main main prints

The Charter of Trust is a non-profit alliance of global companies that are thought leaders and pioneer practitioners in cybersecurity and digital trust.

Activities

Strengthening cyber resilience

Key Initiatives in Security by Default, Supply Chain Security, Emerging Technologies, Education, and External Engagement
circles
Security by Default
Help integrate robust security measures into the core of every digital innovation and business operation.
circles
Supply Chain Security
Develop best practices on effectively ensuring the resilience of our respective supply chains against cyber threats.
circles
Emerging Technologies
Address and provide guidance to businesses on how to manage the complexities triggered by AI and Post Quantum Cryptography.
circles
Education
Raise awareness about cyber threats, promote best practices, and provide comprehensive training opportunities to individuals, students and organizations across the world.
circles
External Engagement
Foster public-private dialogue, prioritise greater alignment and reciprocity of cyber regulations internationally and advise regulators on practical implementation.
prints
News and publications

Latest updates

Important milestones towards more cybersecurity
CyberTrust Talk 2026 - Trust by Design or Trust by Regulation?
icon External Engagement

CyberTrust Talk 2026 - Trust by Design or Trust by Regulation?

Join us for a timely and dynamic fourth edition of the Charter of Trust CyberTrust Talk focused on “ Trust by Design or Trust by Regulation?” kindly hosted by Siemens. 
August 15, 2026
Charter of Trust launches Cyber Deterrence in the private sector
icon General announcements

Charter of Trust launches Cyber Deterrence in the private sector

The Charter of Trust has launched its Cyber Deterrence Working Group to address a central gap in today’s cybersecurity landscape: the disconnect between strong defensive investments and the persistent economic attractiveness of cybercrime. The group brings together industry partners to develop and validate practical deterrence methods that raise attacker cost and risk across sectors and borders.
June 30, 2026
Decrypting the Future: Global Timelines for PostQuantum Cryptography and why they matter
icon

Decrypting the Future: Global Timelines for PostQuantum Cryptography and why they matter

The transition to post-quantum cryptography is not a future problem — it is a present one. The threat of adversaries harvesting encrypted data today for decryption once quantum computing matures means that organizations with long-lived data and systems are already exposed. Waiting for cryptographically relevant quantum computers to arrive before acting is not a viable risk management strategy.



Exposure is not uniform across sectors. Financial services, government and defense, operational technology, and healthcare face the sharpest quantum risk, driven by decades-long data retention obligations, slow system replacement cycles, and the societal consequences of cryptographic failure. For these sectors, PQC readiness has moved from best practice to strategic imperative.



Globally, the direction of travel is clear. The United States, European Union, United Kingdom, Singapore, and Australia have each established structured PQC transition frameworks, with mandatory deadlines converging around the late 2020s and 2030. Organizations operating across jurisdictions should expect compounding compliance requirements and align migration plans accordingly.



At the same time, the geopolitical dimension of PQC standardization is becoming increasingly salient. The emergence of a “splinternet” infrastructure, characterized by regionally fragmented digital ecosystems, suggests that cryptographic standards diverge along political and strategic lines. As a result, organizations must not only manage technical migration but also navigate a politically charged landscape in which interoperability, regulatory alignment, and long-term cryptographic agility become critical strategic considerations.



This paper offers a comparative overview of regional PQC transition frameworks and identifies the business and systemic risks associated with quantum-vulnerable cryptography, providing insights for organizations preparing for the transition to post-quantum cryptography. Overall, PQC migration is a strategic transformation, not a technical patch. Cryptographic inventory, governance structures, crypto-agility, and supply chain engagement are as central to success as algorithm selection — and organizations that treat PQC readiness as an architectural and organizational challenge will be best positioned as quantum risks continue to mature.
April 9, 2026
--> -->