The PQC Landscape Today.
50%+
Web traffic using PQ key agreement (Cloudflare, Oct 2025)
5%
Federal agencies with PQC deployed (Federal News Network, May 2025)
$7.1B
Estimated federal migration cost, 2025 to 2035 (White House, Jul 2024)
$29.9B
PQC market size by 2034 (Precedence Research, Jun 2025)
Post-Quantum Transition Timeline.

Key milestones in the global transition to quantum-resistant cryptography, from policy directives to compliance deadlines.

YearMilestoneDetails
2022White House NSM-10National Security Memorandum directing agencies to begin PQC inventory and migration planning.
2022NSA Publishes CNSA 2.0Requires all National Security Systems to transition to ML-KEM, ML-DSA, and approved quantum-resistant algorithms.
2022OMB M-23-02 DirectiveFederal agencies must inventory all cryptographic systems, prioritize high-value assets, and submit migration plans.
2024NIST Finalizes PQC StandardsFIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) published. End of 8-year standardization process.
2024Federal Migration Cost: $7.1BWhite House estimates government-wide PQC migration at approximately $7.1 billion over 2025 to 2035.
2025NIST Selects HQCHamming Quasi-Cyclic selected as code-based backup to lattice-based ML-KEM. Draft standard expected 2026.
2025EU PQC RoadmapEuropean Commission publishes comprehensive PQC migration recommendations for member states.
2025EO 14306 and CISA Product ListFederal agencies directed to buy PQC-only products in "Widely Available" categories.
2025CNSA 2.0: Software DeadlineVendors must support and prefer quantum-resistant algorithms in new software and cloud services.
2027CNSA 2.0: Acquisition DeadlineAll new NSS equipment acquisitions must be CNSA 2.0-compliant starting January 1, 2027.
2031CNSA 2.0: Contractor DeadlineGovernment contractors operating NSS required to implement ML-KEM and ML-DSA.
2033UK NCSC DeadlineUK targets full PQC adoption across critical national infrastructure and government systems.
2035NSM-10: Full MigrationAll federal National Security Systems required to be fully quantum-resistant.
Government & Policy Updates.

Federal directives, NIST standards, and government mandates driving PQC adoption.

DateHeadline
Feb 2026Google Announces Merkle Tree Certificates for Post-Quantum HTTPS. Chrome develops MTCs to shrink PQ authentication data from ~14,700 bytes to 736 bytes.
Jan 2026CISA Publishes PQC Product Categories per EO 14306. Federal agencies directed to buy only PQC-capable products in "Widely Available" categories.
Oct 2025Over 50% of Web Traffic Now Protected by Post-Quantum Key Agreement. Cloudflare reports majority of human-initiated web traffic uses hybrid ML-KEM + X25519.
Sep 2025NCCoE Releases PQC Migration Practice Guide. SP 1800-38 covering cryptographic discovery, interoperability testing, and HSM integration.
Jun 2025Executive Order 14306: Sustaining Cybersecurity Efforts. Continues the bipartisan quantum security initiative. Affirms 2035 full-migration deadline.
May 2025Federal Survey: Only 5% Have Deployed Quantum-Safe Encryption. Despite 69% recognizing quantum as a top-three concern, just 5% have implemented PQC.
Mar 2025NIST Selects HQC as Fifth Post-Quantum Algorithm. Code-based backup to lattice-based ML-KEM. Different mathematical foundation for defense-in-depth.
Jan 2025EU Issues Comprehensive Post-Quantum Cryptography Roadmap. Urges immediate action across member states for critical infrastructure.
Aug 2024NIST Releases First 3 Finalized Post-Quantum Standards. FIPS 203/204/205 published. End of 8-year standardization process begun in 2016.
Industry & Technology Developments.

Product launches, protocol upgrades, and enterprise deployments across the PQC ecosystem.

DateHeadline
Jul 2025Microsoft Launches Azure Quantum-Safe with PQC Accelerator. Hardware-accelerated PQC for Azure targeting 10 to 15x performance improvement.
Jun 2025HP Launches Quantum-Resistant PC Series. Enterprise PCs with integrated PQC hardware modules for CNSA 2.0 compliance.
Jun 2025Orange Launches Quantum Defender Infrastructure. PQC/QKD-compatible network infrastructure with Toshiba Europe hardware.
Nov 2024Chrome Switches to ML-KEM for Post-Quantum TLS. Chrome 131 upgrades to final ML-KEM-768 + X25519 hybrid key agreement.
Feb 2024Apple Deploys PQ3 Post-Quantum Protocol for iMessage. Hybrid ML-KEM + ECC key exchange with ongoing post-quantum ratcheting.
Sep 2023Signal Adds PQXDH Post-Quantum Key Exchange. First major messaging app with PQ protection via PQXDH protocol.
Key Takeaways for Decision Makers.

Standards Are Final

FIPS 203/204/205 are published. HQC selected as backup. The "wait for standards" excuse is over.

Bipartisan Mandate

PQC migration spans administrations: NSM-10 (Biden, 2022) to EO 14306 (Trump, 2025). CNSA 2.0 acquisition deadline: January 1, 2027.

Hardware Gap Is Critical

Software-only PQC creates 100 to 1000x performance bottlenecks. Hardware acceleration required for TLS termination, HSMs, and code signing.

Web Is Already Migrating

50%+ of web traffic uses PQ key agreement. Enterprise and IoT infrastructure lags significantly behind.

Global Coordination

US (CNSA 2.0, 2027 to 2035), EU (2025 roadmap), UK NCSC (2033 deadline). Coordinated timelines converging.

Harvest Now, Decrypt Later

Adversaries are already collecting encrypted data for future quantum decryption. Every day without PQ protection increases exposure.

Start building
quantum-safe
infrastructure.

Pilot program now accepting applications. Request evaluation hardware or talk to our engineering team.