up:: For Press

The primary documents behind every claim

Every factual claim in this resource traces to a document below. Each row names the issuer, the date, and what that document actually establishes, so a claim can be checked against the original rather than against a summary of it.

Where a document is a draft, that’s stated. Where a figure inside it carries the issuer’s own uncertainty language, that’s stated too.

The short version:

  • The U.S. schedule comes from 4 instruments, and their dates sit years apart from each other.
  • The most-quoted date, 2035, comes from the softest document, a policy goal with “as is feasible” written into the sentence.
  • The retirement schedule is still a draft, so its years are stated intent rather than settled rule.
  • Seven countries or blocs have published their own timelines, and they differ on strategy as well as on dates.
  • The mathematics rests on 1 paper from 1994, and the hardware estimates on 2 papers 6 years apart.
  • The precedent record is documentary, drawn from court opinions, regulator settlements, and incident investigations rather than from analysis.

Which documents set the United States schedule?

DocumentIssuer, dateWhat it establishes
National Security Memorandum 10The White House, May 4, 2022The whole-of-government goal of mitigating quantum risk “as is feasible” by 2035. The hedge is in the operative sentence, which is why this is the softest of the 4. bidenwhitehouse.archives.gov
Memorandum M-23-02Office of Management and Budget, November 18, 2022Requires federal civilian agencies to submit a prioritized, algorithm-level cryptographic inventory annually, first due May 2023, and reaches contractor-operated systems. whitehouse.gov
Report on Post-Quantum CryptographyOffice of Management and Budget, July 2024The $7.1 billion in 2024 dollars estimate to migrate priority federal civilian systems 2025 to 2035, excluding national security systems. OMB labels it an initial projection carrying “a high, but expected, level of uncertainty.” bidenwhitehouse.archives.gov
Executive Order 14412The White House, June 22, 2026Federal civilian High Value Assets and high impact systems migrated for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. The scope qualifier is load-bearing: §4(b)(ii) and §4(b)(iii) reach HVAs and high impact systems, not every federal civilian system. whitehouse.gov
CNSA 2.0 and its FAQNational Security Agency, September 2022, FAQ updated December 2024Post-quantum required in all new national security system acquisitions from January 1, 2027, exclusive for software signing and networking gear by 2030, and web, cloud, and operating systems by 2033. Keeps AES-256 in place. nsa.gov · FAQ
NIST IR 8547NIST, initial public draft, November 2024The retirement schedule: 112-bit RSA and elliptic-curve deprecated after 2030, all classical public-key disallowed after 2035. A draft, so the years are NIST’s stated intent. csrc.nist.gov
Quantum-Readiness joint factsheetCISA, NSA, and NIST, August 21, 2023The government’s own statement that attackers “could be targeting data today that would still require protection in the future… using a catch now, break later or harvest now, decrypt later operation.” Also the source of the inventory-first sequence. cisa.gov · factsheet PDF
NSPM-12The White House, June 12, 2026Rewrites cybersecurity governance for national security systems, rescinding NSD-42 (1990) and NSM-8 (2022), and naming CNSSP 15 as the commercial cryptographic standard for those systems. Contains no explicit mention of post-quantum cryptography and sets no migration date. whitehouse.gov
Executive Order 13526The White House, December 29, 2009Classification horizons of 25 years, extendable to 50 and 75 for defined categories. The document that puts today’s classified traffic inside its own exposure window. archives.gov

Which documents are the standards themselves?

DocumentIssuer, dateWhat it establishes
FIPS 203, 204, and 205NIST, August 13, 2024The first 3 finalized post-quantum standards: ML-KEM for key establishment, ML-DSA and SLH-DSA for signatures. This is the date that ends “the standards aren’t ready.” nist.gov
HQC selectionNIST, March 2025A fifth algorithm selected as a backup key-establishment mechanism built on different mathematics from ML-KEM. nist.gov
NISTIR 8105NIST, April 2016The authority for what survives: Grover’s algorithm “does not render cryptographic technologies obsolete,” and “doubling the key size will be sufficient to preserve security.” csrc.nist.gov
SP 800-63BNISTThe federal digital identity guidance behind password practice, including the treatment of stored password verifiers. pages.nist.gov

Which documents set the international schedules?

DocumentIssuer, dateWhat it establishes
Cyber Resilience Act, Reg (EU) 2024/2847European UnionBinds any manufacturer worldwide placing a connected product on the EU market. Reporting obligations from September 11, 2026, full obligations from December 11, 2027. Names no algorithm and sets no post-quantum date. eur-lex.europa.eu · Commission summary, including the 15 million euro or 2.5% turnover penalty ceiling
Coordinated Implementation RoadmapEuropean Commission, June 2025Where the EU’s actual post-quantum dates live: start by end of 2026, high-risk use cases by end of 2030, complete by end of 2035. A recommendation to member states. digital-strategy.ec.europa.eu
Timelines for migration to PQCUK NCSC, March 20, 2025Discovery and plan by 2028, highest-priority migrations by 2031, all systems by 2035. Advisory, and used by UK buyers as a vendor expectation. ncsc.gov.uk
Guidelines for cryptography, Information Security ManualAustralian Signals DirectorateThe most aggressive national schedule: traditional public-key cryptography out by the end of 2030, 5 years ahead of most peers. cyber.gov.au
Implementation of Quantum Safe Ecosystem in IndiaDepartment of Science and Technology, Government of India, February 4, 2026India’s national roadmap. Critical infrastructure: foundations by 2027, high-priority migration by 2028, full adoption by 2029. Enterprises: 2028, 2030, 2033. Mandates vendor CBOM submissions from FY 2027-28 and prohibits new classical-only deployments. dst.gov.in
ITSM.40.001Canadian Centre for Cyber Security, June 23, 2025Departmental plans by April 2026, high-priority systems by end of 2031, remainder by end of 2035. cyber.gc.ca
Technical Guideline TR-02102-1German BSI, version 2026-01Germany’s position: hybrid deployment for long-term confidentiality, and the most conservative classical sizing of the major authorities. bsi.bund.de
ANSSI views on the PQC transitionFrench ANSSIFrance’s position: hybrid-first as a standing rule with no security regression, applied to signatures as well as key establishment, with a certification gate from 2027. cyber.gouv.fr

Which papers underpin the technical claims?

PaperAuthor, dateWhat it establishes
Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum ComputerPeter W. Shor, presented 1994, journal version SIAM J. Computing 26(5), 1997The single paper the entire subject rests on. Never overturned. arxiv.org
How to factor 2048 bit RSA integers in 8 hours using 20 million noisy qubitsCraig Gidney and Martin Ekerå, Quantum 5, 433, 2021The 2019 resource estimate, and the earlier of the 2 numbers in the widely cited collapse. arxiv.org
How to factor 2048 bit RSA integers with less than a million noisy qubitsCraig Gidney, 2025The revised estimate, roughly a 20-fold reduction in 6 years. Both papers together are the strongest available evidence on hardware trajectory. arxiv.org
Quantum Resource Estimates for Computing Elliptic Curve Discrete LogarithmsRoetteler, Naehrig, Svore, and Lauter, ASIACRYPT 2017Why elliptic-curve cryptography falls to a smaller machine than RSA, which runs against most people’s intuition. arxiv.org
Quantum Threat Timeline ReportMichele Mosca and Marco Piani, Global Risk InstituteThe expert survey behind every probability range quoted in this field: 28% to 49% within 10 years, 51% to 70% within 15, from 26 specialists. globalriskinstitute.org
How Quantum Computers FailGil Kalai, June 2011The most credible standing argument that a fault-tolerant quantum computer may never be built. The strongest version of the skeptic case. arxiv.org
Identity inference of genomic data using long-range familial searchesErlich, Shor, Pe’er, and Carmi, Science 362(6415), November 2018The ~60% familial-match finding: a genealogy-database search for a person of European descent in the U.S. already returns a third cousin or closer. science.org
Operationalising Post-Quantum TLSBalaji et al., 2026An analysis of Nginx TLS configurations published to public GitHub repositories, finding 28.9% specifying an RSA key exchange with no forward secrecy. Read the qualifiers before quoting it: the corpus is 8,443 configuration files rather than a scan of live servers, the paper doesn’t state which subset the 28.9% is drawn from, 42.6% of its TLS-enabled contexts use non-production hostnames, and the authors include a commercial post-quantum vendor and the bank that funded the study and hosted its deployment. arxiv.org
Quantum computers and the Bitcoin blockchainBarmes and Bosch, DeloitteThe ~4 million BTC, roughly 25% of supply, sitting in addresses with exposed public keys. deloitte.com

Which documents make up the precedent record?

Every historical parallel in this resource is drawn from an investigation, a court record, or a regulator’s own account rather than from commentary.

DocumentIssuer, dateWhat it establishes
Venona historical releaseNational Security AgencyCables intercepted from 1943 and stored unreadable, read from around 1946 onward, with the project running until 1980. The documented precedent for collecting now and decrypting later. nsa.gov
APT1: Exposing One of China’s Cyber Espionage UnitsMandiant, February 19, 2013Intellectual property taken from at least 141 organizations across 20 industries, hundreds of terabytes, when each intrusion still had to be worked by hand. services.google.com
Black Tulip: the DigiNotar investigationFox-IT, 2012At least 531 fraudulent certificates, and interception affecting roughly 300,000 Iranian users. What a forged trust anchor does in practice, with no quantum computer involved. enisa.europa.eu
Equifax settlement announcementFederal Trade Commission, July 22, 2019147 million people exposed, at least $575 million in settlement. The clearest case of the loss landing on people who were never customers. ftc.gov
Merck & Co. v. ACE American InsuranceN.J. Superior Court, Appellate Division, opinion approved for publication May 1, 2023A war-and-hostile-action exclusion held not to reach a cyberattack on a non-military company. The roughly $1.4 billion claim settled in January 2024. njcourts.gov · settlement report
Travelers v. International Control ServicesC.D. Ill., rescinded by stipulated judgment August 26, 2022A cyber policy voided over a security attestation the insured couldn’t substantiate. insurancejournal.com
Market Bulletin Y5381Lloyd’s of London, August 16, 2022State-backed cyber-attack exclusions required in the Lloyd’s market from March 31, 2023. lloyds.com
23andMe settlement and consumer alertsTexas Attorney General; California Attorney General6.9 million people exposed from 14,000 compromised accounts, a state consumer alert dated March 21, 2025, bankruptcy days later, and the company later sued as “Chrome Holding Co., formerly known as 23andMe.” Texas AG · California AG alert · California AG suit
Y2K spending reportU.S. Senate Special Committee, S. Prt. 106-42The ~8.5 billion was federal. The anchor for every Y2K comparison. govinfo.gov

Which documents are argument rather than record?

Three sources that carry weight in this debate and are analysis, projection, or a record of what people said, rather than findings of fact. Each is worth citing, and each needs its nature stated alongside it.

DocumentAuthor, dateWhat it is, and what to attach to it
”The Coming Quantum National Security Crisis”Anne Neuberger, Foreign Affairs, June 2026The highest-profile recent policy essay on the subject, by a former U.S. Deputy National Security Adviser (2021 to 2025). It argues China and Russia are already collecting encrypted data to decrypt later. That harvesting claim is made on the article’s own account and is uncorroborated, which is how it was characterized when discussed at Quantum USA 2026. Cite it as a named argument by a former senior official rather than as an established finding. foreignaffairs.com
”Quantum Computing On Track to Create Up to $850 Billion of Economic Value By 2040”Boston Consulting Group, July 18, 2024The source of the 850 billion economic-value figure, sustaining a projected 170 billion market for hardware and software providers. A consultancy projection to 2040, so attribute it and label it a forecast. bcg.com
The Report: Quantum USA 2026Forum Global, Washington D.C., June 18, 2026A record of what was said at a named conference, with named attribution and commercial interests carried inline. Useful for attributable positions from NIST, industry, and vendors. Its publisher states plainly that third-party figures, projections, intelligence-community characterizations, and vendor claims belong to the sources who advanced them and are not findings. Treat every number inside it as a claim by its named speaker.

The pattern across all 3: they’re citable and they’re arguments. A projection restated as a measurement, or a vendor’s Q-Day estimate restated as a consensus timeline, is the most common way an otherwise careful piece goes wrong. See What gets reported wrong.

Which documents cover deployment and market reality?

DocumentIssuerWhat it establishes
PQXDH specificationSignal, 2023The first major consumer deployment of post-quantum protection. signal.org
iMessage with PQ3Apple, February 2024Post-quantum protection deployed to iMessage. security.apple.com
A new path for Kyber on the webGoogle, September 2024Post-quantum key exchange in Chrome and Edge. security.googleblog.com
Firefox 135 release notesMozilla, February 2025Post-quantum key exchange in Firefox. mozilla.org
Post-quantum adoption dashboardCloudflare RadarLive measurement of how much internet traffic uses post-quantum key exchange. A moving figure, so cite the dashboard rather than pinning a percentage. radar.cloudflare.com
Facts and Figures 2025International Telecommunication Union6 billion people online, about 74% of the world’s population. itu.int
Report on the Cybersecurity Insurance MarketNAIC, 2025 report on 2024 dataU.S. cyber direct written premium of roughly $9.14 billion in 2024, down about 7%, its first annual contraction. naic.org
Minimum Elements For a Software Bill of MaterialsNTIA, July 12, 2021The U.S. definition of a software bill of materials, the mechanism that makes vendor-supplied cryptography checkable. ntia.gov
Shared Responsibility ModelAWSWhere the cloud provider’s responsibility ends and the customer’s begins, including data encryption and key management. aws.amazon.com
Cybersecurity in Medical DevicesU.S. Food and Drug AdministrationPremarket cybersecurity expectations for medical devices. fda.gov
Genomic Data PrivacyNational Human Genome Research InstituteThe federal position on genomic privacy. genome.gov
Retention rules45 CFR § 164.316; 17 CFR § 240.17a-4The health and securities record-retention periods that set data confidentiality lifetimes by law. 45 CFR 164.316 · 17 CFR 240.17a-4
Finding the Right LoanFreddie MacNearly 90% of U.S. homebuyers hold a 30-year mortgage, which is one document set that stays live for 3 decades. myhome.freddiemac.com

Questions people ask

Which single document should I read first? The CISA, NSA, and NIST joint factsheet from August 2023. It’s short, it’s signed by 3 agencies, and it contains the government’s own statement of the harvesting concern.

Which numbers here are drafts or estimates rather than settled facts? Three: the NIST IR 8547 retirement years sit in an initial public draft, the OMB $7.1 billion carries OMB’s own uncertainty language, and the Global Risk Institute probabilities are an expert survey rather than a measurement.

Which figures change over time? Post-quantum adoption across internet traffic moves continuously, so the Cloudflare dashboard should be cited rather than a pinned percentage. Hardware qubit records also move, which is why the resource estimates matter more than any machine’s specification.

Are any of these behind a paywall? The Science paper on familial matching is the main one. Every government document, court opinion, standard, and arXiv paper listed here is freely accessible.

Why does the 1994 date appear alongside a 1997 citation? Shor presented the algorithm in 1994, and the peer-reviewed journal version appeared in SIAM Journal on Computing in 1997. Both dates are correct for different things.

Is anything important missing from this list? Two categories, deliberately. Vendor white papers and market-forecast reports are excluded, because commercial interest sits behind the numbers. And no classified or non-public material is cited anywhere in this resource.

How current is this? Each page in this resource carries its own last-verified date in the byline, and the schedules move as drafts finalize.

Where to go next


Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.