{"event":"cryptography-security-tracker","title":"Post-quantum cryptography and security tracker","state":"developing","updated":"2026-10-10T00:00:00.000Z","entries":[{"id":"1wj713o","at":"2026-10-06T00:00:00.000Z","title":"Anthropic expands tiered Cyber Verification Program","status":"confirmed","cites":[{"id":"cryptography-security-cvp-expansion","n":24,"url":"https://www.anthropic.com/glasswing","publisher":"Anthropic","short":"Anthropic"}]},{"id":"nludm2","at":"2026-09-03T00:00:00.000Z","title":"CISA and G7 issue post-quantum \"Call to Action\"","status":"confirmed","cites":[{"id":"cryptography-security-g7-call","n":51,"url":"https://www.cisa.gov/resources-tools/resources/preparing-post-quantum-era-call-action","publisher":"CISA","short":"CISA"},{"id":"cryptography-security-g7-advances","n":52,"url":"https://cyber.gouv.fr/en/publications/jointly-led-international-publications/preparing-for-the-post-quantum-era-a-call-to-action/","publisher":"ANSSI (France)","short":"ANSSI"}]},{"id":"1ycqb7j","at":"2026-08-10T00:00:00.000Z","title":"IETF publishes RFC 10024 for hybrid ML-KEM in TLS 1.3","status":"confirmed","body":"Defines X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024.","cites":[{"id":"cryptography-security-rfc-10024","n":3,"url":"https://www.rfc-editor.org/rfc/rfc10024.txt","publisher":"IETF (RFC Editor)","short":"IETF"},{"id":"cryptography-security-rfc-10024-date","n":50,"url":"https://datatracker.ietf.org/api/v1/doc/docevent/?doc__name=rfc10024&type=published_rfc&format=json","publisher":"IETF","short":"IETF"}]},{"id":"1tzwry4","at":"2026-06-22T00:00:00.000Z","title":"US Executive Order 14412 on post-quantum migration is signed","status":"confirmed","body":"Dated 22 June 2026 and published in the Federal Register on 25 June. Deadlines are end-2030 for key establishment and end-2031 for signatures in high-value federal systems.","cites":[{"id":"cryptography-security-eo-signed-fr","n":28,"url":"https://www.govinfo.gov/content/pkg/FR-2026-06-25/pdf/2026-12909.pdf","publisher":"Federal Register (Executive Office of the President)","short":"Federal Register"},{"id":"cryptography-security-eo-14412","n":2,"url":"https://www.govinfo.gov/content/pkg/FR-2026-06-25/pdf/2026-12909.pdf","publisher":"Federal Register (Executive Office of the President)","short":"Federal Register"},{"id":"cryptography-security-eo-deadlines","n":15,"url":"https://www.govinfo.gov/content/pkg/FR-2026-06-25/pdf/2026-12909.pdf","publisher":"Federal Register (Executive Office of the President)","short":"Federal Register"},{"id":"cryptography-security-eo-contractors","n":18,"url":"https://www.govinfo.gov/content/pkg/FR-2026-06-25/pdf/2026-12909.pdf","publisher":"Federal Register (Executive Office of the President)","short":"Federal Register"}]},{"id":"1t2u7ks","at":"2026-05-14T00:00:00.000Z","title":"Nine additional signature schemes advance to NIST's third round","status":"confirmed","cites":[{"id":"cryptography-security-additional-sigs-round3","n":49,"url":"https://csrc.nist.gov/projects/post-quantum-cryptography/news","publisher":"NIST Computer Security Resource Center","short":"NIST Computer Security…"}]},{"id":"9mq8s8","at":"2026-04-15T00:00:00.000Z","title":"EU FAQ compares national post-quantum deadlines","status":"confirmed","body":"The EU's 2035 target matches the UK, US and Canada; Australia's is end-2030.","cites":[{"id":"cryptography-security-eu-faq-global-dates","n":29,"url":"https://ec.europa.eu/newsroom/dae/redirection/document/132120","publisher":"NIS Cooperation Group (European Commission)","short":"NIS Cooperation Group"}]},{"id":"gzllh4","at":"2026-04-07T00:00:00.000Z","title":"Cloudflare targets full post-quantum security by 2029; Anthropic launches Project Glasswing","status":"confirmed","cites":[{"id":"cryptography-security-cloudflare-2029","n":14,"url":"https://blog.cloudflare.com/post-quantum-roadmap","publisher":"Cloudflare","short":"Cloudflare"},{"id":"cryptography-security-glasswing","n":48,"url":"https://www.anthropic.com/glasswing","publisher":"Anthropic","short":"Anthropic"},{"id":"cryptography-security-mythos-vulns","n":25,"url":"https://www.anthropic.com/glasswing","publisher":"Anthropic","short":"Anthropic"}]},{"id":"1ij0fpe","at":"2026-03-31T00:00:00.000Z","title":"Google estimates ECC-256 falls to under 1,200 logical qubits","status":"confirmed","body":"Disclosed with a zero-knowledge proof.","cites":[{"id":"cryptography-security-google-ecc-2026","n":22,"url":"https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/","publisher":"Google Research","short":"Google Research"},{"id":"cryptography-security-google-ecc-zkp","n":47,"url":"https://research.google/blog/safeguarding-cryptocurrency-by-disclosing-quantum-vulnerabilities-responsibly/","publisher":"Google Research","short":"Google Research"}]},{"id":"1fwefga","at":"2026-03-30T00:00:00.000Z","title":"Oratomic preprint puts Shor's algorithm within reach of about 10,000 neutral-atom qubits","status":"confirmed","body":"A theoretical resource estimate, not a demonstration; P-256 in days on 26,000 qubits under the authors' assumptions.","cites":[{"id":"cryptography-security-oratomic-preprint","n":31,"url":"https://arxiv.org/abs/2603.28627","publisher":"arXiv (Oratomic, Caltech, UC Berkeley)","short":"arXiv"},{"id":"cryptography-security-oratomic-caveat","n":32,"url":"https://arxiv.org/abs/2603.28627","publisher":"arXiv (Oratomic, Caltech, UC Berkeley)","short":"arXiv"}]},{"id":"15835rc","at":"2026-03-25T00:00:00.000Z","title":"Google sets a 2029 post-quantum migration target","status":"confirmed","cites":[{"id":"cryptography-security-google-2029","n":46,"url":"https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/","publisher":"Google","short":"Google"},{"id":"cryptography-security-google-auth-priority","n":13,"url":"https://blog.google/innovation-and-ai/technology/safety-security/cryptography-migration-timeline/","publisher":"Google","short":"Google"}]},{"id":"xswuek","at":"2026-02-27T00:00:00.000Z","title":"Post-quantum client support passes 60% on Cloudflare Radar","status":"confirmed","cites":[{"id":"cryptography-security-cloudflare-client-growth","n":12,"url":"https://blog.cloudflare.com/radar-origin-pq-key-transparency-aspa/","publisher":"Cloudflare","short":"Cloudflare"}]},{"id":"629xix","at":"2025-11-13T00:00:00.000Z","title":"Anthropic reports a largely AI-run espionage campaign","status":"confirmed","body":"Anthropic says AI performed 80-90% of the campaign; the account and its attribution come from Anthropic alone.","cites":[{"id":"cryptography-security-anthropic-espionage-autonomy","n":9,"url":"https://www.anthropic.com/news/disrupting-AI-espionage","publisher":"Anthropic","short":"Anthropic"},{"id":"cryptography-security-anthropic-espionage-limits","n":45,"url":"https://www.anthropic.com/news/disrupting-AI-espionage","publisher":"Anthropic","short":"Anthropic"}]},{"id":"bjg0mc","at":"2025-10-02T00:00:00.000Z","title":"Signal announces SPQR and the Triple Ratchet","status":"confirmed","cites":[{"id":"cryptography-security-signal-spqr","n":44,"url":"https://signal.org/blog/spqr/","publisher":"Signal","short":"Signal"}]},{"id":"7cra6d","at":"2025-08-08T00:00:00.000Z","title":"Team Atlanta wins DARPA's AI Cyber Challenge","status":"confirmed","cites":[{"id":"cryptography-security-aixcc-winner","n":43,"url":"https://www.darpa.mil/news/2025/aixcc-results","publisher":"DARPA","short":"DARPA"},{"id":"cryptography-security-aixcc-results","n":8,"url":"https://www.darpa.mil/news/2025/aixcc-results","publisher":"DARPA","short":"DARPA"}]},{"id":"1dwojb6","at":"2025-06-23T00:00:00.000Z","title":"EU adopts coordinated post-quantum roadmap","status":"confirmed","body":"Member states to start by end-2026; high-risk use cases migrated by end-2030; as many systems as feasible by 2035.","cites":[{"id":"cryptography-security-eu-roadmap","n":20,"url":"https://digital-strategy.ec.europa.eu/en/policies/post-quantum-cryptography","publisher":"European Commission","short":"European Commission"},{"id":"cryptography-security-eu-2035-roadmap","n":21,"url":"https://ec.europa.eu/newsroom/dae/redirection/document/117507","publisher":"NIS Cooperation Group, EU PQC Workstream (European Commission)","short":"NIS Cooperation Group"}]},{"id":"16u57oz","at":"2025-05-21T00:00:00.000Z","title":"RSA-2048 estimate falls below a million noisy qubits","status":"confirmed","cites":[{"id":"cryptography-security-gidney-rsa-2025","n":30,"url":"https://arxiv.org/abs/2505.15917","publisher":"arXiv (Google Quantum AI author)","short":"arXiv"}]},{"id":"dppjxz","at":"2025-03-20T00:00:00.000Z","title":"UK NCSC sets 2028, 2031 and 2035 migration milestones","status":"confirmed","cites":[{"id":"cryptography-security-ncsc-timeline","n":42,"url":"https://www.ncsc.gov.uk/guidance/pqc-migration-timelines","publisher":"UK National Cyber Security Centre","short":"UK National Cyber Security…"}]},{"id":"r472qu","at":"2025-03-11T00:00:00.000Z","title":"NIST selects HQC as backup to ML-KEM","status":"confirmed","body":"NIST's fourth-round report picks HQC over BIKE and drops Classic McEliece pending ISO standardization.","cites":[{"id":"cryptography-security-hqc-selected","n":39,"url":"https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption","publisher":"NIST","short":"NIST"},{"id":"cryptography-security-hqc-timeline","n":16,"url":"https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption","publisher":"NIST","short":"NIST"},{"id":"cryptography-security-hqc-round4","n":40,"url":"https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf","publisher":"NIST","short":"NIST"},{"id":"cryptography-security-mceliece-iso","n":41,"url":"https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf","publisher":"NIST","short":"NIST"}]},{"id":"j8dn6c","at":"2024-11-12T00:00:00.000Z","title":"NIST drafts its transition plan (IR 8547)","status":"confirmed","body":"Proposes deprecating 112-bit RSA and ECC after 2030 and disallowing quantum-vulnerable algorithms after 2035.","cites":[{"id":"cryptography-security-ir8547-dates","n":38,"url":"https://nvlpubs.nist.gov/nistpubs/ir/2024/NIST.IR.8547.ipd.pdf","publisher":"NIST","short":"NIST"}]},{"id":"1hh4uia","at":"2024-11-01T00:00:00.000Z","title":"Google's Big Sleep AI agent finds a SQLite vulnerability","status":"confirmed","cites":[{"id":"cryptography-security-big-sleep-sqlite","n":36,"url":"https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html","publisher":"Google Project Zero","short":"Google Project Zero"},{"id":"cryptography-security-big-sleep-fixed","n":37,"url":"https://googleprojectzero.blogspot.com/2024/10/from-naptime-to-big-sleep.html","publisher":"Google Project Zero","short":"Google Project Zero"}]},{"id":"1ayj7nq","at":"2024-09-13T00:00:00.000Z","title":"Chrome announces move from Kyber to ML-KEM","status":"confirmed","body":"Chrome 131 switches its hybrid key exchange to ML-KEM768+X25519 (codepoint 0x11EC).","cites":[{"id":"cryptography-security-chrome-131-mlkem","n":35,"url":"https://security.googleblog.com/2024/09/a-new-path-for-kyber-on-web.html","publisher":"Google Security Blog","short":"Google Security Blog"}]},{"id":"q0q027","at":"2024-08-13T00:00:00.000Z","title":"NIST publishes FIPS 203, 204 and 205","status":"confirmed","body":"ML-KEM, ML-DSA and SLH-DSA become the first finalized post-quantum standards; NIST urges immediate integration.","cites":[{"id":"cryptography-security-fips-published","n":1,"url":"https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards","publisher":"NIST","short":"NIST"},{"id":"cryptography-security-nist-integrate-now","n":34,"url":"https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards","publisher":"NIST","short":"NIST"}]},{"id":"194oyo4","at":"2022-09-07T00:00:00.000Z","title":"NSA announces the CNSA 2.0 algorithm suite","status":"confirmed","body":"National security systems are to complete the move to quantum-resistant algorithms by 2035, with earlier exclusive-use dates by product type.","cites":[{"id":"cryptography-security-cnsa2-nsa","n":26,"url":"http://web.archive.org/web/20260928212413/https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF","publisher":"National Security Agency","short":"National Security Agency"},{"id":"cryptography-security-cnsa2-level-v","n":33,"url":"http://web.archive.org/web/20260928212413/https://media.defense.gov/2025/May/30/2003728741/-1/-1/0/CSA_CNSA_2.0_ALGORITHMS.PDF","publisher":"National Security Agency","short":"National Security Agency"}]}]}