Dutch Quantum Strategy of 5 October 2026: Post-Quantum Deadlines From 2026 to 2035, No QKD, and Police Access to a Code-Breaking Quantum Computer
The Dutch government's new quantum strategy, drawing on the PQC migration handbook of the intelligence service AIVD, the research institute TNO and the mathematics institute CWI, states on page 36 that migrating a central government organization to quantum-safe cryptography will take at least eight years, because preconditions have to be in place before the technical work starts. Take that figure as an illustration. Count eight years back from 2035 and you arrive at 2027. Count back from 2030 and you arrive at 2022. On 5 October 2026 the Dutch cabinet sent parliament a strategy that has to live with that arithmetic.
The Rijksbrede Quantumstrategie (government-wide quantum strategy, a 73-page document) was presented by Minister Heleen Herbert of Economic Affairs and Climate and State Secretary Willemijn Aerdts of Digital Economy and Sovereignty, on behalf of nine ministries in all, from Defence and Justice to Health and Education. The government announcement leads with medicines, batteries and navigation. The more consequential pages are in the security chapter, where the state sets deadlines for itself and then describes what it would like to do with the machine those deadlines guard against.
Practical takeaway. The Dutch strategy turns the EU's post-quantum roadmap into deadlines for central government: risk policy by the end of 2026, migration plans by the end of 2027, quantum-safe procurement clauses by the end of 2028, high-risk systems migrated by the end of 2030 and medium-risk systems by the end of 2035. Suppliers to Dutch ministries should expect the 2028 procurement step to reach them first.
The Dutch post-quantum timetable, year by year, from end-2026 to end-2035
The timetable on pages 36 and 37 of the strategy applies to every central government organization. By the end of 2026, each has folded quantum risk into its risk-management process and adopted its own cryptography policy under the government-wide cryptography framework. By the end of 2027, each has addressed the harvest-now-decrypt-later scenario where needed, drawn up at least a draft migration plan, prepared or started pilots for high- and medium-risk uses, set up cryptographic asset management, and costed the people and money the migration needs.
By the end of 2028, organizations must be able to set requirements for quantum-safe cryptography in purchasing and tenders, and they must have issued guidance to essential companies. By the end of 2030, high-risk uses are migrated, software and firmware use quantum-safe cryptography by default, and the government has agreed in a European setting which cryptographic standards will be retired. By the end of 2035, medium-risk uses are migrated and low-risk uses as far as possible.
These dates follow the EU coordinated implementation roadmap agreed with the member states in 2025, and the strategy says the Dutch government aims to keep to it while reserving the right to accelerate. The new element is the granularity. The 2028 procurement step is where a ministry's deadline can become a supplier's contract term, the pattern Quentir described when quantum deadlines turned into a supply-chain question. The strategy also ties the work to the Cyberbeveiligingswet, the Dutch law implementing NIS2, and its implementing rules, which require organizations in scope to have a specific cryptography policy.
Why the 2029–2035 window and the eight-year migration do not fit together
The strategy states that a quantum computer able to break current asymmetric cryptography is expected between 2029 and 2035, that the exact moment is uncertain, and that the AIVD and the Dutch digital infrastructure inspectorate (RDI) advise organizations to prepare for such a machine around 2030. It adds that for sensitive information a small chance of that scenario is reason enough to act, because traffic intercepted today can be decrypted later.
Set those sentences next to the strategy's eight-year estimate and the gap is plain. Under that illustrative assumption, an organization that starts its preconditions in 2027 could finish around 2035, five years after the date the security service asks it to plan for. The strategy does not hide this. It cites the Algemene Rekenkamer's report Focus op Quantum bij de Rijksoverheid of 4 February 2026, which found that too few central government organizations had started tackling the quantum threat in a structured way. The 2030 deadline for high-risk systems is therefore a deadline the state may meet only for the systems it reaches first, and the strategy's risk classification of uses decides which systems those are.
Why the Dutch government does not use quantum key distribution
Quantum key distribution (QKD) exchanges encryption keys over a quantum channel, and its security rests on physics. The strategy grants that QKD can offer information-theoretic security in principle, then sets out its position: several European security agencies have raised serious objections to QKD for information security, QKD still needs post-quantum cryptography for authentication, and it offers limited end-to-end protection. The strategy expects those objections to remain unresolved in the short and medium term. QKD is not used for information security in central government, in line with an earlier cabinet position.
That does not end Dutch QKD work. The same document describes MDI-QKD experience gained in the OCINed project under the EuroQCI programme and keeps QKD on the research agenda. The position concerns what protects government information today. It puts The Hague in a different place from the field deployments that pair the two technologies, such as the Airbus trial of combined QKD and post-quantum encryption in Malta in September, and it gives Dutch public buyers a reason to ask for a stated rationale before any QKD purchase.
What the strategy says about police access to a code-breaking quantum computer
On pages 41 and 42, under the heading "Use case: deciphering encrypted criminal communications", the strategy turns to offense. Quantum computers could break asymmetric encryption, it says, which offers opportunities for police, forensic institutes and intelligence and security services analyzing encrypted traffic within criminal networks or between terrorists preparing an attack. It compares targeted decryption in exceptional cases with the breaking of Enigma and with the dismantling of EncroChat by French and Dutch police.
Two sentences follow. The impact of decrypting criminal communications depends on the speed of the migration to post-quantum cryptography, which is designed to resist quantum attack. For this use case it is important that police, forensic institutes and intelligence services gain access to a quantum computer relatively quickly, to get the best return on the investment a cryptographically relevant machine requires. The value of that capability declines as migration advances, including migration by the Netherlands' own suppliers and citizens.
The strategy elsewhere commits to responsible use with fundamental rights such as non-discrimination and equal treatment as the starting point, and it says security use cases will be discussed structurally from 2027 in existing interdepartmental structures. It does not describe a legal framework, oversight body or proportionality test specific to quantum decryption. Whether such a framework will follow is an open question for the Tweede Kamer.
How Quentir Reads It
The Netherlands has written down, in one cabinet document, both sides of the cryptographic race: a defensive clock that wants every important system migrated before a quantum computer arrives, and an investigative interest that gains value only for as long as targets have not migrated. The Dutch strategy puts them a few pages apart in the same security chapter, under the same signatures, which makes the tension readable and gives parliament something concrete to examine.
For companies the operational signal is quieter and nearer. The 2028 procurement step prepares ministries to specify quantum-safe requirements in tenders and contract management, although actual obligations will depend on individual tenders and contracts. The guidance to essential companies due by the same date will sit next to the cryptography-policy requirement that already follows from the Cyberbeveiligingswet and its implementing rules. The budget sentence on page 65 matters as much as the deadlines: the actions must fit within existing departmental means, and "if sufficient means are not found, the ambitions will be adjusted." A deadline that may shrink with the budget still binds a supplier once it is written into a contract.
Turning a government timetable like this one into an organization's own sequence of inventory, prioritization and supplier terms is the subject of our Signature Report on the PQC Migration Roadmap for Boards, which adds a fixed scope, an executive summary and a checklist that this post does not try to reproduce. The next document to read is the cabinet's first annual progress letter to the Tweede Kamer, due in 2027, which will show whether the end-2026 risk-policy step was met.
Sources: Ministry of Economic Affairs and Climate, Rijksbrede Quantumstrategie (attachment to Kamerbrief DGBI / 108513997, published 5 October 2026; record page on open.overheid.nl), sections 4.1.1 and 4.2.1 and the financing section; Kamerbrief "Aanbieding Rijksbrede Quantumstrategie", 5 October 2026; Rijksoverheid, "Kabinet: Nederland in 2035 leidend met quantum én weerbaar tegen risico's", 5 October 2026; AIVD, CWI and TNO, Het PQC-migratie handboek, second edition, 3 December 2024; NIS Cooperation Group, A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, 2025; Algemene Rekenkamer, Focus op Quantum bij de Rijksoverheid, 4 February 2026. Page references are to the strategy PDF as published on 5 October 2026.
Published intelligence, built to inform your own decisions. Published: October 6, 2026.