a new algorithm but a cryptographic inventory, followed by prioritisation by data lifetime, crypto-agility and the hybrid operation the BSI recommends.
Why the clock is running on encryption
Classical encryption has been given an expiry date. Anyone running critical energy infrastructure has to plan the migration to post-quantum cryptography now, not once a quantum computer actually breaks today's schemes. That sounds paradoxical. The reason lies in the logic of the threat, though, not in a news headline.
Data captured today can be decrypted later, once the computing power arrives. This pattern is called harvest now, decrypt later, and it works retroactively. For data that must stay confidential beyond 2030, what counts is not the day a quantum computer appears, but the day the data leaves the network.
This is exactly where the BSI steps in. With the update of technical guideline TR-02102 on 11 February 2026, it turned a recommendation into a deadline. The shift is no longer a question of whether, but of when. And the when is now fixed.
What the BSI actually requires
The BSI deadlines are graded by protection need and scheme type. They give a clear timeframe but leave little room. Anyone starting the migration only in 2029 will barely meet the deadline for complex operational technology.
At the core sit three dates. For very high protection needs, stand-alone classical asymmetric encryption should end at the end of 2030. In general the date is the end of 2031, after which only hybrid operation is permitted, combining classical and post-quantum schemes. For signature-only schemes the deadline runs to the end of 2035, because a forged signature only causes harm in the future, whereas captured data is exposed today.
For classified IT the BSI agreed a tougher line with manufacturers back in October 2025: from 2030, products should be available that withstand the threat from future high-performance quantum computers. That is not a soft target but a procurement date. Anyone without a quantum-safe product on the shelf by then drops out of approval.
The standards are already here
Unlike many regulatory deadlines, the technology is not the missing piece here. NIST standardised the core algorithms back in 2024. The task is integration, not invention.
On 13 August 2024 NIST finalised three standards: FIPS 203 for key exchange, based on the Kyber scheme, plus FIPS 204 and FIPS 205 for signatures. NIST recommends starting the integration immediately, because it takes time. That is the decisive sentence for planning: the clock does not start on Q-Day, it started today.
The BSI deliberately goes beyond the NIST selection. It additionally recommends FrodoKEM and Classic McEliece, two more conservative schemes whose security rests on long-studied problems. The reasoning is caution: if one scheme later shows weaknesses, a second stands ready. That raises the effort but lowers the risk of a wrong bet.
Why energy grids are especially exposed
Energy infrastructure faces the quantum threat harder than many IT systems. The reason is simple: its technology lives long, and its data stays sensitive for a long time. A substation is not swapped out every three years.
Remote control technology, SCADA and control systems have life cycles of 15 to 30 years. Anyone installing a control unit today that uses classical keys is committing to it for half the migration window. Add the volume: by the end of 2025 around 3.09 million smart metering systems were installed, each with a smart meter gateway secured through a smart meter PKI. That trust infrastructure has to carry the crypto change too.
And the data? Control commands, grid operation protocols and metering values are not a fleeting good. They reveal how a grid is built and how it reacts. Capture and store them today, and you hold a map of the infrastructure tomorrow. That is exactly why harvest now, decrypt later is no theoretical scenario for energy grids, but a reason to act now.
German and EU perspective
The German deadline does not stand alone. In June 2025 the EU published a coordinated roadmap for the transition to post-quantum cryptography, and it names energy explicitly as critical infrastructure. German grid operators move within an aligned European framework, not on a national special path.
The roadmap sets two markers. By the end of 2026, member states should present national plans, cryptographic inventories and first pilot projects. By the end of 2030, the high-risk cases and critical infrastructures should be migrated. The core sentence is clear: quantum-vulnerable public-key schemes must not be used stand-alone after the end of 2030. That aligns almost to the day with the BSI line.
The regulatory frame runs further. The NIS2 directive and the German critical-infrastructure umbrella law tighten security requirements for the energy sector anyway, and the classification of AI in energy infrastructure as high-risk points the same way. Cryptography is part of that picture, not an isolated topic. An operator taking NIS2 seriously cannot avoid the crypto migration.
Challenges and risks
The migration is not a software update. It touches hardware, protocols, certificates and supply chains, often in systems never designed for a crypto change. At the same time the urgency is contested, and that belongs in the picture honestly.
The practical core of the problem is missing crypto-agility. Many operational technology components cannot be switched to a new scheme by update, they have to be replaced. For large organisations, migration windows of well over ten years are quoted. Those figures are estimates from the consulting literature, not energy-specific, but they show the order of magnitude. With a deadline of 2030, that leaves little buffer.
Then the counter-voices. Critics see the timeline for a practically usable quantum computer as open and warn against rushed switches to still-young implementations. A 2026 commentary in heise puts it bluntly, that many organisations barely encrypt at all while everyone talks about post-quantum crypto. The objection has something to it.
Only it points the wrong way. If the migration itself can take a decade, waiting is the bigger risk, not the smaller one. The dispute over the exact date of Q-Day changes nothing in the arithmetic: data lifetime plus migration time has to be shorter than the time until a quantum computer arrives. For long-lived grid data, that sum is already tight today.
What grid operators should do now
The first step is not a new algorithm but an overview. Anyone who does not know where classical cryptography sits in their operation cannot replace it. From the deadlines and the threat, a concrete action list follows.
- Build a cryptographic inventory: systematically record which systems, protocols and certificates use which cryptographic schemes. Without that map, any migration stays piecemeal.
- Prioritise by data lifetime: protect first the data and systems that must stay confidential beyond 2030. That is exactly where harvest now, decrypt later bites hardest.
- Build in crypto-agility: design systems and procurement so schemes stay replaceable. New hardware should allow a crypto change by update, rather than baking one scheme in.
- Hybrid, not a solo run: combine post-quantum schemes with classical ones in hybrid mode first, as the BSI recommends. Security holds even if a new scheme later shows weaknesses.
- Bind suppliers early: commit procurement and manufacturers to quantum-safe products now, so operational technology with a 20-year life is not obsolete from the factory.
Further reading
Frequently asked questions
Post-quantum cryptography covers encryption and signature schemes that even a powerful quantum computer cannot break. Classical asymmetric schemes such as RSA and ECC rest on computational problems that such a machine could solve. The new schemes use different mathematical foundations, for example lattices. NIST standardised them in 2024 as FIPS 203, 204 and 205.
With the update of technical guideline TR-02102 on 11 February 2026, the BSI set end dates. Stand-alone classical asymmetric encryption should end at the end of 2030 for very high protection needs and at the end of 2031 in general. After that only hybrid operation, combining a classical and a post-quantum scheme, is permitted. For signature-only schemes the deadline is the end of 2035.
Energy infrastructure has long life cycles. Remote control technology, SCADA and control systems run for 15 to 30 years, and their data stays sensitive for a long time. Under the harvest now, decrypt later pattern, control and metering data captured today can be decrypted later, once a quantum computer is available. By the end of 2025 around 3.09 million smart metering systems were already installed.
Harvest now, decrypt later describes an attack in which encrypted data is captured and stored today, to be decrypted later with a quantum computer. The attack works retroactively. So it is not enough to act only once a quantum computer exists. Anyone protecting data that must stay confidential beyond 2030 has to plan the migration now.
The first step is a cryptographic inventory: recording which systems use which schemes. Then comes prioritisation by data lifetime, so that long-lived sensitive data is protected first. Systems should be built to be crypto-agile, so schemes stay replaceable. The BSI recommends hybrid schemes combining a classical and a post-quantum algorithm. Procurement and suppliers should be involved early.