top of page

🌐 Quantum Weekly - The Global Signals That Actually Mattered (28 September - 4 October 2026)

Writer: Brian Couzens
Brian Couzens
2 hours ago
23 min read

The week of 28 September to 4 October fixed the dates and moved the algorithms. The NSA restated its 2027 and 2030 requirements for National Security Systems, NATO attached quarters to its post-quantum cryptography work, and South Korea's science ministry opened a national migration competition. In the same days, Germany's BSI advised against Classic McEliece for new developments, a web infrastructure operator set out a certificate authority built for post-quantum Merkle Tree Certificates, and the ECB's supervisory Vice-Chair described quantum risk to cryptography as a present risk. Kazakhstan's Deputy Prime Minister proposed a national PQC roadmap. Capital and research funding ran alongside: a county approval for IBM's USD 2.51 billion fault-tolerant facility, a state-backed Diraq laboratory under DARPA's benchmarking programme, a defence programme exit in France, a consolidation in post-quantum signatures, a cryogenic supply partnership, Quandela's search for Korean manufacturing partners, and public programmes in the European Union, Australia and Japan. Signals came from North America, Europe, Asia-Pacific, Central Asia and NATO; five carry a sourcing caveat. No signal this week changes the timeline for a cryptographically relevant quantum computer.


🇫🇷 France - Pasqal Exits a French Defence Programme and Moves to Civil Funding

Sovereign Dependency / Programme Risk / Listed-Company Disclosure

The Detail: On 28 September 2026, Pasqal (Nasdaq: PSQL) announced an evolution of its collaboration framework with the French public authorities. Pasqal states that it took part in the first phase of the defence programme LSQUARE (also known as PROQCIMA), that it "successfully completed all the technological objectives", and that its participation in the programme is terminated. It thanked the Direction générale de l'armement (DGA) for supporting the first phase. Pasqal states that it has been invited into civil public support programmes "currently being defined", and that the Secrétariat général pour l'investissement (SGPI) and the Direction générale des entreprises (DGE) have asked it to submit a research and development programme for fault-tolerant quantum computing based on neutral atoms. No DGA statement on the change was located in the window.

Why it matters: A defence programme exit changes the funding source and the obligations attached to it. It does not change the technology. Investors and customers reading Pasqal's roadmap should separate what was paid for by sovereign defence demand from what must now be funded through a civil programme that, on Pasqal's own wording, is still being defined. Boards that depend on a quantum vendor for a sovereign or defence-adjacent workload should ask three questions: which obligations ended, who holds the phase 1 deliverables, and whether the civil programme carries the same milestone discipline. A vendor's statement that all objectives were met is an attribution that still needs assessing.

Pasqual logo white on black

🇨🇦 Canada - RBC Puts a Named Owner and a Multi-Year Horizon Behind Quantum-Safe Client Services

Financial Sector Governance / Quantum-Safe Security / Workforce

The Detail: On 28 September 2026, Royal Bank of Canada announced the appointment of Dr Elizabeth Iwasawa to the newly created role of Director of Quantum, two multi-year academic partnerships (the RBC Quantum Talent Initiative with the University of Waterloo's Institute for Quantum Computing, and PhD fellowships and conference sponsorship with the University of Toronto), and a workforce training collaboration with Xanadu. RBC states that it is implementing a Quantum-Safe Security Program "designed to achieve quantum-safe client services in the next several years", covering migration to post-quantum cryptography and quantum key distribution for secure communications, "among other elements". The release refers to RBC's first direct equity investment in quantum hardware, through Photonic Inc.'s C$180 million round in December 2025. Naim Kazmi, Group Head, Technology and Operations, stated that RBC is "taking a leadership position". No dates, budgets or scope boundaries are published.

Why it matters: A Canadian systemically important bank has named an executive owner and a stated horizon for quantum-safe client services. That is the governance shape supervised firms should benchmark against. The missing content matters as much. "The next several years" cannot be tested by a supervisor, a counterparty or an auditor without dates, scope and evidence criteria. Peer institutions should compare on those three facts, and should treat QKD as a separate, narrower control with its own deployment constraints. I set out the evidence a migration has to produce in "What Evidence Actually Proves a PQC Migration Is Good" (1 October 2026). A PQC readiness assessment converts a stated strategy into a dated, owned plan.


🇰🇷 South Korea - Quandela Sets Out a Two-Year Plan to Build Korean Manufacturing Partnerships for Photonic Quantum Hardware

Supply Chain / Manufacturing Partnerships / Market Entry

The Detail: On 28 September 2026, Quandela chief executive Niccolo Somaschi presented the company's Korea strategy and a medium- to long-term roadmap towards fault-tolerant quantum computing at a press conference in Seoul, as reported by Seoul Economic Daily. Quandela intends to spend the next two years identifying Korean partners for photonic module manufacturing, advanced packaging, wafer-level inspection, optical alignment, cryogenic control and system integration, and to run a proof of concept in Korea connecting QPUs with HPC. It is weighing a Korean quantum manufacturing consortium in which each party keeps its existing intellectual property and new IP is shared by role and contribution. Samsung, SK hynix and LG Innotek were named as possible partners. Somaschi stated that the long-term aim is to develop Korea into "a key hub for cooperation across Asia". No agreement was announced.

Why it matters: Photonic quantum hardware depends on semiconductor-grade manufacturing and inspection, and a European vendor is looking to Korea's base to supply it. Named prospective partners are not signed partners. For buyers, the relevance is supply chain geography: future modules from a European vendor may be produced under a Korean consortium IP model, which bears on export control, sovereign procurement terms and ownership of jointly developed IP.

Caveat: This evidences progress. It rests on a press conference reported by Korean media; no Quandela release or signed agreement was located.

Image of a man at Quandela press conference 2026

🌐 NATO - The Allied Quantum Roadmap Puts Quarters on Post-Quantum Cryptography and Industry Readiness

Alliance Policy / Supplier Readiness / Dated Milestones

The Detail: On 29 September 2026, NATO published a public summary of its Quantum Technology Roadmap, which Allies approved on 30 July 2026. The roadmap sets five lines of effort: identifying use cases; testing, developing and adopting quantum-enabled solutions; standardisation and interoperability; safeguarding NATO against quantum risks and threats; and training and education. The cryptographic content is explicit. Line of effort 3 lists "Adopt and Implement Post-Quantum Cryptography Standards" as ongoing, an STO Quantum Standardisation Specialist Team by Q3 2027, an Alliance quantum standards roadmap by Q3 2029, and the Quantum Zero Beacon Project, a pilot between NATO Headquarters in Brussels and SHAPE in Mons to validate "a practical pathway for NATO's transition to quantum-resilient communications", by Q4 2027. Line of effort 4 schedules a NATO Industrial Advisory Group study on "Assessing Industry Readiness for Quantum-Resistant Cryptographic Solutions" for Q2 2027 and the next update of the Action Plan for NATO's Response to the Quantum Threat to Cryptography for Q3 2027. NATO's Cryptographic Services Capability Team will implement the cryptographic elements. Other dated items include NATO Quantum Assessment Criteria by Q2 2027, a first pilot report in Q1 2027 and QUESTOR sea trials in 2026 and 2027. The Transatlantic Quantum Community, chaired by the Netherlands with Canada as Vice-Chair, welcomed Belgium and Bulgaria at its Washington meeting on 24 to 25 September.

Why it matters: Defence suppliers now have a date by which NATO intends to have assessed their readiness for quantum-resistant cryptography: Q2 2027. That study will shape what the Alliance expects from industry, and suppliers who cannot evidence an inventory, a migration plan and product roadmaps by then will be assessed on what they lack. The public text is a summary of selected activities, so the absence of a fixed migration deadline should not be read as the absence of one. Critical-infrastructure operators with Allied customers should treat the Industry Network as the channel through which requirements will be shaped. I covered line of effort 4 in "PQC Governance Digest: Cut-off 2 October 2026" (3 October 2026).

NATO and OTAN LOGO saying they release a roadmap for PQC

🇺🇸 United States - Cloudflare Sets Out a Public Certificate Authority Built Around Post-Quantum Merkle Tree Certificates

Web PKI Concentration / Certificate Lifecycle / Vendor Claim Discipline

The Detail: On 29 September 2026, Cloudflare (NYSE: NET) announced its intent to become a public certificate authority issuing classical certificates and Merkle Tree Certificates (MTCs). Cloudflare states that it has agreed to acquire publicly trusted root CA key material from GlobalSign, with closing expected within two months and subject to customary conditions, and that it has applied to the Chrome, Apple, Microsoft and Mozilla root programmes. Classical issuance will follow root programme acceptance; production MTC issuance is scheduled for Q1 2027, targeting inclusion in Chrome's Quantum-resistant Root Store, and standard MTC issuance is stated to be free. Cloudflare's engineering post states that post-quantum signatures are roughly 40 times larger than classical ones, and that an experiment serving MTCs to half of Chrome Beta 146 users measured a 9% median speed gain over a classical signature chain, and attributes the bulk of that gain to intermediate elision rather than to MTCs as such. Chrome's own draft Quantum-resistant Root Program policy (version 0.3.0, last updated 14 August 2026) states that Chrome will not add X.509 certificates containing post-quantum cryptography to its existing root store, and restricts initial eligibility for MTC CA operators to organisations that ran a usable Certificate Transparency log before 1 February 2026.

Why it matters: Post-quantum web authentication is being decided by one browser's root programme and a small set of eligible operators, and Chrome's draft policy narrows that set by design. Enterprises sit downstream of those decisions. The performance figure is Cloudflare's own, from a browser beta, and Cloudflare itself attributes much of it to a design choice. The exposure for relying parties is lifecycle: MTC validation needs client support, so estates with non-browser clients, embedded devices or pinned trust stores will run dual stacks for years. Certificate owners should establish where certificates are issued, which clients validate them and which automation controls renewal, because those three facts set how fast any CA can be adopted or replaced. That is the scope of cryptographic transformation and modernisation. I set out a vendor-neutral approach to a first deployment in "Beyond the Hype: A Vendor-Neutral Framework for Your First PQC Hybrid Pilot" (28 September 2026).

🇺🇸 United States - Project Eleven Acquires Riva Labs as Post-Quantum Signature Capability Consolidates Around Digital Assets

Consolidation / Digital Asset Custody / Cryptographic Diligence

The Detail: On 29 September 2026, Project Eleven announced the acquisition of Riva Labs. Terms were not disclosed. Project Eleven states that Riva Labs' work spans hash-based post-quantum signatures, post-quantum multi-party computation (MPC), account abstraction, wallet infrastructure and hardware signing across Ethereum and other public blockchains. Chief executive Alex Pruden stated that the combination accelerates the company's ability to lead the post-quantum transition across digital assets. Project Eleven states that AI is accelerating cryptographic research and cryptanalysis, and that Riva has made AI a core part of its research and engineering process.

Why it matters: Signature migration on public blockchains has no central owner and a thin bench of specialist teams. Consolidation shortens the supplier list for custodians, exchanges and wallet providers, and concentrates cryptographic code in a single acquirer whose integration record is not yet visible. Buyers should ask for continuity commitments, the review status of the acquired code, and whether the hash-based and MPC components have been assessed outside the vendor. The same discipline applies to any acquirer of cryptographic capability: remediation cost inherited with the target is a diligence item. I published "The Hidden PQC Cost in Quantum M&A" (5 October 2026), after this window closed. A PQC Discovery Sprint is the control that prices that exposure before signature.

🇰🇿 Kazakhstan - Deputy Prime Minister Proposes a National Roadmap for Transition to Post-Quantum Cryptography

Sovereign Policy / National Roadmap / Central Asia

The Detail: On 29 September 2026, at the opening of the KazHackStan 2026 conference in Astana, Zhaslan Madiyev, Deputy Prime Minister and Minister of Artificial Intelligence and Digital Development, proposed developing a national roadmap for Kazakhstan's transition to post-quantum cryptography, as reported by DKNews. He named preparation for post-quantum security as one of five cybersecurity priorities, alongside safe use of AI, international technical cooperation, workforce development and domestic cybersecurity solutions. He stated that Kazakhstan has adopted a Law on Cybersecurity, identified more than 400 critical digital assets and has over 40 operational cybersecurity centres. No transition deadline was announced.

Why it matters: A proposal to prepare a roadmap is the earliest stage of national migration governance: there is no deadline, owner or scope yet. Its stated base matters more than the announcement. More than 400 critical digital assets are already identified, which is the register a PQC roadmap would draw on. Operators and suppliers of Kazakh critical infrastructure should expect PQC questions to follow that register, and should be able to show what cryptography protects the assets they run or supply.

Caveat: This evidences progress. It rests on press reporting of a ministerial speech; the government's own text was not retrieved, and the roadmap is proposed, not adopted.

Image of a Kazhackstan a play on Karzachstan

🇺🇸 United States - Dutchess County IDA Approves Incentives for IBM's USD 2.51 Billion Quantum Facility in Poughkeepsie

Capital Commitment / Onshore Manufacturing / Fault-Tolerant Delivery

The Detail: On 29 September 2026, the board of the Dutchess County Industrial Development Agency approved, by five votes to one, a final authorising resolution granting IBM a sales tax exemption and a payment in lieu of taxes (PILOT) for an approximately USD 2,509,700,000 project to build a quantum-computing facility at its campus at 2455 South Road, Town of Poughkeepsie, according to the agency's draft minutes. A motion to move the sales tax recapture dates three years forward was not seconded. The agency's project summary describes approximately 300,000 square feet of new and renovated space, including a cryogenic plant, dilution refrigerators and cleanroom tooling, to support IBM's "development, integration, test, and delivery of fault-tolerant quantum-computing systems". It states construction completion in the first half of 2029, occupancy at year-end 2029, a capital programme across 2026 to 2035, estimated sales tax benefits of about USD 99.4 million, and 2,000 jobs retained with 140 created.

Why it matters: A vendor roadmap has become a dated, publicly recorded capital commitment with recapture terms attached. Buyers assessing IBM's fault-tolerant plans now have an occupancy date of year-end 2029 to measure claims against. For cryptographic risk owners, this is evidence of investment in capacity, and says nothing about cryptanalytic capability; it leaves migration timelines unchanged while confirming that fault-tolerant infrastructure is being built against public schedules.

Caveat: This evidences progress. The minutes are marked draft pending approval at the agency's next meeting, and the project figures are the agency's estimates.

🇺🇸 United States - Diraq Signs to Open a Quantum Device Characterisation Laboratory in New Mexico Under DARPA's Benchmarking Initiative

State Co-Investment / Independent Benchmarking / Silicon Spin Qubits

The Detail: On 29 September 2026, New Mexico's Economic Development Department announced that Diraq, an Australia-founded quantum computing company, has signed a memorandum of understanding to establish operations at the Roadrunner Quantum Lab in Albuquerque, a joint effort of Roadrunner Venture Studios and the state's Technology and Innovation Office. The lab will house Maybell cryogenic equipment and a measurement engineering team for device testing and characterisation, and is expected to begin operations by the end of 2026. The state says its matching funds support Diraq as a Stage B performer in DARPA's Quantum Benchmarking Initiative (QBI). Diraq states that its roadmap targets 150,000 physical qubits on a single chip by 2029 and more than two million by 2031.

Why it matters: QBI is the US government's structured test of whether utility-scale quantum computing is achievable by 2033, and states are now co-funding the infrastructure its performers use. That ties public money to an independent benchmarking process, which is the evidence model buyers should prefer over vendor roadmaps. Diraq's qubit targets are company projections; the markers to track are QBI stage progression and the lab's start of operations.

🇨🇦 Canada - Xanadu and Bluefors Commit to a Modular Cryogenic Design for Photonic Quantum Data Centres

Infrastructure Supply / Hardware Architecture / Supplier Concentration

The Detail: On 29 September 2026, Xanadu Quantum Technologies (Nasdaq/TSX: XNDU) and Bluefors announced a strategic partnership, described as a multi-million US dollar collaboration, to develop a cryogenic prototype for utility-scale quantum computing. Xanadu chief executive Christian Weedbrook stated that the industry had assumed utility-scale systems would need "massive, industrial-scale cryoplants", and that the concept of a compact module is "expected to remove the need for traditional cryoplants". The longer-term aim is a mass-manufacturable module for single-photon detector infrastructure. No performance data, delivery dates or contract value were published.

Why it matters: Cryogenic supply is a physical dependency beneath superconducting and detector-based roadmaps alike. A partnership with a cryogenics supplier shows intent to engineer for volume. It does not show that the module works. Investors and customers underwriting Xanadu's data-centre plans should treat "expected to remove the need" as an engineering hypothesis and ask for thermal load, detector count and reliability data before giving it weight. The procurement point is concentration: where a small number of suppliers cool several modalities, a delay at one supplier becomes a sector delay.

Blue FORS and Xanadu logos showing the tieup

🇳🇱 🇪🇺 Netherlands / European Union - Quantum Internet Alliance Secures EUR 47.5 Million for a 42-Month Second Phase

Network Architecture / Public Funding / Prototype Milestones

The Detail: The Quantum Internet Alliance (QIA), based in Delft, announced on 30 September 2026 that it has received EUR 47.5 million from the European Commission under a second Specific Grant Agreement (SGA 2) covering 42 months. The first phase ran from October 2022 to March 2026. QIA states that the second phase will integrate hardware, software and networking research into a complete, programmable quantum network prototype, with a key milestone of interconnecting two metropolitan-scale quantum networks over a long-distance fibre link using quantum repeaters. It also states that it will prepare for quantum internet pilot facilities and open-access infrastructure. QIA Director Stephanie Wehner stated that the prototype "may become the first of its kind in the world".

Why it matters: This is public research funding with a defined prototype milestone; no service is deployed. Quantum networking and post-quantum cryptography address different problems, and a repeater demonstration does not move the migration schedule for any organisation's RSA and elliptic-curve estate. Risk teams should log it as a long-horizon infrastructure programme and keep QKD and quantum networking out of near-term migration plans unless a regulator or sovereign programme requires them. The milestone to watch is the metropolitan interconnect.

🇪🇺 European Union - ECB Supervisory Vice-Chair Tells Global Bank Supervisors That Quantum Risk to Cryptography Is Already a Risk

Supervisory Posture / Financial Stability / Harvest Now, Decrypt Later

The Detail: On 30 September 2026, Frank Elderson, Vice-Chair of the Supervisory Board of the ECB, spoke on a panel at the Basel Committee's International Conference of Banking Supervisors in Bali. The published text states that quantum computing "could become widely available by 2030" and that "quantum risk to cryptography is already a risk" because encrypted information can be collected now and decrypted later. He stated that supervisors "increasingly need to engage with experts far beyond the financial sector". The remark set no supervisory expectation, instrument or deadline.

Why it matters: A senior euro area supervisor has placed harvest-now-decrypt-later exposure in the present tense in front of the global supervisory community, one week after the European Supervisory Authorities named quantum risk in their autumn risk update. The position is supervisory posture, and no instrument follows from it yet. Banks that wait for a dated instruction will meet the question first in supervisory dialogue, where the answer that holds is an inventory with owners and a dated plan. Firms should be able to show which data has a confidentiality horizon beyond 2030 and how it is protected today.

🇩🇪 Germany - BSI Advises Against Classic McEliece for New Developments After Cryptanalytic Progress

Algorithm Lifecycle / Hybrid Design / Cryptographic Agility

The Detail: On 1 October 2026, Germany's Federal Office for Information Security (BSI) published a notice titled "Fortschritte in der Kryptoanalyse von Classic McEliece". BSI states that significant progress in the cryptanalysis of the Classic McEliece key agreement scheme in 2026 indicates a lower security level than previously assumed, that current results do not enable a practical attack on the parameter sets recommended in Technical Guideline TR-02102-1, and that further improvements are to be expected. BSI now recommends against using Classic McEliece for new developments and when planning new cryptographic applications, and expects to revise the relevant TR-02102-1 entries in its next edition in early 2027. BSI has recommended post-quantum key agreement only in hybrid combination with a classical scheme.

Why it matters: A national cryptographic authority has withdrawn its recommendation for a post-quantum scheme for new work, on evidence, without a practical break. That is how the algorithm lifecycle will behave for the next decade, and it is the case for hybrid construction and crypto-agility made by a national authority rather than a vendor. Organisations that hold Classic McEliece for long-lived keys should confirm it sits inside a hybrid construction, record it as a planned replacement, and check which suppliers embed it. Programmes that cannot locate an algorithm across their estate cannot respond to a notice like this one. Cryptographic agility services exist for that response. I argued why an inventory record without discovery beneath it fails this test in "Discovery Is Table Stakes for PQC. A CBOM Is Not Discovery." (30 September 2026).

Image of a letter from BSI

🇺🇸 United States - NSA Restates the 2027 and 2030 Dates for National Security Systems and Opens a PQC Resource Hub

Federal Mandate / Defence Industrial Base / Supply Chain Timelines

The Detail: On 1 October 2026, the National Security Agency announced post-quantum cryptography measures for National Security Systems (NSS), framed under Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks". The release restates that, as mandated by Committee on National Security Systems Policy 15, "starting in 2027, all new commercial NSS must be capable of supporting quantum-resistant algorithms", and that legacy systems unable to support them "are to be phased out by 2030". It launches a Post-Quantum Cryptography Resource Hub for the Department of War, NSS and Defense Industrial Base stakeholders. Morgan Stern, NSA Effort Lead for Quantum Resistance, stated that the quantum threat is "an existential threat to the digital ecosystem, but we have the tools today to combat it". The release names "harvest now, decrypt later" and a "trust now, exploit later" threat to authentication. It introduces no new deadline.

Why it matters: The dates were restated, not extended. For suppliers into the US national security market, 2027 is a product requirement and 2030 is a removal date, and both cascade into commercial supply chains that share components with defence buyers. The "trust now, exploit later" framing places signatures and authentication alongside confidentiality, which widens the inventory to certificates, firmware signing and code signing. I set out how to calculate when migration has to start in "Mosca's Theorem: The Equation That Tells You When to Start Post-Quantum Migration" (4 October 2026).

🇰🇷 South Korea - MSIT and KISA Open a National PQC Transition Competition and Hackathon

Workforce Capacity / Applied Migration / State-Led Readiness

The Detail: On 1 October 2026, South Korea's Ministry of Science and ICT (MSIT) and the Korea Internet and Security Agency (KISA) opened applications for what the ministry describes as its first quantum-resistant cryptography (PQC) transition competition and hackathon, as reported by Korean outlets citing the ministry and a KISA notice. The competition invites proposals for problems that arise in industrial PQC transitions. The hackathon requires teams to convert existing cryptographic systems to PQC in a virtual environment, judged on completeness of the transition, whether services operate normally, and performance before and after conversion. Applications close on 30 October; awards follow on 26 November. Im Jeong-gyu, MSIT's director general for information security and network policy, stated that the aim is to strengthen national-level PQC capability.

Why it matters: The scoring criteria are the signal: service continuity and measured performance after conversion. A government is training a migration workforce against operational outcomes. Organisations with Korean operations should expect that framing to reach sector pilots and supervisory conversations. Elsewhere, boards should ask whether their own teams have ever converted a live-like system and measured the result. I wrote "Post Quantum Cryptography: A Practical Introduction for New Graduates and Early-Stage Partners" (4 October 2026) for the same workforce gap.

Caveat: This evidences progress. It rests on Korean press reports citing the ministry and a KISA notice; the ministry's own release was not retrieved.

Image of the competition in Korean

🇮🇳 India - IBM Research India Extends Quantum-HPC Work with IISc and Academic Collaboration with IIT Bombay

Sovereign Capability / Academic Alliance / Quantum-Centric Computing

The Detail: On 1 October 2026, IBM announced the expansion of its research collaborations with the Indian Institute of Technology Bombay (since 2018) and the Indian Institute of Science (since 2021). The IISc collaboration covers agentic systems, energy-focused AI models and quantum-HPC algorithms for scientific and industry applications. The IIT Bombay collaboration centres on sovereign and Indic-language model adaptation, multimodal AI, knowledge retrieval and AI infrastructure. Dr Amith Singhee, Director of IBM Research India, stated that the next wave of computing will be shaped by agentic AI, sovereign AI and quantum computing. Funding and access to IBM quantum systems are not specified.

Why it matters: The signal is scope rather than scale. IBM is aligning its quantum research in India with the sovereign AI agenda, where Indian institutional funding is directed. Without funding, system access or milestones, procurement and investment teams should not read this as capacity coming online. Organisations with Indian operations should note that quantum-centric computing work will be framed as an AI and HPC question first, and that this announcement carries no cryptographic content.

🇦🇺 Australia - Government Funds Six Quantum Demonstrator Projects Worth AUD 12.3 Million

Sovereign Capability / Applied Quantum / Grid Timing and Sensing

The Detail: On 2 October 2026, Australia's Department of Industry, Science and Resources announced AUD 12.3 million for six company-led consortia under round 2 stage 2 of the Critical Technologies Challenge Program, part of the National Quantum Strategy. Awards are: Silicon Quantum Computing, AUD 3.6 million for a quantum computing and AI platform for energy forecasting; FeBI Technologies, AUD 2.2 million for iron deficiency diagnosis in First Nations peoples; QuantX Labs, AUD 2.2 million for a quantum clock to keep the electricity grid timed without external signals; Avicena Systems, AUD 2 million for a quantum biosensor for border inspection; iQ Sense, AUD 1.2 million for livestock health monitoring; and Q Factorial, AUD 1.1 million for transport planning software. Only applicants that completed a stage 1 feasibility project were eligible. The programme provides up to AUD 36 million in total.

Why it matters: The grid timing award is the item for risk owners. A quantum clock that holds time without external signals addresses GNSS dependence in critical infrastructure, a resilience question that sits beside cryptographic migration in the same operational risk register. The funding is demonstrator-scale and staged on prior feasibility work, which is the right discipline for public money; the outcomes to watch are field results.

Caveat: This evidences progress. The department's page was located but its text would not render in my tools; the date and awards rest on a reproduction of the department's release.

🇯🇵 Japan - NEDO Selects an NEC-Led Quantum and AI Cancer Immunotherapy Project for Its Use-Case Demonstration Programme

Sovereign Compute / Applied Quantum / Public Programme Selection

The Detail: On 2 October 2026, NEC announced that a joint project with Taiho Pharmaceutical, the Japanese Foundation for Cancer Research, the National Institute of Advanced Industrial Science and Technology (AIST) and Waseda University has been selected for the Large-Scale Demonstration for Use Case Creation, administered by Japan's New Energy and Industrial Technology Development Organization (NEDO). The project runs from September 2026 to March 2029. It will apply AI to predict immune responses and quantum computing technology to the design of neoantigen candidate sequences, then validate candidates through immunological experiments. It will use ABCI-Q, the integrated quantum, HPC and AI infrastructure developed by AIST's G-QuAT centre. No funding amount or quantum hardware specification is published.

Why it matters: Japan is directing public money to use cases that run on its own sovereign quantum-HPC infrastructure, with experimental validation built into the design. That structure produces evidence rather than claims, and it gives procurement teams a reference model: fund the use case, specify the validation, publish the timeline. The absence of a published budget and of a stated quantum advantage target means this should be read as capability building.

Image of microscopes electronic quantum ones

🇮🇳 India - QNu Labs, BISAG-N and IIT Gandhinagar Report a 5.56 km Free-Space QKD Link Paired with a PQC Platform

QKD Engineering / Hybrid Design / Field Evidence

The Detail: On 3 October 2026, the Ministry of Electronics and Information Technology reported through the Press Information Bureau a free-space quantum key distribution (QKD) demonstration by QNu Labs with BISAG-N and IIT Gandhinagar, described in the release as India's first free-space QKD link. The field trial ran on the night of 27 to 28 September over 5.56 km between the two institutions. The release states a quantum bit error rate below 5% and secure key generation of 230 to 260 bits per second, using QNu Labs' pointing, acquisition and tracking system. Keys were fed into BISAG-N's Vedic Kavach platform, which the release describes as built on post-quantum cryptography, and test messages were encrypted and decrypted end to end. Earlier PIB releases have reported other Indian free-space quantum communication demonstrations, including C-DOT with PRL and DRDO with IIT Delhi, so the "first" claim rests on the release's own framing.

Why it matters: A key rate of 230 to 260 bits per second supports key refresh for a small number of symmetric sessions, not bulk key delivery, and a night-time trial excludes daylight background conditions. The evidence is a ministry release of a vendor and academic trial, with no independent assessment cited. The architectural point holds regardless: the trial pairs QKD with a post-quantum software layer, which is a hybrid design. Operators evaluating QKD should require device certification, side-channel evidence and acceptance results under daytime and degraded conditions before it enters a design. I set out why product claims are not the starting point in "Why PQC Vendors Are Not the Starting Point for Your Post-Quantum Transition" (30 September 2026). Independent assurance of product claims is the control that separates a demonstration from a deployable specification.

🌐 Global Sweep - Fixed Dates, Moving Algorithms, Narrowing Trust Operators

Ecosystem / Capital Markets / PQC Infrastructure / Hardware Architecture / Sovereign Security

The Detail:

  • Mandates and dates: the NSA restated 2027 for new commercial NSS and 2030 for legacy phase-out; NATO dated an industry readiness study on quantum-resistant cryptography for Q2 2027 and its next cryptographic Action Plan update for Q3 2027; South Korea opened a national migration competition scored on service continuity; Kazakhstan's Deputy Prime Minister proposed a national PQC roadmap.

  • Algorithm lifecycle: BSI advised against Classic McEliece for new developments on cryptanalytic evidence, with a TR-02102-1 revision expected in early 2027.

  • Supervisory posture: the ECB's supervisory Vice-Chair called quantum risk to cryptography a present risk, without an accompanying expectation; RBC named an owner and a multi-year horizon for quantum-safe client services.

  • PQC infrastructure: Cloudflare set out a public CA with production MTC issuance targeted for Q1 2027; Chrome's draft root policy restricts initial MTC CA eligibility to existing Certificate Transparency log operators.

  • Capital and supply: the Dutchess County IDA approved incentives for IBM's USD 2.51 billion Poughkeepsie facility; Project Eleven acquired Riva Labs; Xanadu and Bluefors committed to a modular cryogenic design; Quandela set out a two-year search for Korean manufacturing partners; Pasqal left a French defence programme for civil funding.

  • Public research funding: EUR 47.5 million for the Quantum Internet Alliance, AUD 12.3 million across six Australian demonstrators, a NEDO selection in Japan running to March 2029, and New Mexico matching funds for Diraq's QBI laboratory; IBM extended quantum-HPC research in India; India reported a 5.56 km free-space QKD trial paired with a PQC platform.

  • Sourcing caveats: five items rest on draft, reproduced or press-reported sources and carry a caveat in their sections: Quandela and MSIT/KISA (South Korea), Kazakhstan, Australia and the IBM Poughkeepsie approval.

  • My own publications this week, which are not signals: "The State of Post-Quantum Cryptography in 2026: A Global Map of PQC Algorithms and Migration Deadlines" (28 September 2026), "PQC Governance Digest: Cut off 25 September 2026" (29 September 2026) and "Thematic Reviews and the Governance Visibility Gap in Cryptographic Risk" (1 October 2026), alongside the posts linked in the sections above.

  • Null regions, with no confirmed in-window primary-source signal located in the searches run for this edition: United Kingdom, Italy, Spain, Finland, Sweden, Denmark, China, Singapore, Taiwan, the Gulf Cooperation Council states, Africa and Latin America. Standards bodies and regulators with no in-window item located: NIST (beyond a non-PQC automation paper), ENISA, NCSC, ETSI, ASD and CRYPTREC. Hyperscalers with no in-window PQC release located: Microsoft, Google and AWS.

Why it matters: The dates held and the algorithm set moved in the same week. Programmes built around a single algorithm choice, a single trust anchor or a single vendor will absorb each of these changes as rework. Programmes built on inventory, hybrid construction and the ability to swap components will absorb them as routine maintenance. Geographic coverage this week spans ten countries, the European Union and NATO, with five items carrying a sourcing caveat; the Gulf, Africa and Latin America are declared null.

🔮 SITG-Consulting COMMENT - THE WEEK'S REAL SIGNAL

The deadlines are fixed. The algorithms are not.

On 1 October the NSA restated 2027 and 2030. Two days earlier NATO put Q2 2027 on an assessment of industry readiness for quantum-resistant cryptography. On the same day as the NSA, BSI told its constituency to stop starting new work on Classic McEliece, a post-quantum scheme it had recommended in hybrid form, because the cryptanalysis moved. No practical attack exists. The recommendation changed anyway, and that is the correct behaviour for a cryptographic authority.

Put those together and the governance consequence is plain. A migration plan that treats algorithm selection as a one-time decision will be wrong within its own delivery window. The controls that survive are an inventory that can locate an algorithm across the estate within days, hybrid construction that preserves classical security while a component is replaced, and supplier contracts that oblige vendors to follow an authority's revised guidance. That is cryptographic agility, and this week a national authority demonstrated why it is required.

Trust infrastructure is narrowing at the same time. Chrome's draft Quantum-resistant Root Program restricts initial MTC CA eligibility to existing Certificate Transparency log operators, and Cloudflare has filed to become one of the issuers. The policy logic is sound; the outcome is concentration. Certificate owners should know which of their clients will validate MTCs and which will not, before an issuer tells them.

Supervision is moving in posture before it moves in instruments. The ECB's supervisory Vice-Chair called quantum risk to cryptography a present risk; RBC named an owner and "the next several years". Neither is testable yet. Boards that can produce dated, owned, evidenced plans will set the benchmark supervisors later adopt. I set out how a thematic review tests whether those plans hold across functions and suppliers.

The question for the board this quarter: if an authority withdrew one of your algorithms tomorrow, how many days would it take to find every place it runs?

⚠️ Important - What Was NOT Missed

  • No credible evidence of near-term cryptographically relevant quantum advantage. Nothing in this window changes the case for hybrid post-quantum migration.

  • Not treated as signals: NIST CSWP 37B on automating FIPS 140-3 validation (30 September), which contains no PQC requirement; and a law firm's investigation notice concerning Pasqal Holding (29 September), which is a solicitation, not a finding.

  • Chrome's draft Quantum-resistant Root Program policy (version 0.3.0, 14 August 2026) is cited as context for the Cloudflare section. It is outside the window and is not counted.

  • Outside the window: the US Department of Energy's SCAC quantum roadmap (17 September; republished 25 September and 2 October); the DOE Q Competition request for applications (17 September; applications close 19 October); IonQ's real-time error decoder (22 September); Pasqal's H1 2026 results (24 September); the NSF's USD 290 million Quantum Leap Challenge Institutes award (25 August); and the IBM and Singapore Institute of Technology Quantum-Safe Centre (August).

  • planqc and the LOGIQC consortium's selection for Germany's Quantum Computing Competition is dated 22 September on planqc's own page; trade coverage on 5 October is a republication. Outside the window.

  • No primary-source announcements were located from the Quantum Innovation Summit in Dubai (28 to 30 September).

  • Coming fortnight: OMB Memorandum M-26-15 requires US agency PQC migration plans by 22 October 2026, as set out in my 2 October digest.


⚠️ Disclaimer

This newsletter is produced by SITG-Consulting for informational purposes only. It does not constitute professional advice, whether legal, technical, regulatory, or otherwise. The content reflects publicly available information and the author's independent analysis as of the date of publication. Readers should verify all claims independently and seek qualified professional counsel before making decisions based on this material. SITG-Consulting accepts no liability for actions taken or not taken based on the contents of this newsletter.



 
 
 

Comments


bottom of page