The world is already migrating to post-quantum cryptography.
QRQC tracks the standards, government deadlines, industries and technology dependencies shaping the global transition — with the evidence, document status and review date attached to every claim.
The meaningful quantum-risk clock is already running: migration deadlines, data lifetimes, procurement cycles and supply-chain dependencies all arrive before a cryptographically relevant quantum computer does.
Where each jurisdiction actually stands
Canada
Canadian Centre for Cyber Security (CSE) · Treasury Board SecretariatGovernment of Canada departments and agencies, primarily non-classified systems; CFDIR guidance extends to telecom and critical infrastructure
- 2024-07CFDIR quantum-readiness best practices v04guidance
- 2025-06ITSM.40.001 publishedpolicy roadmap
- 2025-10SPIN takes effectmandate
- 2026Departmental plans and reportingmandate
- 2031-12High-priority systems migratedmandate
- 2035-12Remaining systems migratedmandate
Canada pairs a technical roadmap with a compliance instrument, so every cryptographic dependency has to be located and reported, not simply acknowledged.
- A2ITSM.40.001 — Roadmap for the migration to post-quantum cryptography for the Government of Canada — Canadian Centre for Cyber Security (CSE) · final · reviewed 2026-09-06
- A1SPIN: Migrating the Government of Canada to Post-Quantum Cryptography — Treasury Board of Canada Secretariat · effective · reviewed 2026-09-06
- A2Canadian National Quantum-Readiness — Best Practices and Guidelines v04 — CFDIR Quantum-Readiness Working Group · guidance · reviewed 2026-09-06
Time to published deadlines
These are published policy milestones, not predictions of when a quantum computer will break encryption.
What changed most recently
- IETFRFC 10024 — hybrid ML-KEM TLS 1.3 A1Proposed StandardAug 2026
- GoogleCloud PQC readiness roadmap CVendor targetAug 2026
- Singapore CSAQuantum Readiness Index A2GuidanceJul 2026
- HKMABanking readiness index — 2.3/10 A3AssessmentJul 2026
- NISTCSWP 39 — crypto agility A2FinalJun 2026
- United StatesExecutive Order 14412 A1EffectiveJun 2026
- JapanCRYPTREC e-Government list update A1FinalMar 2026
- FranceANSSI PQC protocol guidance A2GuidanceFeb 2026
Where does quantum risk hit your industry?
Exposure, dependency classes and the actual published signal — with explicit cautions where no mandate exists.
Why migration is a supply-chain problem
Your migration date is set by whoever is slowest on the path between a NIST algorithm and your workload.
What does a standard actually require of you?
Each standard record separates its true document status from what it changes in practice for TLS, PKI, HSMs and devices.
ML-KEM — Module-Lattice Key Encapsulation
The core post-quantum key-establishment primitive.
FIPS 204ML-DSA — Module-Lattice Digital Signature Algorithm
The general-purpose post-quantum signature standard.
FIPS 205SLH-DSA — Stateless Hash-Based Signatures
Conservative hash-based signature alternative.
SP 800-227Recommendations for Key Encapsulation Mechanisms
Translates KEM primitives into secure usage.
NIST IR 8547Transition to Post-Quantum Cryptography Standards
The most quoted — and most misquoted — transition timeline.
CSWP 39Considerations for Achieving Crypto Agility
Connects PQ migration to routine algorithm replacement.
Every material claim is sourced, classified and last-reviewed.
Readiness here measures public evidence of preparation — never quantum-computer capability, and never a promise that a well-prepared jurisdiction is safe.