Quantum Threats

Detailed analysis of quantum threats across industries, including criticality, at-risk cryptography, and PQC replacements.

What this means for you

Executive / Business Leader
"Your Exposure" at the top shows your sector's threats and "Your migration deadline" — the year the Mosca arithmetic says you must be done; the Severity chips in the Threat Catalog cut the list to Critical.
GRC / Risk & Compliance
Sort the Table view by Evidence to put the best-documented records first; each threat opens with its Data Provenance (peer review, vetting body, last verified) and a Reference Source link you can cite.
Developer / Engineer
The "By protocol" chips — TLS / HTTPS, SSH, VPN / IPsec and more — filter threats by what you build on, and say whether each match is stated in the record or inferred; each threat lists its At-Risk Cryptography and PQC Mitigation.
Security Architect
Each threat names its At-Risk Cryptography, its PQC Mitigation and the implementation pitfalls of the replacement (side-channel, fault, RNG); the Class chips split HNDL from HNFL so you know whether the exposure is data or signatures.
Researcher / Academic
"CRQC Threat Horizon" lists the CRQC arrival estimates by source and logical-qubit progress per machine, with a Mosca calculator; the Evidence column sorts records by peer review, source and confidence.
Certification & Validation Engineer
Each threat opens with its Data Provenance (peer review, vetting body, last verified); where a replacement algorithm has attack notes, the detail links to Implementation Attacks on /algorithms.
IT Ops / DevOps
Each threat's Detection & Response section has a "Detection / SOC" tab and an "Incident Response" tab; use the Industry filter for your sector and the Severity chips to work Critical first.
Curious Explorer
A line above the catalog tells you how many known threats there are and what one is; pick an industry in the list on the left to see the ones closest to you, and "Your Exposure" at the top sums it up.
Your sector exposure
71threats apply to all sectors
27
Critical
35
High
61 decrypt-later54 forge-later

Threats classed both (HNDL + HNFL) count in both totals.

CRQC capability watch
28–49%
CRQC expert survey: “quite possible” (28–49%) within 10 years, “likely” (51–70%) within 15 (Global Risk Institute 2025, 26 experts)
2035
planning year (Z) — the forecast's midpoint, used for your deadline

When a cryptographically-relevant quantum computer (CRQC) could break today's public-key crypto — the clock your migration races.

Your Mosca migration windowOVERDUE
Closed in2020
6 years past the safe-start line for all sectors

The recommended start date has already passed — this is not a future target, it is how far behind you already are. Long-lived data for all sectors may already be exposed once a CRQC arrives.

Z 2035 − X 10 − Y 5 = 2020
X = data lifetime, Y = migration time. Mosca's inequality.

Threat EconomicsPhase 0 · Executive Mandate

Why quantum threats have a clock: the two attacker business models and Mosca's migration deadline.

HNDL — Harvest Now, Decrypt Later

Attacker records encrypted traffic today and decrypts it once a CRQC exists. Threatens confidentiality; the clock is your data's secrecy lifetime.

Source: Federal Reserve FEDS 2025-093 (Mascelli & Rodden)
HNFL — Harvest Now, Forge Later

Attacker waits for a CRQC, recovers a signing key, then forges signatures retroactively. Threatens authenticity; the clock is your credential's validity period.

10y
10y
5y
2035
OVERDUEHNDLmigration window
Closed in2020

Migration should have started 6 years ago. Data intercepted today is already at risk.

2035 − 10 − 5 = 2020
Z − X − Y = deadline (data lifetime). If X + Y > (Z − today), you are already exposed.
OVERDUEHNFLmigration window
Closed in2020

Migration should have started 6 years ago. Credentials signed today can be forged retroactively.

2035 − 10 − 5 = 2020
Z − X − Y = deadline (credential validity). If X + Y > (Z − today), you are already exposed.
New-issuance cutoff. The full workshop’s existing-credential re-issuance clock (Z − Y only) can land on a different year — see /learn Quantum Threats → HNFL workshop.

CRQC Capability WatchCTI

When the clock stops: the published expert forecast of CRQC arrival, the migration deadlines regulators have set (deadlines, not forecasts), and how far today's hardware has come.

CRQC expert survey
Open question
28–49%
CRQC expert survey: “quite possible” (28–49%) within 10 years, “likely” (51–70%) within 15 (Global Risk Institute 2025, 26 experts)
Migration deadlines (not forecasts)
  • NIST IR 8547 (IPD, Nov 2024): 2030–2035
  • NSA CNSA 2.0 (2022; FAQ version 2.1, December 2024): 2030–2033
  • ANSSI France (2022 paper; current FAQ): 2030
  • BSI Germany (TR-02102-1, 2026-01): 2030–2035
Calculators on this page start their planning range 2030–2041, set by this site 4 years out.
Hardware progress
96 / ~1,200 LQ
~1,200 LQ is the low-end ECC-256 estimate (Google/Ethereum, 2026); earlier work ranged to ~2,330+ LQ (Roetteler et al. 2017, arXiv:1706.06752). The bar to break RSA-2048 keeps falling: ~20M physical qubits (2019) → <1M (Gidney 2025) → <100k projected (qLDPC, 2026).
The logical-qubit count for the same RSA-2048 target has fallen too: 2n+2, which gives 4,098 (2016-era estimate, arXiv:1611.07995) → ~1,730 (Chevignard–Fouque–Schrottenloher, ePrint 2024/222) → ~1,537 (Gidney 2025, arXiv:2505.15917) — an algorithmic improvement independent of the physical-qubit-overhead cuts above.
Lead: QuEra / Harvard / MIT Neutral-atom FT processor (Neutral atom)

Aerospace / Aviation / Space

(1)
CriticalAERO-002
Moderate

Satellite communication HNDL vulnerability: Military and commercial satellites have 15-25 year operational lifespans. NSA CNSA 2.0 sets a quantum-resistant transition timeline for National Security Systems by equipment category — software/firmware signing exclusively CNSA 2.0 by 2030, web/cloud services by 2033, traditional networking equipment by 2030, operating systems by 2033, niche equipment and custom applications by 2033 — which NSS satellite ground segments and links fall under. Currently intercepted satellite communications are harvestable for future quantum decryption.

At riskCNSA 2.0 will effectively deprecate RSA and ECDSA for National Security Systems when mandated.ML-KEM-1024ML-DSA-87 (named CRYSTALS-Kyber/Dilithium Level V in the Sep 2022 advisory) per CNSA 2.0+1
Open dossier

Cloud Computing / Data Centers

(4)
CriticalCLOUD-003
Authoritative

NIST IR 8547 describes NIST’s expected transition from quantum-vulnerable cryptographic algorithms to post-quantum signature and key-establishment schemes. It is intended to inform migration efforts and timelines for information technology products, services, and infrastructure.

At riskTLS and other network-security protocols that rely on vulnerable classical cryptography are at risk. HSM cryptographic operations and stored sensitive keys require PQC-capable hardware.FIPS 203 (ML-KEM)FIPS 204 (ML-DSA)+1
Open dossier
CriticalCLOUD-004
High

NIST SP 800-210 provides general access control guidance for cloud service models (IaaS, PaaS, SaaS). Because vendors, including cloud service providers, often implement and control the cryptographic mechanisms an organisation depends on, vendor readiness is a critical factor in an organisation's PQC transition.

At riskCloud HSM performs cryptographic operations in FIPS 140-2 Level 3 certified hardware security modules. When you use Cloud HSMyour data is strictly isolated from other tenants and services in Google Cloud. All customer keys are stored wrapped with a regional wrapping key in the Cloud KMS database and can only be unwrapped by an HSM in the region as part of a cryptographic operation. Cloud systems generally pool resources across a multi-tenant model+1Cloud Key Management Service supports ML-KEM-768 and ML-KEM-1024which were standardized by NIST in FIPS-203+2
Open dossier
HighCLOUD-001
Moderate

Long-lived ciphertext in databases, backups, and archives protected by classical key-wrapping mechanisms is exposed to store-now-decrypt-later risk.

At riskLong-lived ciphertext in databasesbackups+1Re-wrap data-encryption keys using ML-KEM-derived key-encryption keys. Use AES-256 for symmetric encryption at rest and in transit.
Open dossier
HighCLOUD-002
Moderate

Cloud Security Alliance quantum readiness guidance: CSA published quantum-safe security guidance identifying crypto-agility as critical requirement for cloud deployments. Multi-cloud environments using 5+ key management systems face fragmented PQC migration paths.

At riskCloud KMS key wrappingmulti-cloud encryption+2Unified PQC key managementML-KEM cloud HSM integration+1
Open dossier

Critical Infrastructure / OT

(6)
CriticalENERGY-002Updated
Low

10 CFR § 73.54 requires nuclear power plant licensees to maintain cybersecurity plans and protect digital computer and communication systems associated with safety, security, emergency preparedness, and supporting functions.

At riskDigital computer and communication systems associated with safety-related functionsincluding the confidentiality and integrity of their data and software.Defense-in-depth protective strategies for detectingresponding to+1
Open dossier
CriticalENERGY-003Updated
Low

More than one billion smart meters are deployed worldwide and need migration planning for future quantum threats. Some meters use unchangeable fixed-function cryptography, while the oldest devices that cannot receive over-the-air updates will need replacement.

At riskRSA/ECC cryptographysmart-meter communication modules and channels+2Low-footprint implementations of NIST PQC standards for embedded and memory-constrained smart meters.
Open dossier
CriticalCI-001Updated
Moderate

CISA’s PQC Initiative addresses quantum-computing security risks and supports critical-infrastructure and government networks during the transition to PQC. CISA is also helping critical-infrastructure owners and operators facilitate the eventual PQC transition for operational technology.

At riskWidely used encryption and digital-signature algorithms that protect data confidentialityintegrity+1Sector-specific PQC migration roadmapsFIPS 203/204/205 compliance+1
Open dossier
CriticalCRIT-002Updated
Low

Many critical-infrastructure OT systems use legacy RSA encryption, which is a primary target of quantum attacks because Shor's algorithm can break it. This creates a strategic "harvest now, decrypt later" risk, where adversaries collect encrypted OT communications today intending to decrypt them once quantum capabilities mature. OT further compounds this risk because a significant share of its endpoints run out-of-date, end-of-life operating systems and software that remain in operation for long periods. Integrating PQC protections adds processing overhead that can exceed the hardware capabilities of these OT systems.

At riskVulnerabilities lie in critical infrastructure that uses RSA encryption. Due to their age and designmany such systems still use RSA encryption.PQC algorithms require greater computational resourcesand integrating them into OT without disrupting real-time or safety-critical operations is complex and costly. The additional processing overhead from adopting or upgrading cryptographic mechanisms may exceed the hardware capabilities of current OT systems.
Open dossier
HighCRIT-001
Moderate

Singapore's Cyber Security Agency released a Quantum-Safe Handbook and Quantum Readiness Index (in public consultation through end-2025) to guide Critical Information Infrastructure owners and government agencies toward quantum-safe migration.

At riskCritical Information Infrastructure cryptographic systemsQuantum-Safe Handbook guidance + Quantum Readiness Index self-assessment
Open dossier
LowENER-001Updated
Low

NERC's January 2026 Critical Infrastructure Protection Roadmap addresses security of the North American bulk power system through measures including MFA, foundational cyber hygiene, and protection of SCADA and AGC communications using protocols such as DNP3, ICCP, and Modbus. Its survey material also identifies quantum computing as a risk to modern cryptography and gives an encrypted-data collection and later quantum decryption scenario.

At riskDNP3 is the IEEE-standardized protocol for electric power systems communications. Legacy protocols including DNP3ICCP+5The roadmap's recommendations focus on MFA and foundational cyber hygienenot a cryptographic-algorithm replacement. Its quantum-computing entry states the risk but names no mitigation or replacement algorithm.
Open dossier

Cross-Industry

(22)
CriticalCROSS-002
High

NIST IR 8547 is an Initial Public Draft dated November 2024. It describes the transition from quantum-vulnerable cryptography and identifies 2035 as the primary federal target for completing migration to post-quantum cryptography. NIST intends to deprecate classical digital signatures at the 112-bit security level after 2030.

At riskShor's algorithm on a future cryptographically relevant quantum computer is projected to defeat classical approved asymmetric algorithmsnamely RSA+2FIPS 203 specifies the ML-KEM key-encapsulation mechanism with three parameter setsML-KEM-512+8
Open dossier
CriticalCROSS-004
Low

The 2024 Quantum Threat Timeline Report suggests that the quantum threat may be closer than previously thought. It emphasizes proactive quantum-threat mitigation.

At riskStandard encryption protocols are at risk from future quantum computers.Organizations should undertake a proactivewell-planned transition to quantum-safe cryptography.
Open dossier
CriticalCROSS-007
Low

The NIS2 Directive requires entities in scope to adopt cybersecurity risk-management measures, including the use of state-of-the-art cryptography. Member States should connect with NIS2 and eIDAS supervisory bodies to understand the implications of the quantum threat for regulated entities. The roadmap also encourages real-world testing through activities such as ETSI Plugtests and IETF PQC hackathons.

At riskAll quantum-vulnerable cryptography in EU member state systems and critical infrastructureMigrating to post-quantum cryptography should use standardised and tested hybrid solutions whenever feasible. Quantum-vulnerable public-key mechanisms must not be used stand-alone for high-risk use cases after the end of 2030and for medium-risk use cases after the end of 2035.
Open dossier
CriticalCROSS-009
Low

DNSSEC quantum signature forgery: DNSSEC uses RSA (RSASHA256 per RFC 5702) and ECDSA (ECDSAP256SHA256 per RFC 6605) to sign DNS records — RFC 8624 covers current algorithm implementation requirements. Approximately 40% of global DNS domains have DNSSEC enabled including 92% root zone adoption. Quantum forgery of DNSSEC signatures enables DNS hijacking for any signed domain redirecting traffic to attacker-controlled servers. PQC signatures face challenges with DNS UDP packet size limits (~1232 bytes) requiring protocol-level changes. IETF draft-sheth-pqc-dnssec-strategy-01 addresses migration strategy.

At riskDNSSEC signing currently relies on RSASHA256 (algorithm 8) and ECDSA (algorithm 13)both vulnerable to quantum attack. ECDSAP256SHA256 (algorithm 13) and ECDSAP384SHA384 (algorithm 14) are the DNSKEY/RRSIG algorithms defined by RFC 6605.PQC signatures such as ML-DSA (2420-4627 bytes) and SLH-DSA (7856-49856 bytes) exceed DNS's UDP size limitrisking excessive TCP fallback and resolver performance degradation. Proposed conservative PQC candidates include SLH-DSA+6
Open dossier
CriticalCROSS-010
Low

RPKI's mandated signature algorithm for certificates, CRLs, CMS signed objects, and certification requests is RSA PKCS #1 v1.5. RSA key pairs used for these RPKI signatures must have a 2048-bit modulus. This RFC 7935 profile obsoletes the earlier RFC 6485 algorithm profile. A quantum computer capable of breaking RSA could forge any RPKI signature, including on resource certificates and ROAs. That capability lets an attacker bypass route origin validation by forging a ROA that authorizes their own malicious route. RSA-2048 signing currently keeps the RPKI dataset at about 838MB. Switching to a post-quantum scheme such as ML-DSA-44 would grow that dataset to roughly 3.0GB.

At riskRSA-2048 ROA signaturesRPKI certificate hierarchy+1RPKI's RSA signatures need a post-quantum replacement. A hybrid signature should combine a post-quantum signature with a traditional signature. Falcon-512 appears to be a good overall choice.
Open dossier
CriticalCROSS-011
Moderate

OpenSSH 10.0 was released on 2025-04-09. It uses the hybrid post-quantum algorithm mlkem768x25519-sha256 by default for key agreement. The algorithm is considered safe against attacks by quantum computers and has been standardized by NIST.

At riskOpenSSH key agreement is the cryptographic function addressed by the hybrid post-quantum default.OpenSSH 10.0 uses mlkem768x25519-sha256 as its default hybrid post-quantum key-agreement algorithm.
Open dossier
HighCROSS-006
High

NIST announced HQC's selection for standardization in March 2025. HQC is a code-based KEM intended to complement ML-KEM by relying on a different underlying security problem. NIST will create a draft HQC standard for public comment and, after adjudicating comments, publish a final version in approximately two years.

At riskML-KEMstandardized in FIPS 203+1HQC as a complementary KEM to ML-KEMproviding diversity through a different underlying security problem.
Open dossier
HighCROSS-008
High

NIST SP 800-227 KEM recommendations: Published as final standard on September 18, 2025 — initially released as Initial Public Draft in January 2025. Provides definitions, security properties, and implementation recommendations for key-encapsulation mechanisms as companion guidance to FIPS 203 (ML-KEM). Establishes best practices for KEM usage in protocols, hybrid constructions, and key management — essential reference for correct PQC deployment.

At riskWidely deployed quantum-vulnerable key-establishment schemes and KEM implementations that do not correctly implement the target KEM.For TLSSP 800-227 describes bilateral key confirmation during the handshake.
Open dossier
HighCROSS-012
Low

Sigstore plans to enable content signing with post-quantum keys and eventually adopt post-quantum cryptography in services including Fulcio and Rekor. ML-DSA has been added to enable experimentation, while Sigstore still needs a plan for transitioning away from traditional cryptographic algorithms.

At riskTraditional cryptographic algorithms used by Sigstore servicesincluding Fulcio+2ML-DSA ephemeral keys in Sigstore bundles for client experimentation. Future end-to-end PQCA support for private Sigstore instances after cryptographic-agility work.
Open dossier
HighCROSS-013
Moderate

Quantum random number generation (QRNG) for PQC key security: PQC algorithm security depends on high-quality randomness for key generation. Classical PRNGs may contain algorithmic biases exploitable by sophisticated adversaries. QRNG uses quantum mechanical processes to generate theoretically unpredictable randomness. Quantinuum Quantum Origin was among the first software-delivered QRNGs to obtain NIST SP 800-90B entropy source validation. Commercial QRNG products from ID Quantique, Quside, and QNu Labs are available for HSM, IoT, and automotive integration. QRNG complements PQC by ensuring cryptographic keys are non-predictable from generation.

At riskQuantum Origin is contrasted with traditional pseudo-random number generators. Hardware solutions can be affected by environmental factors.NIST SP 800-90B validated QRNGquantum entropy sources for HSM key generation+1
Open dossier
HighCROSS-014
Moderate

NIST IR 8547 proposes deprecation after 2030 and disallowance after 2035 for listed quantum-vulnerable digital-signature and key-establishment algorithm families, including RSA, ECDSA, and elliptic-curve key establishment. NSM-10 establishes 2035 as the primary target for completing migration to PQC across federal systems. SP 800-131A separately addresses transitions in algorithms and key lengths used by federal agencies to protect controlled unclassified information.

At riskNIST-approved symmetric primitives providing at least 128 bits of classical security are believed to meet at least Category 1 security. NIST symmetric-cryptography standards at the 112-bit security level will be disallowed in 2030.NIST does not expect migration away from its existing symmetric-cryptography standards as a wholebut applications should move away from symmetric standards at the 112-bit security level during the PQC transition.
Open dossier
HighCROSS-017
High

KyberSlash1 and KyberSlash2 are timing vulnerabilities in several Kyber/ML-KEM implementations, including the official reference code. Their exploitability was demonstrated on the Raspberry Pi 2 and Arm Cortex-M4, with Kyber secret keys recovered within minutes for KyberSlash2 and within a few hours for KyberSlash1.

At riskKyber/ML-KEM implementations containing the KyberSlash1 or KyberSlash2 timing vulnerabilitiesincluding the official reference code.Use dynamic analysis to detect variable-time instructions operating on secret dataor formal methods to guarantee the absence of variable-time instructions in cryptographic software.
Open dossier
HighCROS-002Updated
High

This document examines the specific risks that quantum computing could pose to industrial control systems (ICS) and other operational technology (OT).

At riskOT specifically may be vulnerable due to connectivity or association with IT platforms as well as direct or indirect dependencies on public-key cryptographic features including encryption and decryptionsigning and validation schemas+1OT vendorsowners+5
Open dossier
HighCROS-004
Moderate

BSI TR-02102-1 provides Germany's official security assessment and recommended key lengths for cryptographic mechanisms, forming the baseline against which PQC transition urgency is judged.

At riskTable 1.2 summarises the recommended key lengths of different types of cryptographic primitives. Over timeseveral block cipher algorithms have been specified for use by the Federal Government. The digital signature algorithms are specified in FIPS 186.BSI-recommended cryptographic mechanisms with long-term security orientation
Open dossier
HighCROS-005
Moderate

ANSSI-PG-083 version 3.00 sets out rules and recommendations for choosing and sizing cryptographic mechanisms. It accounts for the quantum threat and aims to remain valid for at least 15 years.

At riskAESRSA+5It also names ML-DSA and SLH-DSA for signatureswith hybrid-use conditions where specified.
Open dossier
HighCROS-006
Moderate

CCN-TEC 009 (Spain's National Cryptologic Centre) recommendations for a safe post-quantum transition, covering CRYSTALS-Kyber, CRYSTALS-Dilithium, Falcon, SPHINCS+, BIKE, HQC, Classic McEliece and SIKE, driven by Shor's/Grover's algorithm risk and harvest-now-decrypt-later.

At riskRSAElGamal+1CRYSTALS-KyberCRYSTALS-Dilithium+4
Open dossier
HighCROS-007
Low

CSA guidance provides a practical framework for modernizing cloud key management for PQC, including cryptographic asset inventory, crypto agility, and mitigation of Store-Now-Decrypt-Later and hybrid-downgrade risks. It discusses hybrid and migration-ready PQC updates affecting TLS, SSH, and IKEv2.

At riskRSAECC+2ML-KEMML-DSA+2
Open dossier
HighCROS-008
Low

Israel's National Cyber Directorate (INCD) Alert 1855 (6 March 2025, TLP:CLEAR) warns that quantum computers can break widely used public-key algorithms — factorization (RSA), discrete logarithms (Diffie-Hellman) and elliptic-curve discrete logarithms — used in TLS, SSL-VPN and API key exchange. It flags forged digital signatures on software and firmware and on documents convertible to money (including digital currencies), especially on ICS/SCADA and medical (IoMT) platforms whose algorithms are hard to replace, and harvest-now-decrypt-later capture of long-sensitive data as a risk that may already be under way. It directs organisations to appoint an owner, find systems with non-resistant components and plan to add NIST's standardised PQC algorithms alongside existing ones, prioritised by system and data sensitivity, with crypto-agility built into development and procurement.

At riskRSA (factorization)Diffie-Hellman (discrete logarithm) and elliptic-curve algorithms; TLS+1Use NIST's first three selected PQC algorithms approved as FIPS as the basis for quantum-resistant solutionsinitially adding resistant algorithms alongside existing ones. Use AES256 for symmetric encryption; SHA-256 may continue to be used+3
Open dossier
HighCROS-009
Low

CISA, NSA, and NIST factsheet recommending a Quantum-Readiness Roadmap, a useful cryptographic inventory, assessment of supply-chain considerations, and engagement with technology vendors about PQC.

At riskCryptographic assets identified through a useful cryptographic inventoryMigration to post-quantum cryptography through a Quantum-Readiness Roadmap
Open dossier
MediumCROSS-015
Authoritative

The estimated security strength of approved hash functions depends on the required property and the hash output length. For collision-resistant applications, the document assigns 128-bit strength to SHA-256 and SHA3-256, 192-bit strength to SHA-384 and SHA3-384, and at least 256-bit strength to SHA-512 and SHA3-512.

At riskSHA-1 for collision-resistant digital-signature applications; SHA-256 collision resistanceSelect an approved hash function with an output length sufficient for the application's required security strength; for collision resistancethe document lists SHA-384 and SHA3-384 at 192 bits and SHA-512 and SHA3-512 at at least 256 bits.
Open dossier
MediumCROS-001
Authoritative

This is IAPH's cyber resilience guidance for emerging technologies in the maritime supply chain. It addresses quantum computing risk in a chapter structure alongside other emerging technologies including Artificial Intelligence and IoT. It recommends integrating cybersecurity into technology planning from the earliest stages, termed "cybersecurity by design." It recommends assessing risks from emerging technologies even when an organization does not plan to deploy them locally. Among the technology-specific protection measures it lists is post-quantum cryptography adoption.

At riskMaritime IT and OT systemswhich rely heavily on cryptography+2The guidelines recommend integrating cybersecurity into emerging-technology planning from the outsetdescribed as "cybersecurity by design." Post-quantum cryptography adoption is listed among the technology-specific protection measures alongside encryption strategies and network segmentation.
Open dossier
MediumCROS-003
Low

Applied Quantum's practitioner-built 8-phase PQC migration framework for enterprise-wide crypto-agility, covering executive mandate through vendor governance, with sector extensions for financial services and OT.

At riskEnterprise-wide cryptographic estate across PKIHSM+18-phase enterprise PQC migration methodology; hybrid/composite signatures
Open dossier

Cryptocurrency / Blockchain

(3)
CriticalCRYPTO-001
Low

Bitcoin address types can differ in how soon they become vulnerable to quantum computers. Potentially quantum-vulnerable types include earlier addresses, reused addresses, and Taproot addresses. Taproot remains vulnerable because it uses ECC, specifically Schnorr signatures.

At riskECDSA used by early Bitcoin addresses. Earlier and reused Bitcoin addresses. ECC/Schnorr-based Taproot addresses.The primary source notes that adopting updated PQC-compliant address types to replace legacy and Taproot addresses is a possible Bitcoin mitigationone that might not require a hard fork. It attributes this PQC address-type proposal to a 2024 Bitcoin Improvement Proposal titled 'Pay-to-QR-Hash (P2QRH).'
Open dossier
CriticalCRYPTO-002
Low

Standard Ethereum accounts use ECDSA on secp256k1 to sign transactions. An account that has sent a transaction exposes its public key onchain, enabling a quantum computer to derive its private key. Ethereum plans to use account abstraction through EIP-8141 to let accounts adopt post-quantum signatures.

At riskStandard Ethereum accounts use ECDSA on secp256k1 to sign transactions. After an account sends a transactionits public key is exposed onchain+1Account abstraction through EIP-8141 would enable individual accounts to switch to post-quantum signature schemes.
Open dossier
CriticalCRYPTO-003
Low

Distributed-ledger networks using traditional cryptography face HNDL data-privacy risk because an attacker can store a ledger replica and later reveal protected data with a sufficiently powerful quantum computer. PQC migration can protect future security and integrity but does not retroactively protect previously recorded Bitcoin transactions.

At riskRSA-2048 and ECC are vulnerable to sufficiently powerful quantum computers.Possible replacements include PQC-compliant address types for legacy and Taproot addressessupported by published NIST PQC standards. The network could require wallets and third-party services to use PQC methods.
Open dossier

Education / Research

(1)
HighEDU-005
Low

The education sector has seen an alarming surge in cyber threats. Schools rely on expansive networks connecting students, faculty, administration, and third-party vendors, with thousands of devices and endpoints — many unmanaged — expanding the attack surface. A cryptographically relevant quantum computer will threaten systems relying on traditional asymmetric cryptography, making both authentication flows and data in transit vulnerable.

At riskWeb applications using TLS to authenticate users and encrypt communications may be vulnerable to attacks compromising integrity or confidentiality. Traditional asymmetric cryptography at risk includes RSA and ECDSA primitives.This document defines three hybrid key agreement mechanisms for TLS 1.3 -- X25519MLKEM768SecP256r1MLKEM768+1
Open dossier

Finance & Banking

(16)
CriticalFIN-001
Low

Project Leap Phase 2 tested post-quantum cryptography in an operational payment system while sending liquidity transfers. The document characterizes migration to quantum-safe payment systems as complex and high-stakes and calls for timely preparation and institutional collaboration.

At riskTraditional digital signatures were the cryptography used for liquidity transfers in the tested payment system before being replaced.Post-quantum cryptography and post-quantum cryptographic protocols.
Open dossier
CriticalFIN-002
Low

HNDL threatens currently protected financial records, transaction data, and long-term financial contracts recorded on blockchains. A bad actor can store protected ledger data now and later use a sufficiently powerful quantum computer to reveal it. Moving Bitcoin users to PQC address types does not retroactively protect transactions previously recorded with less-quantum-resistant address types.

At riskRSA-2048 is an asymmetric encryption method that is the current internet encryption standard. ECC-256 authenticates digital signatures and secures some cryptocurrenciesand can be solved by Shor's algorithm. Early Bitcoin addresses relied on ECDSA+1Standardized post-quantum encryption and PQC-compliant address types to replace legacy and Taproot addresses.
Open dossier
HighFIN-003
Low

BIS Papers No. 149 examines the risk that quantum computers pose to financial stability by potentially breaching widely used cryptographic algorithms. The paper notes that sensitive financial data faces a harvest-now-decrypt-later risk that necessitates immediate preparation.

At riskWidely used asymmetric cryptography (RSA and ECC) securing financial communications is at risk from quantum computing. The most vulnerable areas identified are online/mobile bankingpayment transactions+2Post-quantum cryptography includes NIST-selected quantum-resistant encryption and digital-signature algorithms. Migration should be supported by a flexible quantum-readiness roadmap.
Open dossier
HighFIN-005
Low

Despite increasing awareness, many organizations have yet to define or apply resources adequately supporting quantum-resistant projects. This delay, called crypto-procrastination, threatens the overall migration roadmap by compressing future implementation tasks into unrealistically short timeframes. The period 2030-2031 represents a key milestone, when algorithms like RSA-2048 will be deprecated.

At riskRSAECC+2Hybrid and classical post-quantum key establishment is already supported by major browserscryptographic libraries+1
Open dossier
HighAUS-FIN-002
Moderate

Payment-system HNDL risk: malicious actors may capture encrypted financial data today for future quantum decryption. Project Leap Phase 2 tested post-quantum cryptography in the Eurosystem's T2 payment system.

At riskPayment-system participant authentication and initial key exchange may use RSA or ECC. Communications between bankspayment processors and payment gateways rely on TLS. The tested T2 business-application-header signature uses RSA in the current system.CRYSTALS-Dilithium at NIST security strength category 3 was tested as a replacement for the RSA signature in the T2 business application header. ML-DSA was left for future testing.
Open dossier
HighFINA-002
Authoritative

BIS-led roadmap on quantum-readiness for the global financial system: CRQC risk (27% of surveyed experts expect it within 10 years, 50% within 15), harvest-now-decrypt-later, Shor's/Grover's algorithms — recommends cryptographic inventory, hybrid schemes, and phased migration starting immediately.

At riskAESRSA+2The document recommends hybrid cryptographic schemescryptographic agility+1
Open dossier
HighFINA-003
Moderate

The Swiss Financial Market Supervisory Authority FINMA surveyed 60 Swiss financial institutions on the opportunities and risks of quantum computing. FINMA recommends that a PQC roadmap be drawn up by mid-2027 at the latest. FINMA expects institutions' risk analysis to result in a comprehensive inventory listing all cryptographic methods used. FINMA recommends taking into account the risk of harvest-now-decrypt-later attacks, where data encrypted today may be stolen with the intention of decrypting it later using powerful quantum computers.

At riskFinancial institution data and communications vulnerable to harvest-now-decrypt-laterQuantum-safe encryption transition; crypto-agility
Open dossier
HighFINA-005
Moderate

Japan's FSA Study Group report on post-quantum cryptography, formulated through mid-2024 stakeholder discussions, providing recommendations for deposit-taking institutions transitioning to PQC.

At riskDeposit-taking institution cryptographic systemsPQC transition per FSA Study Group recommendations
Open dossier
HighFINA-006
Moderate

MAS advisory (TCRS/2024/01) outlining cybersecurity risks from quantum computing developments and expected mitigating measures for Singapore financial institutions.

At riskFinancial institution cryptographic systems (MAS-regulated)Mitigating measures per MAS advisory
Open dossier
HighFINA-007
High

ASC X9 report giving financial-industry managers high-level guidance on quantum-enabled cyberattack risk, cryptographic asset inventory, and PQC migration prioritization.

At riskThe report concerns cryptography used by the financial-services industry. Classical asymmetric cryptosystems such as RSA and elliptic-curve cryptography are at risk.Use crypto agility as one quantum-risk mitigation method. Use a roadmap to put the quantum-safe migration strategy into action. Migration may be phased rather than performed for every system at once.
Open dossier
HighFINA-008
Low

With this report, X9 seeks to educate financial industry management on how to identify, analyze, prioritize and manage the significant risks posed by future quantum computers and to offer guidance on how the industry can migrate to post-quantum cryptography to protect sensitive data and networks against quantum-enabled cyberattacks. The report calls for creating a cryptographic asset inventory to identify all cryptographic systems in use. It calls for prioritizing current systems for remediation based on a risk assessment. It calls for working with vendors to develop and deploy PQC solutions in third-party products.

At riskCryptographic systems in useidentified through a cryptographic asset inventoryPQC migration under X9 guidanceincorporating agile architecture where appropriate and developing a crypto-agility strategy
Open dossier
HighFINA-010
Low

FINMA conducted a survey of 60 Swiss financial institutions between November 2025 and January 2026 on the opportunities and risks of quantum computing. In most cases the surveyed institutions lacked a clear roadmap and sufficiently forward-looking planning for migration to quantum-safe encryption. FINMA considers that action is needed in the risk-management process of numerous institutions to continue meeting operational-risk and resilience requirements. FINMA's measures include creating a cryptographic inventory and protecting critical data against "harvest now, decrypt later" attacks.

At riskEncryption protecting critical data at Swiss financial institutions includes data exposed to “harvest nowdecrypt later” attacks.FINMA outlines a strategy and roadmap for migration to quantum-safe encryptiontogether with a transition to crypto-agility+1
Open dossier
MediumFINA-001
Low

The HKMA plans to launch a Quantum Preparedness Index to assess the banking sector’s maturity in adopting PQC and quantum computing, followed by a target index and transition roadmap outlining potential projects and pilots. It also intends to establish a Fintech Cybersecurity Baseline for fintech solution providers. The Blueprint identifies external-platform and third-party dependencies, high implementation costs, skills shortages, and particular difficulty for smaller institutions.

At riskSufficiently advanced quantum machines could break current encryption standardsundermining data confidentiality across financial networks. A.I.+1Following the assessmenta transition roadmap will be developed+1
Open dossier
MediumFINA-004
Moderate

OSFI's overview of digital and crypto risks for Canadian financial institutions, including quantum computing's threat to encryption and store-now-decrypt-later exposure, alongside a joint OSFI/FCAC quantum-readiness questionnaire.

At riskEncryption protecting Canadian financial-sector datavulnerable to store-now-decrypt-laterQuantum-computing preparedness questionnaire issued jointly by OSFI and FCAC
Open dossier
MediumFINA-009
Low

HKMA launched a Quantum Preparedness Index (QPI) and whitepaper for the banking sector: initial sector-wide QPI score of 2.3, with 32% of banks not yet started on PQC planning; HKMA targets full sectoral readiness (QPI 10) by 2030.

At riskBanking-sector preparedness for the transition to Post-Quantum Cryptography is benchmarked via the HKMA Quantum Preparedness Index.Sector-wide PQC migration supported by an HKMA PQC toolkit and workshops
Open dossier
MediumFINA-011
Low

Japan FSA study group report on deposit-taking financial institutions' response to post-quantum cryptography, chaired by Mizuho Financial Group's Group Information Security Officer (study conducted July-October 2024).

At riskQuantum-vulnerable public-key cryptography is used in many places within Japanese deposit-taking financial institutions.PQC transition per FSA study group recommendations
Open dossier

Government & Defense

(5)
CriticalGOV-001
Moderate

A future cryptanalytically relevant quantum computer could break public-key systems still used today. NSA's direction covers public cryptographic algorithms on both unclassified and classified National Security Systems.

At riskRSA with a minimum 3072-bit modulusECDH P-384+1CRYSTALS-Kyber Level V is selected for key establishment. CRYSTALS-Dilithium Level V is selected for digital signatures. AES with 256-bit keys is selected for information protection.
Open dossier
CriticalGOV-002
Moderate

CNSA 2.0 compliance deadline pressure: NSA mandates CNSA 2.0 compliance with phased deadlines — software/firmware signing supported and preferred by 2025 (exclusively by 2030), networking equipment supported and preferred by 2026 (exclusively by 2030), NSS acquisitions by January 2027, web browsers/servers/cloud supported and preferred by 2025 (exclusively by 2033), full transition by 2033.

At riskThe advisory protects National Security Systems (NSS) and related assetsincluding both unclassified and classified NSS. Its direction applies to all unclassified and classified NSS. The Federal PKI is also at risk+3NSS solutions must be NSA-approved rather than assessed as FIPS-validated. Software and hardware providing cryptographic services require NIAP or NSA validation.
Open dossier
CriticalGOV-005Updated
Moderate

NSA CNSA 2.0 mandates technology-category migration timelines for National Security System operators, requiring software/firmware signing and web/cloud services to prefer PQC by 2025, networking by 2026, operating systems by 2027, and constrained devices by 2030, with exclusive deadlines between 2030 and 2033. The December 2024 FAQ further requires phasing out non-compliant equipment by December 31, 2030, enforcing mandatory CNSA 2.0 use by December 31, 2031, and achieving full NSS quantum resistance by 2033.

At riskCNSA 2.0's direction applies to all National Security Systems' use of public cryptographic algorithmsboth unclassified and classified. Specifically+3CNSA 2.0 uses AES with 256-bit keys for information protection. It specifies CRYSTALS-Kyber Level V for key establishment. It specifies CRYSTALS-Dilithium Level V for digital signatures.
Open dossier
CriticalAUS-GOV-001
Moderate

Harvest-now-decrypt-later attacks targeting Australian classified data: Foreign state actors actively intercepting and storing encrypted Australian government communications. ASD's Annual Cyber Threat Report 2024-2025 identifies nation-state actors targeting Australian government networks. Classified data encrypted with current RSA/ECDSA is at full Shor's-algorithm risk when CRQCs become available; AES-128 retains 64-bit effective security against Grover's algorithm (weakened, not broken) — AES-256 is the symmetric mitigation.

At riskA cryptographically relevant quantum computer could break contemporary public-key cryptography. Adversaries could use this capability to compromise communications based on current public-key technology.Organisations should start preparing for post-quantum cryptographywhich the report identifies as the best way to protect networks from the future quantum-computing threat. Effective transition plans are needed for operation in 2030 and beyond.
Open dossier
HighGOV-003
Moderate

CISA's January 23, 2026 product-category guidance responds to Executive Order 14306. Organizations should acquire only PQC-capable products when planning acquisitions in categories where such products are widely available. The widely available categories include cloud services, collaboration software, web software, and endpoint security.

At riskThe affected scope includes hardware and software products typically acquired by the federal government. The relevant vulnerable cryptography includes digital-signature algorithms and key-establishment schemes.ML-KEM is the FIPS 203 key-establishment standard. ML-DSA is the FIPS 204 digital-signature standard. SLH-DSA is the FIPS 205 digital-signature standard.
Open dossier

Healthcare / Pharmaceutical

(2)
CriticalHLTH-002
Low

Only 4% of Healthcare & Life Sciences organizations have encrypted 80% or more of their sensitive cloud data. Fifty-nine percent are concerned about future decryption of today’s data, including harvest now, decrypt later. The report says the clock is ticking on post-quantum readiness.

At riskEncryption protecting sensitive cloud data and today’s data.Plan for post-quantum readiness. Prototype new ciphers.
Open dossier
MediumHEAL-001
Low

HSCC Cybersecurity Working Group's Q1 2026 report identifies a joint HSCC/Health-ISAC Post Quantum Cryptography task group and reports three new task groups for Policy, Isolation and Segmentation, and Workforce.

At riskThe task group will develop a shared cryptographic-asset inventory framework for organizations to baseline their current exposure. Its roadmap work will include interoperability and supply-chain considerations.The task group plans a cross-industry PQC migration roadmap. It also plans guidelines and reference architectures for pilot implementations.
Open dossier

Insurance

(1)
HighINSU-001
Low

Munich Re’s Cyber Insurance Risks and Trends 2025 says NIST finalized its principal set of quantum-resistant encryption algorithms in August 2024. It says RSA will be vulnerable to quantum-based decryption but should continue to offer sufficient protection through at least 2030. It also says attackers are already stealing data to decrypt once sufficiently powerful quantum computers become available.

At riskRSA used for secure data transmission is at risk from future quantum-based decryption.NIST finalized its principal set of quantum-resistant encryption algorithms in August 2024. Transition to the new standards is imminent.
Open dossier

Internet of Things (IoT)

(2)
HighIOT-003Updated
High

A manifest specification for IoT firmware updates must support different cryptographic algorithms and algorithm extensibility. Because signature schemes based on RSA and Elliptic Curve Cryptography (ECC) may become vulnerable to quantum-accelerated key extraction in the future, unchangeable bootloader code in ROM is recommended to use post-quantum secure signature schemes such as hash-based signatures. Where COSE (RFC 9052) is used, its COSE_Sign structure can carry signatures generated with the Elliptic Curve Digital Signature Algorithm (ECDSA) or the Edwards-curve Digital Signature Algorithm (EdDSA).

At risksince signature schemes based on RSA and Elliptic Curve Cryptography (ECC) may become vulnerable to quantum-accelerated key extraction in the future Under a CRQCtraditional signature algorithms (RSA+3For unchangeable bootloader code in ROMuse post-quantum-secure signature schemes such as hash-based signatures.
Open dossier
HighINTE-001Updated
Moderate

ETSI TR 104 005 V1.1.1 technical report analyzing PQC impacts on ETSI TC SET's Secure Element Technologies specifications (SIM/UICC/Secure Element), driven by Shor's and Grover's algorithms.

At riskECKA-EG (ECC-based key agreement) used in remote application/OTA provisioning for SIM/UICC/Secure Element -- SCP03/SCP04 secure channel protocols themselves are AES-based (symmetric) and already considered quantum-safe per ETSI TC SET analysisQuantum-safe adaptation of ETSI TC SET specifications (specific PQC algorithms not yet named — monitoring GlobalPlatform updates recommended)
Open dossier

IT Industry / Software

(2)
CriticalIT-002
Low

Apple will start accepting PQC roots in late 2025 or in 2026. Microsoft is updating Windows and Linux builds to allow PQC integration. Mozilla identified preventing capture-and-decrypt attacks as an immediate priority.

At riskRSA and ECC remain in use for the time being. The stated PQC priorities are key exchange first and authentication second.The meeting discussed ML-KEM deployment and a planned transition to ML-DSA.
Open dossier
CriticalIT-003
Moderate

NIST FIPS 203/204/205 standardization milestone: First official PQC standards published August 2024. FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) provide the foundation for all PQC migration. CMVP validation of implementations is ongoing with first validated modules expected 2025-2026.

At riskCurrent encryption and digital-signature systems are threatened by sufficiently capable quantum computers.FIPS 203 (ML-KEM-512/768/1024)FIPS 204 (ML-DSA-44/65/87)+1
Open dossier

Media / Entertainment / DRM

(1)
CriticalMEDIA-002
Low

Digital rights management (DRM) solutions aim to prevent the copying or distribution of copyrighted material. This addresses the modern paradigm of cloud-based content delivery followed by major platforms such as Netflix, Disney+, and Amazon Prime. Three widely used DRM solutions — Google Widevine, Apple FairPlay, and Microsoft PlayReady — are deployed on billions of devices worldwide. These systems have design-level shortcomings that leave them vulnerable to emerging attacks, including an absence of post-quantum security.

At riskGoogle WidevineApple FairPlay+1The KEMRecipientInfo structure is used with the Composite ML-KEM algorithm to securely transfer the content-encryption key from the originator to the recipient.
Open dossier

Payment Card Industry

(1)
HighPAYM-001
Low

FS-ISAC report on quantum computing's impact on the Payment Card Industry: cryptographic asset inventory across HSMs/databases/physical systems, AES-256 migration against Grover's algorithm, and RSA/ECC replacement with PQC, produced with PCI SSC/NIST/BIAN input.

At riskRSAECC+5AES-256 for symmetric migration (Grover's algorithm mitigation); PQC algorithms to replace RSA/ECC (specific algorithms not named); crypto-agility
Open dossier

Telecommunications

(4)
CriticalTELCO-001
Moderate

Subscriber personal data, including call and location history, is stored in operator systems and must be protected with quantum-safe encryption over its lifetime. Sensitive data on 5G SBI and N32 interfaces is exposed to store-now/decrypt-later attacks.

At riskRSA and elliptic-curve public-key algorithms used for signaturesauthentication+2Use standardized ML-KEM for quantum-safe key establishment and ML-DSA for digital signatures. AES-256 may be used as a conservative response to potential Grover attacksalthough the document notes that guidance differs.
Open dossier
HighTELCO-002
Moderate

The GSMA Post Quantum Telco Network Task Force publishes guidance on PQC impacts and migration for telecommunications, building on PQ.01 and referring to PQ.02 for quantum-risk assessment. Migration depends on standards bodies, equipment manufacturers, infrastructure providers, and operators implementing quantum-safe protocols and algorithms.

At riskThe affected scope includes secure transport between the 4G/5G RAN and security gateways. IPsec/IKE key establishment and certificate authentication are quantum-vulnerable components.Integrate standardized PQC into affected telecommunications protocols and 3GPP specifications. For TLS 1.3hybrid key exchange can combine ECDHE with ML-KEM+1
Open dossier
HighTELCO-005
Moderate

GSMA PQ.05 analyzes threats, impacts, and mitigations for a cryptographically relevant quantum computer targeting 4G and 5G roaming architectures and interfaces. It prioritizes protection of roaming interfaces against harvest-now-decrypt-later attacks and also addresses future impersonation, spoofing, and tampering.

At riskTLS 1.3 and IPsec with X.509 certificate authentication protect roaming interfaces. JWS provides integrity and authentication for JSON payloads in PRINS mode.Use ML-KEM for quantum-safe key establishment on roaming interfaces. Use ML-DSA for certificatessignatures+1
Open dossier
HighTELE-001
Moderate

ANSSI-FT-117 technical guide for IPsec's post-quantum transition — hybridizing IKEv2 key exchange and signature authentication, noting significant message-size increases from PQC key/ciphertext/signature sizes.

At riskDiffie-Hellman key exchange and classical signature authentication within IKEv2/IPsecHybrid PQC key exchange and hybrid PQC signature authentication within IKEv2 (per ANSSI guidance; specific algorithms not named in extracted text)
Open dossier

Try it

An adversary records your encrypted traffic today so it can be decrypted once a quantum computer exists. Which threat class is that, and which security property does it attack?

Next step

Assess your exposure

The assessment scores the threats on this page against your own estate.