CRQC logoCRQCQuantum Risk, Quantified
MapTimelineTechnologyNews
Observatory ยท Industries

Where does quantum risk hit your industry?

Relevance is not the same as obligation. Each industry record separates cryptographic exposure and dependency classes from the actual published policy signal โ€” and says so when no mandate exists.

Dataset as of 2026-09-06

Finance

A2

Long-lived confidential information, TLS and VPN, payment messaging, signing, identity, HSMs and certificates.

HSM / KMSPayment networksCore banking vendorsCloudPrivate PKI

Telecom

C

5G core interfaces, IPsec and TLS, roaming, network identity, subscriber and device trust, IoT.

Network equipmentSIM / eSIMPKIOSS / BSSCloudDevice OEMs

Cloud

C

TLS, service-to-service identity, KMS, IAM, storage key wrapping and signatures.

Crypto librariesHSMsCustomer agentsCDNService meshAPIs

IoT / OT

A2

Secure boot, firmware updates, device certificates, VPN, and very long device lifetimes.

Secure elementsMCUsFirmwareOEM signing PKIGateways

Automotive

D

OTA updates, V2X, manufacturing identity, ECU boot and signing, backend TLS.

Tier suppliersChipsSecure elementsPKI / HSMConnectivity providers

Healthcare

D

Long-confidentiality records, medical-device identity, remote management, signing and interoperability.

Cloud / EHRDevice OEMsPKINetwork securityIdentity providers

Defense

A1

Classified and NSS communications, firmware, supply-chain trust, credentials and long-term secrets.

Accredited productsHSMsNetwork vendorsPKIProcurement
CRQC

An observatory of the transition from quantum-vulnerable cryptography to post-quantum cryptography, including sourced quantum-capability evidence and migration readiness.

ObservatoryMapTimelineTechnologyNewsStandardsRegulationIndustriesSupply chainVendorsGlossaryMethodology
Evidence discipline

Every material claim carries an authority, an evidence class, a document status and a review date. Draft documents are labelled as drafts. Gaps are recorded as gaps.

Dataset as of 2026-09-06Editor sign in โ†’