PQ-NEXT Core: The Pilot Edition-Motor Oil Hellas
PQ-NEXT Core: The Pilot Edition-Motor Oil Hellas
Discover the PQ-NEXT Pilots
The PQ-NEXT solutions will be validated through large-scale pilots across the finance, critical infrastructure, telecommunications, and digital identity sectors, leveraging selected digital twin use cases. Throughout this blog series, we will take a closer look at each pilot, exploring its objectives, implementation, expected outcomes, and its role in advancing the transition to post-quantum security.
The Motor Oil Hellas Pilot
Pilot 3: Application of Quantum Resistant Crypto to Critical Infrastructure deployments
The Pilot
Pilot 3 “Application of Quantum-Resistant Cryptography to Critical Infrastructure deployments” is led by Motor Oil, with NCSR Demokritos, INDRA, Telefónica Innovación Digital and AFCEA as contributors. Its scope is to demonstrate how post-quantum cryptography can secure operational technology, smart metering and energy-network components in a representative refinery and energy critical-infrastructure environment. To do this safely, the pilot is built around a digital twin of Motor Oil’s testbed, a parallel, production-like environment in which hybrid PQC can be deployed, exercised and measured without any risk to live operations.
The Why
What is the problem the pilot will address, the sector motivation, and the quantum threat rationale?
Critical infrastructure depends on classical public-key cryptography (such as RSA and elliptic-curve) to protect VPNs, firmware updates, authentication and the exchange of sensitive operational data. A future cryptographically-relevant quantum computer would break these schemes, and because operational data and assets have very long lifetimes, the “harvest-now, decrypt-later” risk makes the threat effectively present today. For the energy sector the stakes are high: disruption to essential services has wide societal impact, and obligations such as NIS2 raise the bar for resilience. At the same time, operators cannot simply switch cryptography on live systems, because availability and safety must be preserved at all times. Pilot 3 addresses exactly this gap and it provides a safe, representative environment in which Motor Oil, as an industrial operator, can confront the quantum threat early and plan a controlled migration.
The How
The technical approach, deployment environment, tools, and expected outcomes
The technical approach is to reproduce Motor Oil’s critical-infrastructure network as a digital twin, replicating the real communication paths, routers, firewalls and field devices, including the PLC, the SCADA monitoring system, the Historian database, the pressure sensors and the smart-metering components. Within this environment we deploy hybrid post-quantum cryptography, combining CRYSTALS-Kyber for key establishment and CRYSTALS-Dilithium for digital signatures alongside classical algorithms. The deployment is implemented over StrongSwan (an IPsec-based VPN) using the liboqs library across the relevant application protocols, with the PQ-NEXT toolbox providing the cryptographic support to the OT components.
Three operational use cases are exercised: reading data from the field sensors, sending commands to the pump, and importing or exporting logs to and from the Historian. For each, we assess quality, latency, scalability and energy consumption against two headline KPIs, keeping the additional communication latency introduced by PQC below 50 ms for key exchanges and firmware updates, and supporting at least a 20% increase in the number of devices without performance degradation. The expected outcomes are validated, quantitative evidence that hybrid PQC can run in an OT environment with acceptable operational impact, together with reusable deployment profiles, a KPI methodology and lessons learned. These feed the project’s validation and simulation suite and its network-security enablers, and inform best practice for the wider critical-infrastructure sector.
PQ-NEXT Core: The Pilot Edition - Telefónica Innovación Digital
PQ-NEXT Core: The Pilot Edition - Telefónica Innovación Digital
Discover the PQ-NEXT Pilots
The PQ-NEXT solutions will be validated through large-scale pilots across the finance, critical infrastructure, telecommunications, and digital identity sectors, leveraging selected digital twin use cases. Throughout this blog series, we will take a closer look at each pilot, exploring its objectives, implementation, expected outcomes, and its role in advancing the transition to post-quantum security.
The Telefónica Innovación Digital Pilot
Pilot 2: Quantum-secure orchestration on a Telco Network
The Pilot
In recent years, networks have evolved into infrastructures that are more complex than they used to be, with multi-domain architectures, network programmability (SDN or NFV), and even the inclusion of AI-based automation. This is the scenario in which Pilot 2, Quantum-secure orchestration on a Telco Network, will be developed. This use case will evaluate the transition of network Operation and Management (OAM) to quantum-secure solutions. This pilot will identify the protocols and tools involved in the management plane and demonstrate the transition solution for the critical protocols. This scenario will select relevant domains in telco networks (cloud, transport, access, interconnection, etc.) and apply the best transition approach based on PQC and QKD hybridization.
This use case will be developed by TID in collaboration with UPM, using real infrastructure, since part of it will be developed and tested on a segment of MadQCI (Madrid Quantum Communication Infrastructure) in order to extract relevant information from real networks.
The Why
What is the problem the pilot will address, the sector motivation, and the quantum threat rationale?
Telecommunications networks have now reached a very high level of complexity, with many components depending on one another, including multi-domain architectures, IoT devices, and even the use of AI for automation. This creates significant security challenges, since with so many components involved, a vulnerability in just one of them may put the entire network at risk.
The threat posed by quantum attacks is particularly sensitive for telecommunications networks, as they are built upon highly heterogeneous infrastructures involving multiple vendors, technological domains, equipment generations, and software releases. This complexity is further increased by the fact that network infrastructures continuously evolve, while some components progressively become legacy systems. In many cases, these legacy devices may not be included in vendors’ quantum-safe migration roadmaps, leaving operators dependent on third-party decisions and timelines. As a result, the transition to post-quantum technologies may introduce interoperability challenges, some devices may become incompatible with others during the transition to post-quantum technologies is carried out.
Another issue that has been identified is that the roadmaps for the post-quantum transition of network equipment manufacturers are very long-term, which means that we currently cannot be certain how networks will behave once the transition to post-quantum technologies takes place. Moreover, since the telecommunications networks are already in operation, any update towards PQC-based solutions is particularly sensitive and must first be tested on a small-scale laboratory environments before being introduced into production networks. For this reason, it is very important to start carrying out this type of testing on a smaller scale in order to validate the transition.
With this use case, we aim to understand how the post-quantum transition will affect the quality of service provided by current networks, in order to fully understand all the implications it brings and to help define a set of recommendations and a roadmap for how the transition should be implemented while minimizing its impact on the current infrastructure.
The How
The technical approach, deployment environment, tools, and expected outcomes
To carry out the use case, quantum-safe implementations of the different protocols used in telecommunications networks will be tested, using standardized PQC algorithms and QKD. The pilot will test not only the security of the protocols, but also the deployment of a PKI system that uses PQC algorithms and hybridization based on the ACME (RFC 8555) and ACME-STAR standard (RFC 8739).
Another aspect to be tested in this pilot is the use of solutions that enable not only interoperability between quantum-safe solutions across devices from different manufacturers, in order to avoid dependence on third parties, but also ways to secure the legacy parts of the networks; that is, to identify mechanisms to protect equipment that does not have the capability to implement post-quantum solutions.
All these tests will be carried out both in emulated environments and in real telecommunications network environments. For the real network, MadQCI (Madrid Quantum Communication Infrastructure) will be used; it is one of the largest quantum networks in Europe. All tests performed in these environments will be aimed at assessing the feasibility of the post-quantum transition in real networks.
With all this, the pilot aims to draw conclusions on how the post-quantum transition will affect the current communications network infrastructure, studying both its impact on the quality of service provided and the impact of integrating the systems required for the transition. As a result, it is expected to define a set of guidelines or recommendations on how to carry out the transition, taking into account the importance of ensuring crypto-agility in the systems.
PQ-NEXT Core with Danai Theochari, Motor Oil Hellas
PQ-NEXT Core with Danai Theochari, Motor Oil Hellas
What drives PQ-NEXT from within? PQ-NEXT Core reveals the minds and teams behind the project. By showcasing the perspectives, insights, and ambitions of those leading its key areas, we uncover the vision and collaboration that shape PQ-NEXT’s vision.
Let’s start by getting to know Danai Theochari, Motor Oil Hellas, a little better and by introducing the team that will work on the project.
My name is Danai Theochari, and I am a Cybersecurity Expert at Motor Oil Hellas (MOH). I represent the Cybersecurity department in PQ-NEXT, where MOH serves as the owner of Pilot 3. My background is in incident response, penetration testing, cyber defence and resilience, with more than 6 years of experience protecting the kind of OT and IT environments that underpin energy operations. Motor Oil is a diversified, integrated energy provider in Southeastern Europe: we operate one of the most complex refineries in Europe and rank among the leading suppliers of electricity, energy-efficiency and electromobility services in Greece.
The journey to PQ-NEXT began from a simple operational concern: the cryptography that protects our critical communications today will not withstand a future quantum computer, yet our assets and the data they exchange have very long lifetimes. Joining the consortium gave us the opportunity to confront that risk early and in a controlled way, and to make sure the post-quantum transition is shaped around the realities of an industrial operator rather than only in the laboratory.
The Motor Oil team working on PQ-NEXT is deliberately multidisciplinary, bringing together the competencies needed to validate post-quantum cryptography in a live industrial setting:
- OT and automation engineers, who understand the SCADA, PLC and field-device environment that the pilot reproduces;
- IT and network-security specialists, responsible for the digital twin, the VPN and the integration of post-quantum and hybrid cryptography;
- compliance and risk colleagues, who connect the technical work to our regulatory obligations under NIS2 and the GDPR.
Within the project, this team works closely with our Pilot 3 contributors, the coordinator NCSR Demokritos, together with INDRA Sistemas de Comunicaciones Seguras (ISCS), Telefónica Innovación Digital (TID) and AFCEA.
What problem does your role in the project address in simple terms, and why is it critical for the project’s implementation?
In simple terms, my role makes the project real. As the industrial end-user and leader of Pilot 3, Motor Oil contributes to the operational environment, the requirements and the validation that turn post-quantum cryptography from a promising idea into something an energy operator can actually deploy. The problem we address is that critical-infrastructure operators cannot experiment with new cryptography on live systems, availability and safety come first, so there has been no safe, representative place to find out what hybrid post-quantum protection really costs in latency, scalability and energy.
This is critical for PQ-NEXT’s implementation because the project’s credibility depends on evidence from a realistic setting. By building a digital twin of our own infrastructure, we let the consortium test, measure and refine its tools against genuine industrial constraints without ever touching production. Our role also anchors the work in the regulatory reality of the sector, NIS2 and the GDPR, so that the results are not only technically sound but defensible for operators who have to justify every change.
What are the main activities, tasks, and objectives of your work and your work in PQ-NEXT?
Our overall objective is to demonstrate that post-quantum cryptography can secure operational technology, smart metering and energy-network components against future quantum-enabled threats without unacceptable operational impact. Concretely, Motor Oil’s work spans several work packages:
- Leading the Critical Infrastructure Pilot (WP4, M8–M36): designing and building the digital twin, integrating PQC algorithms (Kyber, Dilithium), measuring latency and energy KPIs, validating performance and reporting results in the context of Pilot 3.
- Pilot integration and planning (WP4, M4–M10): defining pilot 3 requirements, KPIs and integration support so that our activities align with the overall WP4 validation and demonstration plan.
- Feedback on migration tools and benchmarking (WP2 & WP3, M6–M24): providing industrial validation and feedback for hybrid deployment and crypto-agility optimisation.
- Compliance and risk input (WP5, M10–M30): supplying GDPR and NIS2 insights to the legal-navigator and risk-management framework.
- Dissemination and standardisation (WP6, M18–M36): sharing pilot outputs and best practices with the wider community and standardisation activities.
Moving on, a personal note. What is the main outcome you personally hope this project will achieve?
On a personal level, what I most hope this project achieves is to turn the quantum threat from an abstract worry into a manageable engineering decision for operators like us. If, by the end of PQ-NEXT, a critical-infrastructure operator can look at our pilot and see a credible, evidence-based path for adopting hybrid post-quantum protection in stages, with real numbers on latency, scalability and energy, and a clear way to stay compliant, then we will have removed a great deal of the uncertainty that holds the sector back today. I would like the digital-twin approach we are validating to become a trusted, repeatable way to de-risk this transition, so that protecting essential energy services for the long term becomes a matter of routine good practice rather than a leap of faith.
Looking ahead, what excites you most about the post-quantum era?
What excites me most is crypto-agility, the shift from cryptography as a fixed, one-off choice to something we can adapt as the threat landscape and the standards evolve. For an energy operator that is genuinely empowering: instead of reacting to each new risk, we can design resilience into our communications from the outset and update it with confidence. I am also drawn to the idea that security and sustainability can advance together. PQ-NEXT explicitly measures energy impact, which matters a great deal to us as an energy company. More broadly, the post-quantum era is a chance for industrial operators to move from the back foot to being proactive, protecting the essential services that society depends on well before the threat fully materialises.
PQ-NEXT Core: The Pilot Edition - Municipality of Aigaleo
PQ-NEXT Core: The Pilot Edition - Municipality of Aigaleo
Discover the PQ-NEXT Pilots
The PQ-NEXT solutions will be validated through large-scale pilots across the finance, critical infrastructure, telecommunications, and digital identity sectors, leveraging selected digital twin use cases. Throughout this blog series, we will take a closer look at each pilot, exploring its objectives, implementation, expected outcomes, and its role in advancing the transition to post-quantum security.
The Municipality of Aigaleo Pilot
Pilot 4: Quantum-Safe Digital Documents and Identity for Municipality Services of Aigaleo using Quantum-Safe Blockchain and EBSI Integration
The Pilot
The pilot focuses on the digital issuance and verification of the Property Exact Address Certificate (Βεβαίωση Ακριβούς Διεύθυνσης Ακινήτου), a real municipal administrative service. Citizens submit an application either electronically or in person, the Municipality processes the request and issues the official certificate, which is represented as a Verifiable Credential (VC). The pilot demonstrates how post-quantum secure digital credentials can support trusted and future-proof municipal service delivery.
The Why
What is the problem the pilot will address, the sector motivation, and the quantum threat rationale?
Municipal administrations issue hundreds of official certificates every year, many of which are still processed using conventional document exchange and paper-based verification procedures. Citizens often need to present these documents repeatedly to different public authorities or organisations, while municipalities need to ensure the authenticity and integrity of the issued certificates.
The pilot addresses these challenges by demonstrating how a commonly requested municipal certificate can be issued as a digitally verifiable credential, simplifying verification while reducing administrative burden. At the same time, PQ-NEXT investigates how post-quantum cryptography can protect these digital credentials against future quantum-enabled attacks, ensuring the long-term trustworthiness of municipal digital services.
The How
The technical approach, deployment environment, tools, and expected outcomes
The pilot digitalises the existing municipal workflow without changing its administrative logic. A municipal officer registers the application, uploads the required supporting document, and issues an Application Receipt Verifiable Credential after the request is officially registered. Once the application has been processed, the Municipality issues the final Property Exact Address Certificate as a Verifiable Credential, which is stored in the citizen's digital wallet.
The solution is deployed within the Municipality of Aigaleo and integrates the PQ-NEXT credential management components with the municipal workflow. The pilot demonstrates secure credential issuance, wallet-based presentation, verification of Verifiable Presentations (VPs), and trusted certificate validation using post-quantum-ready cryptographic mechanisms. The expected outcome is a practical demonstration of secure, privacy-preserving and future-proof digital public service delivery that can be replicated by other municipalities.
PQ-NEXT Core with Dimitris Tzempelikos & Maria Gotzia, Municipality of Aigaleo
PQ-NEXT Core with Dimitris Tzempelikos & Maria Gotzia, Municipality of Aigaleo
What drives PQ-NEXT from within? PQ-NEXT Core reveals the minds and teams behind the project. By showcasing the perspectives, insights, and ambitions of those leading its key areas, we uncover the vision and collaboration that shape PQ-NEXT’s vision.
Let’s start by getting to know Dimitris Tzempelikos, from the Municipality of Aigaleo, a little better and by introducing the team that will work on the project.
My name is Dimitris Tzempelikos, and I am the Head of the Programming and Development Department of the Municipality of Aigaleo in Greece. I am a mechanical engineer with postgraduate studies in computational mechanics and applied informatics. Throughout my career in local government, I have been involved in the coordination and implementation of European projects related to smart cities, digital transformation, cybersecurity, advanced connectivity, climate resilience and innovative public services.
This experience gradually brought me closer to the field of cybersecurity and to the challenge of protecting public-sector digital services against emerging threats. Joining PQ-NEXT was therefore a natural next step, as the project connects advanced post-quantum technologies with practical applications that can directly benefit citizens and public administrations.
The Municipality of Aigaleo’s team in PQ-NEXT also includes Maria Gotzia, an IT Engineer, and Evridiki Pavlidi, a Social Scientist. Maria contributes her technical knowledge and supports the connection between the project’s technological solutions, the Municipality’s digital infrastructure and the operational requirements of the pilot. Evridiki contributes the social science and user-centred perspective, helping us consider the needs of citizens and municipal staff, as well as issues related to usability, accessibility, engagement and social impact.
Together, we form a multidisciplinary team combining project coordination, public administration, information technology and social science expertise. This allows us to connect the technical work of PQ-NEXT with the Municipality’s real administrative procedures and with the practical needs of both municipal officers and citizens.
What problem does your role in the project address in simple terms, and why is it critical for the project’s implementation?
In simple terms, our role is to ensure that the technologies developed by PQ-NEXT can work in a real municipal environment and not only under laboratory conditions. Municipalities issue official documents that citizens use in important administrative and legal procedures. These documents must remain authentic, secure and verifiable. As public services become increasingly digital, we must also consider whether today’s security mechanisms will remain reliable in the future, when quantum computers may be able to compromise some of the cryptographic methods currently in use.
Our role is critical because we provide the real administrative process, the practical requirements and the end-user perspective. We help the technical partners understand how a municipal service operates, what information is required, which steps must be followed and what constraints must be respected. Without this connection to the real operational environment, even a technically advanced solution may be difficult to deploy, use or replicate in public administration.
What are the main activities, tasks, and objectives of your work and your work in PQ-NEXT?
Our main objective is to support the design, implementation and validation of the Municipality of Aigaleo pilot.
The first activity is to analyse and document the existing process for issuing the Property Exact Address Certificate. This includes understanding how citizens submit their applications, how municipal officers register and assess each request, which supporting documents are required and how the final certificate is issued.
We then translate this administrative process into functional and technical requirements for the PQ-NEXT solution. We work closely with the technical partners to ensure that the Verifiable Credential components, the digital wallet and the post-quantum security mechanisms are properly integrated into the municipal workflow.
We will also support the deployment and testing of the solution, involve the relevant municipal officers and users, collect feedback and evaluate its usability, security and practical value.
Finally, we contribute to project coordination, reporting, dissemination and the replication of the pilot, so that the experience gained in Aigaleo can also be useful for other municipalities and public authorities.
Moving on, a personal note. What is the main outcome you personally hope this project will achieve?
Personally, I hope that PQ-NEXT will demonstrate that post-quantum security can move from highly specialised research into practical public services that citizens can understand and use.
For me, success would mean that a citizen can request an official municipal certificate, receive it securely in a digital wallet and present it to another organisation without unnecessary paperwork or repeated verification procedures. At the same time, the citizen should be confident that the certificate is authentic, privacy-preserving and protected for the long term.
I would also like the Aigaleo pilot to become a practical example that can be replicated by other municipalities. Local authorities often have limited technical and financial resources, so solutions must not only be secure but also realistic, interoperable and easy to adopt.
The most important outcome would therefore be increased trust: citizens trusting digital public services and public authorities being confident that their digital infrastructure is prepared for future security challenges.
Looking ahead, what excites you most about the post-quantum era?
What excites me most is the opportunity to prepare our digital infrastructure before the threat becomes an immediate crisis.
The transition to the post-quantum era is not simply about replacing one cryptographic algorithm with another. It gives us the opportunity to reconsider how digital trust, identity, authentication and secure information exchange are designed across public administration.
I am particularly interested in the potential of post-quantum technologies to protect digital identities and official credentials that may need to remain valid for many years. This is especially important for governments and municipalities, which manage information and documents with long-term administrative, legal and social value.
The post-quantum era can also encourage public organisations to become more adaptable and crypto-agile, meaning that their systems will be able to respond more quickly to new threats and security standards.
Ultimately, what excites me is the possibility of combining innovation with public value: using advanced technology to create digital services that are safer, simpler and more trustworthy for citizens.
PQ-NEXT Core: The Pilot Edition - CaixaBank
PQ-NEXT Core: The Pilot Edition - CaixaBank
Discover the PQ-NEXT Pilots
The PQ-NEXT solutions will be validated through large-scale pilots across the finance, critical infrastructure, telecommunications, and digital identity sectors, leveraging selected digital twin use cases. Throughout this blog series, we will take a closer look at each pilot, exploring its objectives, implementation, expected outcomes, and its role in advancing the transition to post-quantum security.
The CaixaBank Pilot
Pilot 1: Secure Transition to Post-Quantum Cryptography in Financial Environments
The Pilot
The CaixaBank pilot is the financial-sector pilot within the PQ-NEXT project, with CaixaBank acting as the pilot leader. The pilot brings together CaixaBank, CyberAId, and other PQ-NEXT partners to address one of the key challenges facing the financial industry: preparing for the transition to post-quantum cryptography.
The pilot focuses on gaining visibility into cryptographic assets deployed within a banking environment, assessing potential exposure to quantum-related risks, and evaluating technologies and methodologies that can support future migration to quantum-safe solutions.
As the pilot leader, CaixaBank provides the real-world banking use case, defines operational requirements, coordinates pilot activities, and validates the outcomes from a financial-sector perspective.
The Why
What is the problem the pilot will address, the sector motivation, and the quantum threat rationale?
The financial sector is one of the industries most dependent on cryptography. Banking services rely on cryptographic mechanisms to protect customer information, secure digital identities, authenticate transactions, and safeguard communications across complex technology ecosystems.
The emergence of large-scale quantum computing could eventually compromise some of the public-key cryptographic algorithms currently used throughout the financial industry. Although this threat is not immediate, preparing for it requires significant planning and a long-term strategy.
One of the biggest challenges organisations face today is understanding their existing cryptographic landscape. In large enterprises such as banks, cryptographic assets are often distributed across thousands of applications, systems, devices, certificates, and communication channels.
The pilot addresses this challenge by improving visibility into cryptographic usage and helping establish the foundations required for a future migration toward quantum-safe cryptography. The ultimate goal is to enable informed decision-making and improve the long-term resilience of financial services against emerging quantum threats.
The How
The technical approach, deployment environment, tools, and expected outcomes
The pilot combines CaixaBank's operational banking environment with CyberAId's cryptographic discovery and assessment capabilities, along with the expertise provided by the broader PQ-NEXT consortium.
The technical approach focuses on identifying and inventorying cryptographic assets across selected banking environments, including cryptographic algorithms, certificates, protocols, and associated dependencies. This information is analysed to understand potential exposure to quantum-related risks and to identify areas that may require future migration efforts.
CaixaBank evaluates the results from the perspective of a large financial institution, validating both the effectiveness of the discovery process and the usefulness of the generated insights for future planning.
The expected outcomes include increased visibility of cryptographic assets, a better understanding of quantum-related risks, the identification of migration priorities, and the definition of best practices that can support not only CaixaBank's quantum-readiness strategy but also the broader financial sector's transition toward quantum-safe security.
PQ-NEXT Core with Ramón Martín de Pozuelo, CaixaBank
PQ-NEXT Core with Ramón Martín de Pozuelo, CaixaBank
What drives PQ-NEXT from within? PQ-NEXT Core reveals the minds and teams behind the project. By showcasing the perspectives, insights, and ambitions of those leading its key areas, we uncover the vision and collaboration that shape PQ-NEXT’s vision.
Let’s start by getting to know Ramón Martín de Pozuelo from the CaixaBank, and by introducing the team that will work on the project.
My name is Ramon Martín de Pozuelo, and I work at CaixaBank, where I am involved in cybersecurity and innovation initiatives related to the protection of critical assets and emerging technology risks. Throughout my career at CaixaBank, I have had the opportunity to work on projects focused on strengthening the bank’s security posture, improving risk management capabilities, and supporting the adoption of new technologies in a secure and controlled manner. As cybersecurity evolves, the emergence of quantum computing has become one of the most important long-term challenges for the financial sector. This is what led us to PQ-NEXT. The project offers a unique opportunity to collaborate with leading European organizations, research institutions, and technology providers to better understand the impact of the quantum threat and prepare our infrastructure for the transition to post-quantum cryptography. Being part of this initiative allows us not only to assess future risks but also to contribute to practical solutions that will help protect financial services in the years ahead.
CaixaBank leads the financial-sector pilot within PQ-NEXT. Our team brings together professionals from cybersecurity, cryptography, technology architecture, infrastructure, and innovation areas. We work closely with the project partners to evaluate how quantum-safe technologies can be adopted within a large banking environment. As pilot leaders, our role is not only to provide the use case and deployment environment but also to help define requirements, validate results, and ensure that the proposed solutions address real-world challenges faced by financial institutions.
What problem does your role in the project address in simple terms, and why is it critical for the project’s implementation?
Our role focuses on helping ensure that the project addresses real operational and security needs from the perspective of a large financial institution.
The financial sector depends heavily on cryptography to secure transactions, customer data, authentication systems, and internal communications. Before organisations can migrate to post-quantum cryptography, they need a clear understanding of where and how cryptography is currently being used.
By providing business requirements, operational feedback, and access to realistic banking environments, we help ensure that the solutions developed within PQ-NEXT are practical, scalable, and aligned with the challenges that financial institutions will face during their quantum-safe transformation.
What are the main activities, tasks, and objectives of your work and your work in PQ-NEXT?
Our main objective is to assess how a large financial institution can prepare for the transition to post-quantum cryptography.
This involves identifying cryptographic assets, evaluating potential quantum-related risks, validating discovery and assessment tools, and understanding the operational impact of future migration activities.
As leaders of the financial-sector pilot, we also coordinate pilot activities, provide the banking use cases, and evaluate the effectiveness of the solutions being tested. Ultimately, our goal is to generate practical knowledge that can help both CaixaBank and the wider financial industry develop realistic strategies for achieving quantum readiness.
Moving on, a personal note. What is the main outcome you personally hope this project will achieve?
Personally, I hope PQ-NEXT helps transform post-quantum security from a theoretical discussion into a practical and actionable roadmap.
Many organisations understand that quantum computing may eventually impact current cryptographic systems, but translating that awareness into concrete actions remains a challenge. I would like this project to provide clear methodologies, best practices, and lessons learned that organisations could use to start their own transition journey with confidence
Looking ahead, what excites you most about the post-quantum era?
What excites me most is the opportunity to build the next generation of cybersecurity foundations.
The transition to post-quantum cryptography is one of the largest security transformations our industry has faced in decades. It requires collaboration between industry, academia, technology providers, and regulators. Being part of that transformation and helping shape a more resilient digital future for financial services is both an exciting and highly motivating challenge.
PQ-NEXT Core: Bringing PQ-NEXT into higher education- the case of HSRM
PQ-NEXT Core: Bringing PQ-NEXT into higher education- the case of HSRM
What drives PQ-NEXT from within? This time, we sat down with our academic partners to discuss their role and contributions to the PQ-NEXT project.
Let’s meet and greet the RheinMain University of Applied Sciences and Arts. We will discover the university, the background, the team and the journey that led them in PQ-NEXT.
The RheinMain University of Applied Sciences and Arts is a university in the city of Wiesbaden, the capital of the German state of Hesse. We have a strong research focus on smart cities, metropolitan networks, and the application of quantum technology in smart city infrastructures. For example, one of the pioneering QKD networks in Germany is currently being operated over a distance of around 7 km between RheinMain University of Applied Sciences and the Hessische Zentrale für Datenverarbeitung, the Hessian full-stack IT provider for public institutions.
Due to the interplay between public service infrastructures, smart cities, post-quantum cryptography, and specialised network expertise, we are the ideal partner to address the synergies between applied research and practical teaching within the PQ-NEXT project. Our long-term collaboration with various project partners has led to several ideas, which we hope to further develop and mature during the project.
The RheinMain University of Applied Sciences and Arts and its role within PQ-NEXT
As mentioned above, RheinMain University of Applied Sciences is a public university of applied sciences with a strong research focus and independent doctoral rights in fields such as computer science, mobility and logistics, and social sciences, among others. Within PQ-NEXT, we plan to work on migration strategies from traditional cryptography to post-quantum infrastructures. By involving two PhD students, we aim to make substantial contributions to the infrastructure migration kit in Work Package 2, thereby creating a practical tool for public institutions to support the migration of their networks and data centres toward resilient post-quantum cryptography.
How does your work in PQ-NEXT influence your teaching activities and curriculum development?
The university already offers many relevant courses, such as telecommunications networks, post-quantum cryptography, cybersecurity, digital government, and information and communication technology for smart cities. The participation in PQ-NEXT will help us to enhance excellence in teaching by creating a bridge between cutting-edge research and practical teaching for the engineers and computer scientists of the future. We plan to supervise bachelor’s, master’s, and PhD theses throughout the project, as well as offer practical student projects to complement our existing curriculum.
What skills should today's students develop to be ready for the post-quantum era?
Depending on their specific role, students would need skills in cryptography, public key infrastructures, network protocols and telecommunication infrastructures, data centres and cloud computing, as well as cybersecurity, risk management, and structured vulnerability analysis and penetration testing.
How can students participate in quantum-safe cybersecurity research at your institution, and, in particular, in the PQ-NEXT project?
Students will be involved in projects, as well as in bachelor’s, master’s, and PhD theses, with the additional opportunity to work on cutting-edge research as junior researchers in the participating research groups.
How does collaboration with industry partners within PQ-NEXT enrich academic research?
Collaboration with industry partners will help us align the applied aspects of our research more closely with practical needs and increase the relevance of our activities in the fields of smart cities and metropolitan network architecture. It will also support the transfer between fundamental research, applied teaching, and the use of future technologies within industries and companies in the RheinMain region of Germany.
What excites you most about the future impact of PQ-NEXT?
We are convinced that the PQ-NEXT research will have a major impact on the future of networks and data centres across Europe. The shift to new cryptographic schemes is inevitable, and the transition needs to be carefully prepared and systematically executed. This is exactly the area in which our PQ-NEXT research will support the future transition of our infrastructure.
PQ-NEXT Core: Bringing PQ-NEXT into higher education - the case of AGH
PQ-NEXT Core: Bringing PQ-NEXT into higher education - the case of AGH
What drives PQ-NEXT from within? This time, we sat down with our academic partners to discuss their role and contributions in the PQ-NEXT project.
Let’s meet and greet the AGH University of Krakow (AGH). We will discover the university, the background, the team and the journey that led them to PQ-NEXT.
AGH University of Krakow (AGH) is a public university in Poland, founded in 1913. The university is one of 10 Polish higher education institutions that have been granted the title of a research university. AGH is recognized as the best of Polish technical universities in many international rankings (including CWUR, CWTS Leiden Ranking or Shanghai Ranking). The university comprises 18 faculties, research centers, and other didactic centers and departments. The supercomputers from the TOP500 list of the fastest supercomputers in the world operate in the Academic Computer Centre Cyfronet AGH. AGH offers three levels of education, including doctoral schools. The university educates more than 20,000 students and employs approx. 2,000 academic staff.
The PQ-NEXT team at AGH University works on Institute of Telecommunications and Cybersecurity. The Institute has broad experience in teaching and research in the field of telecommunications, computer science, and cybersecurity. The development strategy includes quantum technology and post-quantum solutions (e.g., quantum and post-quantum cryptography, security architectures and protocols, intrusion detection and mitigation, etc.). The institute has participated in many 4th, 5th, 6th, 7th, H2020 UE Framework Programs, EUREKA CELTIC, EDA, and COSTs projects.
The AGH University of Krakow (AGH) and its role within PQ-NEXT
AGH team—consisting of ten researchers, including two professors—is supporting PQ-NEXT project in research on quantum and post-quantum cryptography solutions, especially security analysis and performance evaluation. Also, integration of post-quantum cryptography algorithms with contemporary systems and networks is important research direction. Our contribution to the PQ-NEXT project is mainly focusing on post-quantum migration and quantum cryptanalysis.
How does your work in PQ-NEXT influence your teaching activities and curriculum development?
The influence is significant indeed. Universities are not only at the forefront of research in quantum computing and post-quantum cryptography, but they are also responsible for preparing the next generation of professionals. Therefore, we teach the future engineers, researchers, and security experts how and why post-quantum solutions work. For example, as part of the second-cycle Cybersecurity programme, AGH has introduced a compulsory master-level course dedicated specifically to post-quantum cryptography, positioned as a core subject directly linked to ongoing research projects, international collaboration and standardisation activities. This ensures that every graduate of the programme encounters quantum-related security challenges not as a niche curiosity, but as an integral element of their professional formation.
What skills should today's students develop to be ready for the post-quantum era?
Firstly, students should introduce quantum-related concepts early in the educational journey. Introducing fundamental concepts of quantum computing and post-quantum cryptography at the undergraduate level allows students to gradually build awareness of upcoming technological shifts and better understand the context of more advanced topics. However, the education should be consistently continued and deepened at the master’s level, where a more advanced knowledge and specialized skills are developing, covering both theoretical foundations and practical applications. Practical experience—such as standard analysis, implementation of post-quantum algorithms, integration of them into network protocols and systems, and benchmarking their performance—allows students to move beyond theory and understand real-world constraints, even if these are group projects within existing courses. Such approaches not only strengthen technical competence but also better reflect the challenges graduates will face in practice. However, universities should also foster interdisciplinary collaboration across computer science (including quantum algorithmics), mathematics, physics, and telecommunications to provide students with a holistic understanding of quantum technologies.
How can students participate in quantum-safe cybersecurity research at your institution, and, in particular, in the PQ-NEXT project?
Interested AGH students are actively involved in collaborative research activities within PQ-NEXT project, where they contribute to the implementation and testing of post-quantum solutions. This provides valuable hands-on experience with cutting-edge technologies, and the most successful outcomes often lead to joint scientific publications. In addition, the explored research topics frequently inspire the selection of bachelor's and master's thesis topics, enabling students to further develop their expertise in post-quantum cryptography and related fields. Then, the most motivated students have a smooth path to their PhD studies devoted to the post-quantum cryptography topics.
How does collaboration with industry partners within PQ-NEXT enrich academic research?
Close collaboration between academia and industry is essential for bridging the gap between research and real-world applications. Such partnerships facilitate the transfer of scientific advances into practical solutions, enable researchers and students to address genuine industrial challenges, and ensure that research remains aligned with current technological and societal needs. They also foster innovation, accelerate the adoption of emerging technologies, and better prepare graduates for careers in both academia and industry.
What excites you most about the future impact of PQ-NEXT?
The most exciting aspect is the opportunity to actively participate in one of the hottest research topics today—the development of quantum technologies. It is a unique chance to witness firsthand the ongoing migration toward post-quantum cryptography and to contribute to this historic technological transition while collaborating within an outstanding European research consortium.
PQ-NEXT core with Giulia Pastor and Marva Arampatzi, AUSTRALO
PQ-NEXT Core with Giulia Pastor and Marva Arampatzi, AUSTRALO
What drives PQ-NEXT from within? PQ-NEXT Core reveals the minds and teams behind the project. By showcasing the perspectives, insights, and ambitions of those leading its key areas, we uncover the vision and collaboration that shape PQ-NEXT’s vision.
Let’s start by getting to know Giulia Pastor and Marva Arampatzi, from AUSTRALO a little better.
I am Giulia Pastor, working in AUSTRALO and with my colleague Marva Arabatzi we are leading Work Package 6 Dissemination, Communication and Exploitation. I have a mixed background in political sciences, international relations and European affairs. After completing my BA and two MAs in Italy and France, I started working on EU-funded projects, initially focusing on administrative and financial management. Over time, I transitioned into communication and dissemination, and that’s where I realised I liked working closely with researchers and helping them translate complex scientific work into something more accessible and engaging.
“Scientists are experts in their fields but often need support in communicating their results to broader audiences. That’s where we, as science communication experts, come in — making sure that research doesn’t stay within academic circles, but reaches society as a whole”.
I am Marva Arampatzi, with a background in Marketing and International Business Management and over six years of experience working on EU projects, with a focus on dissemination and communication. What I enjoy most about working on EU projects is that, each time, depending on the project's topic, new challenges arise for me. One of them is the opportunity to explore a new scientific field by developing an understanding of the topic and then finding meaningful ways to make it accessible to people who, like me, come from outside that area of expertise.
You are the dissemination and communication partner for the PQ-NEXT project. What does this entail?
At AUSTRALO, we specialise in science communication, and in this project we lead WP6, which is the WP related to dissemination, communication, exploitation and standardisation. Specifically, we are in charge of the communication and dissemination activities, as well as the collaboration with other initiatives (such as the SPQR cluster). We work on a range of activities, including promoting the project to a wide range of stakeholders and ensuring that technical results are shared effectively in line with open science principles.
As I mentioned, our work is built around two main pillars: communication and dissemination. Communication focuses on raising awareness about the project, its objectives and its progress; dissemination, on the other hand, is about sharing scientific results with targeted audiences, including researchers and potential end-users.
A big part of our work also involves engaging with diverse audiences, from scientists and end users to the general public. Each group requires a different communication approach, which makes our jobs both challenging and interesting. Imagine explaining a complex, technical topic like post-quantum cryptography to the general public: it requires clarity, patience, and the ability to translate abstract concepts into relatable ideas.
We also led the D&C team for the PQ-REACT project, so we will utilise the knowledge gained from that project to enhance our activities and make the promotion of this project even more engaging!

Moving on, a personal note. What is the main outcome you personally hope this project will achieve?
Giulia: One of the most exciting results of the PQ-NEXT project is the development of a practical migration framework that assists governments, telecom providers, financial institutions, and critical infrastructure operators in transitioning safely from current encryption systems to post-quantum cryptography. Instead of focusing solely on theory, the project is creating real-world tools, hybrid cryptographic solutions, and large-scale pilot deployments to prepare Europe for the quantum era.
Additionally, this project brings together professionals from diverse backgrounds and expertise, so, as dissemination and communication leader, I am eager to promote the work behind it, transforming their complex activities into clear and engaging materials and campaigns!
Marva: For me, I hope this project will help raise awareness of the post-quantum transition in a way that feels relevant and understandable to everyone. Cybersecurity is something that affects all of us in our daily lives, and I believe that informed communities are better equipped to navigate the changes ahead.
Looking ahead, what excites you most about the post-quantum era?
Giulia: As someone with a social science background, it is fascinating to be part of a team of researchers, scientists, and experts working at such a transformative moment in the evolution of security technologies. It gives me the opportunity to witness real change, to see how technology develops and moves in the right direction: safeguarding people. Because in the digital world, protecting data means protecting people.
Marva: What I look forward to most is witnessing how this transition will shape our everyday lives, from the way we communicate and share information, to how we trust the digital systems around us, especially nowadays, when almost all of our everyday activities are becoming digital. It is one thing to work on something at a project level, but seeing it eventually reflected in the real world, in ways that people can feel and benefit from, is what makes this work truly worthwhile.









