up:: For Press
What changed recently
This subject moves in specific, dateable steps rather than continuously, which makes staleness easy to check.
Three things below have changed the accurate version of common sentences within the last 2 years: the standards were finalized, the hardware estimate dropped by a factor of about 20, and the U.S. federal deadlines became specific dates rather than a goal year.
Anything written before August 2024 that says the standards aren’t ready is now wrong.
The short version:
- August 13, 2024 is the pivot. Before it, “waiting for standards” was accurate. After it, that sentence is checkably wrong.
- The hardware estimate moved by roughly 20 times between 2019 and 2025, which is the most significant technical change in the field.
- U.S. federal deadlines became dates in June 2026, replacing a hedged 2035 goal with December 31, 2030 and December 31, 2031 for High Value Assets and high impact systems.
- Two new U.S. instruments landed in June 2026, and only 1 of them is about post-quantum cryptography.
- China opened its own standards call in February 2025, which forked a previously unified global transition.
- The first national-scope deployment measurement landed in August 2026, covering 4,665 UK organizations across web and email, and it found the certificate half of the transition still at 0.
- Five things are expected to change next, and each would date a piece.
What changed in 2026?
| When | What happened | What it changes |
|---|---|---|
| August 15, 2026 | A claimed polynomial-time quantum algorithm for the Dihedral Coset Problem, posted August 3 and connected through an existing reduction to lattice problems including LWE, is met with a formal no-go. Three researchers at MIT, Google and Stanford prove the algorithm cannot extract the secret bit it depends on, stating that they show “directly that the algorithm cannot possibly work” rather than only faulting its analysis | A claim that would have undercut the mathematics beneath ML-KEM and ML-DSA, examined in public in 12 days. Two gaps were named while it stood: it addressed plain LWE where the deployed standards rest on Module-LWE, and no end-to-end composition was ever demonstrated. The author’s own listing records a corrected error in the first draft’s Lemma 3. Both papers are still posted and the author says he is evaluating the no-go, so the accurate sentence is that a formal refutation currently stands rather than that the matter is settled |
| August 3, 2026 | Newcastle University researchers publish a scan of 4,665 UK organizations, run on June 30, finding 44.0% of reachable web endpoints negotiating post-quantum key exchange, 6.4% of email endpoints, and 0 post-quantum certificates anywhere in the sample | The first national-scope measurement anchor, sitting beside the global figures. It also establishes that which hosting provider an organization uses predicts its posture far better than which industry it is in. A preprint, UK-only, and a single-day snapshot |
| July 29, 2026 | HAWK, the only lattice-based candidate in NIST’s additional-signatures competition, is withdrawn by its authors 1 day after an AI-assisted attack halved its effective key size | The competition’s 9 candidates become 8, with no lattice option left among them. Coverage framing this as a break of post-quantum encryption is wrong: HAWK was never standardized or deployed. See Did AI just break post-quantum encryption |
| June 22, 2026 | Executive Order 14412 sets U.S. federal civilian deadlines for High Value Assets and high impact systems: key establishment by December 31, 2030, digital signatures by December 31, 2031 | The operative federal civilian dates. Quoting 2035 as the federal deadline is now imprecise |
| June 12, 2026 | NSPM-12 rewrites cybersecurity governance for national security systems, rescinding a 1990 directive and a 2022 memorandum | Governance, not migration. It contains no explicit mention of post-quantum cryptography and sets no date |
| June 2026 | Anne Neuberger publishes “The Coming Quantum National Security Crisis” in Foreign Affairs | The highest-profile recent policy argument. Its harvesting claim is on its own account and uncorroborated |
| June 18, 2026 | Quantum USA 2026 held in Washington, with NIST, federal, and vendor positions on the record | A citable source of attributed positions, with vendor claims labeled as such |
| 2026 | An analysis of Nginx TLS configurations published on GitHub finds 28.9% specifying an RSA key exchange with no forward secrecy | Evidence that the pattern persists in configurations people write, rather than a census of live servers |
Source: Simon, “A Polynomial-Time Quantum Algorithm for the Dihedral Coset Problem,” eprint.iacr.org/2026/1591; Gupte, Ragavan, and Zhandry, “The ePrint:2026/1591 Quantum Algorithm Does Not Solve DCP,” 15 August 2026, eprint.iacr.org/2026/1693; Wen and Zheng, “Module Learning With Errors and Structured Extrapolated Dihedral Cosets,” CRYPTO 2026, eprint.iacr.org/2026/155; NIST, “Round 3 Additional Signatures,” updated 29 July 2026, csrc.nist.gov; Anthropic, “Discovering cryptographic weaknesses,” 28 July 2026, anthropic.com; Executive Order 14412, whitehouse.gov; NSPM-12, whitehouse.gov; Neuberger, foreignaffairs.com; Balaji et al., arxiv.org; K. Loizou and E. Ghadafi, “Measuring Post-Quantum TLS Deployment Across UK Internet Sectors,” School of Computing, Newcastle University, arXiv:2608.02147, submitted August 3, 2026, arxiv.org/abs/2608.02147, a preprint rather than peer-reviewed work.
What changed in 2025?
| When | What happened | What it changes |
|---|---|---|
| 2025 | Gidney revises the resource estimate for breaking RSA-2048 from 20 million noisy qubits to under 1 million | The most important technical change in the field. Any piece citing only the 2019 figure is a generation behind |
| June 2025 | The EU publishes its Coordinated Implementation Roadmap: start by end of 2026, high-risk by end of 2030, complete by end of 2035 | Where the EU’s actual post-quantum dates live, separate from the Cyber Resilience Act |
| June 23, 2025 | Canada publishes ITSM.40.001: plans by April 2026, high-priority by end of 2031, remainder by end of 2035 | Adds Canada to the list of jurisdictions with dated schedules |
| June 6, 2025 | Executive Order 14306 requires federal agencies to support TLS 1.3 by January 2, 2030 | A transport-readiness milestone rather than a completed migration |
| March 2025 | NIST selects HQC as a fifth algorithm, built on different mathematics as a backup | ”NIST standardized 3 algorithms” needs updating to reflect the fifth selection |
| March 20, 2025 | The UK NCSC publishes timelines: discovery by 2028, priority migrations by 2031, complete by 2035 | The UK’s dates, advisory but used commercially |
| March 2025 | A state consumer alert on 23andMe is followed within days by a Chapter 11 filing | The clearest worked example of genetic data outliving the company holding it |
| February 2025 | Firefox ships post-quantum key exchange | Completes the major-browser rollout |
| February 2025 | China’s Institute of Commercial Cryptography Standards opens a call for quantum-resistant algorithms | Forks a previously unified global standards picture |
Source: C. Gidney, 2025, arxiv.org; European Commission roadmap, digital-strategy.ec.europa.eu; CCCS ITSM.40.001, cyber.gc.ca; Executive Order 14306, whitehouse.gov; NIST HQC selection, nist.gov; NCSC, ncsc.gov.uk; California Attorney General, oag.ca.gov; Mozilla, mozilla.org; ICCS, niccs.org.cn.
What changed in 2024, and why is August the pivot?
| When | What happened | What it changes |
|---|---|---|
| November 2024 | Chrome and Edge enable post-quantum key exchange by default; NIST publishes IR 8547 as an initial public draft | Real traffic starts carrying it. The retirement schedule appears, in draft |
| August 13, 2024 | NIST finalizes the first 3 standards: ML-KEM, ML-DSA, and SLH-DSA | The pivot. “We’re waiting for the standards” stops being true on this date |
| July 2024 | OMB publishes its post-quantum report with the $7.1 billion projection | The only large primary-source cost anchor in the field |
| February 2024 | Apple deploys PQ3 in iMessage | Consumer deployment ahead of the standards being final |
Source: Google Security Blog, security.googleblog.com; NIST IR 8547, csrc.nist.gov; NIST, August 13, 2024, nist.gov; OMB, OMB report; Apple, security.apple.com.
The reason August 2024 matters more than any other date is that it moved the whole subject from a research question to an execution question. Before it, an organization saying it was waiting for the standards was describing a real constraint. After it, that same sentence describes a choice.
What’s expected to change next?
Five things, each of which would date a piece written today.
- NIST IR 8547 going final. The 2030 and 2035 retirement years currently sit in an initial public draft. Whether the final publication keeps those years is the single most consequential open item in the U.S. schedule.
- FIPS 206 publishing. The compact signature standard, derived from FALCON, is selected and in development rather than published. Its arrival completes the signature set.
- China’s standards arriving. Reported as roughly 3 years out from 2026. Their publication would make the fork concrete rather than prospective.
- The first harmonized European standard with post-quantum content. That’s the mechanism by which the EU’s “state of the art” requirement quietly becomes a post-quantum requirement for products on the EU market.
- The first cryptographic question on a cyber insurance application. No published standard market clause yet names cryptographic obsolescence. When the encryption question decomposes into which algorithms, underwriting has arrived.
How do you check whether something you’re reading is stale?
Four tests, in order of how quickly they settle it.
- Does it say the standards aren’t final? Written before, or not updated since, August 2024.
- Does it cite 20 million qubits without the 2025 revision? Missing the most significant technical change in the field.
- Does it call 2035 the deadline? Predates the June 2026 executive order, or is quoting the hedged policy goal rather than the binding dates.
- Does it use the names Kyber, Dilithium, or FALCON? Those are the competition names, replaced when the standards were finalized. Useful for dating a piece rather than for judging it, since some technical writing still uses them deliberately.
Questions people ask
How current is this resource? Every page carries its own last-verified date in the byline, and this page is the summary view of what moved.
What’s the single most out-of-date claim still in circulation? That the industry is waiting for standards. They were finalized on August 13, 2024.
Has anything happened that would change the core story? No. Nothing has broken encryption, no machine capable of it exists, and the collection concern is unchanged. What’s moved is the standards, the deadlines, and the resource estimates.
How much has actually been deployed? Enough on the encryption half to be measurable, and nothing yet on the identity half. The August 2026 UK scan found 44.0% of reachable web endpoints negotiating post-quantum key exchange and 6.4% of email endpoints, with 0 post-quantum certificates across all 7,921 certificates it collected. Most of that web coverage came from a handful of large hosting providers turning the feature on rather than from organizations configuring it themselves. Figures for global traffic move month to month and belong to a live check at the moment of writing.
Which industries are furthest ahead? On the web, the same UK scan put government highest at 56.0% of its reachable endpoints (255 of 455) and universities lowest at 26.4% (39 of 148), with retail, technology, and telecommunications in between. On email it published counts without the per-industry denominators needed to turn them into percentages, so technology (72 endpoints), retail (57), and telecommunications (30) led on raw count and no per-industry email rate exists. Treat the whole ranking as a description of hosting choices: a model that knew only an organization’s industry predicted its web posture at barely better than a coin flip, and predicted its email posture worse than guessing. Cloud and Browser PQC Status carries the full table.
Is the qubit estimate likely to fall further? Possibly. The 2019 to 2025 movement came from better methods rather than better hardware, and methods keep improving. The trajectory is the story rather than any single figure.
Should I re-check dates before publishing? The draft-status ones, yes: the NIST retirement years and anything about FIPS 206 or China’s standards. The finalized standards and the executive orders are settled.
What changed that most reporters have missed? That China is building its own standards rather than adopting NIST’s. See What is China doing.
Where to go next
- A timeline of the quantum transition carries the full dated record back to 1994.
- Every figure and where it comes from carries each number with its qualifier.
- The primary documents behind every claim indexes the documents themselves.
- What gets reported wrong covers the errors that outlive the facts.
- For Press returns to the index.
Last verified 2026-08-10 · Maintained by Addie LaMarr, LaMarr Labs.