Post-quantum migration observatory · dataset as of 2026-09-06

The world is migrating to post-quantum cryptography.

CRQC tracks the standards, government deadlines, industries and technology dependencies shaping the global transition — with the evidence, document status and review date attached to every claim.

The meaningful quantum-risk clock is already running: migration deadlines, data lifetimes, procurement cycles and supply-chain dependencies all arrive before a cryptographically relevant quantum computer does.

Global readiness

Where each jurisdiction actually stands

Compare published policy, technical standards and execution evidence without compressing unlike signals into a single ranking.

Lens
Americas
Europe
Asia-Pacific
BandsObservedPlanningMobilizingExecutingBroad transitionEvidence insufficient

Canada

Canadian Centre for Cyber Security (CSE) · Treasury Board Secretariat
Executing

Canada pairs a technical roadmap with a compliance instrument, so every cryptographic dependency has to be located and reported, not simply acknowledged.

Published milestones
  1. 2024-07-10CFDIR quantum-readiness best practices v04
  2. 2025-06ITSM.40.001 published
  3. 2025-10-09SPIN takes effect
Open full record →
Quantum technology

Measure the capability gap, not the hype

Follow physical scale, logical error correction and the published resources needed to threaten RSA, ECC and AES—without turning unlike qubit counts into a Q-day forecast.

Current statusNo cryptographic break
Key distinctionPhysical ≠ logical
CoverageRSA · ECC · AES
Industry impact

Where does quantum risk hit your industry?

Exposure, dependency classes and the actual published signal — with explicit cautions where no mandate exists.

Dependency graph

Why migration is a supply-chain problem

Your migration date is set by whoever is slowest on the path between a NIST algorithm and your workload.

Standards & authoritiesImplementationsTrust infrastructurePlatformsIndustry workflows
From standard to action

What does a standard actually require of you?

Each standard record separates its true document status from what it changes in practice for TLS, PKI, HSMs and devices.

Methodology

Every material claim is sourced, classified and last-reviewed.

Readiness measures public evidence of preparation. Quantum capability is tracked separately with source-specific metrics and is never treated as a promise that a well-prepared jurisdiction is safe.

How CRQC verifies evidence