Satellite communication HNDL vulnerability: Military and commercial satellites have 15-25 year operational lifespans. NSA CNSA 2.0 sets a quantum-resistant transition timeline for National Security Systems by equipment category — software/firmware signing exclusively CNSA 2.0 by 2030, web/cloud services by 2033, traditional networking equipment by 2030, operating systems by 2033, niche equipment and custom applications by 2033 — which NSS satellite ground segments and links fall under. Currently intercepted satellite communications are harvestable for future quantum decryption.
Quantum Threats
Detailed analysis of quantum threats across industries, including criticality, at-risk cryptography, and PQC replacements.
Detailed analysis of quantum threats across industries, including criticality, at-risk cryptography, and PQC replacements.
What this means for you
- Executive / Business Leader
- "Your Exposure" at the top shows your sector's threats and "Your migration deadline" — the year the Mosca arithmetic says you must be done; the Severity chips in the Threat Catalog cut the list to Critical.
- GRC / Risk & Compliance
- Sort the Table view by Evidence to put the best-documented records first; each threat opens with its Data Provenance (peer review, vetting body, last verified) and a Reference Source link you can cite.
- Developer / Engineer
- The "By protocol" chips — TLS / HTTPS, SSH, VPN / IPsec and more — filter threats by what you build on, and say whether each match is stated in the record or inferred; each threat lists its At-Risk Cryptography and PQC Mitigation.
- Security Architect
- Each threat names its At-Risk Cryptography, its PQC Mitigation and the implementation pitfalls of the replacement (side-channel, fault, RNG); the Class chips split HNDL from HNFL so you know whether the exposure is data or signatures.
- Researcher / Academic
- "CRQC Threat Horizon" lists the CRQC arrival estimates by source and logical-qubit progress per machine, with a Mosca calculator; the Evidence column sorts records by peer review, source and confidence.
- Certification & Validation Engineer
- Each threat opens with its Data Provenance (peer review, vetting body, last verified); where a replacement algorithm has attack notes, the detail links to Implementation Attacks on /algorithms.
- IT Ops / DevOps
- Each threat's Detection & Response section has a "Detection / SOC" tab and an "Incident Response" tab; use the Industry filter for your sector and the Severity chips to work Critical first.
- Curious Explorer
- A line above the catalog tells you how many known threats there are and what one is; pick an industry in the list on the left to see the ones closest to you, and "Your Exposure" at the top sums it up.
Threats classed both (HNDL + HNFL) count in both totals.
When a cryptographically-relevant quantum computer (CRQC) could break today's public-key crypto — the clock your migration races.
The recommended start date has already passed — this is not a future target, it is how far behind you already are. Long-lived data for all sectors may already be exposed once a CRQC arrives.
Threat EconomicsPhase 0 · Executive Mandate
Why quantum threats have a clock: the two attacker business models and Mosca's migration deadline.
Attacker records encrypted traffic today and decrypts it once a CRQC exists. Threatens confidentiality; the clock is your data's secrecy lifetime.
Source: Federal Reserve FEDS 2025-093 (Mascelli & Rodden)Attacker waits for a CRQC, recovers a signing key, then forges signatures retroactively. Threatens authenticity; the clock is your credential's validity period.
Migration should have started 6 years ago. Data intercepted today is already at risk.
Migration should have started 6 years ago. Credentials signed today can be forged retroactively.
CRQC Capability WatchCTI
When the clock stops: the published expert forecast of CRQC arrival, the migration deadlines regulators have set (deadlines, not forecasts), and how far today's hardware has come.
- NIST IR 8547 (IPD, Nov 2024): 2030–2035
- NSA CNSA 2.0 (2022; FAQ version 2.1, December 2024): 2030–2033
- ANSSI France (2022 paper; current FAQ): 2030
- BSI Germany (TR-02102-1, 2026-01): 2030–2035
Industry | ID | Description | Crit.Criticality | Crypto | PQC Repl. | Actions |
|---|---|---|---|---|---|---|
| Aerospace / Aviation / Space | ||||||
| Aerospace / Aviation / Space | Moderate | Satellite communication HNDL vulnerability: Military and commercial satellites have 15-25 year operational lifespans. NSA CNSA 2.0 sets a quantum-resistant transition timeline for National Security Systems by equipment category — software/firmware signing exclusively CNSA 2.0 by 2030, web/cloud services by 2033, traditional networking equipment by 2030, operating systems by 2033, niche equipment and custom applications by 2033 — which NSS satellite ground segments and links fall under. Currently intercepted satellite communications are harvestable for future quantum decryption. Source: NSA CNSA 2.0 Cybersecurity Advisory | Critical | CNSA 2.0 will effectively deprecate RSA and ECDSA for National Security Systems when mandated. | ML-KEM-1024ML-DSA-87 (named CRYSTALS-Kyber/Dilithium Level V in the Sep 2022 advisory) per CNSA 2.0AES-256 | |
| Cloud Computing / Data Centers | ||||||
| Cloud Computing / Data Centers | Authoritative | NIST IR 8547 describes NIST’s expected transition from quantum-vulnerable cryptographic algorithms to post-quantum signature and key-establishment schemes. It is intended to inform migration efforts and timelines for information technology products, services, and infrastructure. Source: NIST IR 8547 / NIST SP 800-210 | Critical | TLS and other network-security protocols that rely on vulnerable classical cryptography are at risk. HSM cryptographic operations and stored sensitive keys require PQC-capable hardware. | FIPS 203 (ML-KEM)FIPS 204 (ML-DSA)FIPS 205 (SLH-DSA) cloud implementations | |
| Cloud Computing / Data Centers | High | NIST SP 800-210 provides general access control guidance for cloud service models (IaaS, PaaS, SaaS). Because vendors, including cloud service providers, often implement and control the cryptographic mechanisms an organisation depends on, vendor readiness is a critical factor in an organisation's PQC transition. Source: NIST SP 800-210: General Access Control Guidance for Cloud Systems | Critical | Cloud HSM performs cryptographic operations in FIPS 140-2 Level 3 certified hardware security modules. When you use Cloud HSMyour data is strictly isolated from other tenants and services in Google Cloud. All customer keys are stored wrapped with a regional wrapping key in the Cloud KMS database and can only be unwrapped by an HSM in the region as part of a cryptographic operation. Cloud systems generally pool resources across a multi-tenant modelso access-control design must ensure isolation of shared resources. | Cloud Key Management Service supports ML-KEM-768 and ML-KEM-1024which were standardized by NIST in FIPS-203and X-Wing+1 more | |
| Cloud Computing / Data Centers | Moderate | Long-lived ciphertext in databases, backups, and archives protected by classical key-wrapping mechanisms is exposed to store-now-decrypt-later risk. Source: Cloud Security Alliance — A Practitioner's Guide to Post-Quantum Cryptography | High | Long-lived ciphertext in databasesbackupsand archives protected by classical key-wrapping mechanisms is exposed to SNDL risk. Encrypted TLS traffic using RSA or ECC is exposed to future quantum decryption. | Re-wrap data-encryption keys using ML-KEM-derived key-encryption keys. Use AES-256 for symmetric encryption at rest and in transit. | |
| Cloud Computing / Data Centers | Moderate | Cloud Security Alliance quantum readiness guidance: CSA published quantum-safe security guidance identifying crypto-agility as critical requirement for cloud deployments. Multi-cloud environments using 5+ key management systems face fragmented PQC migration paths. Source: Cloud Security Alliance — A Practitioner's Guide to Post-Quantum Cryptography | High | Cloud KMS key wrappingmulti-cloud encryptionBYOK/HYOK solutions+1 more | Unified PQC key managementML-KEM cloud HSM integrationcrypto-agile KMS | |
| Critical Infrastructure / OT | ||||||
| Critical Infrastructure / OT | UpdatedLow | 10 CFR § 73.54 requires nuclear power plant licensees to maintain cybersecurity plans and protect digital computer and communication systems associated with safety, security, emergency preparedness, and supporting functions. Source: 10 CFR § 73.54 — Protection of digital computer and communication systems and networks | Critical | Digital computer and communication systems associated with safety-related functionsincluding the confidentiality and integrity of their data and software. | Defense-in-depth protective strategies for detectingresponding toand recovering from cyber attacks. | |
| Critical Infrastructure / OT | UpdatedLow | More than one billion smart meters are deployed worldwide and need migration planning for future quantum threats. Some meters use unchangeable fixed-function cryptography, while the oldest devices that cannot receive over-the-air updates will need replacement. Source: TechRadar — The post-quantum smart meter challenge that could cut off households | Critical | RSA/ECC cryptographysmart-meter communication modules and channelsmetering software+1 more | Low-footprint implementations of NIST PQC standards for embedded and memory-constrained smart meters. | |
| Critical Infrastructure / OT | UpdatedModerate | CISA’s PQC Initiative addresses quantum-computing security risks and supports critical-infrastructure and government networks during the transition to PQC. CISA is also helping critical-infrastructure owners and operators facilitate the eventual PQC transition for operational technology. Source: CISA Post-Quantum Cryptography Initiative / PPD-21 | Critical | Widely used encryption and digital-signature algorithms that protect data confidentialityintegrityand essential network-security functions are vulnerable to sufficiently powerful quantum computers. Federal agencies are required to inventory IT vulnerable to quantum decryption. | Sector-specific PQC migration roadmapsFIPS 203/204/205 complianceCISA ACDI deployment | |
| Critical Infrastructure / OT | UpdatedLow | Many critical-infrastructure OT systems use legacy RSA encryption, which is a primary target of quantum attacks because Shor's algorithm can break it. This creates a strategic "harvest now, decrypt later" risk, where adversaries collect encrypted OT communications today intending to decrypt them once quantum capabilities mature. OT further compounds this risk because a significant share of its endpoints run out-of-date, end-of-life operating systems and software that remain in operation for long periods. Integrating PQC protections adds processing overhead that can exceed the hardware capabilities of these OT systems. Source: Assessing Quantum's Risk on Critical Infrastructure - BISI | Critical | Vulnerabilities lie in critical infrastructure that uses RSA encryption. Due to their age and designmany such systems still use RSA encryption. | PQC algorithms require greater computational resourcesand integrating them into OT without disrupting real-time or safety-critical operations is complex and costly. The additional processing overhead from adopting or upgrading cryptographic mechanisms may exceed the hardware capabilities of current OT systems. | |
| Critical Infrastructure / OT | Moderate | Singapore's Cyber Security Agency released a Quantum-Safe Handbook and Quantum Readiness Index (in public consultation through end-2025) to guide Critical Information Infrastructure owners and government agencies toward quantum-safe migration. Source: CSA Releases A Quantum-Safe Handbook And Quantum Readiness Index | High | Critical Information Infrastructure cryptographic systems | Quantum-Safe Handbook guidance + Quantum Readiness Index self-assessment | |
| Critical Infrastructure / OT | UpdatedLow | NERC's January 2026 Critical Infrastructure Protection Roadmap addresses security of the North American bulk power system through measures including MFA, foundational cyber hygiene, and protection of SCADA and AGC communications using protocols such as DNP3, ICCP, and Modbus. Its survey material also identifies quantum computing as a risk to modern cryptography and gives an encrypted-data collection and later quantum decryption scenario. Source: NERC CIP Roadmap (January 2026) | Low | DNP3 is the IEEE-standardized protocol for electric power systems communications. Legacy protocols including DNP3ICCPand Modbus+4 more | The roadmap's recommendations focus on MFA and foundational cyber hygienenot a cryptographic-algorithm replacement. Its quantum-computing entry states the risk but names no mitigation or replacement algorithm. | |
| Cross-Industry | ||||||
| Cross-Industry | High | NIST IR 8547 is an Initial Public Draft dated November 2024. It describes the transition from quantum-vulnerable cryptography and identifies 2035 as the primary federal target for completing migration to post-quantum cryptography. NIST intends to deprecate classical digital signatures at the 112-bit security level after 2030. Source: NIST IR 8547 (IPD, Nov 2024) | Critical | Shor's algorithm on a future cryptographically relevant quantum computer is projected to defeat classical approved asymmetric algorithmsnamely RSAECDSA+1 more | FIPS 203 specifies the ML-KEM key-encapsulation mechanism with three parameter setsML-KEM-512ML-KEM-768+7 more | |
| Cross-Industry | Low | The 2024 Quantum Threat Timeline Report suggests that the quantum threat may be closer than previously thought. It emphasizes proactive quantum-threat mitigation. Source: GRI Quantum Threat Timeline Report 2024 | Critical | Standard encryption protocols are at risk from future quantum computers. | Organizations should undertake a proactivewell-planned transition to quantum-safe cryptography. | |
| Cross-Industry | Low | The NIS2 Directive requires entities in scope to adopt cybersecurity risk-management measures, including the use of state-of-the-art cryptography. Member States should connect with NIS2 and eIDAS supervisory bodies to understand the implications of the quantum threat for regulated entities. The roadmap also encourages real-world testing through activities such as ETSI Plugtests and IETF PQC hackathons. Source: European Commission Digital Strategy — PQC Roadmap | Critical | All quantum-vulnerable cryptography in EU member state systems and critical infrastructure | Migrating to post-quantum cryptography should use standardised and tested hybrid solutions whenever feasible. Quantum-vulnerable public-key mechanisms must not be used stand-alone for high-risk use cases after the end of 2030and for medium-risk use cases after the end of 2035. | |
| Cross-Industry | Low | DNSSEC quantum signature forgery: DNSSEC uses RSA (RSASHA256 per RFC 5702) and ECDSA (ECDSAP256SHA256 per RFC 6605) to sign DNS records — RFC 8624 covers current algorithm implementation requirements. Approximately 40% of global DNS domains have DNSSEC enabled including 92% root zone adoption. Quantum forgery of DNSSEC signatures enables DNS hijacking for any signed domain redirecting traffic to attacker-controlled servers. PQC signatures face challenges with DNS UDP packet size limits (~1232 bytes) requiring protocol-level changes. IETF draft-sheth-pqc-dnssec-strategy-01 addresses migration strategy. Source: IETF DNSSEC PQC Strategy / Verisign Research | Critical | DNSSEC signing currently relies on RSASHA256 (algorithm 8) and ECDSA (algorithm 13)both vulnerable to quantum attack. ECDSAP256SHA256 (algorithm 13) and ECDSAP384SHA384 (algorithm 14) are the DNSKEY/RRSIG algorithms defined by RFC 6605. | PQC signatures such as ML-DSA (2420-4627 bytes) and SLH-DSA (7856-49856 bytes) exceed DNS's UDP size limitrisking excessive TCP fallback and resolver performance degradation. Proposed conservative PQC candidates include SLH-DSAML-DSA (possibly combined with a traditional algorithm)+5 more | |
| Cross-Industry | Low | RPKI's mandated signature algorithm for certificates, CRLs, CMS signed objects, and certification requests is RSA PKCS #1 v1.5. RSA key pairs used for these RPKI signatures must have a 2048-bit modulus. This RFC 7935 profile obsoletes the earlier RFC 6485 algorithm profile. A quantum computer capable of breaking RSA could forge any RPKI signature, including on resource certificates and ROAs. That capability lets an attacker bypass route origin validation by forging a ROA that authorizes their own malicious route. RSA-2048 signing currently keeps the RPKI dataset at about 838MB. Switching to a post-quantum scheme such as ML-DSA-44 would grow that dataset to roughly 3.0GB. Source: APNIC / RIPE Labs RPKI Research | Critical | RSA-2048 ROA signaturesRPKI certificate hierarchyBGP route validation | RPKI's RSA signatures need a post-quantum replacement. A hybrid signature should combine a post-quantum signature with a traditional signature. Falcon-512 appears to be a good overall choice. | |
| Cross-Industry | Moderate | OpenSSH 10.0 was released on 2025-04-09. It uses the hybrid post-quantum algorithm mlkem768x25519-sha256 by default for key agreement. The algorithm is considered safe against attacks by quantum computers and has been standardized by NIST. Source: OpenSSH Post-Quantum Cryptography / GitHub Security | Critical | OpenSSH key agreement is the cryptographic function addressed by the hybrid post-quantum default. | OpenSSH 10.0 uses mlkem768x25519-sha256 as its default hybrid post-quantum key-agreement algorithm. | |
| Cross-Industry | High | NIST announced HQC's selection for standardization in March 2025. HQC is a code-based KEM intended to complement ML-KEM by relying on a different underlying security problem. NIST will create a draft HQC standard for public comment and, after adjudicating comments, publish a final version in approximately two years. Source: Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process | High | ML-KEMstandardized in FIPS 203was the first NIST PQC KEM; HQC was selected for standardization as the second PQC KEM. | HQC as a complementary KEM to ML-KEMproviding diversity through a different underlying security problem. | |
| Cross-Industry | High | NIST SP 800-227 KEM recommendations: Published as final standard on September 18, 2025 — initially released as Initial Public Draft in January 2025. Provides definitions, security properties, and implementation recommendations for key-encapsulation mechanisms as companion guidance to FIPS 203 (ML-KEM). Establishes best practices for KEM usage in protocols, hybrid constructions, and key management — essential reference for correct PQC deployment. Source: NIST SP 800-227 Recommendations for KEMs | High | Widely deployed quantum-vulnerable key-establishment schemes and KEM implementations that do not correctly implement the target KEM. | For TLSSP 800-227 describes bilateral key confirmation during the handshake. | |
| Cross-Industry | Low | Sigstore plans to enable content signing with post-quantum keys and eventually adopt post-quantum cryptography in services including Fulcio and Rekor. ML-DSA has been added to enable experimentation, while Sigstore still needs a plan for transitioning away from traditional cryptographic algorithms. Source: Sigstore & Post-Quantum Cryptography (2025) | High | Traditional cryptographic algorithms used by Sigstore servicesincluding FulcioRekor+1 more | ML-DSA ephemeral keys in Sigstore bundles for client experimentation. Future end-to-end PQCA support for private Sigstore instances after cryptographic-agility work. | |
| Cross-Industry | Moderate | Quantum random number generation (QRNG) for PQC key security: PQC algorithm security depends on high-quality randomness for key generation. Classical PRNGs may contain algorithmic biases exploitable by sophisticated adversaries. QRNG uses quantum mechanical processes to generate theoretically unpredictable randomness. Quantinuum Quantum Origin was among the first software-delivered QRNGs to obtain NIST SP 800-90B entropy source validation. Commercial QRNG products from ID Quantique, Quside, and QNu Labs are available for HSM, IoT, and automotive integration. QRNG complements PQC by ensuring cryptographic keys are non-predictable from generation. Source: NIST SP 800-90B / Quantinuum Quantum Origin | High | Quantum Origin is contrasted with traditional pseudo-random number generators. Hardware solutions can be affected by environmental factors. | NIST SP 800-90B validated QRNGquantum entropy sources for HSM key generationhybrid classical-quantum RNG | |
| Cross-Industry | Moderate | NIST IR 8547 proposes deprecation after 2030 and disallowance after 2035 for listed quantum-vulnerable digital-signature and key-establishment algorithm families, including RSA, ECDSA, and elliptic-curve key establishment. NSM-10 establishes 2035 as the primary target for completing migration to PQC across federal systems. SP 800-131A separately addresses transitions in algorithms and key lengths used by federal agencies to protect controlled unclassified information. Source: NIST IR 8547 (IPD Nov 2024) + SP 800-131A Rev 2 | High | NIST-approved symmetric primitives providing at least 128 bits of classical security are believed to meet at least Category 1 security. NIST symmetric-cryptography standards at the 112-bit security level will be disallowed in 2030. | NIST does not expect migration away from its existing symmetric-cryptography standards as a wholebut applications should move away from symmetric standards at the 112-bit security level during the PQC transition. | |
| Cross-Industry | High | KyberSlash1 and KyberSlash2 are timing vulnerabilities in several Kyber/ML-KEM implementations, including the official reference code. Their exploitability was demonstrated on the Raspberry Pi 2 and Arm Cortex-M4, with Kyber secret keys recovered within minutes for KyberSlash2 and within a few hours for KyberSlash1. Source: KyberSlash: Exploiting secret-dependent division timings in Kyber implementations (IACR TCHES) | High | Kyber/ML-KEM implementations containing the KyberSlash1 or KyberSlash2 timing vulnerabilitiesincluding the official reference code. | Use dynamic analysis to detect variable-time instructions operating on secret dataor formal methods to guarantee the absence of variable-time instructions in cryptographic software. | |
| Cross-Industry | UpdatedHigh | This document examines the specific risks that quantum computing could pose to industrial control systems (ICS) and other operational technology (OT). Source: Post-Quantum Considerations for Operational Technology | CISA | High | OT specifically may be vulnerable due to connectivity or association with IT platforms as well as direct or indirect dependencies on public-key cryptographic features including encryption and decryptionsigning and validation schemasand identity and access management mechanisms. | OT vendorsownersand operators should plan for emerging CRQC capabilities and implement mitigations+4 more | |
| Cross-Industry | Moderate | BSI TR-02102-1 provides Germany's official security assessment and recommended key lengths for cryptographic mechanisms, forming the baseline against which PQC transition urgency is judged. Source: BSI TR-02102-1 Cryptographic Mechanisms: Recommendations and Key Lengths | High | Table 1.2 summarises the recommended key lengths of different types of cryptographic primitives. Over timeseveral block cipher algorithms have been specified for use by the Federal Government. The digital signature algorithms are specified in FIPS 186. | BSI-recommended cryptographic mechanisms with long-term security orientation | |
| Cross-Industry | Moderate | ANSSI-PG-083 version 3.00 sets out rules and recommendations for choosing and sizing cryptographic mechanisms. It accounts for the quantum threat and aims to remain valid for at least 15 years. Source: ANSSI-PG-083 Guide des mecanismes cryptographiques v3.00 | High | AESRSAECDSA+4 more | It also names ML-DSA and SLH-DSA for signatureswith hybrid-use conditions where specified. | |
| Cross-Industry | Moderate | CCN-TEC 009 (Spain's National Cryptologic Centre) recommendations for a safe post-quantum transition, covering CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon, SPHINCS+, BIKE, HQC, Classic McEliece and SIKE, driven by Shor's/Grover's algorithm risk and harvest-now-decrypt-later. Source: CCN-TEC 009 Recommendations for a safe post-quantum transition | High | RSAElGamalelliptic-curve cryptosystems vulnerable to Shor's algorithm; symmetric key lengths need doubling against Grover's algorithm | CRYSTALS-KyberCRYSTALS-DilithiumFalcon+3 more | |
| Cross-Industry | Low | CSA guidance provides a practical framework for modernizing cloud key management for PQC, including cryptographic asset inventory, crypto agility, and mitigation of Store-Now-Decrypt-Later and hybrid-downgrade risks. It discusses hybrid and migration-ready PQC updates affecting TLS, SSH, and IKEv2. Source: Post-Quantum Cryptography Key Management | High | RSAECCECDSA key management; AES-128/256+1 more | ML-KEMML-DSASLH-DSA+1 more | |
| Cross-Industry | Low | Israel's National Cyber Directorate (INCD) Alert 1855 (6 March 2025, TLP:CLEAR) warns that quantum computers can break widely used public-key algorithms — factorization (RSA), discrete logarithms (Diffie-Hellman) and elliptic-curve discrete logarithms — used in TLS, SSL-VPN and API key exchange. It flags forged digital signatures on software and firmware and on documents convertible to money (including digital currencies), especially on ICS/SCADA and medical (IoMT) platforms whose algorithms are hard to replace, and harvest-now-decrypt-later capture of long-sensitive data as a risk that may already be under way. It directs organisations to appoint an owner, find systems with non-resistant components and plan to add NIST's standardised PQC algorithms alongside existing ones, prioritised by system and data sensitivity, with crypto-agility built into development and procurement. Source: Preparing for Post Quantum Cryptography — Alert 1855 | High | RSA (factorization)Diffie-Hellman (discrete logarithm) and elliptic-curve algorithms; TLSSSL-VPN and API key exchange; software and firmware signatures; signatures on financial-asset documents including digital currencies | Use NIST's first three selected PQC algorithms approved as FIPS as the basis for quantum-resistant solutionsinitially adding resistant algorithms alongside existing ones. Use AES256 for symmetric encryption; SHA-256 may continue to be usedwhile SHA-384 or SHA-512 should be considered where supported. Incorporate crypto agility into secure development+2 more | |
| Cross-Industry | Low | CISA, NSA, and NIST factsheet recommending a Quantum-Readiness Roadmap, a useful cryptographic inventory, assessment of supply-chain considerations, and engagement with technology vendors about PQC. Source: Quantum-Readiness: Migration to Post-Quantum Cryptography | High | Cryptographic assets identified through a useful cryptographic inventory | Migration to post-quantum cryptography through a Quantum-Readiness Roadmap | |
| Cross-Industry | Authoritative | The estimated security strength of approved hash functions depends on the required property and the hash output length. For collision-resistant applications, the document assigns 128-bit strength to SHA-256 and SHA3-256, 192-bit strength to SHA-384 and SHA3-384, and at least 256-bit strength to SHA-512 and SHA3-512. Source: NIST SP 800-57 Part 1 Rev. 5 | Medium | SHA-1 for collision-resistant digital-signature applications; SHA-256 collision resistance | Select an approved hash function with an output length sufficient for the application's required security strength; for collision resistancethe document lists SHA-384 and SHA3-384 at 192 bits and SHA-512 and SHA3-512 at at least 256 bits. | |
| Cross-Industry | Authoritative | This is IAPH's cyber resilience guidance for emerging technologies in the maritime supply chain. It addresses quantum computing risk in a chapter structure alongside other emerging technologies including Artificial Intelligence and IoT. It recommends integrating cybersecurity into technology planning from the earliest stages, termed "cybersecurity by design." It recommends assessing risks from emerging technologies even when an organization does not plan to deploy them locally. Among the technology-specific protection measures it lists is post-quantum cryptography adoption. Source: IAPH Cyber Resilience Guidelines for Emerging Technologies in the Maritime Supply Chain | Medium | Maritime IT and OT systemswhich rely heavily on cryptographyare described as particularly vulnerable to quantum-enabled attack+1 more | The guidelines recommend integrating cybersecurity into emerging-technology planning from the outsetdescribed as "cybersecurity by design." Post-quantum cryptography adoption is listed among the technology-specific protection measures alongside encryption strategies and network segmentation. | |
| Cross-Industry | Low | Applied Quantum's practitioner-built 8-phase PQC migration framework for enterprise-wide crypto-agility, covering executive mandate through vendor governance, with sector extensions for financial services and OT. Source: PQC Migration Framework - Marin Ivezic and Applied Quantum | Medium | Enterprise-wide cryptographic estate across PKIHSMand cloud KMS | 8-phase enterprise PQC migration methodology; hybrid/composite signatures | |
| Cryptocurrency / Blockchain | ||||||
| Cryptocurrency / Blockchain | Low | Bitcoin address types can differ in how soon they become vulnerable to quantum computers. Potentially quantum-vulnerable types include earlier addresses, reused addresses, and Taproot addresses. Taproot remains vulnerable because it uses ECC, specifically Schnorr signatures. Source: Federal Reserve HNDL Paper | Critical | ECDSA used by early Bitcoin addresses. Earlier and reused Bitcoin addresses. ECC/Schnorr-based Taproot addresses. | The primary source notes that adopting updated PQC-compliant address types to replace legacy and Taproot addresses is a possible Bitcoin mitigationone that might not require a hard fork. It attributes this PQC address-type proposal to a 2024 Bitcoin Improvement Proposal titled 'Pay-to-QR-Hash (P2QRH).' | |
| Cryptocurrency / Blockchain | Low | Standard Ethereum accounts use ECDSA on secp256k1 to sign transactions. An account that has sent a transaction exposes its public key onchain, enabling a quantum computer to derive its private key. Ethereum plans to use account abstraction through EIP-8141 to let accounts adopt post-quantum signatures. Source: Ethereum Foundation — Post-quantum cryptography on Ethereum | Critical | Standard Ethereum accounts use ECDSA on secp256k1 to sign transactions. After an account sends a transactionits public key is exposed onchainallowing a quantum computer to derive its private key. | Account abstraction through EIP-8141 would enable individual accounts to switch to post-quantum signature schemes. | |
| Cryptocurrency / Blockchain | Low | Distributed-ledger networks using traditional cryptography face HNDL data-privacy risk because an attacker can store a ledger replica and later reveal protected data with a sufficiently powerful quantum computer. PQC migration can protect future security and integrity but does not retroactively protect previously recorded Bitcoin transactions. Source: Federal Reserve Board FEDS Paper September 2025 | Critical | RSA-2048 and ECC are vulnerable to sufficiently powerful quantum computers. | Possible replacements include PQC-compliant address types for legacy and Taproot addressessupported by published NIST PQC standards. The network could require wallets and third-party services to use PQC methods. | |
| Education / Research | ||||||
| Education / Research | Low | The education sector has seen an alarming surge in cyber threats. Schools rely on expansive networks connecting students, faculty, administration, and third-party vendors, with thousands of devices and endpoints — many unmanaged — expanding the attack surface. A cryptographically relevant quantum computer will threaten systems relying on traditional asymmetric cryptography, making both authentication flows and data in transit vulnerable. Source: Cyber Threats Against the Education Sector | High | Web applications using TLS to authenticate users and encrypt communications may be vulnerable to attacks compromising integrity or confidentiality. Traditional asymmetric cryptography at risk includes RSA and ECDSA primitives. | This document defines three hybrid key agreement mechanisms for TLS 1.3 -- X25519MLKEM768SecP256r1MLKEM768and SecP384r1MLKEM1024 -- that combine the post-quantum ML-KEM (Module-Lattice-Based Key Encapsulation Mechanism) with an ECDHE (Ephemeral Elliptic Curve Diffie-Hellman) exchange. | |
| Finance & Banking | ||||||
| Finance & Banking | Low | Project Leap Phase 2 tested post-quantum cryptography in an operational payment system while sending liquidity transfers. The document characterizes migration to quantum-safe payment systems as complex and high-stakes and calls for timely preparation and institutional collaboration. Source: Bank for International Settlements Project Leap Phase 2 | Critical | Traditional digital signatures were the cryptography used for liquidity transfers in the tested payment system before being replaced. | Post-quantum cryptography and post-quantum cryptographic protocols. | |
| Finance & Banking | Low | HNDL threatens currently protected financial records, transaction data, and long-term financial contracts recorded on blockchains. A bad actor can store protected ledger data now and later use a sufficiently powerful quantum computer to reveal it. Moving Bitcoin users to PQC address types does not retroactively protect transactions previously recorded with less-quantum-resistant address types. Source: Federal Reserve Board FEDS Paper September 2025 | Critical | RSA-2048 is an asymmetric encryption method that is the current internet encryption standard. ECC-256 authenticates digital signatures and secures some cryptocurrenciesand can be solved by Shor's algorithm. Early Bitcoin addresses relied on ECDSAwhich the paper identifies as quantum-vulnerable. | Standardized post-quantum encryption and PQC-compliant address types to replace legacy and Taproot addresses. | |
| Finance & Banking | Low | BIS Papers No. 149 examines the risk that quantum computers pose to financial stability by potentially breaching widely used cryptographic algorithms. The paper notes that sensitive financial data faces a harvest-now-decrypt-later risk that necessitates immediate preparation. Source: BIS Papers No. 149 on Quantum Computing (Oct 2024) | High | Widely used asymmetric cryptography (RSA and ECC) securing financial communications is at risk from quantum computing. The most vulnerable areas identified are online/mobile bankingpayment transactionsbusiness-to-business privacy+1 more | Post-quantum cryptography includes NIST-selected quantum-resistant encryption and digital-signature algorithms. Migration should be supported by a flexible quantum-readiness roadmap. | |
| Finance & Banking | Low | Despite increasing awareness, many organizations have yet to define or apply resources adequately supporting quantum-resistant projects. This delay, called crypto-procrastination, threatens the overall migration roadmap by compressing future implementation tasks into unrealistically short timeframes. The period 2030-2031 represents a key milestone, when algorithms like RSA-2048 will be deprecated. Source: FS-ISAC — The Timeline for Post Quantum Cryptographic Migration | High | RSAECCTLS 1.2/1.3 key exchange+1 more | Hybrid and classical post-quantum key establishment is already supported by major browserscryptographic librariesand content-delivery networks. Institutions should maintain a cryptographic inventory and use architectures that permit algorithm changes without major redeployment. | |
| Finance & Banking | Moderate | Payment-system HNDL risk: malicious actors may capture encrypted financial data today for future quantum decryption. Project Leap Phase 2 tested post-quantum cryptography in the Eurosystem's T2 payment system. Source: Project Leap Phase 2: Quantum-proofing payment systems | High | Payment-system participant authentication and initial key exchange may use RSA or ECC. Communications between bankspayment processors and payment gateways rely on TLS. The tested T2 business-application-header signature uses RSA in the current system. | CRYSTALS-Dilithium at NIST security strength category 3 was tested as a replacement for the RSA signature in the T2 business application header. ML-DSA was left for future testing. | |
| Finance & Banking | Authoritative | BIS-led roadmap on quantum-readiness for the global financial system: CRQC risk (27% of surveyed experts expect it within 10 years, 50% within 15), harvest-now-decrypt-later, Shor's/Grover's algorithms — recommends cryptographic inventory, hybrid schemes, and phased migration starting immediately. Source: Quantum-readiness for the financial system: a roadmap | High | AESRSAElliptic Curve Cryptography+1 more | The document recommends hybrid cryptographic schemescryptographic agilityand phased migration plans. It names ML-DSA and SLH-DSA as examples that may be used alongside RSA. | |
| Finance & Banking | Moderate | The Swiss Financial Market Supervisory Authority FINMA surveyed 60 Swiss financial institutions on the opportunities and risks of quantum computing. FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest. FINMA expects institutions' risk analysis to result in a comprehensive inventory listing all cryptographic methods used. FINMA recommends taking into account the risk of harvest-now-decrypt-later attacks, where data encrypted today may be stolen with the intention of decrypting it later using powerful quantum computers. Source: FINMA Guidance 05/2026 on quantum computing | High | Financial institution data and communications vulnerable to harvest-now-decrypt-later | Quantum-safe encryption transition; crypto-agility | |
| Finance & Banking | Moderate | Japan's FSA Study Group report on post-quantum cryptography, formulated through mid-2024 stakeholder discussions, providing recommendations for deposit-taking institutions transitioning to PQC. Source: FSA Report of the Study Group on Deposit-Taking Institutions Response to Post-Quantum Cryptography | High | Deposit-taking institution cryptographic systems | PQC transition per FSA Study Group recommendations | |
| Finance & Banking | Moderate | MAS advisory (TCRS/2024/01) outlining cybersecurity risks from quantum computing developments and expected mitigating measures for Singapore financial institutions. Source: MAS/TCRS/2024/01 Advisory on Addressing the Cybersecurity Risks Associated with Quantum | High | Financial institution cryptographic systems (MAS-regulated) | Mitigating measures per MAS advisory | |
| Finance & Banking | High | ASC X9 report giving financial-industry managers high-level guidance on quantum-enabled cyberattack risk, cryptographic asset inventory, and PQC migration prioritization. Source: X9 Post Quantum Cryptography Financial Readiness Needs Assessment | High | The report concerns cryptography used by the financial-services industry. Classical asymmetric cryptosystems such as RSA and elliptic-curve cryptography are at risk. | Use crypto agility as one quantum-risk mitigation method. Use a roadmap to put the quantum-safe migration strategy into action. Migration may be phased rather than performed for every system at once. | |
| Finance & Banking | Low | With this report, X9 seeks to educate financial industry management on how to identify, analyze, prioritize and manage the significant risks posed by future quantum computers and to offer guidance on how the industry can migrate to post-quantum cryptography to protect sensitive data and networks against quantum-enabled cyberattacks. The report calls for creating a cryptographic asset inventory to identify all cryptographic systems in use. It calls for prioritizing current systems for remediation based on a risk assessment. It calls for working with vendors to develop and deploy PQC solutions in third-party products. Source: New X9 Report Supplies Guidance on Migrating to Post-quantum Cryptography Safely and Cost-effectively | High | Cryptographic systems in useidentified through a cryptographic asset inventory | PQC migration under X9 guidanceincorporating agile architecture where appropriate and developing a crypto-agility strategy | |
| Finance & Banking | Low | FINMA conducted a survey of 60 Swiss financial institutions between November 2025 and January 2026 on the opportunities and risks of quantum computing. In most cases the surveyed institutions lacked a clear roadmap and sufficiently forward-looking planning for migration to quantum-safe encryption. FINMA considers that action is needed in the risk-management process of numerous institutions to continue meeting operational-risk and resilience requirements. FINMA's measures include creating a cryptographic inventory and protecting critical data against "harvest now, decrypt later" attacks. Source: FINMA guidance on quantum computing | High | Encryption protecting critical data at Swiss financial institutions includes data exposed to “harvest nowdecrypt later” attacks. | FINMA outlines a strategy and roadmap for migration to quantum-safe encryptiontogether with a transition to crypto-agilityas possible measures. | |
| Finance & Banking | Low | The HKMA plans to launch a Quantum Preparedness Index to assess the banking sector’s maturity in adopting PQC and quantum computing, followed by a target index and transition roadmap outlining potential projects and pilots. It also intends to establish a Fintech Cybersecurity Baseline for fintech solution providers. The Blueprint identifies external-platform and third-party dependencies, high implementation costs, skills shortages, and particular difficulty for smaller institutions. Source: HKMA Fintech Promotion Blueprint — Quantum Preparedness Index | Medium | Sufficiently advanced quantum machines could break current encryption standardsundermining data confidentiality across financial networks. A.I.DLT and HPC implementations heavily depend on external platforms and third parties. | Following the assessmenta transition roadmap will be developedclearly outlining potential quantum computing and PQC projects and pilot initiatives to address the gaps identified. | |
| Finance & Banking | Moderate | OSFI's overview of digital and crypto risks for Canadian financial institutions, including quantum computing's threat to encryption and store-now-decrypt-later exposure, alongside a joint OSFI/FCAC quantum-readiness questionnaire. Source: Digital and crypto risks | Medium | Encryption protecting Canadian financial-sector datavulnerable to store-now-decrypt-later | Quantum-computing preparedness questionnaire issued jointly by OSFI and FCAC | |
| Finance & Banking | Low | HKMA launched a Quantum Preparedness Index (QPI) and whitepaper for the banking sector: initial sector-wide QPI score of 2.3, with 32% of banks not yet started on PQC planning; HKMA targets full sectoral readiness (QPI 10) by 2030. Source: HKMA launches quantum preparedness whitepaper and index | Medium | Banking-sector preparedness for the transition to Post-Quantum Cryptography is benchmarked via the HKMA Quantum Preparedness Index. | Sector-wide PQC migration supported by an HKMA PQC toolkit and workshops | |
| Finance & Banking | Low | Japan FSA study group report on deposit-taking financial institutions' response to post-quantum cryptography, chaired by Mizuho Financial Group's Group Information Security Officer (study conducted July-October 2024). Source: 預金取扱金融機関の耐量子計算機暗号への対応に関する検討会 報告書 | Medium | Quantum-vulnerable public-key cryptography is used in many places within Japanese deposit-taking financial institutions. | PQC transition per FSA study group recommendations | |
| Government & Defense | ||||||
| Government & Defense | Moderate | A future cryptanalytically relevant quantum computer could break public-key systems still used today. NSA's direction covers public cryptographic algorithms on both unclassified and classified National Security Systems. Source: NSA CNSA 2.0 Cybersecurity Advisory | Critical | RSA with a minimum 3072-bit modulusECDH P-384and ECDSA P-384. | CRYSTALS-Kyber Level V is selected for key establishment. CRYSTALS-Dilithium Level V is selected for digital signatures. AES with 256-bit keys is selected for information protection. | |
| Government & Defense | Moderate | CNSA 2.0 compliance deadline pressure: NSA mandates CNSA 2.0 compliance with phased deadlines — software/firmware signing supported and preferred by 2025 (exclusively by 2030), networking equipment supported and preferred by 2026 (exclusively by 2030), NSS acquisitions by January 2027, web browsers/servers/cloud supported and preferred by 2025 (exclusively by 2033), full transition by 2033. Source: NSA CNSA 2.0 Guidance | Critical | The advisory protects National Security Systems (NSS) and related assetsincluding both unclassified and classified NSS. Its direction applies to all unclassified and classified NSS. The Federal PKI is also at risksince every PIV card+2 more | NSS solutions must be NSA-approved rather than assessed as FIPS-validated. Software and hardware providing cryptographic services require NIAP or NSA validation. | |
| Government & Defense | UpdatedModerate | NSA CNSA 2.0 mandates technology-category migration timelines for National Security System operators, requiring software/firmware signing and web/cloud services to prefer PQC by 2025, networking by 2026, operating systems by 2027, and constrained devices by 2030, with exclusive deadlines between 2030 and 2033. The December 2024 FAQ further requires phasing out non-compliant equipment by December 31, 2030, enforcing mandatory CNSA 2.0 use by December 31, 2031, and achieving full NSS quantum resistance by 2033. Source: NSA CNSA 2.0 Cybersecurity Advisory | Critical | CNSA 2.0's direction applies to all National Security Systems' use of public cryptographic algorithmsboth unclassified and classified. Specificallythis deprecates RSA+2 more | CNSA 2.0 uses AES with 256-bit keys for information protection. It specifies CRYSTALS-Kyber Level V for key establishment. It specifies CRYSTALS-Dilithium Level V for digital signatures. | |
| Government & Defense | Moderate | Harvest-now-decrypt-later attacks targeting Australian classified data: Foreign state actors actively intercepting and storing encrypted Australian government communications. ASD's Annual Cyber Threat Report 2024-2025 identifies nation-state actors targeting Australian government networks. Classified data encrypted with current RSA/ECDSA is at full Shor's-algorithm risk when CRQCs become available; AES-128 retains 64-bit effective security against Grover's algorithm (weakened, not broken) — AES-256 is the symmetric mitigation. Source: ASD ACSC Annual Cyber Threat Report 2024–25 | Critical | A cryptographically relevant quantum computer could break contemporary public-key cryptography. Adversaries could use this capability to compromise communications based on current public-key technology. | Organisations should start preparing for post-quantum cryptographywhich the report identifies as the best way to protect networks from the future quantum-computing threat. Effective transition plans are needed for operation in 2030 and beyond. | |
| Government & Defense | Moderate | CISA's January 23, 2026 product-category guidance responds to Executive Order 14306. Organizations should acquire only PQC-capable products when planning acquisitions in categories where such products are widely available. The widely available categories include cloud services, collaboration software, web software, and endpoint security. Source: Product Categories for Technologies That Use Post-Quantum Cryptography Standards | High | The affected scope includes hardware and software products typically acquired by the federal government. The relevant vulnerable cryptography includes digital-signature algorithms and key-establishment schemes. | ML-KEM is the FIPS 203 key-establishment standard. ML-DSA is the FIPS 204 digital-signature standard. SLH-DSA is the FIPS 205 digital-signature standard. | |
| Healthcare / Pharmaceutical | ||||||
| Healthcare / Pharmaceutical | Low | Only 4% of Healthcare & Life Sciences organizations have encrypted 80% or more of their sensitive cloud data. Fifty-nine percent are concerned about future decryption of today’s data, including harvest now, decrypt later. The report says the clock is ticking on post-quantum readiness. Source: Thales 2025 Data Threat Report Healthcare Edition | Critical | Encryption protecting sensitive cloud data and today’s data. | Plan for post-quantum readiness. Prototype new ciphers. | |
| Healthcare / Pharmaceutical | Low | HSCC Cybersecurity Working Group's Q1 2026 report identifies a joint HSCC/Health-ISAC Post Quantum Cryptography task group and reports three new task groups for Policy, Isolation and Segmentation, and Workforce. Source: HSCC Cyber Working Group Q1 2026 Progress Report | Medium | The task group will develop a shared cryptographic-asset inventory framework for organizations to baseline their current exposure. Its roadmap work will include interoperability and supply-chain considerations. | The task group plans a cross-industry PQC migration roadmap. It also plans guidelines and reference architectures for pilot implementations. | |
| Insurance | ||||||
| Insurance | Low | Munich Re’s Cyber Insurance Risks and Trends 2025 says NIST finalized its principal set of quantum-resistant encryption algorithms in August 2024. It says RSA will be vulnerable to quantum-based decryption but should continue to offer sufficient protection through at least 2030. It also says attackers are already stealing data to decrypt once sufficiently powerful quantum computers become available. Source: Munich Re — Cyber Insurance: Risks and Trends 2025 (Quantum computing security section) | High | RSA used for secure data transmission is at risk from future quantum-based decryption. | NIST finalized its principal set of quantum-resistant encryption algorithms in August 2024. Transition to the new standards is imminent. | |
| Internet of Things (IoT) | ||||||
| Internet of Things (IoT) | UpdatedHigh | A manifest specification for IoT firmware updates must support different cryptographic algorithms and algorithm extensibility. Because signature schemes based on RSA and Elliptic Curve Cryptography (ECC) may become vulnerable to quantum-accelerated key extraction in the future, unchangeable bootloader code in ROM is recommended to use post-quantum secure signature schemes such as hash-based signatures. Where COSE (RFC 9052) is used, its COSE_Sign structure can carry signatures generated with the Elliptic Curve Digital Signature Algorithm (ECDSA) or the Edwards-curve Digital Signature Algorithm (EdDSA). Source: IETF SUIT RFC 9019 + RFC 9124 | High | since signature schemes based on RSA and Elliptic Curve Cryptography (ECC) may become vulnerable to quantum-accelerated key extraction in the future Under a CRQCtraditional signature algorithms (RSAECDSA+2 more | For unchangeable bootloader code in ROMuse post-quantum-secure signature schemes such as hash-based signatures. | |
| Internet of Things (IoT) | UpdatedModerate | ETSI TR 104 005 V1.1.1 technical report analyzing PQC impacts on ETSI TC SET's Secure Element Technologies specifications (SIM/UICC/Secure Element), driven by Shor's and Grover's algorithms. Source: ETSI TR 104 005 V1.1.1 Secure Element Technologies | High | ECKA-EG (ECC-based key agreement) used in remote application/OTA provisioning for SIM/UICC/Secure Element -- SCP03/SCP04 secure channel protocols themselves are AES-based (symmetric) and already considered quantum-safe per ETSI TC SET analysis | Quantum-safe adaptation of ETSI TC SET specifications (specific PQC algorithms not yet named — monitoring GlobalPlatform updates recommended) | |
| IT Industry / Software | ||||||
| IT Industry / Software | Low | Apple will start accepting PQC roots in late 2025 or in 2026. Microsoft is updating Windows and Linux builds to allow PQC integration. Mozilla identified preventing capture-and-decrypt attacks as an immediate priority. Source: CA/Browser Forum — 2025-06-10 Minutes of the Forum Toronto F2F | Critical | RSA and ECC remain in use for the time being. The stated PQC priorities are key exchange first and authentication second. | The meeting discussed ML-KEM deployment and a planned transition to ML-DSA. | |
| IT Industry / Software | Moderate | NIST FIPS 203/204/205 standardization milestone: First official PQC standards published August 2024. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) provide the foundation for all PQC migration. CMVP validation of implementations is ongoing with first validated modules expected 2025-2026. Source: NIST FIPS 203/204/205 Post-Quantum Cryptography Standards | Critical | Current encryption and digital-signature systems are threatened by sufficiently capable quantum computers. | FIPS 203 (ML-KEM-512/768/1024)FIPS 204 (ML-DSA-44/65/87)FIPS 205 (SLH-DSA) | |
| Media / Entertainment / DRM | ||||||
| Media / Entertainment / DRM | Low | Digital rights management (DRM) solutions aim to prevent the copying or distribution of copyrighted material. This addresses the modern paradigm of cloud-based content delivery followed by major platforms such as Netflix, Disney+, and Amazon Prime. Three widely used DRM solutions — Google Widevine, Apple FairPlay, and Microsoft PlayReady — are deployed on billions of devices worldwide. These systems have design-level shortcomings that leave them vulnerable to emerging attacks, including an absence of post-quantum security. Source: "A First Look at Digital Rights Management Systems for Secure Mobile Content Delivery" (academic survey) | Critical | Google WidevineApple FairPlayand Microsoft PlayReady lack post-quantum security. | The KEMRecipientInfo structure is used with the Composite ML-KEM algorithm to securely transfer the content-encryption key from the originator to the recipient. | |
| Payment Card Industry | ||||||
| Payment Card Industry | Low | FS-ISAC report on quantum computing's impact on the Payment Card Industry: cryptographic asset inventory across HSMs/databases/physical systems, AES-256 migration against Grover's algorithm, and RSA/ECC replacement with PQC, produced with PCI SSC/NIST/BIAN input. Source: The Impact of Quantum Computing on the Payment Card Industry | High | RSAECCTriple-DES+4 more | AES-256 for symmetric migration (Grover's algorithm mitigation); PQC algorithms to replace RSA/ECC (specific algorithms not named); crypto-agility | |
| Telecommunications | ||||||
| Telecommunications | Moderate | Subscriber personal data, including call and location history, is stored in operator systems and must be protected with quantum-safe encryption over its lifetime. Sensitive data on 5G SBI and N32 interfaces is exposed to store-now/decrypt-later attacks. Source: GSMA Security Guidelines | Critical | RSA and elliptic-curve public-key algorithms used for signaturesauthenticationand key establishment are quantum-vulnerable. AES-128 is less affected+1 more | Use standardized ML-KEM for quantum-safe key establishment and ML-DSA for digital signatures. AES-256 may be used as a conservative response to potential Grover attacksalthough the document notes that guidance differs. | |
| Telecommunications | Moderate | The GSMA Post Quantum Telco Network Task Force publishes guidance on PQC impacts and migration for telecommunications, building on PQ.01 and referring to PQ.02 for quantum-risk assessment. Migration depends on standards bodies, equipment manufacturers, infrastructure providers, and operators implementing quantum-safe protocols and algorithms. Source: GSMA Post-Quantum Telco Network Taskforce | High | The affected scope includes secure transport between the 4G/5G RAN and security gateways. IPsec/IKE key establishment and certificate authentication are quantum-vulnerable components. | Integrate standardized PQC into affected telecommunications protocols and 3GPP specifications. For TLS 1.3hybrid key exchange can combine ECDHE with ML-KEMwhile signatures and authentication require separate migration. | |
| Telecommunications | Moderate | GSMA PQ.05 analyzes threats, impacts, and mitigations for a cryptographically relevant quantum computer targeting 4G and 5G roaming architectures and interfaces. It prioritizes protection of roaming interfaces against harvest-now-decrypt-later attacks and also addresses future impersonation, spoofing, and tampering. Source: GSMA — PQ.05 Post-Quantum Cryptography for 5G Roaming Use Case | High | TLS 1.3 and IPsec with X.509 certificate authentication protect roaming interfaces. JWS provides integrity and authentication for JSON payloads in PRINS mode. | Use ML-KEM for quantum-safe key establishment on roaming interfaces. Use ML-DSA for certificatessignaturesand verification in roaming entities. | |
| Telecommunications | Moderate | ANSSI-FT-117 technical guide for IPsec's post-quantum transition — hybridizing IKEv2 key exchange and signature authentication, noting significant message-size increases from PQC key/ciphertext/signature sizes. Source: ANSSI-FT-117 Transition post-quantique d'IPsec | High | Diffie-Hellman key exchange and classical signature authentication within IKEv2/IPsec | Hybrid PQC key exchange and hybrid PQC signature authentication within IKEv2 (per ANSSI guidance; specific algorithms not named in extracted text) | |
Aerospace / Aviation / Space
(1)Cloud Computing / Data Centers
(4)NIST IR 8547 describes NIST’s expected transition from quantum-vulnerable cryptographic algorithms to post-quantum signature and key-establishment schemes. It is intended to inform migration efforts and timelines for information technology products, services, and infrastructure.
NIST SP 800-210 provides general access control guidance for cloud service models (IaaS, PaaS, SaaS). Because vendors, including cloud service providers, often implement and control the cryptographic mechanisms an organisation depends on, vendor readiness is a critical factor in an organisation's PQC transition.
Long-lived ciphertext in databases, backups, and archives protected by classical key-wrapping mechanisms is exposed to store-now-decrypt-later risk.
Cloud Security Alliance quantum readiness guidance: CSA published quantum-safe security guidance identifying crypto-agility as critical requirement for cloud deployments. Multi-cloud environments using 5+ key management systems face fragmented PQC migration paths.
Critical Infrastructure / OT
(6)10 CFR § 73.54 requires nuclear power plant licensees to maintain cybersecurity plans and protect digital computer and communication systems associated with safety, security, emergency preparedness, and supporting functions.
More than one billion smart meters are deployed worldwide and need migration planning for future quantum threats. Some meters use unchangeable fixed-function cryptography, while the oldest devices that cannot receive over-the-air updates will need replacement.
CISA’s PQC Initiative addresses quantum-computing security risks and supports critical-infrastructure and government networks during the transition to PQC. CISA is also helping critical-infrastructure owners and operators facilitate the eventual PQC transition for operational technology.
Many critical-infrastructure OT systems use legacy RSA encryption, which is a primary target of quantum attacks because Shor's algorithm can break it. This creates a strategic "harvest now, decrypt later" risk, where adversaries collect encrypted OT communications today intending to decrypt them once quantum capabilities mature. OT further compounds this risk because a significant share of its endpoints run out-of-date, end-of-life operating systems and software that remain in operation for long periods. Integrating PQC protections adds processing overhead that can exceed the hardware capabilities of these OT systems.
Singapore's Cyber Security Agency released a Quantum-Safe Handbook and Quantum Readiness Index (in public consultation through end-2025) to guide Critical Information Infrastructure owners and government agencies toward quantum-safe migration.
NERC's January 2026 Critical Infrastructure Protection Roadmap addresses security of the North American bulk power system through measures including MFA, foundational cyber hygiene, and protection of SCADA and AGC communications using protocols such as DNP3, ICCP, and Modbus. Its survey material also identifies quantum computing as a risk to modern cryptography and gives an encrypted-data collection and later quantum decryption scenario.
Cross-Industry
(22)NIST IR 8547 is an Initial Public Draft dated November 2024. It describes the transition from quantum-vulnerable cryptography and identifies 2035 as the primary federal target for completing migration to post-quantum cryptography. NIST intends to deprecate classical digital signatures at the 112-bit security level after 2030.
The 2024 Quantum Threat Timeline Report suggests that the quantum threat may be closer than previously thought. It emphasizes proactive quantum-threat mitigation.
The NIS2 Directive requires entities in scope to adopt cybersecurity risk-management measures, including the use of state-of-the-art cryptography. Member States should connect with NIS2 and eIDAS supervisory bodies to understand the implications of the quantum threat for regulated entities. The roadmap also encourages real-world testing through activities such as ETSI Plugtests and IETF PQC hackathons.
DNSSEC quantum signature forgery: DNSSEC uses RSA (RSASHA256 per RFC 5702) and ECDSA (ECDSAP256SHA256 per RFC 6605) to sign DNS records — RFC 8624 covers current algorithm implementation requirements. Approximately 40% of global DNS domains have DNSSEC enabled including 92% root zone adoption. Quantum forgery of DNSSEC signatures enables DNS hijacking for any signed domain redirecting traffic to attacker-controlled servers. PQC signatures face challenges with DNS UDP packet size limits (~1232 bytes) requiring protocol-level changes. IETF draft-sheth-pqc-dnssec-strategy-01 addresses migration strategy.
RPKI's mandated signature algorithm for certificates, CRLs, CMS signed objects, and certification requests is RSA PKCS #1 v1.5. RSA key pairs used for these RPKI signatures must have a 2048-bit modulus. This RFC 7935 profile obsoletes the earlier RFC 6485 algorithm profile. A quantum computer capable of breaking RSA could forge any RPKI signature, including on resource certificates and ROAs. That capability lets an attacker bypass route origin validation by forging a ROA that authorizes their own malicious route. RSA-2048 signing currently keeps the RPKI dataset at about 838MB. Switching to a post-quantum scheme such as ML-DSA-44 would grow that dataset to roughly 3.0GB.
OpenSSH 10.0 was released on 2025-04-09. It uses the hybrid post-quantum algorithm mlkem768x25519-sha256 by default for key agreement. The algorithm is considered safe against attacks by quantum computers and has been standardized by NIST.
NIST announced HQC's selection for standardization in March 2025. HQC is a code-based KEM intended to complement ML-KEM by relying on a different underlying security problem. NIST will create a draft HQC standard for public comment and, after adjudicating comments, publish a final version in approximately two years.
NIST SP 800-227 KEM recommendations: Published as final standard on September 18, 2025 — initially released as Initial Public Draft in January 2025. Provides definitions, security properties, and implementation recommendations for key-encapsulation mechanisms as companion guidance to FIPS 203 (ML-KEM). Establishes best practices for KEM usage in protocols, hybrid constructions, and key management — essential reference for correct PQC deployment.
Sigstore plans to enable content signing with post-quantum keys and eventually adopt post-quantum cryptography in services including Fulcio and Rekor. ML-DSA has been added to enable experimentation, while Sigstore still needs a plan for transitioning away from traditional cryptographic algorithms.
Quantum random number generation (QRNG) for PQC key security: PQC algorithm security depends on high-quality randomness for key generation. Classical PRNGs may contain algorithmic biases exploitable by sophisticated adversaries. QRNG uses quantum mechanical processes to generate theoretically unpredictable randomness. Quantinuum Quantum Origin was among the first software-delivered QRNGs to obtain NIST SP 800-90B entropy source validation. Commercial QRNG products from ID Quantique, Quside, and QNu Labs are available for HSM, IoT, and automotive integration. QRNG complements PQC by ensuring cryptographic keys are non-predictable from generation.
NIST IR 8547 proposes deprecation after 2030 and disallowance after 2035 for listed quantum-vulnerable digital-signature and key-establishment algorithm families, including RSA, ECDSA, and elliptic-curve key establishment. NSM-10 establishes 2035 as the primary target for completing migration to PQC across federal systems. SP 800-131A separately addresses transitions in algorithms and key lengths used by federal agencies to protect controlled unclassified information.
KyberSlash1 and KyberSlash2 are timing vulnerabilities in several Kyber/ML-KEM implementations, including the official reference code. Their exploitability was demonstrated on the Raspberry Pi 2 and Arm Cortex-M4, with Kyber secret keys recovered within minutes for KyberSlash2 and within a few hours for KyberSlash1.
This document examines the specific risks that quantum computing could pose to industrial control systems (ICS) and other operational technology (OT).
BSI TR-02102-1 provides Germany's official security assessment and recommended key lengths for cryptographic mechanisms, forming the baseline against which PQC transition urgency is judged.
ANSSI-PG-083 version 3.00 sets out rules and recommendations for choosing and sizing cryptographic mechanisms. It accounts for the quantum threat and aims to remain valid for at least 15 years.
CCN-TEC 009 (Spain's National Cryptologic Centre) recommendations for a safe post-quantum transition, covering CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon, SPHINCS+, BIKE, HQC, Classic McEliece and SIKE, driven by Shor's/Grover's algorithm risk and harvest-now-decrypt-later.
CSA guidance provides a practical framework for modernizing cloud key management for PQC, including cryptographic asset inventory, crypto agility, and mitigation of Store-Now-Decrypt-Later and hybrid-downgrade risks. It discusses hybrid and migration-ready PQC updates affecting TLS, SSH, and IKEv2.
Israel's National Cyber Directorate (INCD) Alert 1855 (6 March 2025, TLP:CLEAR) warns that quantum computers can break widely used public-key algorithms — factorization (RSA), discrete logarithms (Diffie-Hellman) and elliptic-curve discrete logarithms — used in TLS, SSL-VPN and API key exchange. It flags forged digital signatures on software and firmware and on documents convertible to money (including digital currencies), especially on ICS/SCADA and medical (IoMT) platforms whose algorithms are hard to replace, and harvest-now-decrypt-later capture of long-sensitive data as a risk that may already be under way. It directs organisations to appoint an owner, find systems with non-resistant components and plan to add NIST's standardised PQC algorithms alongside existing ones, prioritised by system and data sensitivity, with crypto-agility built into development and procurement.
CISA, NSA, and NIST factsheet recommending a Quantum-Readiness Roadmap, a useful cryptographic inventory, assessment of supply-chain considerations, and engagement with technology vendors about PQC.
The estimated security strength of approved hash functions depends on the required property and the hash output length. For collision-resistant applications, the document assigns 128-bit strength to SHA-256 and SHA3-256, 192-bit strength to SHA-384 and SHA3-384, and at least 256-bit strength to SHA-512 and SHA3-512.
This is IAPH's cyber resilience guidance for emerging technologies in the maritime supply chain. It addresses quantum computing risk in a chapter structure alongside other emerging technologies including Artificial Intelligence and IoT. It recommends integrating cybersecurity into technology planning from the earliest stages, termed "cybersecurity by design." It recommends assessing risks from emerging technologies even when an organization does not plan to deploy them locally. Among the technology-specific protection measures it lists is post-quantum cryptography adoption.
Applied Quantum's practitioner-built 8-phase PQC migration framework for enterprise-wide crypto-agility, covering executive mandate through vendor governance, with sector extensions for financial services and OT.
Cryptocurrency / Blockchain
(3)Bitcoin address types can differ in how soon they become vulnerable to quantum computers. Potentially quantum-vulnerable types include earlier addresses, reused addresses, and Taproot addresses. Taproot remains vulnerable because it uses ECC, specifically Schnorr signatures.
Standard Ethereum accounts use ECDSA on secp256k1 to sign transactions. An account that has sent a transaction exposes its public key onchain, enabling a quantum computer to derive its private key. Ethereum plans to use account abstraction through EIP-8141 to let accounts adopt post-quantum signatures.
Distributed-ledger networks using traditional cryptography face HNDL data-privacy risk because an attacker can store a ledger replica and later reveal protected data with a sufficiently powerful quantum computer. PQC migration can protect future security and integrity but does not retroactively protect previously recorded Bitcoin transactions.
Education / Research
(1)The education sector has seen an alarming surge in cyber threats. Schools rely on expansive networks connecting students, faculty, administration, and third-party vendors, with thousands of devices and endpoints — many unmanaged — expanding the attack surface. A cryptographically relevant quantum computer will threaten systems relying on traditional asymmetric cryptography, making both authentication flows and data in transit vulnerable.
Finance & Banking
(16)Project Leap Phase 2 tested post-quantum cryptography in an operational payment system while sending liquidity transfers. The document characterizes migration to quantum-safe payment systems as complex and high-stakes and calls for timely preparation and institutional collaboration.
HNDL threatens currently protected financial records, transaction data, and long-term financial contracts recorded on blockchains. A bad actor can store protected ledger data now and later use a sufficiently powerful quantum computer to reveal it. Moving Bitcoin users to PQC address types does not retroactively protect transactions previously recorded with less-quantum-resistant address types.
BIS Papers No. 149 examines the risk that quantum computers pose to financial stability by potentially breaching widely used cryptographic algorithms. The paper notes that sensitive financial data faces a harvest-now-decrypt-later risk that necessitates immediate preparation.
Despite increasing awareness, many organizations have yet to define or apply resources adequately supporting quantum-resistant projects. This delay, called crypto-procrastination, threatens the overall migration roadmap by compressing future implementation tasks into unrealistically short timeframes. The period 2030-2031 represents a key milestone, when algorithms like RSA-2048 will be deprecated.
Payment-system HNDL risk: malicious actors may capture encrypted financial data today for future quantum decryption. Project Leap Phase 2 tested post-quantum cryptography in the Eurosystem's T2 payment system.
BIS-led roadmap on quantum-readiness for the global financial system: CRQC risk (27% of surveyed experts expect it within 10 years, 50% within 15), harvest-now-decrypt-later, Shor's/Grover's algorithms — recommends cryptographic inventory, hybrid schemes, and phased migration starting immediately.
The Swiss Financial Market Supervisory Authority FINMA surveyed 60 Swiss financial institutions on the opportunities and risks of quantum computing. FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest. FINMA expects institutions' risk analysis to result in a comprehensive inventory listing all cryptographic methods used. FINMA recommends taking into account the risk of harvest-now-decrypt-later attacks, where data encrypted today may be stolen with the intention of decrypting it later using powerful quantum computers.
Japan's FSA Study Group report on post-quantum cryptography, formulated through mid-2024 stakeholder discussions, providing recommendations for deposit-taking institutions transitioning to PQC.
MAS advisory (TCRS/2024/01) outlining cybersecurity risks from quantum computing developments and expected mitigating measures for Singapore financial institutions.
ASC X9 report giving financial-industry managers high-level guidance on quantum-enabled cyberattack risk, cryptographic asset inventory, and PQC migration prioritization.
With this report, X9 seeks to educate financial industry management on how to identify, analyze, prioritize and manage the significant risks posed by future quantum computers and to offer guidance on how the industry can migrate to post-quantum cryptography to protect sensitive data and networks against quantum-enabled cyberattacks. The report calls for creating a cryptographic asset inventory to identify all cryptographic systems in use. It calls for prioritizing current systems for remediation based on a risk assessment. It calls for working with vendors to develop and deploy PQC solutions in third-party products.
FINMA conducted a survey of 60 Swiss financial institutions between November 2025 and January 2026 on the opportunities and risks of quantum computing. In most cases the surveyed institutions lacked a clear roadmap and sufficiently forward-looking planning for migration to quantum-safe encryption. FINMA considers that action is needed in the risk-management process of numerous institutions to continue meeting operational-risk and resilience requirements. FINMA's measures include creating a cryptographic inventory and protecting critical data against "harvest now, decrypt later" attacks.
The HKMA plans to launch a Quantum Preparedness Index to assess the banking sector’s maturity in adopting PQC and quantum computing, followed by a target index and transition roadmap outlining potential projects and pilots. It also intends to establish a Fintech Cybersecurity Baseline for fintech solution providers. The Blueprint identifies external-platform and third-party dependencies, high implementation costs, skills shortages, and particular difficulty for smaller institutions.
OSFI's overview of digital and crypto risks for Canadian financial institutions, including quantum computing's threat to encryption and store-now-decrypt-later exposure, alongside a joint OSFI/FCAC quantum-readiness questionnaire.
HKMA launched a Quantum Preparedness Index (QPI) and whitepaper for the banking sector: initial sector-wide QPI score of 2.3, with 32% of banks not yet started on PQC planning; HKMA targets full sectoral readiness (QPI 10) by 2030.
Japan FSA study group report on deposit-taking financial institutions' response to post-quantum cryptography, chaired by Mizuho Financial Group's Group Information Security Officer (study conducted July-October 2024).
Government & Defense
(5)A future cryptanalytically relevant quantum computer could break public-key systems still used today. NSA's direction covers public cryptographic algorithms on both unclassified and classified National Security Systems.
CNSA 2.0 compliance deadline pressure: NSA mandates CNSA 2.0 compliance with phased deadlines — software/firmware signing supported and preferred by 2025 (exclusively by 2030), networking equipment supported and preferred by 2026 (exclusively by 2030), NSS acquisitions by January 2027, web browsers/servers/cloud supported and preferred by 2025 (exclusively by 2033), full transition by 2033.
NSA CNSA 2.0 mandates technology-category migration timelines for National Security System operators, requiring software/firmware signing and web/cloud services to prefer PQC by 2025, networking by 2026, operating systems by 2027, and constrained devices by 2030, with exclusive deadlines between 2030 and 2033. The December 2024 FAQ further requires phasing out non-compliant equipment by December 31, 2030, enforcing mandatory CNSA 2.0 use by December 31, 2031, and achieving full NSS quantum resistance by 2033.
Harvest-now-decrypt-later attacks targeting Australian classified data: Foreign state actors actively intercepting and storing encrypted Australian government communications. ASD's Annual Cyber Threat Report 2024-2025 identifies nation-state actors targeting Australian government networks. Classified data encrypted with current RSA/ECDSA is at full Shor's-algorithm risk when CRQCs become available; AES-128 retains 64-bit effective security against Grover's algorithm (weakened, not broken) — AES-256 is the symmetric mitigation.
CISA's January 23, 2026 product-category guidance responds to Executive Order 14306. Organizations should acquire only PQC-capable products when planning acquisitions in categories where such products are widely available. The widely available categories include cloud services, collaboration software, web software, and endpoint security.
Healthcare / Pharmaceutical
(2)Only 4% of Healthcare & Life Sciences organizations have encrypted 80% or more of their sensitive cloud data. Fifty-nine percent are concerned about future decryption of today’s data, including harvest now, decrypt later. The report says the clock is ticking on post-quantum readiness.
HSCC Cybersecurity Working Group's Q1 2026 report identifies a joint HSCC/Health-ISAC Post Quantum Cryptography task group and reports three new task groups for Policy, Isolation and Segmentation, and Workforce.
Insurance
(1)Munich Re’s Cyber Insurance Risks and Trends 2025 says NIST finalized its principal set of quantum-resistant encryption algorithms in August 2024. It says RSA will be vulnerable to quantum-based decryption but should continue to offer sufficient protection through at least 2030. It also says attackers are already stealing data to decrypt once sufficiently powerful quantum computers become available.
Internet of Things (IoT)
(2)A manifest specification for IoT firmware updates must support different cryptographic algorithms and algorithm extensibility. Because signature schemes based on RSA and Elliptic Curve Cryptography (ECC) may become vulnerable to quantum-accelerated key extraction in the future, unchangeable bootloader code in ROM is recommended to use post-quantum secure signature schemes such as hash-based signatures. Where COSE (RFC 9052) is used, its COSE_Sign structure can carry signatures generated with the Elliptic Curve Digital Signature Algorithm (ECDSA) or the Edwards-curve Digital Signature Algorithm (EdDSA).
ETSI TR 104 005 V1.1.1 technical report analyzing PQC impacts on ETSI TC SET's Secure Element Technologies specifications (SIM/UICC/Secure Element), driven by Shor's and Grover's algorithms.
IT Industry / Software
(2)Apple will start accepting PQC roots in late 2025 or in 2026. Microsoft is updating Windows and Linux builds to allow PQC integration. Mozilla identified preventing capture-and-decrypt attacks as an immediate priority.
NIST FIPS 203/204/205 standardization milestone: First official PQC standards published August 2024. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) provide the foundation for all PQC migration. CMVP validation of implementations is ongoing with first validated modules expected 2025-2026.
Media / Entertainment / DRM
(1)Digital rights management (DRM) solutions aim to prevent the copying or distribution of copyrighted material. This addresses the modern paradigm of cloud-based content delivery followed by major platforms such as Netflix, Disney+, and Amazon Prime. Three widely used DRM solutions — Google Widevine, Apple FairPlay, and Microsoft PlayReady — are deployed on billions of devices worldwide. These systems have design-level shortcomings that leave them vulnerable to emerging attacks, including an absence of post-quantum security.
Payment Card Industry
(1)FS-ISAC report on quantum computing's impact on the Payment Card Industry: cryptographic asset inventory across HSMs/databases/physical systems, AES-256 migration against Grover's algorithm, and RSA/ECC replacement with PQC, produced with PCI SSC/NIST/BIAN input.
Telecommunications
(4)Subscriber personal data, including call and location history, is stored in operator systems and must be protected with quantum-safe encryption over its lifetime. Sensitive data on 5G SBI and N32 interfaces is exposed to store-now/decrypt-later attacks.
The GSMA Post Quantum Telco Network Task Force publishes guidance on PQC impacts and migration for telecommunications, building on PQ.01 and referring to PQ.02 for quantum-risk assessment. Migration depends on standards bodies, equipment manufacturers, infrastructure providers, and operators implementing quantum-safe protocols and algorithms.
GSMA PQ.05 analyzes threats, impacts, and mitigations for a cryptographically relevant quantum computer targeting 4G and 5G roaming architectures and interfaces. It prioritizes protection of roaming interfaces against harvest-now-decrypt-later attacks and also addresses future impersonation, spoofing, and tampering.
ANSSI-FT-117 technical guide for IPsec's post-quantum transition — hybridizing IKEv2 key exchange and signature authentication, noting significant message-size increases from PQC key/ciphertext/signature sizes.
Try it
An adversary records your encrypted traffic today so it can be decrypted once a quantum computer exists. Which threat class is that, and which security property does it attack?
Related content
Next step
Assess your exposureThe assessment scores the threats on this page against your own estate.