Back to Blog
2026-09-04 QuantaLabs Team

India's quantum-safe compliance timeline: what it means and who it affects

India has set an aggressive regulatory timeline for quantum-safe compliance. Here is the complete breakdown of the 2026-2030 migration timeline for Critical Information Infrastructure.

India's quantum-safe compliance timeline: what it means and who it affects

India's Post-Quantum Cryptography (PQC) migration is not optional guidance sitting in a drawer. Driven by the DST National Quantum Mission Task Force and intersecting with stringent sectoral regulations, the timeline for compliance is concrete, aggressive, and already in motion.

This guide explains the actual regulatory timeline, who is bound by what, and what "starting before the deadline" means in practice.

The DST National Quantum Mission Task Force Roadmap

The Department of Science and Technology (DST) Task Force has outlined a rigorous, multi-track roadmap for national PQC adoption. It is critical to understand that while this roadmap serves as the national baseline, its immediate legal enforcement depends on individual sectoral regulators (like SEBI and RBI) adopting it into their specific frameworks.

The roadmap is divided into two primary tracks:

Track 1: Critical Information Infrastructure (CII) For sectors like Defense, Power, Telecom, Transport, and BFSI (Banking, Financial Services, and Insurance), the timeline is accelerated:

  • December 2027: Foundational readiness established.
  • December 2028: High-priority migrations completed.
  • December 2029: Full PQC adoption mandated.

Track 2: Standard Enterprises & Government Other government entities and private enterprises follow a slightly longer curve:

  • 2028: Foundational readiness.
  • 2030: High-priority migrations.
  • 2033: Full PQC adoption.

What Does "Foundations" Mean Near-Term?

The 2027-2028 foundational deadlines require concrete action items, not just policy meetings. The roadmap specifically calls for mandatory Cryptographic Bills of Materials (CBOMs) to baseline existing infrastructure, followed by live pilot programs using hybrid cryptography in high-priority systems.

SEBI CSCRF: Binding Compliance Today

While the DST roadmap targets future milestones, the SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) is a live, binding regulation today.

Applying to all SEBI-registered entities (brokers, AMCs, market intermediaries, and depositories), the CSCRF enforces rigorous structural security requirements. Relevant mandates include:

  • Mandatory CISO appointments.
  • Annual Vulnerability Assessment and Penetration Testing (VAPT).
  • 6-hour critical incident reporting windows.
  • Strict 5-year audit log retention.

This audit trail requirement heavily intersects with PQC readiness. Implementing immutable, tamper-evident compliance logging-such as the Sigstore Rekor-anchored audit trails generated by the QuantaCipher Gateway-builds the infrastructural muscle memory required to prove compliance when PQC mandates formally arrive.

The DPDP Act 2023

The Digital Personal Data Protection (DPDP) Act is another critical compliance vector. With DPDP Rules officially notified in November 2025, the substantive obligations for data fiduciaries phase in by May 2027. While the DPDP Act is primarily a data privacy law governing consent and breach notification, it mandates "reasonable security safeguards" to prevent personal data breaches. As classical cryptography becomes fundamentally vulnerable to quantum adversaries, failing to migrate to PQC will directly violate the DPDP's mandate to safeguard data.

Who is Actually Affected?

The blast radius of these frameworks extends further than many realize:

  1. Direct Operators: CII operators, BFSI, SEBI-regulated entities, and PSUs.
  2. The Vendor Ecosystem: Per the Task Force’s procurement language, any vendor selling software or digital services into these regulated sectors will be required to demonstrate crypto-agile and PQC-compliant architectures.

What "Migrating Before the Timeline" Actually Means

Given that a real, zero-downtime hybrid migration takes several quarters to engineer and execute, waiting until the deadline year is an existential operational risk.

The math is unforgiving: mapping your cryptography via CBOMs takes time, engineering a hybrid TLS edge termination takes time, and conducting safe, phased rollouts takes time.

Enterprises that begin their discovery phase today will be positioned to seamlessly navigate the 2027-2029 compliance wave, while those who wait will find themselves rushing highly complex cryptographic overhauls in production.

Share Article