Annual Threat Landscape Report
This annual threat landscape review finds that the cited evidence is concentrated on a strategic, future-facing cyber risk: quantum computers may eventually undermine widely used public-key cryptography, while adversaries may collect encrypted information today for later decryption. The evidence does not establish when a cryptographically relevant quantum computer will exist, nor does it provide incident counts, sector loss totals, or measured adoption rates. It does establish a practical response: organizations should inventory cryptographic dependencies, prioritize high-impact and long-secrecy systems, engage suppliers, plan staged migration to post-quantum cryptography (PQC), and build crypto agility so algorithms can be replaced without unacceptable disruption.123
- The cited material is a primary-source desk-review bundle, not an original survey or incident dataset.
- Quantum timing is uncertain, but the evidence treats preparation as urgent because migration can take years and encrypted data may retain value for many years.
- NIST released three principal PQC standards in August 2024: FIPS 203 ML-KEM, FIPS 204 ML-DSA, and FIPS 205 SLH-DSA.
- The first operational step is a cryptographic inventory covering IT, operational technology, applications, protocols, devices, services, dependencies, versions, and patch levels where available.
- Prioritization should emphasize high-impact systems, industrial control systems, and data with long-term confidentiality or secrecy requirements.
- The evidence supports staged migration, testing, assurance metrics, supplier engagement, and crypto-agility planning; it does not support precise market-size, attack-frequency, or adoption claims.
Scope, date, and evidence method
Review date: 2026-06-29. This article is a dated desk review of the cited primary-source passages and source metadata. It is not an original the organization survey, forecast, incident study, or statistical estimate. The cited source set contains current or final materials from NIST, CISA, NSA, the UK National Cyber Security Centre (NCSC), and OWASP. The review gives priority to passages that directly describe threat conditions, standards, migration actions, governance practices, and limitations. Where this article draws an implication for decision-makers, that implication is identified as an inference rather than presented as a measured observation.31
The evidence set is uneven in subject and scope. Most of the directly relevant material concerns post-quantum cryptography and organizational readiness. NIST Cybersecurity Framework material supplies a general risk-management structure; NIST’s AI Risk Management Framework and OWASP CycloneDX material provide adjacent context about voluntary risk management and transparency capabilities, but they do not constitute evidence of quantum attacks, quantum-related losses, or PQC adoption. The source bundle also contains future-dated metadata for NIST CSWP 39 Update 1 and a future-dated AI RMF concept-note passage. Those dates and statuses are preserved as cited rather than independently validated.456
123What the evidence says about the threat landscape
The central observation is a future cryptographic threat, not a documented present-day quantum compromise. NIST describes quantum machines as potentially breaking many widely used cryptographic systems, while also stating that such machines may be years or decades away. The same material says that it is not possible to predict exactly when—or even if—quantum computers will break present-day encryption. This combination matters: the evidence supports preparedness under uncertainty, but it does not justify a precise countdown or a claim that a cryptographically relevant quantum computer already exists.12
The most immediate concern identified in the cited source set is “harvest now, decrypt later.” An adversary may capture encrypted data while unable to decrypt it and retain that data in the hope that future quantum capability will make it readable. The risk is therefore related to the useful lifetime of secrets, not only to the date of a future machine. CISA, NSA, and NIST similarly warn that actors could target data today whose protection is still required in the future. This is an evidence-supported threat scenario; the cited passages do not quantify how often it occurs or identify particular victims.23
The exposure is broader than a single encryption library. The readiness guidance identifies public-key cryptography in network protocols, end-user and server assets, applications and libraries, software and firmware updates, IT and operational-technology systems, cloud services, and commercial products. NCSC’s migration guidance additionally names applications, networking equipment, mobile devices, servers and workstations, internet-of-things and industrial-control devices, user tokens, and field-installed devices as objects to consider. The inference for an organization is that a narrow application scan is unlikely to represent the whole migration challenge.36
Standards, timing, and transition signals
NIST reports that, in August 2024, it released three principal post-quantum standards as Federal Information Processing Standards. FIPS 203 specifies ML-KEM, a module-lattice-based key-encapsulation mechanism; FIPS 204 specifies ML-DSA, a module-lattice-based digital-signature standard; and FIPS 205 specifies SLH-DSA, a stateless hash-based digital-signature standard. NIST’s project material says these standards are expected to provide the foundation for most deployments and can and should be put into use now.1
The standards story remains active rather than closed. NIST says it continues evaluating security and performance of additional algorithms; Falcon and HQC were selected for ongoing standardization, and additional digital-signature work was solicited for backup or specialized use cases. The cited evidence therefore supports treating the three principal standards as an immediate migration foundation while preserving the ability to incorporate additional standards later. It does not support claiming that every implementation, protocol, product, or certification is already ready.1
The sources provide two different kinds of timing signal. NIST’s overview says integration of a new algorithm into products and services has historically taken 10 to 20 years, while the NIST project material states that, under the transition timeline in NIST IR 8547, quantum-vulnerable algorithms will be deprecated and ultimately removed from NIST standards by 2035, with high-risk systems transitioning much earlier. NCSC cautions that global cryptographic infrastructure and trusted implementations will take years to become fully PQC-ready. These are planning signals, not a prediction of the date of a quantum breakthrough.216
| Signal | Cited observation | Practical interpretation | Limitation |
|---|---|---|---|
| Quantum-computer timing | NIST says timing is not predictable and machines may be years or decades away. | Plan under uncertainty rather than waiting for a date. | No probability or breakthrough forecast is cited. |
| Algorithm integration | NIST overview cites a historical 10–20 year integration period for new algorithms. | Start discovery, architecture, procurement, and testing early. | This is a general historical estimate, not an organization-specific schedule. |
| Principal PQC standards | NIST released FIPS 203 ML-KEM, FIPS 204 ML-DSA, and FIPS 205 SLH-DSA in August 2024. | Use the principal standards as the immediate migration foundation while monitoring further work. | The evidence does not establish readiness of every product or protocol. |
| NIST transition endpoint | The cited NIST project material says quantum-vulnerable algorithms will be deprecated and ultimately removed from NIST standards by 2035, with high-risk systems earlier. | Use the cited endpoint as a planning signal for federal-standard alignment. | The passage does not specify every system’s deadline or an organization’s compliance obligation. |
| Global implementation readiness | NCSC says fully PQC-ready global infrastructure and trusted implementations will take years. | Expect staged migration, interoperability work, and supplier dependencies. | The evidence does not quantify implementation availability by vendor or sector. |
Practical readiness sequence
A defensible readiness program begins with governance and scope. CISA, NSA, and NIST recommend creating a quantum-readiness roadmap, establishing a project-management team, conducting inventories and risk assessments, and engaging vendors. The inventory should be led with IT, operational-technology, procurement, cybersecurity, and privacy-risk participation so that technical dependencies and business consequences are considered together. This is an evidence-supported sequence; the cited sources do not prescribe one universal staffing model or budget.3
- Define the scope of the roadmap and identify owners for information technology, operational technology, procurement, cybersecurity, privacy risk, architecture, and service management.
- Build a cryptographic inventory. Record where public-key cryptography is used, which algorithms and protocols are involved, what data or function depends on them, and the associated system criticality.
- Map dependencies across applications, libraries, network equipment, cloud services, firmware, certificates, tokens, suppliers, and operational-technology environments. Capture versions and patch levels where available.
- Classify systems by impact, secrecy lifetime, exposure, replaceability, and migration complexity. Give early attention to high-impact systems, industrial-control systems, and long-term confidentiality needs.
- Create a target state and gap-based action plan. Use staged migration where simultaneous replacement is not feasible, and document exceptions, retirement decisions, modernization opportunities, and residual risk.
- Test implementations and measure adoption. Verify that negotiated protocols use intended PQC suites rather than silently falling back to traditional cryptography, and track systems or clients that have and have not migrated.
- Review the roadmap continuously as standards, vendor implementations, dependencies, and organizational priorities change.
NCSC explicitly cautions that an initial inventory need not be a formal asset register. At the early stage, understanding the nature of each system can be more important than listing every individual item; however, organizations should seek to quantify the scale of each system and capture versions and patch levels where available. The guidance also recommends identifying dependencies because some migrations may be relatively straightforward through service providers or routine updates, while others may require architectural change.6
Prioritization, staging, and assurance
Prioritization should follow consequences and feasibility rather than the mere presence of a cryptographic algorithm. The joint readiness fact sheet recommends giving priority to high-impact systems, industrial-control systems, and systems with long-term confidentiality or secrecy needs. Custom-built technologies, especially in older systems, may require the most effort to make quantum-resistant. For commercial off-the-shelf products, vendor engagement is critical, and the roadmap should record when and how each vendor plans to deliver updates or upgrades.3
A staged transition may be necessary. NCSC says organizations may need to operate old and new arrangements simultaneously for a period, using protocols that permit appropriate certificates to be negotiated as both communicating parties are upgraded. It also describes possible root-of-trust approaches and emphasizes case-by-case assessment. Authentication is not quantum-secure merely because some PQC components are present: in general, the system does not provide quantum-secure authentication until PKI migration is complete and traditional certificates have expired or been revoked.6
Assurance must test actual behavior, not only design intent. NCSC recommends checking that systems use standardized PQC cipher suites rather than falling back to traditional cryptography. It also recommends metrics such as the number of software clients using PQC and the identification of clients that are not. Such metrics can show migration progress, reveal remedial needs, and inform decisions about when support for traditional algorithms can be turned off. The cited evidence does not provide a universal threshold for “complete” migration.6
Crypto agility and broader governance
NIST defines cryptographic agility as the capability to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware, and infrastructure while preserving security and ongoing operations. In this review, crypto agility is best understood as a resilience characteristic: it reduces dependence on a single migration event and helps an organization respond when standards, implementations, performance requirements, or discovered weaknesses change. That final operational implication is an inference from the definition and the migration evidence, not a measured outcome in the cited bundle.7
The NIST CSF 2.0 passages support a governance pattern of documenting a current profile, defining a target profile, analyzing gaps, creating a prioritized action plan, implementing it, and updating the profile through continual improvement. Applied to quantum readiness, this can organize inventory findings, risk decisions, supplier commitments, exceptions, and migration metrics. The CSF material also emphasizes protecting identified and prioritized assets, detecting and analyzing adverse activity, and improving policies, plans, processes, and practices.8
The cited source set’s adjacent transparency evidence is relevant but limited. OWASP CycloneDX is described as an ECMA-424 bill-of-materials standard supporting software, software-as-a-service, hardware, machine-learning, cryptography, manufacturing, and operations bills of materials, as well as vulnerability disclosure and exploitability-exchange artifacts. Such artifacts may help structure dependency visibility, including cryptographic dependencies, but the cited passage does not demonstrate that any particular organization has implemented CycloneDX or that a bill of materials alone completes a quantum-readiness inventory.5
Missing, conflicting, and non-quantifiable evidence
This review should not be read as a statistical annual threat report. The cited evidence contains no incident count, breach count, loss estimate, sector-by-sector prevalence rate, percentage of systems using vulnerable algorithms, percentage of organizations that have migrated, or measured return on investment. It also does not establish that quantum attacks have been observed in the wild. Accordingly, the article uses qualitative findings and the few source-provided quantities—such as the 10-to-20-year integration estimate, the 2035 NIST transition endpoint, and the historical algorithm-selection counts—without extrapolating them into market or attack probabilities.31
The evidence is not fully uniform in date or purpose. The NIST PQC overview is dated 2024-08-13; the joint CISA, NSA, and NIST fact sheet is dated 2023-08-17; NIST CSF 2.0 is dated 2024-02-26; and NCSC migration guidance is dated 2025-03-20. NIST CSWP 39 Update 1 is marked final with cited publication and update dates of 2025-12-19 and 2026-06-29. The AI RMF and CycloneDX passages are contextual rather than direct quantum-threat measurements. These differences mean that readers should verify the current status of standards, implementation guidance, regulatory requirements, and supplier roadmaps before making binding decisions.456
- 01Define method
- 02Collect sources
- 03Analyze evidence
- 04State limits
- 05Draw implications
Conclusion
The cited primary sources describe a threat landscape defined by uncertainty in quantum timing but urgency in cryptographic preparation. The strongest evidence-based response is not to predict a breakthrough date; it is to discover dependencies, protect long-lived secrets, prioritize consequential systems, engage suppliers, migrate in tested stages, measure actual protocol behavior, and design for cryptographic change. The evidence supports a structured readiness program, but it does not support claims about current quantum attack prevalence, organization-wide adoption, or financial impact. Those questions remain outside this desk review’s evidence.1236
Frequently asked questions
Does this review say that a cryptographically relevant quantum computer already exists?
No. The cited NIST evidence says it is not possible to predict exactly when—or even if—quantum computers will break present-day encryption, and describes such machines as potentially years or decades away. The review therefore treats quantum compromise as a future risk requiring preparation, not as an established current incident pattern.12
Why begin migration before the quantum threat can be dated?
The evidence gives two reasons: integrating a new algorithm into products and services can historically take 10 to 20 years, and adversaries may collect encrypted data now for later decryption if it remains valuable for many years. These observations support early planning without establishing a precise quantum-computer timeline.231
What should a first cryptographic inventory contain?
It should identify the organization’s reliance on cryptography across IT and operational technology, including network protocols, applications and libraries, servers, end-user systems, software and firmware updates, cloud services, devices, certificates, tokens, and supplier products. Where available, record system scale, versions, patch levels, dependencies, data criticality, and secrecy lifetime. The initial effort need not be a formal asset register.36
Which PQC standards does the evidence identify?
The cited NIST project material identifies FIPS 203 ML-KEM for key establishment, FIPS 204 ML-DSA for digital signatures, and FIPS 205 SLH-DSA for digital signatures. NIST says these principal standards were released in August 2024 and can and should be put into use now, while additional standardization work continues.1
Is partial deployment enough to provide quantum-secure authentication?
Not necessarily. NCSC states that, in general, a system will not provide quantum-secure authentication until PKI migration is complete and traditional certificates have expired or been revoked. Organizations should also test that systems use intended PQC cipher suites and do not fall back to traditional cryptography.6
Sources
- 1Post-Quantum Cryptography Standardization Project
National Institute of Standards and Technology · current · NIST PQC project
Accessed July 26, 2026 - 2What Is Post-Quantum Cryptography?
National Institute of Standards and Technology · current · NIST PQC overview
Accessed July 26, 2026 - 3Quantum-Readiness: Migration to Post-Quantum Cryptography
CISA, NSA, and NIST · final · Joint Quantum-Readiness Fact Sheet
Accessed July 26, 2026 - 4AI Risk Management Framework
National Institute of Standards and Technology · current · NIST AI RMF 1.0
Accessed July 26, 2026 - 5OWASP CycloneDX (ECMA-424)
OWASP Foundation · current · ECMA-424
Accessed July 26, 2026 - 6Timelines for Migration to Post-Quantum Cryptography
UK National Cyber Security Centre · current
Accessed July 26, 2026 - 7Considerations for Achieving Crypto Agility: Strategies and Practices
National Institute of Standards and Technology · final · NIST CSWP 39 Update 1
Accessed July 26, 2026 - 8The NIST Cybersecurity Framework (CSF) 2.0
National Institute of Standards and Technology · final · NIST CSWP 29
Accessed July 26, 2026