The State of Post-Quantum Cryptography in 2026: A Global Map of PQC Algorithms and Migration Deadlines

Post-quantum cryptography (PQC) has crossed an important line: it is no longer a research topic but a compliance deadline. As of September 2026, the algorithms are standardized, national migration timelines are published across five continents, and the main risk has shifted from "will the math hold?" to "will your organization migrate in time?" This article maps the current global state of PQC: the algorithms, the country-by-country deadlines, and the uncomfortable adoption gap.
What Is Post-Quantum Cryptography?
Post-quantum cryptography refers to cryptographic algorithms designed to resist attack by quantum computers running Shor's algorithm, which breaks today's RSA and elliptic-curve cryptography. Unlike quantum key distribution (QKD), PQC runs on classical hardware and can be deployed as a software upgrade, which is why nearly every government now treats it as the primary quantum-safe defence.
The 2026 PQC Algorithm Landscape
NIST's first three standards, ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205), have been final since August 2024. FN-DSA (FIPS 206) remains in draft, delayed by the difficulty of constant-time floating-point sampling. In March 2025 NIST selected HQC, a code-based backup KEM intended for future standardization, as insurance against a lattice break; it is not yet a finalized FIPS standard. In August 2026 the IETF published RFC 10024, standardizing hybrid post-quantum key exchange in TLS 1.3, though authentication and certificates remain unresolved.
The science is still moving: in July 2026, AI-assisted cryptanalysis found a structural weakness in the NIST candidate HAWK, materially reducing its security margin, and the HAWK team withdrew the scheme within days. The standardized algorithms were unaffected, and since HAWK was never deployed, the episode showed the open evaluation process working as designed.
Global PQC Migration Timelines by Country

The pattern is clear: PQC standardization has multipolarised. Korea and China are building national alternatives to NIST's suite, while Europe, India and Southeast Asia converged on 2030–2035 migration windows. For multinational organizations, "which PQC algorithms should we deploy?" is now partly a jurisdictional question: a product sold into Seoul, Beijing, Brussels and Washington may need to support more than one national suite, or at least be built crypto-agile enough to swap algorithms without a redesign.
Germany's BSI and France's ANSSI add a further twist: both require hybrid deployments (classical and post-quantum algorithms combined) rather than pure PQC, reasoning that if either layer holds, the system stays secure.
Real-World PQC Adoption: The Readiness Gap
Deployment is real but thin. Cloudflare reports over 50% of human web traffic now uses post-quantum key exchange, but that is transport-layer protection, not complete migration: authentication, certificates, applications and enterprise systems remain separate challenges. Apple iMessage (PQ3) and Signal (SPQR ratchet) are quantum-safe in production; Microsoft, AWS and Google Cloud all ship PQC. Yet enterprise surveys suggest only a small minority, often reported in the 5–7% range depending on the definition, has moved beyond assessment into meaningful deployment; zero post-quantum certificates exist in the public web PKI; and FINMA found that 72% of surveyed Swiss financial institutions had neither planned nor implemented quantum-safe measures. Meanwhile, "harvest now, decrypt later" collection means data intercepted today is already exposed to future decryption.
What Organizations Should Do Now
Build a cryptographic inventory: you cannot migrate what you cannot find.
Demand crypto-agility from vendors, in writing, in contracts.
Pilot hybrid PQC (classical + ML-KEM) on non-critical systems now.
Map your regulator's deadline: 2030 arrives faster than a typical PKI refresh cycle.
FAQ
When will quantum computers break RSA? Expert panels put the odds within 10 years at roughly one in three; within 15 years, above 50%. Google research published in 2025 estimated that RSA-2048 could theoretically be broken with fewer than one million noisy qubits running for under a week, under specific hardware and error-correction assumptions.
Is PQC standardized? Yes. NIST finalized three standards in 2024, with more (FN-DSA, HQC) still in progress, and the IETF standardized hybrid post-quantum TLS in 2026.
What is "harvest now, decrypt later"? Adversaries record encrypted traffic today and store it until a quantum computer can decrypt it. Any data with a secrecy lifetime beyond ~10 years is already at risk.
Do I need quantum hardware to use PQC? No. PQC is ordinary software running on today's devices; browsers, phones and servers already use it.
-----------------------------------------------------------------------------------------
Sources: NIST CSRC, IETF RFC 10024, EU NIS Cooperation Group roadmap (2025), UK NCSC (2025), ASD ISM, KpqC, Cloudflare Radar, Global Risk Institute Quantum Threat Timeline 2025.




Comments