One set of algorithms now sits underneath almost every national plan for post-quantum
cryptography. When a United States federal agency published three standards in August 2024, a
contested question became a settled technical fact, and within months those choices were in
European certification catalogues, in national guidance from Paris to Bonn, and in the browsers
shipping to the world. The core is shared. What surrounds it is not.
The wrappers: an instrument cascade
The same algorithms arrive wrapped in very different instruments. In the European Union they are
becoming binding through NIS2 and DORA and, from December 2027, the Cyber Resilience Act, though
rarely by name. The obligation is carried by an undefined phrase, state of the art, whose
cryptographic content is supplied by an interpretive layer of certification guidance that sits
between legislation and practice. Elsewhere the same core is wrapped in soft national roadmaps,
and across much of the world in nothing at all.
The clocks diverge, against an uncertain threat
The timetables fragment as sharply as the instruments, and every one of them is set against a
threat that cannot be dated. Germany works to 2032; the European Union coordinates to 2035; the
United States now sets 2030 and 2033 deadlines for its federal systems; India, more aggressive
than any, wants its critical infrastructure quantum-safe by 2029 and the rest by 2033; Thailand's
cyber agency runs a phased roadmap that completes in 2035; while China alone publishes no fixed
national date. What each clock races is not an
observed danger but an expectation. Climate governance can point to rising temperatures;
quantum-safe governance has no such observable, only the qubit counts the industry says it will
reach and an uncertain threshold at which they break today's encryption. The gap between the two
is the whole risk: on its own roadmap one firm expects to cross that threshold around 2029, as
early as the most aggressive migration deadline. The deadlines do their work anyway, because
expectations are performative: they cascade vertically, a revised hardware estimate registering
at once in Washington's gates and Brussels' milestones, and they align horizontally, as when
four national agencies co-signed a single position in January 2024 that confined quantum key
distribution to niche uses and named post-quantum migration the priority. Each national clock
is, in the end, a wager that migration will finish before the machine arrives.
Drag sideways to see the full chart →
The quantum-safe race. Above, where industry says its qubit counts are heading, against the
threshold at which a machine could break RSA-2048; one stated target reaches it around 2029.
Below, when each actor must have migrated: from India's 2029 for critical infrastructure to
Thailand's and the EU's 2035, with the United States at 2030 and 2033 for federal systems,
while China alone sets no fixed date. Qubit figures and targets are industry-stated; deadlines
are the national instruments. Sources below.
The failure mode is congestion, not absence
A network of expectations can fail, and its failure mode is congestion rather than a missing
authority. The financial sector already faces DORA, national supervisors, G7 guidance and
sectoral roadmaps at once, and the result is deferral: ENISA finds only a small share of European
stakeholders have begun to migrate. The answer is not necessarily a central authority. It is to
make the state of the transition common knowledge, who stands where, on which instrument, to what
clock.
One shared core, many wrappers, held loosely together by a network of expectations. The Atlas
maps the wrappers, country by country, so the fragmentation can at least be read.
Sources
NIST, FIPS 203, 204 and 205: post-quantum cryptography standards (August 2024).
European Union: Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2022/2554 (DORA); Regulation (EU) 2024/2847 (Cyber Resilience Act), applicable from December 2027.
ENISA, European Union Agency for Cybersecurity: cryptographic certification (EUCC) and post-quantum readiness surveys (with ISACA).
NIS Cooperation Group: A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography (2026), setting the 2030 and 2035 milestones.
BSI (Germany): guidance on the migration to post-quantum cryptography.
United States: NSA Commercial National Security Algorithm Suite 2.0 (CNSA 2.0), with 2030 and 2033 milestones for national security systems; Executive Order 14412 (2026) setting federal deadlines; and Executive Order 14306 (2025), which removed the earlier mandatory procurement requirement.
India: Department of Science and Technology task force, Implementation of a Quantum-Safe Ecosystem in India (2026), targeting critical infrastructure by 2029 and full migration by 2033.
Thailand: NCSA QUANTA post-quantum readiness platform (pqc-learn.ncsa.or.th), a phased advisory roadmap recommending the NIST standards, with high-priority systems migrated by 2028 to 2029 and national completion by 2035.
China: OSCCA SM-series national cryptographic algorithms.
Industry qubit figures and targets: IBM Quantum roadmap (Condor, 2023; about 100,000 qubits by 2033); Google Quantum AI roadmap (Willow, 2024; about 1,000,000 qubits); Microsoft (Majorana 1, 2025); Amazon (Ocelot, 2025).
CRQC qubit-threshold estimate for RSA-2048: Gidney and EkerÄ (2019); Gidney (2025).
ANSSI, BSI, the Netherlands NLNCSA and the Swedish National Communications Security Authority: joint position paper on quantum key distribution (January 2024), prioritising post-quantum migration.
Global Risk Institute and evolutionQ: Quantum Threat Timeline Report (2024), and Mosca's risk inequality (x + y > z).
G7 Cyber Expert Group: statement on quantum computing risks to the financial sector (2024).
Bradford, A. (2020). The Brussels Effect. Oxford University Press.
Budde, B., and Konrad, K. (2019). Tentative governing in a dynamic network of expectations. Research Policy (the governance of expectations).
CEPS: Pupillo, L., et al. (2025). Strengthening the EU Transition to a Quantum-Safe World, Task Force report.
Data, code and structure are openly available: the Atlas is open source on
GitHub,
and archived on Zenodo (DOI: 10.5281/zenodo.21262284).
An explanation from the QSC Atlas, drawing on the CEPS Task Force on Strengthening the EU
Transition to a Quantum-Safe World (2025). How the Atlas classifies countries →
QSC Atlas explanation
One shared core, many wrappers
Why the post-quantum transition is fragmenting, and how it is governed all the same.
How the Atlas classifies countries →
One set of algorithms now sits underneath almost every national plan for post-quantum cryptography. When a United States federal agency published three standards in August 2024, a contested question became a settled technical fact, and within months those choices were in European certification catalogues, in national guidance from Paris to Bonn, and in the browsers shipping to the world. The core is shared. What surrounds it is not.
The wrappers: an instrument cascade
The same algorithms arrive wrapped in very different instruments. In the European Union they are becoming binding through NIS2 and DORA and, from December 2027, the Cyber Resilience Act, though rarely by name. The obligation is carried by an undefined phrase, state of the art, whose cryptographic content is supplied by an interpretive layer of certification guidance that sits between legislation and practice. Elsewhere the same core is wrapped in soft national roadmaps, and across much of the world in nothing at all.
The clocks diverge, against an uncertain threat
The timetables fragment as sharply as the instruments, and every one of them is set against a threat that cannot be dated. Germany works to 2032; the European Union coordinates to 2035; the United States now sets 2030 and 2033 deadlines for its federal systems; India, more aggressive than any, wants its critical infrastructure quantum-safe by 2029 and the rest by 2033; Thailand's cyber agency runs a phased roadmap that completes in 2035; while China alone publishes no fixed national date. What each clock races is not an observed danger but an expectation. Climate governance can point to rising temperatures; quantum-safe governance has no such observable, only the qubit counts the industry says it will reach and an uncertain threshold at which they break today's encryption. The gap between the two is the whole risk: on its own roadmap one firm expects to cross that threshold around 2029, as early as the most aggressive migration deadline. The deadlines do their work anyway, because expectations are performative: they cascade vertically, a revised hardware estimate registering at once in Washington's gates and Brussels' milestones, and they align horizontally, as when four national agencies co-signed a single position in January 2024 that confined quantum key distribution to niche uses and named post-quantum migration the priority. Each national clock is, in the end, a wager that migration will finish before the machine arrives.
Drag sideways to see the full chart →
The failure mode is congestion, not absence
A network of expectations can fail, and its failure mode is congestion rather than a missing authority. The financial sector already faces DORA, national supervisors, G7 guidance and sectoral roadmaps at once, and the result is deferral: ENISA finds only a small share of European stakeholders have begun to migrate. The answer is not necessarily a central authority. It is to make the state of the transition common knowledge, who stands where, on which instrument, to what clock.
One shared core, many wrappers, held loosely together by a network of expectations. The Atlas maps the wrappers, country by country, so the fragmentation can at least be read.
Sources
Data, code and structure are openly available: the Atlas is open source on GitHub, and archived on Zenodo (DOI: 10.5281/zenodo.21262284).
An explanation from the QSC Atlas, drawing on the CEPS Task Force on Strengthening the EU Transition to a Quantum-Safe World (2025). How the Atlas classifies countries →