Cloudflare
NETHybrid post-quantum key agreement enabled by default across its edge network.
Company profileWho supplies the post-quantum transition, from discovery tooling and PKI to secure silicon and quantum key distribution, plus where the capital is going.
Hybrid post-quantum key agreement enabled by default across its edge network.
Company profileC-QRL post-quantum library and integrations for European enterprises.
Company profilePublic CA piloting PQC certificate issuance and crypto-agility tooling.
Company profilePKI, HSM and certificate lifecycle products adding PQC support.
Company profileBasejumpQDN quantum-safe key distribution and risk advisory.
Company profileQuantum key distribution systems and quantum random number generators.
Company profileSmart cards and secure elements moving to PQC-capable chips.
Company profileTPM and secure element silicon with PQC firmware update paths.
Company profileCrypto-agility tooling and PQC certificate management.
Company profileMachine identity management with PQC-ready certificate automation.
Company profileQuantum-safe VPN and inspection features across its firewall line.
Company profileHardware IP cores and embedded libraries implementing NIST PQC standards.
Company profileQuantum Origin verifiable quantum randomness alongside quantum computing hardware.
Company profilePhio TX quantum-safe key delivery across existing networks.
Company profileQuProtect orchestration layer for post-quantum network overlays.
Company profileQuantum entropy chips for high-throughput key generation.
Company profileCryptographic discovery, inventory and migration tooling (AQtive Guard) for large enterprises.
Company profileLuna HSMs and payment security hardware with PQC firmware support.
Company profileLong-distance QKD networking trials with telecom operators.
Company profileGeneral-purpose HSMs shipping quantum-safe firmware.
Company profile| Company | Round | Amount | Lead investor | Announced |
|---|---|---|---|---|
| SandboxAQ | Growth extension | $450M | Nvidia / Google | 8 Apr 2025 |
| Quantinuum | Series B | $300M | JPMorgan Chase | 20 Nov 2024 |
| CryptoNext Security | Series A | $13M | Bpifrance | 2 Oct 2024 |
| PQShield | Series B | $37M | Addition | 19 Jun 2024 |
| Quside | Series A | $22M | Bullhost Capital | 5 Mar 2024 |
| SandboxAQ | Growth | $300M | T. Rowe Price | 14 Feb 2024 |
| QuSecure | Series A | $28M | Two Bear Capital | 24 Jan 2024 |
| Quantum Xchange | Series B | $15M | New Technology Ventures | 12 Sept 2023 |
| Keyfactor | Growth | $125M | Sixth Street Growth | 11 Jul 2023 |
| evolutionQ | Series A | $5M | Quantonation | 16 May 2023 |
Scored on published mandates, standards alignment, inventory requirements and deadline clarity.
The most complete mandate regime in the world. NIST has published the FIPS 203/204/205 standards and set 2030 deprecation and 2035 disallowance for RSA and ECC in IR 8547, NSA CNSA 2.0 binds national security systems to a 2033 exclusive-quantum-resistant date, OMB M-23-02 forces annual cryptographic inventories, and CISA runs cross-sector migration guidance. Federal research funding through DARPA, IARPA and DOE is also aimed squarely at lowering the qubit cost of factoring, which is what actually sets the deadline.
5 programs · view detailBSI pushes hybrid key exchange and long-term confidentiality; strong guidance on Classic McEliece and FrodoKEM.
1 program · view detailANSSI mandates hybrid schemes through at least 2030 and is skeptical of PQC-only deployments.
1 program · view detailNCSC published a three-phase national timeline: discovery by 2028, high-priority migration by 2031, completion by 2035.
1 program · view detailAIVD/TNO PQC Migration Handbook is widely used across European enterprises.
1 program · view detailCCCS aligned with NIST standards; federal roadmap targets high-priority systems by 2031.
1 program · view detailChina is on a parallel and deliberately independent track. The Institute of Commercial Cryptography Standards ran a national next-generation commercial cryptography competition and shortlisted domestic lattice and hash based schemes rather than adopting the NIST portfolio, and the Cryptography Law plus GM/T commercial standards give Beijing a mandate lever most states lack. Public research output on reducing qubit and circuit requirements for factoring, including hybrid quantum-classical and annealing based attempts, is unusually heavy relative to its published hardware, which is why China is the hardest actor to score.
3 programs · view detailASD set an aggressive 2030 deadline to remove RSA, ECDH and ECDSA from government systems.
1 program · view detailCRYPTREC evaluating PQC for the next e-Government recommended ciphers list.
0 programs · view detailKpqC competition selected domestic PQC algorithms; migration master plan targets 2035.
1 program · view detailMAS advisory requires financial institutions to build crypto inventories and pilot PQC.
1 program · view detailEarly-stage national roadmap; RBI and MeitY issuing preparatory guidance.
0 programs · view detailEvery migration deadline is really a bet on one number: how many qubits it takes to break RSA-2048. That number is not fixed. It has fallen by more than an order of magnitude in six years because the algorithms and error-correction schemes improved, not because the hardware did. Both the United States and China fund work aimed at pushing it lower.
Scoring note
High mandate clarity, high standards leverage, uneven execution below the federal level.
Scoring note
Lower published mandate clarity, but a distinct standards path and heavy investment on both sides of the problem.
Shor 1994, textbook circuit
About 2n logical qubits
Roughly 4,100 logical qubits for RSA-2048, with no error correction accounted for. This is the number that gets misquoted.
Read the paperGidney and Ekera 2019
20 million noisy qubits, 8 hours
The reference surface-code estimate that anchored a decade of planning assumptions.
Read the paperGidney 2025
Under 1 million noisy qubits, about 1 week
A 20x reduction in qubit count in six years through approximate modular arithmetic, magic state cultivation and yoked surface codes. The trend line, not the endpoint, is the planning input.
Read the paperChevignard, Fouque and Schrottenloher 2024
About 1,730 logical qubits, very long runtime
Trades qubit width for circuit depth. Shows the qubit threshold is a dial, not a wall, if you are willing to run longer.
Read the paperAnnealing and hybrid claims
Contested
Chinese groups have published D-Wave assisted factoring and Schnorr-lattice hybrid results. Peer review has so far shown these do not scale to RSA-2048, but they define where the research pressure is.
Read the paperPlanning implication: do not anchor your timeline to a qubit count. Anchor it to the length of time your data must stay confidential plus the time your migration will take. If that sum crosses any credible Q-Day estimate, the harvest-now-decrypt-later exposure already exists today.