The mandate differs.
The cryptography problem doesn't.
Every sector below holds long-lived data on systems that cannot be recoded. QuProtect answers each one's regulator with the same platform.
Each links to its definition, with the source it came from.
All terms-
Federal
EO 14412 puts PQC on high-value assets by end-2030. Deployed with the U.S. Army and in SBIR-backed U.S. Air Force work.
Explore
-
State and Local Government
Citizen records that stay sensitive for a lifetime, on systems no vendor will touch. Software only, bought through vehicles procurement already uses.
Explore
- CJIS
- HIPAA
-
Banking and Financial Services
PCI DSS 12.3.3 already requires a cryptographic inventory. Payment paths on TLS below 1.3 are findings waiting to be written.
Explore
-
Telecommunications
Core networks, signaling, and transport encryption can outlive the algorithms protecting them. NIS2 covers public electronic communications, while the EU PQC roadmap calls for critical infrastructure to transition by the end of 2030.
Explore
- NIS2
- EU PQC Roadmap
- ETSI QSC
-
Critical Infrastructure
Long-lived operational systems make rip-and-replace unrealistic. EO 14412 directs CISA and sector agencies to help critical-infrastructure owners develop PQC migration plans as NIST moves industry toward quantum-resistant cryptography.
Explore
- EO 14412
- NIST IR 8547
- EU PQC Roadmap
-
Oil, Gas, and Industrial IoT
Pipelines, SCADA, and connected field assets can operate for decades with narrow maintenance windows. TSA pipeline requirements and NIS2 raise the cybersecurity baseline while PQC migration adds pressure to modernize cryptography without replacing operational systems.
Explore
- TSA Security Directives
- NIS2
- EU PQC Roadmap
-
IoT, Edge & Satellite
Deploy lightweight, crypto-agile protection for connected devices and high-latency networks without operational drag.
Explore
Terms on this page
-
CISA Cybersecurity and Infrastructure Security Agency
The National Coordinator for Critical Infrastructure Security and Resilience, which leads the national effort to understand, manage and reduce risk to cyber and physical infrastructure. EO 14412 directs CISA to issue the guidance agencies follow when migrating their systems.
Source: CISA , About CISA (www.cisa.gov)
-
CNSA Commercial National Security Algorithm Suite
A specific set of cryptographic algorithms and key strengths that may be used to protect classified and unclassified national security systems. The suite was announced in 2015, replacing the former release of Suite B algorithms; CNSA 2.0 is the current revision.
Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)
-
EO 14412 Executive Order 14412
Securing the Nation Against Advanced Cryptographic Attacks, the Executive Order directing federal agencies to move to post-quantum cryptography. It requires agencies to transition all high value assets and high impact systems to PQC for key establishment by 31 December 2030, and for digital signatures by 31 December 2031, excluding national security systems.
Source: Federal Register , Executive Order 14412, signed 22 June 2026 (www.federalregister.gov)
-
GLBA Gramm-Leach-Bliley Act
The federal statute placing “an affirmative and continuing obligation” on each financial institution to respect its customers’ privacy and to protect the security and confidentiality of their nonpublic personal information. The safeguards its regulators require are where cryptography in transit and at rest comes in.
Source: U.S. Code , 15 U.S.C. 6801 (www.govinfo.gov)
-
HIPAA Health Insurance Portability and Accountability Act
A federal statute that called on the Department of Health and Human Services to establish regulatory standards protecting the privacy and security of individually identifiable health information.
Source: NIST , NIST SP 800-66r2 (csrc.nist.gov)
-
HVA High value asset
Federal information or a federal information system designated as a high value asset under OMB Memorandum M-19-03 or any successor document. HVAs are the systems EO 14412 puts first in the migration, alongside high impact systems.
Source: Federal Register , Executive Order 14412, section 4(d) (www.federalregister.gov)
-
IoT Internet of Things
The network of devices containing the hardware, software, firmware and actuators that allow them to connect, interact and exchange data. IoT devices are often the hardest part of an estate to migrate, because many cannot be updated in place.
Source: NIST , NIST SP 800-172r3 (csrc.nist.gov)
-
NIS2 NIS 2 Directive
The European directive on measures for a high common level of cybersecurity across the Union, replacing the 2016 NIS Directive. It sets baseline cybersecurity risk-management and incident-reporting obligations across sectors including energy, transport, water and digital infrastructure.
Source: EUR-Lex , Directive (EU) 2022/2555 (eur-lex.europa.eu)
-
NIST IR 8547 Transition to Post-Quantum Cryptography Standards
NIST’s report describing its expected approach to moving from quantum-vulnerable algorithms to post-quantum signatures and key-establishment schemes. It names the existing standards that are quantum-vulnerable and the quantum-resistant ones products will need to transition to, which is what makes it the document a migration plan is written against.
Source: NIST , NIST IR 8547: Transition to Post-Quantum Cryptography Standards (csrc.nist.gov)
-
NIST SP 800-208 Recommendation for Stateful Hash-Based Signature Schemes
NIST’s recommendation for stateful hash-based signatures, specifying the Leighton-Micali Signature system and the eXtended Merkle Signature Scheme along with their multi-tree variants. Stateful schemes suit firmware and code signing, where a signer can track state; SLH-DSA is the stateless alternative for general use.
Source: NIST , NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes (csrc.nist.gov)
-
NSM-10 National Security Memorandum 10
The 2022 policy directive setting United States government policy on migrating to quantum-resistant cryptography. It is the mandate that predates EO 14412 and is usually cited alongside CNSSP 15 for national security systems.
Source: The White House , National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, 4 May 2022 (bidenwhitehouse.archives.gov)
-
NSS National Security System
A system whose function involves intelligence activities, cryptologic activities related to national security, command and control of military forces, or equipment integral to a weapons system, or which is protected at all times by procedures for classified information. National security systems are governed separately from ordinary federal systems, which is why CNSA applies to them rather than the civilian baselines.
Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)
-
NYDFS 500 NYDFS Part 500
The New York Department of Financial Services regulation establishing cybersecurity requirements for financial services companies. It applies to Covered Entities licensed in New York, which is why it reaches institutions headquartered elsewhere.
Source: NYDFS , 23 NYCRR Part 500 (www.dfs.ny.gov)
-
PCI DSS Payment Card Industry Data Security Standard
The payment security standard intended for entities that store, process or transmit payment account data, and for developers and manufacturers of the software and devices used in those transactions.
Source: PCI Security Standards Council , PCI Security Standards Council (www.pcisecuritystandards.org)
-
SBIR Small Business Innovation Research
A federal program awarding non-dilutive, equity-free funding to American small businesses to develop technology and chart a path toward commercialization.
Source: SBIR , America's Seed Fund program overview (www.sbir.gov)
-
SCADA Supervisory control and data acquisition
A computerized system that gathers and processes data and applies operational controls over long distances, typically across power transmission and distribution or pipeline systems. SCADA equipment is often long-lived and cannot be modified, which is what makes cryptography it depends on hard to change.
Source: NIST , NIST SP 800-82r3 (csrc.nist.gov)
Somewhere else?
If your sector holds long-lived data in motion, the platform applies. Talk to a solutions engineer about your environment.