State of Post-Quantum Cryptography
Post-quantum cryptography has moved from algorithm selection into implementation and migration. NIST released three principal final standards in August 2024: FIPS 203 for ML-KEM key establishment, FIPS 204 for ML-DSA digital signatures, and FIPS 205 for SLH-DSA digital signatures. The cited evidence does not establish a universal completion rate or a date for cryptographically relevant quantum computers. It does show a consistent operational direction: inventory cryptographic use, prioritize high-impact and long-secrecy systems, engage suppliers, build adaptable architectures, and test that deployed systems actually use post-quantum mechanisms. NIST and the UK NCSC identify 2035 as a significant transition horizon, while high-risk systems should move earlier.12
- The evidence describes PQC as an active migration and modernization program, not merely a future research topic.
- NIST’s principal 2024 standards are ML-KEM, ML-DSA, and SLH-DSA, while additional standardization work continues.
- The first practical control is visibility: organizations need inventories of cryptographic use, dependencies, criticality, versions, and suppliers.
- Prioritization should emphasize high-impact systems, operational technology, industrial control systems, and information with long-term confidentiality requirements.
- Migration assurance requires testing, metrics, and checks against fallback to traditional cryptography.
- The cited sources do not provide market-wide adoption statistics, a forecast date for a cryptographically relevant quantum computer, or a universal migration completion rate.
Scope, date, and evidence method
Review date: 2026-06-29. This is a dated primary-source desk review of the cited source set cited for this article. It synthesizes passages from primary government and standards sources, together with the cited OWASP CycloneDX specification description. It is not original survey research, market-measurement data, or a claim that the reviewed sources represent every sector or jurisdiction. The review preserves the cited publication dates, document statuses, versions, and uncertainty. Where a passage recommends an action, this article reports it as source guidance; where the article draws an operational implication by combining passages, that implication is identified as an inference.12
The evidence set is uneven in purpose. NIST materials describe the PQC program and standards; the CISA, NSA, and NIST fact sheet addresses organizational readiness; the UK NCSC material addresses migration planning and a target horizon; NIST CSWP 39 Update 1 addresses crypto agility; NIST CSF 2.0 supplies a broader risk-management structure; and CycloneDX describes bill-of-materials formats, including a cryptography bill of materials. The cited AI RMF passages are contextual framework material rather than direct evidence of PQC adoption, so they are not treated as PQC market evidence.345
1What the evidence says about the state of PQC
Post-quantum cryptography is presented in the evidence as cryptography intended to protect electronic information against a future threat from quantum computers that could eventually break many widely used cryptographic systems. NIST describes advanced quantum computers as a strong possibility while also stating that the field remains in its infancy, that major technical hurdles remain, and that how formidable such computers can become is still an open question. Therefore, the evidence supports preparation for a consequential future risk, but it does not support a precise arrival date or a claim that such a computer currently exists.6
The migration problem is not limited to selecting an algorithm. The CISA, NSA, and NIST guidance says organizations may be unaware of the breadth of dependencies on public-key cryptography across products, applications, and services. The NCSC similarly calls for understanding systems, services, data flows, software, hardware, dependencies, versions, patch levels, and management arrangements. The resulting state-of-practice observation is that PQC readiness is primarily an estate-visibility, architecture, supplier, and assurance challenge as well as a cryptographic-standardization challenge.27
Standards: what is final and what remains in motion
NIST reports that, in August 2024, it released three principal post-quantum cryptography standards as Federal Information Processing Standards. FIPS 203 specifies ML-KEM, a module-lattice-based key-encapsulation mechanism; FIPS 204 specifies ML-DSA, a module-lattice-based digital-signature standard; and FIPS 205 specifies SLH-DSA, a stateless hash-based digital-signature standard. NIST says these standards specify key-establishment and digital-signature schemes derived from candidates evaluated through a multiyear process.1
The standardization process was open and international in the cited NIST account. NIST initiated the selection and standardization effort in 2015, formally solicited algorithms in 2016, received 69 candidate algorithms by the stated deadline, and subjected candidates to multiple rounds of public analysis. Another cited passage describes an assessment of 82 algorithms from 25 countries and identifies 15 top algorithms, with finalists and alternatives and draft standards released in 2023. Because these passages describe different stages or summaries of the process, this review reports both figures without treating them as a single undifferentiated count.6
Standardization is not finished in the sense of a closed algorithmic ecosystem. NIST expects ML-KEM, ML-DSA, and SLH-DSA to form the foundation for most deployments, but it continues evaluating additional algorithms. The cited project passage says Falcon and HQC were selected for ongoing standardization and that longer-term work sought additional digital-signature schemes that could back up ML-DSA or address unique use cases. The practical inference is that organizations should begin implementation planning around the final standards while preserving room for future alternatives.1
| Standard | Algorithm | Function | Evidence status |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key establishment | Principal final PQC standard released in August 2024 |
| FIPS 204 | ML-DSA | Digital signatures | Principal final PQC standard released in August 2024 |
| FIPS 205 | SLH-DSA | Digital signatures | Principal final PQC standard released in August 2024 |
| Additional work | Falcon and HQC | Digital signatures and key encapsulation work | Selected for ongoing standardization; process continues |
Migration priorities: inventory before replacement
The readiness guidance places a cryptographic inventory at the beginning of the migration process. It should provide visibility into how cryptography is used across information-technology and operational-technology systems and help identify quantum-vulnerable algorithms in network protocols, end-user assets, servers, applications, and associated libraries. The inventory should be connected to data criticality and risk so that migration can be prioritized rather than treated as an undifferentiated replacement exercise.2
The NCSC evidence adds important inventory dimensions. Organizations should understand the nature and scale of systems, capture version information and patch levels where available, identify dependencies between components and services, and map systems through which data is processed. The estate may include internally operated services, externally accessible services, products with cryptography or data-processing functions, applications, network equipment, managed mobile devices, servers, workstations, IoT devices, ICS devices, end-user tokens, and field sensors. This is explicitly not intended to be a formal asset register at the initial stage.7
The cited guidance identifies several priority categories: high-impact systems, industrial control systems, operational technology, and systems with long-term confidentiality or secrecy needs. It also warns that information collected now could be targeted and decrypted later, commonly described in the evidence as a “harvest now, decrypt later” concern. This supports an immediate risk-based planning response even though the timing and capability of future quantum computers remain uncertain.2
For detailed assessment, the NCSC describes both top-down and bottom-up approaches. A top-down analysis focuses on core services and architectural interdependencies; lower-level exploration examines cryptographic use on networks and identifies components requiring updates. The CISA, NSA, and NIST material adds procurement and supplier engagement, including questions for vendors about quantum-readiness roadmaps. For commercial off-the-shelf products and cloud-hosted services, the roadmap should address when and how updates, upgrades, configuration changes, or application updates will enable PQC.72
Implementation, testing, and measurable assurance
The evidence treats migration as a controlled engineering and modernization program. Custom-built technologies, particularly older systems, may require substantial effort to become quantum-resistant; organizations should identify the data or functions at risk and either migrate the technology or develop security upgrades that mitigate continued use. The joint guidance describes PQC migration as an IT/OT modernization effort and calls for vendor plans to include timing, enablement mechanisms, and expected migration cost.2
Deployment must be verified rather than assumed. The NCSC warns that a change may not necessarily cause loss of service but can weaken security, and recommends additional testing to confirm that cryptography performs as expected. Its example is especially operationally important: once standardized PQC cipher suites are available for TLS, organizations should check that systems actually use them and do not fall back to traditional cryptography. The evidence therefore supports testing both functional continuity and cryptographic path selection.7
Assurance should include metrics. The NCSC gives examples such as quantifying how many software clients use PQC and identifying those that do not. Such measures can show migration progress, indicate remedial work, and help determine when support for traditional algorithms can be turned off. This is an evidence-supported measurement pattern, not a cited industry benchmark: the cited source set does not provide a percentage of clients using PQC or a market-wide adoption figure.7
A cryptography bill of materials may be a useful supporting artifact where an organization adopts it, but the cited CycloneDX passage establishes only that CycloneDX is an ECMA-424 full-stack bill-of-materials standard and that it supports a cryptography bill of materials among other formats. It does not establish that a CBOM alone discovers every cryptographic dependency, proves PQC readiness, or replaces architecture analysis and testing.12
Timelines, governance, and the limits of certainty
The cited NCSC timeline passage says the NCSC believes 10 years is sufficient for a rich set of PQC standards to appear, an ecosystem of products using them to develop, and uptake to become widespread. On that basis it identifies 2035 as a target date for completing migration to PQC, while acknowledging a tail of technologies that may take longer. It recommends that organizations focus on the 2035 target and prioritize systems processing business or personally sensitive data and systems managing critical communications.345
NIST’s cited project passage separately states that, under the transition timeline in NIST IR 8547, quantum-vulnerable algorithms will be deprecated and ultimately removed from NIST standards by 2035, with high-risk systems transitioning much earlier. These are related but not identical statements: one is an NCSC organizational target and the other describes a NIST standards-transition timeline. The evidence supports treating 2035 as a major planning horizon, not as proof that every organization will complete migration by that date.345
Governance should connect the migration to existing risk-management practices. NIST CSF 2.0 describes organizational profiles, current-to-target gap analysis, action plans, prioritization, and measurement of changes in operational risk. Applying that structure to PQC is an inference from the cited framework and PQC guidance: an organization can define a PQC current state, establish a target state, record dependencies and exceptions, assign actions, and report indicators to managers and executives. The framework itself is not presented here as a PQC-specific standard.345
The evidence also supports maintaining flexibility. NCSC says initial migration plans should be adaptable to future ecosystem developments, including evolving architectures and modern key-management solutions. NIST’s continuing work on additional algorithms reinforces that point. Accordingly, a defensible roadmap should distinguish fixed decisions—such as ownership, inventory scope, criticality criteria, and testing obligations—from decisions that may change as products, standards, and implementation guidance develop.345
What this desk review cannot establish
The closed bundle does not contain a survey of organizations, sector-by-sector deployment counts, product telemetry, cost data, migration completion percentages, or a statistically representative estimate of PQC adoption. It therefore cannot quantify the market’s current implementation rate or compare vendors. It also does not establish a date on which a cryptographically relevant quantum computer will be available. The cited NIST passage explicitly describes that question as open and the technical hurdles as substantial.6
The evidence includes a final NIST crypto-agility document with a document-history entry dated 2026-06-29, a 2025 publication date for the cited NCSC migration-timelines source, 2024 NIST standards and framework material, and a 2023 joint readiness fact sheet. Those dates matter: recommendations and ecosystem conditions may evolve. The review reports the cited source statuses—current or final—and versions rather than assuming that all passages have the same publication context.6
- 01Define method
- 02Collect sources
- 03Analyze evidence
- 04State limits
- 05Draw implications
Conclusion
The evidence supports a clear but qualified conclusion: post-quantum cryptography is in the transition phase between standardized algorithms and broad operational adoption. NIST’s three principal 2024 standards provide a foundation, while additional algorithm work and ecosystem development continue. Organizations should begin with cryptographic and dependency visibility, prioritize long-lived and high-impact data and systems, engage suppliers, design for algorithm change, and verify deployments through testing and metrics. A 2035 horizon is prominent in the cited NIST and NCSC material, but it is a planning milestone—not evidence of universal readiness, a guaranteed quantum-computer date, or a measured market completion rate.12
Frequently asked questions
Are the NIST PQC standards final?
The cited NIST evidence says that, in August 2024, NIST released three principal standards as FIPS: FIPS 203 for ML-KEM, FIPS 204 for ML-DSA, and FIPS 205 for SLH-DSA. NIST also continues work on additional algorithms, so finalization of these principal standards does not mean that all future standardization work has ended.1
Should organizations wait until a cryptographically relevant quantum computer exists?
No. The cited CISA, NSA, and NIST guidance urges organizations to begin preparing now because migration takes time and data may have long secrecy lifetimes. The evidence does not say when such a quantum computer will exist; it describes that timing as uncertain while recommending inventories, risk assessment, roadmaps, and supplier engagement.62
What should an organization do first?
Begin by creating a cryptographic inventory linked to data criticality and system dependencies. Include relevant IT and OT systems, applications, protocols, libraries, hardware, cloud and managed services, versions and patch levels where available, and supplier dependencies. Then prioritize high-impact systems, ICS and OT, and data requiring long-term confidentiality.27
How can an organization tell whether migration is working?
Test that implementations perform as expected and do not silently fall back to traditional cryptography. Track measures such as which software clients use PQC and which do not, then use the results to identify remediation and assess when traditional-algorithm support might be retired. The cited evidence provides these as examples, not as a universal KPI standard.7
Sources
- 1Post-Quantum Cryptography Standardization Project
National Institute of Standards and Technology · current · NIST PQC project
Accessed July 26, 2026 - 2Quantum-Readiness: Migration to Post-Quantum Cryptography
CISA, NSA, and NIST · final · Joint Quantum-Readiness Fact Sheet
Accessed July 26, 2026 - 3Considerations for Achieving Crypto Agility: Strategies and Practices
National Institute of Standards and Technology · final · NIST CSWP 39 Update 1
Accessed July 26, 2026 - 4OWASP CycloneDX (ECMA-424)
OWASP Foundation · current · ECMA-424
Accessed July 26, 2026 - 5The NIST Cybersecurity Framework (CSF) 2.0
National Institute of Standards and Technology · final · NIST CSWP 29
Accessed July 26, 2026 - 6What Is Post-Quantum Cryptography?
National Institute of Standards and Technology · current · NIST PQC overview
Accessed July 26, 2026 - 7Timelines for Migration to Post-Quantum Cryptography
UK National Cyber Security Centre · current
Accessed July 26, 2026