The world is migrating to post-quantum cryptography.
CRQC tracks the standards, government deadlines, industries and technology dependencies shaping the global transition — with the evidence, document status and review date attached to every claim.
The meaningful quantum-risk clock is already running: migration deadlines, data lifetimes, procurement cycles and supply-chain dependencies all arrive before a cryptographically relevant quantum computer does.
Where each jurisdiction actually stands
Compare published policy, technical standards and execution evidence without compressing unlike signals into a single ranking.
Canada
Canadian Centre for Cyber Security (CSE) · Treasury Board SecretariatCanada pairs a technical roadmap with a compliance instrument, so every cryptographic dependency has to be located and reported, not simply acknowledged.
- 2024-07-10CFDIR quantum-readiness best practices v04
- 2025-06ITSM.40.001 published
- 2025-10-09SPIN takes effect
Published deadlines, not Q-day guesses
The next policy milestones already shape inventory, procurement and replacement schedules.
These are published policy milestones, not predictions of when a quantum computer will break encryption.
What changed most recently
- IETFRFC 10024 — hybrid ML-KEM TLS 1.3 A1Proposed StandardAug 2026
- GoogleCloud PQC readiness roadmap CVendor targetAug 2026
- Singapore CSAQuantum Readiness Index A2GuidanceJul 2026
- HKMABanking readiness index — 2.3/10 A3AssessmentJul 2026
- NISTCSWP 39 — crypto agility A2FinalJun 2026
- United StatesExecutive Order 14412 A1EffectiveJun 2026
- JapanCRYPTREC e-Government list update A1FinalMar 2026
- FranceANSSI PQC protocol guidance A2GuidanceFeb 2026
Recent security migration updates
What changed in regulation, standards, vendor readiness and quantum capability — each with sources and a full timeline of events.
Measure the capability gap, not the hype
Follow physical scale, logical error correction and the published resources needed to threaten RSA, ECC and AES—without turning unlike qubit counts into a Q-day forecast.
Where does quantum risk hit your industry?
Exposure, dependency classes and the actual published signal — with explicit cautions where no mandate exists.
Why migration is a supply-chain problem
Your migration date is set by whoever is slowest on the path between a NIST algorithm and your workload.
What does a standard actually require of you?
Each standard record separates its true document status from what it changes in practice for TLS, PKI, HSMs and devices.
ML-KEM — Module-Lattice Key Encapsulation
The core post-quantum key-establishment primitive.
FIPS 204ML-DSA — Module-Lattice Digital Signature Algorithm
The general-purpose post-quantum signature standard.
FIPS 205SLH-DSA — Stateless Hash-Based Signatures
Conservative hash-based signature alternative.
SP 800-227Recommendations for Key Encapsulation Mechanisms
Translates KEM primitives into secure usage.
NIST IR 8547Transition to Post-Quantum Cryptography Standards
The most quoted — and most misquoted — transition timeline.
CSWP 39Considerations for Achieving Crypto Agility
Connects PQ migration to routine algorithm replacement.
Every material claim is sourced, classified and last-reviewed.
Readiness measures public evidence of preparation. Quantum capability is tracked separately with source-specific metrics and is never treated as a promise that a well-prepared jurisdiction is safe.