Spain’s position in the post-quantum transition is defined by recognition without visible execution machinery: the country has strategic language, technical guidance, and institutions with relevant authority, but the public record does not yet show a national migration program that converts those ingredients into assigned responsibilities, coordinated deadlines, procurement pressure, certification updates, and measurable progress across public bodies. This diagnosis is limited to publicly visible evidence, since internal ministry and agency work sits outside the evidence base. Public accountability nevertheless depends on the public record, and that record still shows a gap.
European pressure
The European context makes deferral harder to justify because Member States now have a coordinated transition mandate in addition to technical warnings. In April 2024, the European Commission issued Recommendation (EU) 2024/1101, asking Member States to coordinate the transition to post-quantum cryptography, define milestones and timelines, and use a common roadmap as the basis for national plans. By June 2025, Member States, supported by the Commission, had published a coordinated roadmap and timeline. The direction is now administrative as much as technical: countries are expected to move from awareness to inventories, risk classes, pilots, procurement requirements, and migration schedules. The European roadmap expects Member States to begin the transition by the end of 2026 and to migrate high-risk use cases, including critical infrastructure, by 2030. The schedule allows staged execution, but it makes a public posture built mainly from general awareness increasingly difficult to defend.
Post-quantum migration reaches far beyond software updates because a state has to identify where public-key cryptography is used, which systems protect long-lived data, which suppliers need new requirements, which certification schemes must change, which procurements should require crypto-agility, and which high-risk use cases need pilots before deadlines become expensive. Cryptographic dependencies are distributed across protocols, products, certificates, signing workflows, identity systems, procurement contracts, outsourced services, and sector-specific assurance regimes. A national plan has to connect those layers, because no single technical update reaches all of them.
Public recognition
The public record already recognizes the problem through technical guidance and strategic material, beginning with CCN-TEC 009, “Recomendaciones para una transición postcuántica segura”, which the Centro Criptológico Nacional published in December 2022. That guide covers quantum and post-quantum cryptography, risks, hybrid solutions, crypto-agility, and a recommended calendar. The later CCN-STIC-221 guide on authorized cryptographic mechanisms includes post-quantum considerations and a phased view of transition. Spain’s 2025-2030 Quantum Technologies Strategy places post-quantum confidentiality and privacy on the national agenda and assigns CCN and INCIBE roles in accompanying the transition for public and private ecosystems.
Those documents make the criticism more specific because Spain has named the problem, has institutions with relevant authority, and has placed post-quantum language inside technical and strategic material. The public record still lacks an execution roadmap: a document or program that names which public bodies must build inventories, which systems count as high risk, which pilots begin first, which procurement clauses must change, which certification criteria will be updated, how suppliers will receive requirements, and how progress will be measured. Guidance identifies the issue for public and private actors. A roadmap assigns the next action and its deadline.
Institutional machinery
The Centro Criptológico Nacional is the natural institution to examine because it already sits near the operational center of public-sector cybersecurity in Spain. The CCN issues standards, instructions, guides, and recommendations; trains public-sector security personnel; coordinates security technologies; evaluates and accredits cryptographic products and systems; and operates as a certification body. If post-quantum cryptography is to become an operational public program, the CCN is the institution where that program should become visible.
Spain also has a working model for this kind of translation in the Esquema Nacional de Seguridad, which has produced compliance processes, certification practices, public guidance, training, metrics, and institutional routines that make cybersecurity assessable across public bodies and suppliers. Post-quantum migration needs a comparable administrative translation through classification, reporting, procurement requirements, accreditation criteria, and review cycles. The ENS machinery shows that Spain can build these structures; the remaining question is whether they are being built for the cryptographic transition.
Diffused responsibility
The risk in the current public posture is the diffusion of responsibility across layers that each have plausible reasons to wait. Ministries may wait for central guidance before building inventories. Vendors may wait for procurement pressure before implementing support. Certification schemes may wait for product demand before defining criteria. Public buyers may wait for certified offerings before changing tenders. Each actor can justify delay by pointing to another layer, and the transition becomes generally acknowledged without becoming assigned to anyone in particular.
A useful Spanish roadmap could start modestly and still change the structure of the problem: cryptographic inventories, risk classification, pilot selection, procurement language, and dependency mapping. It could distinguish near-term work by 2026 from high-risk migration targets around 2030. It could state which sectors and systems are being treated first because they involve long-lived confidentiality, authentication, firmware signing, identity assurance, critical service continuity, or legally sensitive records. It could also record what is unknown, because unknown dependencies are part of the migration problem.
The roadmap should distinguish capability failures from policy failures, since missing platform support and a certification regime that blocks a proposed fallback require different responses. A supplier unable to support hybrid deployment creates a different remediation path from a public body that lacks the basis for a degraded posture. Collapsing those outcomes into a general statement that migration is difficult leaves no basis for deciding who must act, what must change, and when a decision should be revisited.
Governed execution
Spain has a national quantum strategy, CCN guidance, ENS machinery, and an ecosystem capable of operational execution, but the public record still lacks the migration program that converts those ingredients into assignments, deadlines, pilots, procurement pressure, certification updates, audit evidence, and institutional accountability. Europe has moved from warning to roadmap. The Spanish public record still needs the step from recognition to governed execution.