· Michal Pietrus · 8 min read
Analysis of Poland's Cybersecurity Strategy in the Post-Quantum Context
Does the newly published Strategy adequately address the problem of digital communication in the era of advancing quantum technology?

The Cybersecurity Strategy of the Republic of Poland, updated in March this year, raises a number of topics. Here, however, we focus in particular on the aspect of digital communication security in relation to threats resulting from the existence of an effective quantum computer.
In this context, the Cybersecurity Strategy of the Republic of Poland discusses both post-quantum cryptography (PQC) and solutions based on quantum key distribution (QKD).
The Cybersecurity Strategy of the Republic of Poland and threats resulting from the existence of a quantum computer
Chapter “7.2 Development of national cryptology, including migration to post-quantum cryptography and development of quantum technologies” is where you will find most of this. While it requires some structuring of the argument and its logic, as it moves through several different, independent topics, i.e., cloud infrastructure, mechanisms increasing the accountability of operations performed on data (unclear what the author had in mind), or DLT, it is worth quoting several important points:
- In order to increase the resilience of information systems, national cryptographic capabilities will be developed, taking into account the challenges of post-quantum cryptography, including the ability to design and produce solutions based on cryptographic techniques, the ability to assess risk and act in crisis situations, and a scientific and research base prepared to develop and validate cryptographic technologies independently of foreign organisations and institutions.
- In the face of progress in cryptanalytic techniques, including in particular quantum cryptanalysis, the development of hostile cryptographic capabilities, and the possibility of embedding hostile components in hardware and software products, techniques will be developed to limit the effectiveness of attacks through alternative safeguards allowing at least the detection of data resulting from an attack. New cryptographic standards and algorithms adopted by foreign bodies will be assessed in terms of the mode of their implementation in the Republic of Poland.
- In order to develop national technological and industrial competences, research and development projects and programmes will be established in the area of cryptographic technologies, taking into account new technologies such as post-quantum cryptography, new communication techniques, including quantum key distribution (QKD) solutions […]
- The cybersecurity of the Republic of Poland will be strengthened by using the potential of national entities, including special services. Mechanisms of civil-military cooperation will be developed, as well as the involvement of Polish industry and academia in the development of cryptography and cryptanalysis. To this end, the Republic of Poland will also conduct active activities internationally, including within the EU and NATO, and bilaterally with key partners, while maintaining full control and sovereignty over cryptography used for national security purposes.
Then, I compare the above points with the “action plan” included in the second part of the Strategy:
| No. | Corresponding item in the action plan |
|---|---|
| Point 1 | 3.2.1; partly 3.2.3 |
| Point 2 | None; partly 4.2.1 |
| Point 3 | 3.2.1, 3.2.2; partly 4.2.1 |
| Point 4 | 4.2.1 |
Task descriptions:
- 3.2.1 – Development of a migration plan to post-quantum cryptography
- 3.2.2 – Construction of a national quantum communication network based on the QKD mechanism – PIONIER-Q, as part of EURO-QCI
- 3.2.3 – Development and provision to citizens, organisations and entrepreneurs of modern national cryptographic tools, such as pseudonyms, domain signatures, anonymous attribute certificates, one-time tokens
- 4.2.1 – R+D+I initiatives in the area of cybersecurity
Chapter 7.2 of the Strategy and concrete tasks: discussion
It is important that the Strategy includes areas specifically related to the problem of the existence of an effective quantum computer and the migration of cryptography to a post-quantum variants. It is also important that the Strategy touches on the problem of cryptographic sovereignty and its importance in the context of national security. However, bold strategic slogans are good to support with precision: what they are supposed to mean in practice, and what concrete KPIs allow to assess their effect.
What, however, do we actually find in the Strategy when translated into its concrete tasks?
Task 3.2.1
Task 3.2.1 is defined for the years 2025–2029. In practice, however, we should already have a framework plan today.
A detailed plan is not feasible at this stage due to organisational, sectoral, regulatory and operational complexity. This is not about already having a complete map for replacing every cryptographic scheme in every system. It is about having a decision-making framework:
- what we inventory,
- according to what risk we prioritise,
- what classes of systems we treat as critical,
- assigning agency and defining who is responsible in individual organisations.
Time is running out, and there are already several credible frameworks for how to approach this, for example:
- [The PQC Migration Handbook] (TNO, 12.2024),
- [A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography] (The Network and Information Systems (NIS) Cooperation Group, 11.04.2024),
- [G7 Cybersecurity Working Group Statement on preparing for a post-quantum cryptography migration] (G7 Group, 30.05.2026)
Task 3.2.1 has strategic importance, but in its current wording it does not define an execution mechanism for migration to post-quantum cryptography.
Task 3.2.2
Building a national backbone network based on QKD may have an operational justification in the context of action “3.3 Cloud solutions for strengthening the resilience of information systems” (see the Strategy).
Although we do not know the architectural details, QKD could form part of the communication layer responsible for establishing encrypted links between trusted data centres, especially in a model based on geographic redundancy of data processing centres. In other words, if many data sources and services are concentrated in a limited number of trusted locations, the case for QKD becomes more plausible.
I mentioned this in the post PQC vs. QKD.
Task 3.2.3
This is one of the more concrete application tasks in the entire area 3.2, because it includes specific proposals of services, not tools, where PQC cryptography will be applicable. However, it has little to do with the problem of migration to post-quantum cryptography, and is rather a support element for eGov services.
Task 4.2.1
This task serves as a very broad umbrella category. The problem is that with such a general scope, it is difficult to define clear KPIs, execution priorities, and expected outcomes in the context of migration to post-quantum cryptography.
Will this task have a real impact on the operational readiness of the state for PQC migration, or will it remain merely a declaration of support for innovation?
Cryptographic sovereignty
As I wrote in [Cryptographic sovereignty: Korea shows it can be done], cryptographic sovereignty is a choice that demonstrates several aspects:
- the determination of the state to have 100% its own solutions;
- scientific staff capable of designing their own cryptographic schemes, not to be confused with protocols, because this is a completely different field: applied cryptography, and capable of taking responsibility for them;
- eGov, critical infrastructure, electronic and military industry as the recipients of those schemes.
At the same time, this does not mean that Koreans plan to cut themselves off from the currently proposed safeguards in the context of the global internet, such as Merkle tree certs for WEBPKI, or hybrid key encapsulation mechanisms; KEM such as X-Wing KEM. It means that areas important from the point of view of the state are addressed with 100% domestic solutions, without being guided by what NIST or anyone else is doing.
Does the Republic of Poland need such sovereignty?
This question is inadequate today. The question that should be asked earlier is: for what purpose should the the Republic of Poland think about such a level of sovereignty?
Nevertheless, what would undoubtedly be a major success for the Republic of Poland is having the capability both to assess existing proposals and recommendations, such as those coming from NIST or Korea, and to prepare own guidelines for applying cryptographic schemes. Having guidelines similar to the French ANSSI Guide de sélection d’algorithmes cryptographiques, German BSI TR-02102 Cryptographic Mechanisms, or even EUCC Guidelines on Cryptography demonstrates not only analytical capabilities and cryptographic competence, but above all shows the maturity of the Republic of Poland to independently assess risk and define threat models in relation to its own infrastructure, industry and strategic interests.
Conclusions
Both cryptographic sovereignty and post-quantum cryptography are today important aspects, affecting the resilience of the Republic of Poland in the context of present and future threats directly related to digital identity and digital communication.
When thinking about sovereignty, the Republic of Poland should think in terms of agency, and demonstrate that agency through its own actions.
The geographic concept of the Baltic–Black Sea bridge coined by Romer over one hundred years ago is, on the other hand, sovereignty and agency not only of the Republic of Poland, but also of the entire local ecosystem of neighbouring states. Building redundant infrastructure, cooperation in the information domain, and building capabilities, including the foundations of secure communication such as cryptography.
Sovereignty, therefore, is not isolation, but agency. The ability of the state to act independently, but at the same time to build cooperation that strengthens the resilience of infrastructure, institutions and society.
Hypothetical annex to the Cybersecurity Strategy of the Republic of Poland
I consider the current Strategy insufficient in relation to threats resulting from the emergence of an effective quantum computer, but also in relation to the broader problem of cryptographic resilience. Therefore, I propose the following modifications:
Task 3.2.1: modification of the completion deadline
If post-quantum migration is to be operationally real, the task completion deadline is this year.
KPI:
publication of a report on the implementation of the task in Q3–Q4 2026;
definition of deadlines for completing migration in individual market segments;
Task 3.2.4: new task: National cryptographic guidelines
A factual demonstration of capability.
KPI:
- publication of national cryptographic guidelines,
- standardisation of cryptographic libraries integrated into national infrastructure and industry, e.g. following the NIST and FIPS path, or the German path: see the Botan library developed by BSI,
- legislative agency.

