up:: For Policymakers MOC

What about the rest of the world?

Almost every comparison of national post-quantum timelines lists the same 6 jurisdictions: the United States, the European Union, the United Kingdom, Germany, France, Canada, and Australia. That’s a list of wealthy Western states, and it leaves out most of the world’s internet users.

The most striking omission is India, which published a national roadmap in February 2026 setting a full post-quantum adoption target of 2029 for critical infrastructure. That’s earlier than any Western timeline in the standard comparison.

The rest of the accounting is less encouraging. Most countries have published nothing, and the gap between having a roadmap and having no roadmap is now larger than the gaps between the roadmaps.

The short version:

  • India’s critical-infrastructure target is 2029, ahead of the U.S., the EU, the UK, and Canada.
  • India mandates vendor component disclosures, which is more prescriptive than anything the U.S. asks of its private sector.
  • Japan runs a long-standing standards body whose evaluation work predates most national roadmaps.
  • Most of the world has published nothing, and that’s the finding rather than an omission from this page.
  • The standard 6-jurisdiction comparison is a wealth map, and treating it as the global picture is an error.
  • A country without a roadmap is a routing path everyone else depends on.

What is India doing?

More, and earlier, than most coverage reflects.

India’s Department of Science and Technology published “Implementation of Quantum Safe Ecosystem in India,” a task-force report dated February 4, 2026, produced under the National Quantum Mission. It sets phased milestones with deliberately accelerated timelines for critical infrastructure, treating defense, power, and telecom as urgent adopters.

MilestoneCritical infrastructureEnterprises
1. Build foundationsby 2027by 2028
2. Migrate high-priority systemsby 2028by 2030
3. Full adoptionby 2029by 2033

Source: Department of Science and Technology, Government of India, “Implementation of Quantum Safe Ecosystem in India,” report of the task force, February 4, 2026, dst.gov.in.

Three provisions in it go further than most Western instruments:

  1. Vendor component disclosure is mandated. Milestone 1 requires organizations to “mandate CBOM submissions from vendors starting FY 2027-28.” A cryptographic bill of materials is the artifact that makes a supplier’s cryptography checkable, and no U.S. instrument requires private organizations to obtain one.
  2. New classical-only deployment is prohibited. Milestone 2 requires enforcing “no new classical-only deployments,” which addresses the problem of continuing to install equipment that makes the exposure permanent.
  3. Procurement carries the requirement. PQC readiness enters procurement at Milestone 1, which is the lever every analysis identifies as the fastest and cheapest, and which many jurisdictions have discussed rather than adopted.

The report also proposes a national testing and certification program, and takes a balanced position on quantum key distribution as a targeted complement to post-quantum cryptography rather than a substitute for it.

Why this matters beyond India. A 2029 critical-infrastructure target from a country with over a billion people, a large technology services industry, and deep supply-chain integration with Western enterprises is a date that reaches other markets through vendors. Indian technology suppliers migrating on that schedule will carry it into their customers’ estates.

What is Japan doing?

Japan runs one of the longest-standing cryptographic evaluation bodies in the world, CRYPTREC, which maintains the list of ciphers recommended for Japanese government procurement and has been evaluating cryptographic algorithms since long before post-quantum migration became a policy topic.

Its role is closer to Germany’s BSI than to a migration mandate: it evaluates and lists rather than setting a whole-of-government migration deadline. The practical effect is the same pointer mechanism that appears everywhere else, where obligations reference an approved list and the list changes underneath them.

Full treatment at CRYPTREC (Japan).

How much of the world has published nothing?

Most of it, and this is the honest finding.

The jurisdictions with published, dated national roadmaps number under a dozen. Every one of them is a wealthy state or bloc. There is no published national post-quantum migration timeline for the large majority of countries, including most of Africa, most of Latin America, most of South and Southeast Asia outside India, and most of the Middle East.

That absence is a fact about published policy rather than about competence or awareness. Producing a national cryptographic roadmap requires a standards body, a supervisory apparatus, and specialist staff, which is precisely the capacity a resource-constrained state lacks.

Why it reaches everyone. International traffic crosses networks in countries with no migration program, and a message is protected by the weakest configuration on its path. A country that cannot migrate is a routing path that stays vulnerable for every country that can. See What happens to countries that cannot afford this.

Why is the standard comparison misleading?

Because it silently converts a wealth map into a readiness map.

The recurring 6-jurisdiction table appears in nearly every analysis, including elsewhere in this Guide, and it’s accurate about the jurisdictions it lists. What it invites is an unstated inference: that those are the countries that matter, or that the rest are behind.

Three corrections worth holding:

  1. Absence of a published roadmap is not absence of activity. It’s absence of a published roadmap.
  2. The comparison omits the largest democracy on earth, which has a roadmap more aggressive on critical infrastructure than most in the table.
  3. Publishing a timeline and meeting it are different things. Every jurisdiction in the standard table is measured on what it published, not on what it has completed.

Questions people ask

Is India genuinely ahead? On the published critical-infrastructure target, yes: 2029 against 2030 for U.S. federal civilian key establishment and 2035 for the EU, UK, and Canada. Whether it’s met is a separate question, and the same caveat applies to every jurisdiction.

Why is India usually left out of comparisons? Its roadmap is recent, published in February 2026, and most comparison tables predate it or were built from Western sources.

Does China belong in this page? China is covered separately, because it’s running its own standards competition rather than adopting the NIST algorithms, which makes it a different kind of case. See What is China doing.

What about Brazil, Nigeria, Indonesia, or the Gulf states? No published national post-quantum migration timeline that this resource can cite. If one exists that isn’t reflected here, that’s a correction worth sending. See Corrections and verification.

Does a country need its own roadmap? Not necessarily. The algorithms are free public standards, and a country can adopt them without publishing a national timeline. What a roadmap adds is sequencing, procurement leverage, and a date that regulated entities can be held to.

Is the divergence between roadmaps a problem? Yes, and it’s covered at Is anyone coordinating this internationally. The larger problem is the divergence between having one and having none.

Where to go next


Last verified 2026-07-31 · Maintained by Addie LaMarr, LaMarr Labs.