up:: For Policymakers MOC
What is China doing?
Running its own competition, on its own timeline, to produce cryptographic standards it controls.
That’s the single most consequential fact about China in this transition, and it’s the one most often missed in coverage that treats China only as a threat actor. Most of the world is converging on the algorithms NIST standardized. China is building a parallel set.
The result is a genuine fork in what has otherwise been a remarkably unified global transition, and it lands on every organization that operates across both markets.
The short version:
- China is running its own standards competition rather than adopting the NIST algorithms, through the Institute of Commercial Cryptography Standards.
- This continues an existing pattern. China already maintains its own national commercial cryptography algorithms rather than using the international defaults.
- Its clearest lead is in quantum communications, a different technology from post-quantum cryptography, and one an American think-tank fellow has said the U.S. deliberately ceded.
- The program is notoriously opaque. Chinese labs rarely open hardware for external benchmarking, so the public record is a floor rather than a measure, and that cuts in both directions.
- The claims about Chinese harvesting are widely repeated and unproven, and the distinction between what’s documented and what’s asserted is the thing to get right.
- What is documented is industrial-scale intellectual property theft from 141 organizations across 20 industries in a single campaign, when every intrusion still had to be worked by hand.
- A split standards world is the practical consequence, and it reaches any company selling into both markets.
- China’s own timeline is reported as roughly 3 years, which would place its standards years behind the August 2024 NIST publication.
Is China adopting the NIST post-quantum standards?
No. China’s Institute of Commercial Cryptography Standards, the body responsible for commercial cryptography standardization, has announced a program to standardize next-generation commercial cryptographic algorithms in response to the threat of quantum computing.
Source: Institute of Commercial Cryptography Standards, niccs.org.cn.
Reporting on that announcement describes a global call for candidate algorithms issued in February 2025, covering public-key encryption and key exchange, digital signatures, and quantum-resistant hash functions and block ciphers, with draft guidelines for hash-function proposals opened for public comment. The call invites submissions from researchers worldwide while producing standards China controls.
Source: reporting on the ICCS announcement, The Quantum Insider, February 18, 2025, thequantuminsider.com. Details of the call beyond the ICCS announcement itself come from this reporting rather than from a primary Chinese-language standards document.
On timing, a Tsinghua University professor, Wang Xiaoyun, has been reported as saying China will likely have national post-quantum standards within about 3 years, and naming finance and energy as the priority sectors for migration given the sensitivity of the data.
Source: reporting on remarks by Wang Xiaoyun, March 2026, thequantuminsider.com. Attributed remarks reported secondhand rather than a published Chinese government timeline.
What has China demonstrably built?
The strongest part of the public record is quantum communications, which is a different technology from the post-quantum cryptography most of this Guide covers, and it’s the field where China’s lead is least disputed.
| What | Reported detail |
|---|---|
| Micius satellite | Launched August 2016 by a Chinese Academy of Sciences team led by Pan Jian-Wei, orbiting at roughly 500 km, built for satellite-based quantum key distribution |
| Beijing to Shanghai backbone | A fiber quantum-communication trunk line of about 2,000 km running through Jinan and Hefei, using 32 trusted relays, reported as tested with government, banking, securities, and insurance users |
| Integrated space-to-ground network | Micius combined with the trunk line into a reported integrated network reaching about 4,600 km |
| Intercontinental key exchange | A joint China-Austria team reported creating a shared secret key between ground stations separated by up to 7,600 km, using Micius as a trusted relay |
| Long-distance teleportation | Quantum states reported teleported between ground stations 1,200 km apart via Micius in 2022 |
Source: reporting on the integrated space-to-ground network, phys.org; intercontinental quantum communication via Micius, phys.org; assessment of Chinese quantum capability, ITIF, September 9, 2024, itif.org; U.S.-China Economic and Security Review Commission, “Vying for Quantum Supremacy: U.S.-China Competition in Quantum Technologies,” November 2025, uscc.gov.
On quantum computing specifically, the University of Science and Technology of China reported a photonic quantum-advantage result with Jiuzhang in 2020, and a superconducting machine, Zuchongzhi 3.0, reported as the highest publicly reported benchmark for a system of that type.
Worth holding precisely: none of this breaks encryption. Quantum communications distributes keys over dedicated physical links and addresses none of the signature and authentication half, and quantum-advantage benchmarks are contrived tasks rather than steps toward factoring. A lead in quantum communications is a real lead in a real field, and it isn’t a lead toward Q-Day.
One line from Quantum USA 2026 is worth carrying because it’s an attributable American assessment rather than a Chinese claim. A fellow in the technology and national security program at CNAS set out that the United States had to a degree deliberately ceded quantum communications, a field it saw less strategic value in, while China moved quantum to the top of its industries of the future in its latest 5-year plan.
Source: Forum Global, “The Report: Quantum USA 2026,” Washington D.C., June 18, 2026, recording remarks by Constanza M. Vidal Bustamante of CNAS. Statements are attributed to the speakers who made them.
How much of China’s program is actually visible?
Less than for any comparable Western program, and this is the caveat that should attach to every China claim in this subject, in both directions.
Chinese laboratories rarely open their hardware platforms for external benchmarking or reproducibility testing, and methodologies are frequently described with less granularity than a U.S. or European group would publish. That isn’t evidence the science is invalid, and much of it has held up where it could be checked independently. It does mean the ecosystem is substantially closed, and that state-directed work sits outside the publishing conventions the rest of the field runs on.
Source: assessment of transparency and reproducibility in Chinese quantum results, medium.com; ITIF, September 9, 2024, itif.org.
The consequence for anyone writing about this is a single discipline: treat the public record as a floor rather than a measure. That cuts in both directions, and getting only one of them is how coverage goes wrong.
| The tempting conclusion | Why the opacity defeats it |
|---|---|
| ”China is behind, because it hasn’t published post-quantum standards yet” | Absence of a published standard is a fact about the public record. A state program’s internal progress isn’t something the published record measures |
| ”China has secretly broken encryption already” | Equally unfounded. No public evidence supports it, and opacity is not evidence of capability any more than it’s evidence of its absence |
| ”Chinese benchmark results prove they lead” | Where results can’t be independently reproduced or externally benchmarked, they’re claims rather than confirmations, and the strongest of them have been in contrived tasks |
| ”China is harvesting encrypted data” | Asserted and uncorroborated, as below. Collection leaves no trace regardless of who does it |
The honest formulation is that China publishes selectively about a program that is substantially state-directed, so the visible record understates activity by an unknown amount. An unknown amount is not a large amount and it is not a small one, and a piece that quietly converts opacity into either conclusion has added a claim its sources don’t carry.
Why would a country build its own algorithms?
Because cryptographic standards are infrastructure, and a country that uses somebody else’s standards depends on somebody else’s process.
China has done this before. It maintains its own national commercial cryptographic algorithms and mandates them in domestic contexts where other countries would use the international defaults. A separate post-quantum track continues that policy rather than departing from it.
The reasoning is symmetrical to the reasoning Western authorities give for scrutinizing foreign technology. A standard is trustworthy because you can audit the process that produced it, and a government that can’t audit a foreign standardization process has a defensible reason to run its own.
Two things follow that matter more than the geopolitics:
- The mathematics is public either way. Post-quantum algorithms are published and attacked openly by cryptographers everywhere, so a Chinese standard built on lattice or hash constructions is checkable by the same global community.
- The divergence is in which algorithms get mandated where, rather than in whether the underlying science is shared.
What does the evidence actually show about Chinese harvesting?
This is where coverage most often overreaches, and where getting it right is the difference between a piece that survives scrutiny and one that doesn’t.
| The claim | What supports it |
|---|---|
| ”China and Russia are harvesting encrypted data now” | Asserted in a June 2026 Foreign Affairs essay by a former U.S. Deputy National Security Adviser. The claim is made on the article’s own account and is uncorroborated, which is how it was characterized when discussed at Quantum USA 2026 |
| ”Adversaries are already harvesting U.S. data” | Attributed at the same conference to unnamed and uncorroborated U.S. intelligence-agency reporting |
| ”Somebody is collecting encrypted traffic” | Three U.S. agencies stated jointly in August 2023 that attackers “could be targeting data today that would still require protection in the future.” Note the conditional. It names the concern without naming a party |
| Industrial-scale theft of intellectual property by a Chinese unit | Documented. At least 141 organizations across 20 industries, hundreds of terabytes, in one campaign, with forensic attribution published in 2013 |
Source: Anne Neuberger, “The Coming Quantum National Security Crisis,” Foreign Affairs, June 2026, foreignaffairs.com; CISA, NSA, and NIST, August 21, 2023, cisa.gov; Mandiant, “APT1: Exposing One of China’s Cyber Espionage Units,” February 19, 2013, services.google.com.
The honest formulation is that collection of encrypted traffic leaves no trace, so no party can be named and proven for any specific dataset. What can be said is that a documented appetite for industrial-scale data theft exists, that the labor cost which capped that campaign at 141 organizations doesn’t apply to passive collection, and that storage costs a fraction of a cent per gigabyte per month.
That formulation is stronger than the assertion, because nobody can knock it down.
What does a split standards world mean in practice?
Four consequences, and the first reaches ordinary companies fastest.
- Products sold into both markets may need both algorithm sets. A device or platform serving Chinese and Western customers could face 2 different mandated cryptographic suites, which is an engineering and certification cost rather than a policy abstraction.
- Crypto-agility stops being optional. The ability to swap algorithms by configuration rather than by re-engineering is what lets 1 codebase serve divergent mandates. See What can I not fix myself.
- Interoperability becomes a design question. Systems that need to communicate across the divide need a deliberately chosen common configuration, the same problem allied governments face among themselves. See Is anyone coordinating this internationally.
- The timing gap creates an asymmetry. If Chinese standards arrive years after the August 2024 NIST publication, Chinese domestic migration starts later, while Western vendors selling into China face a moving target.
Questions people ask
Is China ahead or behind on post-quantum cryptography? On published standards, behind: NIST finalized in August 2024 and China’s own timeline is reported as roughly 3 years from 2026. On quantum computing research and state investment, it’s a serious competitor. Those are different races and conflating them produces bad coverage.
Can I say China is harvesting encrypted data? You can say it’s been asserted, by whom, and that it’s uncorroborated. Stating it as established fact goes beyond what any public evidence supports.
Is a Chinese cryptographic standard less trustworthy? The mathematics is public and attackable by cryptographers everywhere, so the question is about the standardization process rather than the algorithms. That’s the same question other countries ask about standards they didn’t produce.
Does this affect my company if we don’t operate in China? Indirectly, through suppliers. A component or platform in your supply chain that also serves the Chinese market inherits the divergence.
Why isn’t China in most comparisons of national timelines? Because those comparisons list jurisdictions that have published dated migration schedules, and China’s standards program hasn’t produced one. Its absence is a fact about the published record rather than an absence of activity.
What about Russia? Russia also maintains its own national cryptographic standards. The public documentation of a Russian post-quantum program is thinner than for China, and this Guide doesn’t carry claims it can’t source.
What’s the single most accurate framing? That the world is converging on shared post-quantum mathematics while diverging on which algorithms get mandated where, and China is the largest single instance of that divergence.
Where to go next
- What are other countries doing compares the jurisdictions that have published dated schedules.
- Is anyone coordinating this internationally covers the fork and what it costs.
- What is not legislated yet covers the gaps a split world widens.
- Every figure and where it comes from carries the evidence tiering for every claim above.
- For Policymakers MOC is the full legislative route.
Go deeper into the technical detail
The technical treatment of attribution is Store-Now-Decrypt-Later Actor Landscape, and the algorithm landscape is The New Standards MOC.
These open the Post-Quantum Field Guide, a separate site written for security professionals.
Last verified 2026-07-30 · Maintained by Addie LaMarr, LaMarr Labs.