
The Compliance Landscape
Compliance frameworks are catching up to Post Quantum Cryptography. Here is where each stands as of April 2026.
FedRAMP
FedRAMP authorizations require FIPS 140-3 validated cryptographic modules. As ML-KEM, ML-DSA, and SLH-DSA FIPS-validated modules become available through 2026-2027, FedRAMP-authorized services will progressively incorporate them.
NIST IR 8547 (November 2024 draft) proposes deprecating RSA-2048 and equivalent algorithms by 2035 and disallowing them thereafter for federal use. FedRAMP follows FIPS, so the de facto FedRAMP PQC timeline aligns with IR 8547.
SOC 2
SOC 2 trust service criteria include encryption during transmission and at rest. As of April 2026, SOC 2 does not specifically require PQC. Auditors expect "appropriate" cryptographic measures; for services with long-lived customer data, this increasingly means addressing HNDL via PQC.
Expect SOC 2 guidance to explicitly address PQC through 2027-2028.
FIPS 140-3
FIPS 140-3 is the module-level certification. NIST CMVP (Cryptographic Module Validation Program) is validating ML-KEM and ML-DSA modules through 2026-2027. Check CMVP's public lists for current validated PQC modules.
ISO 27001
ISO 27001 Annex A controls require appropriate cryptography. PQC adoption is consistent with ISO 27001 expectations but not specifically mandated. ISO/IEC 27002:2022 controls include cryptographic key management and secure communication.
HIPAA
HIPAA Security Rule (45 CFR 164.312) lists encryption as an "addressable" safeguard. Not strictly required, but best practice. Covered entities with multi-decade data confidentiality should treat PQC as part of appropriate safeguards.
PCI-DSS
PCI-DSS 4.0 (effective 2025) requires strong cryptography. Does not specifically mandate PQC but requires organizations to address emerging threats. Expect PQC to be explicitly addressed in future PCI-DSS revisions.
GDPR
GDPR Article 32 requires appropriate technical measures. For data with multi-decade retention, PQC is a reasonable interpretation of appropriate measures against HNDL.
Practical Compliance Steps
- Track FIPS 140-3 CMVP PQC validations.
- Include PQC algorithm choices in your Information Security Policy.
- Update vendor contracts to require PQC roadmaps.
- Document PQC migration timeline in your SOC 2 SOC 2 Type 2 description.
- Include PQC in annual security risk assessments.
Frequently Asked Questions
Does FedRAMP require PQC today?
Not directly. FedRAMP requires FIPS 140-3 validated modules. As PQC FIPS validations become available, PQC enters FedRAMP compliance automatically.
Is SOC 2 mandating PQC?
Not specifically. SOC 2 requires appropriate cryptographic controls. Auditors increasingly expect PQC for services with long-lived sensitive data.
When will FIPS-validated ML-KEM modules be available?
Through 2026-2027. NIST CMVP's Validated Modules list is the authoritative source. Major vendors (AWS, Microsoft, Red Hat) are pursuing validations.
Does HIPAA require PQC?
Not explicitly. HIPAA Security Rule lists encryption as addressable. For patient data with lifetime-plus retention, PQC is part of appropriate safeguards.
Sources
Related Articles
Protect Your Data Before Q-Day Arrives
QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.
Try QNSQYOriginally published at quantumsequrity.com/blog/fedramp-soc2-pqc-requirements.