October 2, 2026
Sovereign Cryptography: The European and Italian Path to Strategic Autonomy in the Post-Quantum Era
Introduction

By Elia Pinto
4 min read
Sovereign Cryptography: The European and Italian Path to Strategic Autonomy in the Post-Quantum Era
In the European cybersecurity debate, encryption is no longer a technical detail for specialists. It is now a strategic infrastructure, crucial for data protection, organizational resilience, and the continent's technological autonomy.
Cryptographic sovereignty doesn't mean calling for an impossible digital autarky, nor does it mean abandoning international cooperation. Instead, it means being able to govern standards, verify implementations, control supply chains, and reduce dependence on opaque or unauditable solutions, especially in the most sensitive sectors.
This need has intensified as the post-quantum era approaches. The prospect of quantum computers capable of challenging many of today's most widely used algorithms is forcing institutions, businesses, and public administrations to promptly rethink the entire lifecycle of cryptographic functions. The transition involves more than just algorithms; it also involves architectures, procedures, keys, devices, and governance.
The European Framework: Between Compliance and Economic Strategy
The European Union has taken a leading role in defining common rules. The Union has begun to consider cryptography as a matter of economic, digital, and industrial security. This perspective includes regulatory and strategic instruments that directly impact the technological choices of public administrations and businesses.
Instruments such as the NIS2 Directive and the Cyber Resilience Act (CRA) introduce stringent requirements for security-by-design, vulnerability management, and adequate encryption throughout the entire supply chain. These obligations have a tangible impact on cryptographic implementations adopted in the private sector and public administration. These are complemented by the GDPR and the Data Act, which link data protection to the adoption of robust encryption measures, and the Dual-Use Regulation (EU) 2021/821, which regulates the export of advanced cryptographic technologies and critical components such as Hardware Security Modules (HSMs).
From Theory to Real Construction Sites: Quantum Corridors and EuroQCI
The European strategy on algorithms and secure communications is based on the Quantum Secure Networks Partnership (QSNP) and the European Quantum Communication Infrastructure (EuroQCI). After an initial phase focused on national quantum networks, attention is shifting to operational testing and the concrete interconnection of infrastructures. Three initiatives in particular point to this direction:
· **Cross-border corridors, starting from the SEEWQCI case:**An operational phase geared towards cross-border interconnections has been launched. The SEEWQCI (South-East Europe to Western Europe Quantum Communication Infrastructure) project is a significant example: a terrestrial quantum corridor of over 1,100 km connecting Greece and Bulgaria, with extensions via optical ground stations (OGS) to Cyprus and the Netherlands, to test quantum key distribution (QKD) on a continental scale.
· **The space component with EAGLE-1:**Quantum key distribution also requires satellite infrastructure. EAGLE-1, Europe's first prototype satellite for validating QKD from space, fits into this framework. The project is designed to extend secure encrypted communications to areas where fiber optics cannot reach, such as embassies, fleets, and remote areas, and is a key component of the future secure IRIS satellite constellation.
· **Certification with NOSTRADAMUS:**To reduce reliance on proprietary and unverifiable solutions, the European Union has launched the Nostradamus pilot infrastructure. Funded by the Digital Europe program and also hosted at the Joint Research Centre (JRC) laboratories in Ispra, this pan-European initiative aims to test, evaluate, and certify commercial QKD products before their adoption in sensitive public administration and critical infrastructure networks.
The Italian Presidium: The Synergy between ACN and De Cifris
Italy plays a significant role in this European architecture. The country boasts an ecosystem that combines institutional direction, scientific expertise, and the ability to connect research, the market, and public administration. The national model is based specifically on cooperation between two key players:
The National Cybersecurity Agency (ACN) represents the institutional and regulatory reference. Through its Guidelines on Cryptographic Functions, the ACN provides guidance on stream ciphers, the TLS protocol, and digital signatures, progressively translating post-quantum requirements into operational criteria for public procurement, public administrations, and entities included in the National Cybersecurity Perimeter.
The De Cifris Association, on the other hand, performs a scientific, academic, and community function. While the ACN defines the regulatory framework and criteria for technological scrutiny, De Cifris contributes to building the expertise, training, and applied research necessary to support migration in the medium to long term. This relationship confirms a key point: cryptographic sovereignty requires solid institutions, but also a scientific community capable of engaging with the market, with cutting-edge research — from the CNR to the INRiM — and with the space and defense industries.
Scenarios Compared: The Geopolitics of Global Cryptographic Models
International comparisons highlight that cryptographic sovereignty depends not only on the quality of algorithms, but also on the ability to build integrated ecosystems of research, standardization, industry, and governance. The strategies of the main global players reflect very different approaches:
Crypto-Agility and Control: The Roadmap for CISOs
The cryptographic transition cannot be treated as a simple software update. It is a paradigm shift that requires crypto-agility: the ability to isolate and replace a vulnerable or outdated algorithm without compromising business continuity. For CISOs and decision makers in public administration and businesses, cryptographic sovereignty translates into a few priority actions:
-
**Census and priorities:**Map legacy crypto assets, identifying data requiring long-term confidentiality and exposed to the "Harvest Now, Decrypt Later" risk — that is, the possibility of interception today and decryption in the future. In this process, the adoption of hybrid classical and post-quantum PQC primitives represents an essential step.
-
**Verifiability and open source:**Avoid closed, proprietary solutions without independent audits. It's preferable to favor open source software with European governance, requiring vendors to submit a Software Bill of Materials (SBOM) and align with Coordinated Vulnerability Disclosure (CVD) protocols.
-
**Trust anchors control:**Ensure that key management, PKIs, and root CAs remain under European jurisdiction, through certified HSMs located on-premises or within certified sovereign cloud architectures, such as Polo Strategico Nazionale.
-
**Leveraging testbeds:**use national and European validation infrastructures, such as the Nostradamus laboratory at the JRC in Ispra, to verify the resilience of their technology supply chain before implementing it into production systems.
The European and Italian path to cryptographic sovereignty does not involve isolation, but rather an open, verifiable, and concrete model. Managing adopted technologies, validating cryptographic libraries, and anticipating quantum threats, both on land and in space, are essential to safeguarding competitiveness, regulatory compliance, and national security.
Essential Bibliography
- National Cybersecurity Agency,Guidelines on Cryptographic Functions, National Cybersecurity Agency.
- De Cifris Association,Institutional website and technical reports on cryptographic research in Italy, De Cifris.
- European Commission,Recommendation (EU) 2024/1101 on a Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography, EUR-Lex.
- European Commission,European Quantum Communication Infrastructure (EuroQCI) — Deployment updates for Eagle-1, Nostradamus, and SEEWQCI, Official documents of the Directorate-General for Communications Networks, Content and Technology (DG CONNECT).
- CORDIS / European Commission,Quantum Secure Networks Partnership (QSNP)Project Fact Sheet, CORDIS Portal.
- ENISA,Post-Quantum Cryptography: Current state and recommendations, ENISA Publications.
- European Parliament and Council,Directive (EU) 2022/2555 on measures for a high common level of cybersecurity across the Union (NIS2 Directive), EUR-Lex.
- European Parliament and Council,Regulation (EU) 2021/821 setting up a Union regime for the control of exports, brokering, technical assistance, transit and transfer of dual-use items, EUR-Lex.
- Joint Research Centre (JRC),Quantum Technologies — EuroQCI Testing and Evaluation Laboratory Infrastructure, Scientific portal of the European Commission.