Post-quantum migration observatory · dataset as of 2026-09-06

The world is already migrating to post-quantum cryptography.

QRQC tracks the standards, government deadlines, industries and technology dependencies shaping the global transition — with the evidence, document status and review date attached to every claim.

The meaningful quantum-risk clock is already running: migration deadlines, data lifetimes, procurement cycles and supply-chain dependencies all arrive before a cryptographically relevant quantum computer does.

Global map

Where each jurisdiction actually stands

Lens
Americas
Europe
Asia-Pacific
BandsObservedPlanningMobilizingExecutingBroad transitionEvidence insufficient

Canada

Canadian Centre for Cyber Security (CSE) · Treasury Board Secretariat
Executing

Government of Canada departments and agencies, primarily non-classified systems; CFDIR guidance extends to telecom and critical infrastructure

Milestones
  1. 2024-07CFDIR quantum-readiness best practices v04guidance
  2. 2025-06ITSM.40.001 publishedpolicy roadmap
  3. 2025-10SPIN takes effectmandate
  4. 2026Departmental plans and reportingmandate
  5. 2031-12High-priority systems migratedmandate
  6. 2035-12Remaining systems migratedmandate
Policy
Deadline maturity
Technical standards
Execution evidence
Supply-chain enablement
Evidence confidence
Why it matters

Canada pairs a technical roadmap with a compliance instrument, so every cryptographic dependency has to be located and reported, not simply acknowledged.

Evidence
Full jurisdiction record
Migration clock

Time to published deadlines

These are published policy milestones, not predictions of when a quantum computer will break encryption.

Industry impact

Where does quantum risk hit your industry?

Exposure, dependency classes and the actual published signal — with explicit cautions where no mandate exists.

Dependency graph

Why migration is a supply-chain problem

Your migration date is set by whoever is slowest on the path between a NIST algorithm and your workload.

Standards & authoritiesImplementationsTrust infrastructurePlatformsIndustry workflows
From standard to action

What does a standard actually require of you?

Each standard record separates its true document status from what it changes in practice for TLS, PKI, HSMs and devices.

Methodology

Every material claim is sourced, classified and last-reviewed.

Readiness here measures public evidence of preparation — never quantum-computer capability, and never a promise that a well-prepared jurisdiction is safe.

How QRQC verifies evidence