The mandate differs.
The cryptography problem doesn't.
Each sector below holds long-lived data on systems that cannot be recoded. QuProtect answers each one's regulator with the same platform, and each page tells the story on that sector's own network.
Each links to its definition, with the source it came from.
All terms-
Financial services
PCI DSS 12.3.3 already requires a cryptographic inventory. Payments and core banking move to post-quantum TLS without touching the applications.
Explore
-
Insurance
The same encryption duties as banking, over records kept for thirty years or more, across carrier, agency and field systems.
Explore
-
Energy and grid
Substation and control-centre links protected in place with post-quantum mutual TLS, with the inventory a NERC audit reads. Covers critical infrastructure and oil and gas.
Explore
- NIST IR 8547
- TSA Security Directives
-
Hospital systems
ePHI in motion across bedside devices, imaging and interface engines, without touching them, and the asset inventory and network map HIPAA asks for.
Explore
-
Telecom
Post-quantum TLS across core, backhaul and interconnect without re-platforming, and CNSA 2.0 on the federal circuits you carry.
Explore
- NIS2
- EU PQC Roadmap
- ETSI QSC
-
Defense
CNSA 2.0 on the systems already fielded: software-only, air-gap capable, with the inventory EO 14412 and the annual filing require.
Explore
-
Manufacturing
The compensating control NIST SP 800-82 describes: encryption and identity around PLCs and the OT/IT boundary, with no firmware change. Covers IoT, edge and satellite.
Explore
-
Pharma and life sciences
Post-quantum signatures and encryption for batch records, LIMS and trial data, without changing validated instruments.
Explore
-
State and local government
Citizen records that stay sensitive for a lifetime, on systems no vendor will touch. Software only, bought through vehicles procurement already uses.
Explore
- CJIS
- HIPAA
Terms on this page
-
CISA Cybersecurity and Infrastructure Security Agency
The National Coordinator for Critical Infrastructure Security and Resilience, which leads the national effort to understand, manage and reduce risk to cyber and physical infrastructure. EO 14412 directs CISA to issue the guidance agencies follow when migrating their systems.
Source: CISA , About CISA (www.cisa.gov)
-
CNSA Commercial National Security Algorithm Suite
A specific set of cryptographic algorithms and key strengths that may be used to protect classified and unclassified national security systems. The suite was announced in 2015, replacing the former release of Suite B algorithms; CNSA 2.0 is the current revision.
Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)
-
EO 14412 Executive Order 14412
Securing the Nation Against Advanced Cryptographic Attacks, the Executive Order directing federal agencies to move to post-quantum cryptography. It requires agencies to transition all high value assets and high impact systems to PQC for key establishment by 31 December 2030, and for digital signatures by 31 December 2031, excluding national security systems.
Source: Federal Register , Executive Order 14412, signed 22 June 2026 (www.federalregister.gov)
-
GLBA Gramm-Leach-Bliley Act
The federal statute placing “an affirmative and continuing obligation” on each financial institution to respect its customers’ privacy and to protect the security and confidentiality of their nonpublic personal information. The safeguards its regulators require are where cryptography in transit and at rest comes in.
Source: U.S. Code , 15 U.S.C. 6801 (www.govinfo.gov)
-
HIPAA Health Insurance Portability and Accountability Act
A federal statute that called on the Department of Health and Human Services to establish regulatory standards protecting the privacy and security of individually identifiable health information.
Source: NIST , NIST SP 800-66r2 (csrc.nist.gov)
-
HVA High value asset
Federal information or a federal information system designated as a high value asset under OMB Memorandum M-19-03 or any successor document. HVAs are the systems EO 14412 puts first in the migration, alongside high impact systems.
Source: Federal Register , Executive Order 14412, section 4(d) (www.federalregister.gov)
-
IoT Internet of Things
The network of devices containing the hardware, software, firmware and actuators that allow them to connect, interact and exchange data. IoT devices are often the hardest part of an estate to migrate, because many cannot be updated in place.
Source: NIST , NIST SP 800-172r3 (csrc.nist.gov)
-
NIS2 NIS 2 Directive
The European directive on measures for a high common level of cybersecurity across the Union, replacing the 2016 NIS Directive. It sets baseline cybersecurity risk-management and incident-reporting obligations across sectors including energy, transport, water and digital infrastructure.
Source: EUR-Lex , Directive (EU) 2022/2555 (eur-lex.europa.eu)
-
NIST IR 8547 Transition to Post-Quantum Cryptography Standards
NIST’s report describing its expected approach to moving from quantum-vulnerable algorithms to post-quantum signatures and key-establishment schemes. It names the existing standards that are quantum-vulnerable and the quantum-resistant ones products will need to transition to, which is what makes it the document a migration plan is written against.
Source: NIST , NIST IR 8547: Transition to Post-Quantum Cryptography Standards (csrc.nist.gov)
-
NIST SP 800-208 Recommendation for Stateful Hash-Based Signature Schemes
NIST’s recommendation for stateful hash-based signatures, specifying the Leighton-Micali Signature system and the eXtended Merkle Signature Scheme along with their multi-tree variants. Stateful schemes suit firmware and code signing, where a signer can track state; SLH-DSA is the stateless alternative for general use.
Source: NIST , NIST SP 800-208: Recommendation for Stateful Hash-Based Signature Schemes (csrc.nist.gov)
-
NSM-10 National Security Memorandum 10
The 2022 policy directive setting United States government policy on migrating to quantum-resistant cryptography. It is the mandate that predates EO 14412 and is usually cited alongside CNSSP 15 for national security systems.
Source: The White House , National Security Memorandum on Promoting United States Leadership in Quantum Computing While Mitigating Risks to Vulnerable Cryptographic Systems, 4 May 2022 (bidenwhitehouse.archives.gov)
-
NSS National Security System
A system whose function involves intelligence activities, cryptologic activities related to national security, command and control of military forces, or equipment integral to a weapons system, or which is protected at all times by procedures for classified information. National security systems are governed separately from ordinary federal systems, which is why CNSA applies to them rather than the civilian baselines.
Source: NIST , CNSSI 4009-2022 (csrc.nist.gov)
-
NYDFS 500 NYDFS Part 500
The New York Department of Financial Services regulation establishing cybersecurity requirements for financial services companies. It applies to Covered Entities licensed in New York, which is why it reaches institutions headquartered elsewhere.
Source: NYDFS , 23 NYCRR Part 500 (www.dfs.ny.gov)
-
PCI DSS Payment Card Industry Data Security Standard
The payment security standard intended for entities that store, process or transmit payment account data, and for developers and manufacturers of the software and devices used in those transactions.
Source: PCI Security Standards Council , PCI Security Standards Council (www.pcisecuritystandards.org)
-
SBIR Small Business Innovation Research
A federal program awarding non-dilutive, equity-free funding to American small businesses to develop technology and chart a path toward commercialization.
Source: SBIR , America's Seed Fund program overview (www.sbir.gov)
-
SCADA Supervisory control and data acquisition
A computerized system that gathers and processes data and applies operational controls over long distances, typically across power transmission and distribution or pipeline systems. SCADA equipment is often long-lived and cannot be modified, which is what makes cryptography it depends on hard to change.
Source: NIST , NIST SP 800-82r3 (csrc.nist.gov)
Somewhere else?
If your sector holds long-lived data in motion, the platform applies. Talk to a solutions engineer about your environment.