Skip to content
ContentLora

    Tip: press / anywhere to search.

    ● Developing story

    Post-quantum cryptography and security tracker

    This tracker follows the move to post-quantum cryptography and the AI security frontier, from NIST's first standards in August 2024 to the June 2026 US executive order and the IETF's August 2026 hybrid TLS standard.[1][2][3] As of 10 October 2026, most browser traffic to large networks uses post-quantum key exchange, but post-quantum authentication, the HQC and FN-DSA standards and the arrival date of a code-breaking quantum computer are all still open.[4][5][6]

    Editor reviewedUpdated Post-quantum cryptography and securityTech policyComputing

    What we know

    • NIST's first three post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) have been final since 13 August 2024.[1]
    • Hybrid X25519MLKEM768 is an IETF Proposed Standard (RFC 10024) and is on by default in Chrome and Apple's 2026 operating systems.[3]
    • Over 65% of human traffic to Cloudflare was post-quantum encrypted as of April 2026.[4]
    • US high-value federal systems must use PQC key establishment by end-2030 and PQC signatures by end-2031.[15]
    • Google and Cloudflare target 2029 for full post-quantum migration, prioritizing authentication.[14]
    • Published estimates for breaking 256-bit elliptic-curve cryptography fell to under 1,200 logical qubits in March 2026.[22]
    • Anthropic reports that AI performed 80-90% of a 2025 espionage campaign run through its Claude Code tool.[9]
    • AI systems found 18 real vulnerabilities in DARPA's 2025 AI Cyber Challenge final.[8]
    • NSA expects US national security systems to finish moving to quantum-resistant algorithms by 2035.[26]
    • The EU roadmap bars stand-alone quantum-vulnerable public-key mechanisms for high-risk uses after 2030 and medium-risk uses after 2035.[21]

    What we don't know yet

    • When, or whether, a cryptographically relevant quantum computer will be built.
    • When NIST will publish the draft HQC standard and finalize FN-DSA (FIPS 206), both originally expected earlier.
    • When NIST IR 8547's 2030/2035 deprecation schedule will be finalized, and whether its dates will move.
    • How the Web PKI will move to post-quantum certificates without unacceptable size and performance costs.
    • Whether AI vulnerability discovery ends up favouring defenders or attackers.
    • Whether the Oratomic estimate of about 10,000 neutral-atom qubits holds up under scrutiny, and how fast neutral-atom hardware can scale toward it.
    Story status

    Story status

    State
    developing
    Started
    2016-04-01
    Timeline entries
    23
    Last entry

    Timeline data (JSON)

    What this tracker covers

    The tracker follows two linked frontiers. The first is the move from RSA and elliptic-curve cryptography to post-quantum algorithms, driven by the risk that a future quantum computer could break today’s public-key systems.[7] The second is the use of AI to find, exploit and fix software vulnerabilities.[8][9] The start date marks NIST’s April 2016 report on post-quantum cryptography, which set out the threat that the project launched that year was meant to address.[10][11] For background, start with the the crash course crash course.

    Where things stand

    Key exchange is well advanced. Client support for post-quantum TLS on Cloudflare’s network rose from under 3% in early 2024 to over 60% in February 2026. The hybrid groups became an IETF standard in August 2026.[12][3] Authentication is next. Google and Cloudflare moved it to the top of their 2029 plans, and the US order gives federal systems until end-2031 for signatures.[13][14][15]

    What to watch next

    • NIST deliverables. The draft HQC standard was originally planned for about a year after March 2025, and FN-DSA (FIPS 206) is also pending.[16][5] A final IR 8547 would fix the 2030/2035 deprecation dates.[17]
    • US implementation. Agency migration plans, the FAR rule requiring contractors to comply with NIST’s post-quantum standards by end-2030, and NIST’s own pilot due by end-2027.[18][19]
    • Europe. National post-quantum roadmaps due from member states by the end of 2026.[20] High-risk use cases must stop relying on quantum-vulnerable public-key cryptography alone after 2030.[21]
    • Attack estimates. Any further drop in the qubits needed to break RSA or elliptic curves, and hardware progress on error-corrected qubits (see quantum computing tracker).[22]
    • Web PKI. Progress on post-quantum certificates, which the UK NCSC flags as one of the hardest problems.[23]
    • AI security. Wider access to Mythos-class models, further reports of AI-run attacks, and patch rates for AI-found bugs. See AI and cybersecurity debate.[24][25]

    Deadlines compared

    The main policy dates now come from primary documents. NSA’s CNSA 2.0 advisory expects US national security systems to finish moving to quantum-resistant algorithms by 2035, in line with National Security Memorandum 10. It sets earlier dates for exclusive use: 2030 for software signing and networking equipment, 2033 for operating systems.[26][27] Executive Order 14412 is dated 22 June 2026, its signing date, and was published in the Federal Register on 25 June.[28] It sets end-2030 for post-quantum key establishment and end-2031 for signatures in high-value federal systems.[15] The EU roadmap aims to move as many systems as practically feasible by 2035.[21] An April 2026 EU FAQ notes that this matches the UK, US and Canada, while Australia’s signals directorate recommends finishing by the end of 2030.[29]

    Attack estimates

    Estimates of the hardware needed to break public-key cryptography kept falling in 2025-2026.[30][22] In a preprint posted on 30 March 2026, researchers at Oratomic, Caltech and UC Berkeley argued that Shor’s algorithm could run at cryptographically relevant scales on as few as 10,000 reconfigurable neutral-atom qubits. Under their assumptions, P-256 discrete logarithms would take just a few days on 26,000 qubits.[31] The authors acknowledge substantial engineering challenges. The experiments they cite had computed on arrays of hundreds of qubits.[32] These are theoretical estimates, and no one knows when a cryptographically relevant machine will exist.[6]

    Timeline

    23 confirmed

    1. confirmed

      Anthropic expands tiered Cyber Verification Program[24]

    2. confirmed

      CISA and G7 issue post-quantum "Call to Action"[51][52]

    3. confirmed

      IETF publishes RFC 10024 for hybrid ML-KEM in TLS 1.3[3][50]

      Defines X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024.

    4. confirmed

      US Executive Order 14412 on post-quantum migration is signed[28][2][15][18]

      Dated 22 June 2026 and published in the Federal Register on 25 June. Deadlines are end-2030 for key establishment and end-2031 for signatures in high-value federal systems.

    5. confirmed

      Nine additional signature schemes advance to NIST's third round[49]

    6. confirmed

      EU FAQ compares national post-quantum deadlines[29]

      The EU's 2035 target matches the UK, US and Canada; Australia's is end-2030.

    7. confirmed

      Cloudflare targets full post-quantum security by 2029; Anthropic launches Project Glasswing[14][48][25]

    8. confirmed

      Google estimates ECC-256 falls to under 1,200 logical qubits[22][47]

      Disclosed with a zero-knowledge proof.

    9. confirmed

      Oratomic preprint puts Shor's algorithm within reach of about 10,000 neutral-atom qubits[31][32]

      A theoretical resource estimate, not a demonstration; P-256 in days on 26,000 qubits under the authors' assumptions.

    10. confirmed

      Google sets a 2029 post-quantum migration target[46][13]

    11. confirmed

      Post-quantum client support passes 60% on Cloudflare Radar[12]

    12. confirmed

      Anthropic reports a largely AI-run espionage campaign[9][45]

      Anthropic says AI performed 80-90% of the campaign; the account and its attribution come from Anthropic alone.

    13. confirmed

      Signal announces SPQR and the Triple Ratchet[44]

    14. confirmed

      Team Atlanta wins DARPA's AI Cyber Challenge[43][8]

    15. confirmed

      EU adopts coordinated post-quantum roadmap[20][21]

      Member states to start by end-2026; high-risk use cases migrated by end-2030; as many systems as feasible by 2035.

    16. confirmed

      RSA-2048 estimate falls below a million noisy qubits[30]

    17. confirmed

      UK NCSC sets 2028, 2031 and 2035 migration milestones[42]

    18. confirmed

      NIST selects HQC as backup to ML-KEM[39][16][40][41]

      NIST's fourth-round report picks HQC over BIKE and drops Classic McEliece pending ISO standardization.

    19. confirmed

      NIST drafts its transition plan (IR 8547)[38]

      Proposes deprecating 112-bit RSA and ECC after 2030 and disallowing quantum-vulnerable algorithms after 2035.

    20. confirmed

      Google's Big Sleep AI agent finds a SQLite vulnerability[36][37]

    21. confirmed

      Chrome announces move from Kyber to ML-KEM[35]

      Chrome 131 switches its hybrid key exchange to ML-KEM768+X25519 (codepoint 0x11EC).

    22. confirmed

      NIST publishes FIPS 203, 204 and 205[1][34]

      ML-KEM, ML-DSA and SLH-DSA become the first finalized post-quantum standards; NIST urges immediate integration.

    23. confirmed

      NSA announces the CNSA 2.0 algorithm suite[26][33]

      National security systems are to complete the move to quantum-resistant algorithms by 2035, with earlier exclusive-use dates by product type.

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13

    2. [2]

      Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks", published in the Federal Register on 25 June 2026, makes it US policy to move federal systems to NIST's post-quantum standards and cites the risk of adversaries collecting data now to decrypt later. confirmedas of 2026-06-25

    3. [3]

      In August 2026 the IETF published RFC 10024, a Proposed Standard defining three hybrid key agreement mechanisms for TLS 1.3, X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024, which combine ML-KEM with elliptic-curve Diffie-Hellman. confirmedas of 2026-08-10

    4. [4]

      As of April 2026, Cloudflare said over 65% of human traffic to its network was post-quantum encrypted. confirmedas of 2026-04-07

    5. [5]

      As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05

    6. [6]

      NIST says no one knows when a quantum computer able to threaten current encryption will appear, with expert estimates ranging from a few years to a few decades. confirmedas of 2026-10-10

    7. [7]

      A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10

    8. [8]

      In the AIxCC final, competing systems found 54 of the synthetic vulnerabilities across 63 challenges, patched 43 of them, and also discovered 18 real, non-synthetic vulnerabilities. confirmedas of 2025-08-08

    9. [9]

      Anthropic said the AI performed 80-90% of that campaign, with humans intervening at perhaps 4-6 critical decision points, and called it the first documented large-scale cyberattack executed without substantial human intervention. confirmedas of 2025-11-13

    10. [10]

      In 1994 Peter Shor of Bell Laboratories showed that quantum computers can efficiently solve the mathematical problems that public-key cryptosystems rely on, such as factoring and discrete logarithms. confirmedas of 2026-10-10

    11. [11]

      NIST launched its Post-Quantum Cryptography project in 2016 and received 69 candidate algorithms that met its submission requirements, which cryptographers then analyzed over several rounds. confirmedas of 2026-10-10

    12. [12]

      Cloudflare Radar measured client support for post-quantum encryption growing from under 3% of traffic at the start of 2024 to over 60% in February 2026. confirmedas of 2026-02-27

    13. [13]

      Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25

    14. [14]

      On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07

    15. [15]

      The order requires agencies to move all high value assets and high-impact systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. confirmedas of 2026-06-25

    16. [16]

      NIST planned a draft HQC standard about a year after March 2025, followed by a 90-day comment period and a final standard in 2027. confirmedas of 2025-03-11

    17. [17]

      As of October 2026 NIST IR 8547 remained an initial public draft dated 12 November 2024. confirmedas of 2026-10-10

    18. [18]

      The order directs the FAR Council to propose a rule requiring covered federal contractors to comply with NIST's post-quantum FIPS by 31 December 2030. confirmedas of 2026-06-25

    19. [19]

      The order directs NIST to run a PQC migration pilot on its own systems, to be completed by 31 December 2027. confirmedas of 2026-06-25

    20. [20]

      Under the EU coordinated roadmap adopted in June 2025, all member states should start transitioning to PQC by the end of 2026, and high-risk use cases should move to PQC no later than the end of 2030. confirmedas of 2025-06-23

    21. [21]

      The EU's coordinated PQC roadmap says the transition should be completed for as many systems as practically feasible by 2035, and that quantum-vulnerable public-key mechanisms should not be used on their own after the end of 2030 for high-risk use cases or after the end of 2035 for medium-risk ones. confirmedas of 2025-06-11

    22. [22]

      In March 2026 Google researchers estimated that breaking 256-bit elliptic-curve cryptography would need fewer than 1,200 logical qubits and 90 million Toffoli gates, or under 500,000 physical superconducting qubits running for a few minutes. confirmedas of 2026-03-31

    23. [23]

      The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20

    24. [24]

      On 6 October 2026 Anthropic expanded its Cyber Verification Program into three access tiers that give qualifying security professionals advanced cyber capabilities with reduced blocking classifiers, moving Project Glasswing members into the top tier. confirmedas of 2026-10-06

    25. [25]

      Anthropic said Claude Mythos Preview had found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. confirmedas of 2026-04-07

    26. [26]

      NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07

    27. [27]

      US National Security Memorandum 10 sets 2035 as the goal for mitigating as much quantum risk as feasible across federal systems. confirmedas of 2024-11-12

    28. [28]

      The Federal Register text dates Executive Order 14412 to 22 June 2026, the day it was signed; it was published in the Federal Register on 25 June 2026. confirmedas of 2026-06-25

    29. [29]

      An April 2026 EU FAQ on the roadmap says its 2035 target matches the UK, US and Canadian timelines, while Australia's signals directorate recommends finishing migration by the end of 2030. confirmedas of 2026-04-15

    30. [30]

      A May 2025 Google preprint estimated that 2048-bit RSA could be factored in less than a week by a quantum computer with fewer than a million noisy qubits, down from a 2019 estimate of 20 million noisy qubits. confirmedas of 2026-10-10

    31. [31]

      A preprint posted on 30 March 2026 by researchers at Oratomic, Caltech and UC Berkeley argued that Shor's algorithm could run at cryptographically relevant scales on as few as 10,000 reconfigurable neutral-atom qubits, with P-256 discrete logarithms taking just a few days on a 26,000-qubit system and RSA-2048 factoring one to two orders of magnitude longer. confirmedas of 2026-03-30

    32. [32]

      The Oratomic authors acknowledged that substantial engineering challenges remain, noting that neutral-atom experiments had so far shown computation on arrays of hundreds of qubits and trapping arrays of more than 6,000 qubits. confirmedas of 2026-03-30

    33. [33]

      CNSA 2.0 lists CRYSTALS-Kyber (standardised as ML-KEM) for key establishment and CRYSTALS-Dilithium (ML-DSA) for signatures, at their highest (Level V) parameters for all classification levels, and NIST SP 800-208 hash-based signatures for software and firmware signing. confirmedas of 2022-09-07

    34. [34]

      When it published the standards, NIST urged system administrators to start integrating them immediately because full integration would take time. confirmedas of 2024-08-13

    35. [35]

      Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13

    36. [36]

      In November 2024 Google's Big Sleep AI agent was reported to have found a previously unknown exploitable memory-safety bug in SQLite, which Google called the first public example of an AI agent doing so in widely used real-world software. confirmedas of 2024-11-01

    37. [37]

      The SQLite bug was reported in early October 2024, fixed the same day and never reached an official release. confirmedas of 2024-11-01

    38. [38]

      NIST's draft transition plan (IR 8547, November 2024) proposes deprecating RSA and elliptic-curve algorithms at 112-bit security after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035. confirmedas of 2024-11-12

    39. [39]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    40. [40]

      NIST's fourth round, which began in July 2022, studied four key-establishment candidates based on different maths from ML-KEM - BIKE, Classic McEliece, HQC and SIKE - and HQC was the only one chosen for standardization. confirmedas of 2025-03-11

    41. [41]

      NIST dropped Classic McEliece from its process because it is under consideration at ISO and parallel standards risked incompatibility; NIST said it may develop a standard based on the ISO version later. confirmedas of 2025-03-11

    42. [42]

      The UK NCSC's March 2025 guidance sets three milestones, define goals and complete discovery by 2028, carry out the highest-priority migration by 2031, and complete migration of all systems by 2035. confirmedas of 2025-03-20

    43. [43]

      On 8 August 2025 DARPA named Team Atlanta, with members from Georgia Tech, Samsung Research, KAIST and POSTECH, the winner of its two-year AI Cyber Challenge, with Trail of Bits second and Theori third. confirmedas of 2025-08-08

    44. [44]

      On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR), which runs alongside its Double Ratchet and mixes both keys in a "Triple Ratchet", rolling out without any user action. confirmedas of 2025-10-02

    45. [45]

      Anthropic reported that the model sometimes hallucinated credentials or overstated what it had found, which it said remains an obstacle to fully autonomous cyberattacks. confirmedas of 2025-11-13

    46. [46]

      On 25 March 2026 Google set 2029 as its timeline for post-quantum cryptography migration, citing progress in quantum hardware, quantum error correction and factoring resource estimates. confirmedas of 2026-03-25

    47. [47]

      Google disclosed its 2026 elliptic-curve attack estimate with a zero-knowledge proof instead of publishing the full attack details. confirmedas of 2026-03-31

    48. [48]

      On 7 April 2026 Anthropic announced Project Glasswing with partners including AWS, Apple, Cisco, CrowdStrike, Google, Microsoft and the Linux Foundation, to use its unreleased Claude Mythos Preview model to find and fix vulnerabilities in critical software. confirmedas of 2026-04-07

    49. [49]

      On 14 May 2026 NIST announced that nine candidates advanced to the third round of its additional digital signature schemes process (NIST IR 8610). confirmedas of 2026-05-14

    50. [50]

      The IETF Datatracker records RFC 10024 as published on 10 August 2026. confirmedas of 2026-08-10

    51. [51]

      On 3 September 2026 CISA and the G7 Cyber Security Working Group published "Preparing for the Post-Quantum Era - A Call to Action", urging organizations and governments to begin the transition to PQC. confirmedas of 2026-09-03

    52. [52]

      The G7 Cybersecurity Working Group said in September 2026 that several recent advances suggest quantum computers able to break widely used public-key cryptography may be developed sooner than anticipated. confirmedas of 2026-09-03

    Revision history (2)
    1. Page created.
    2. Added CNSA 2.0, EU 2035 and FAQ, fourth-round and Oratomic entries from primary sources; dated the EO to its 22 June signing and RFC 10024 to 10 August; added deadline and attack-estimate sections.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Dec 10, 2026.

    Cite this page

    "Post-quantum cryptography and security tracker." ContentLora, updated Oct 10, 2026. https://contentlora.com/events/cryptography-security-tracker

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.