Vendor landscape

Who supplies the post-quantum transition, from discovery tooling and PKI to secure silicon and quantum key distribution, plus where the capital is going.

Companies tracked
20
Funding rounds logged
10
Disclosed capital
$1.29B

Companies

Cloudflare

NET
Network and edge
San Francisco, United States

Hybrid post-quantum key agreement enabled by default across its edge network.

Company profile

CryptoNext Security

PQC libraries
Paris, France

C-QRL post-quantum library and integrations for European enterprises.

Company profile

DigiCert

PKI and certificates
Lehi, United States

Public CA piloting PQC certificate issuance and crypto-agility tooling.

Company profile

Entrust

PKI and certificates
Minneapolis, United States

PKI, HSM and certificate lifecycle products adding PQC support.

Company profile

evolutionQ

Advisory and software
Waterloo, Canada

BasejumpQDN quantum-safe key distribution and risk advisory.

Company profile

ID Quantique

QKD and QRNG
Geneva, Switzerland

Quantum key distribution systems and quantum random number generators.

Company profile

IDEMIA

Secure elements
Courbevoie, France

Smart cards and secure elements moving to PQC-capable chips.

Company profile

Infineon

IFX
Semiconductors
Neubiberg, Germany

TPM and secure element silicon with PQC firmware update paths.

Company profile

ISARA

PQC software
Waterloo, Canada

Crypto-agility tooling and PQC certificate management.

Company profile

Keyfactor

Certificate lifecycle
Cleveland, United States

Machine identity management with PQC-ready certificate automation.

Company profile

Palo Alto Networks

PANW
Network security
Santa Clara, United States

Quantum-safe VPN and inspection features across its firewall line.

Company profile

PQShield

PQC IP and libraries
Oxford, United Kingdom

Hardware IP cores and embedded libraries implementing NIST PQC standards.

Company profile

Quantinuum

Quantum and QRNG
Broomfield, United States

Quantum Origin verifiable quantum randomness alongside quantum computing hardware.

Company profile

Quantum Xchange

PQC networking
Bethesda, United States

Phio TX quantum-safe key delivery across existing networks.

Company profile

QuSecure

PQC software
San Mateo, United States

QuProtect orchestration layer for post-quantum network overlays.

Company profile

Quside

QRNG
Castelldefels, Spain

Quantum entropy chips for high-throughput key generation.

Company profile

SandboxAQ

PQC software
Palo Alto, United States

Cryptographic discovery, inventory and migration tooling (AQtive Guard) for large enterprises.

Company profile

Thales

HO.PA
HSM and security hardware
Paris, France

Luna HSMs and payment security hardware with PQC firmware support.

Company profile

Toshiba

6502
QKD
Tokyo, Japan

Long-distance QKD networking trials with telecom operators.

Company profile

Utimaco

HSM and security hardware
Aachen, Germany

General-purpose HSMs shipping quantum-safe firmware.

Company profile

Funding rounds

CompanyRoundAmountLead investorAnnounced
SandboxAQGrowth extension$450MNvidia / Google8 Apr 2025
QuantinuumSeries B$300MJPMorgan Chase20 Nov 2024
CryptoNext SecuritySeries A$13MBpifrance2 Oct 2024
PQShieldSeries B$37MAddition19 Jun 2024
QusideSeries A$22MBullhost Capital5 Mar 2024
SandboxAQGrowth$300MT. Rowe Price14 Feb 2024
QuSecureSeries A$28MTwo Bear Capital24 Jan 2024
Quantum XchangeSeries B$15MNew Technology Ventures12 Sept 2023
KeyfactorGrowth$125MSixth Street Growth11 Jul 2023
evolutionQSeries A$5MQuantonation16 May 2023

National readiness

Scored on published mandates, standards alignment, inventory requirements and deadline clarity.

United States

North America90

The most complete mandate regime in the world. NIST has published the FIPS 203/204/205 standards and set 2030 deprecation and 2035 disallowance for RSA and ECC in IR 8547, NSA CNSA 2.0 binds national security systems to a 2033 exclusive-quantum-resistant date, OMB M-23-02 forces annual cryptographic inventories, and CISA runs cross-sector migration guidance. Federal research funding through DARPA, IARPA and DOE is also aimed squarely at lowering the qubit cost of factoring, which is what actually sets the deadline.

5 programs · view detail

Germany

Europe78

BSI pushes hybrid key exchange and long-term confidentiality; strong guidance on Classic McEliece and FrodoKEM.

1 program · view detail

France

Europe76

ANSSI mandates hybrid schemes through at least 2030 and is skeptical of PQC-only deployments.

1 program · view detail

United Kingdom

Europe74

NCSC published a three-phase national timeline: discovery by 2028, high-priority migration by 2031, completion by 2035.

1 program · view detail

Netherlands

Europe66

AIVD/TNO PQC Migration Handbook is widely used across European enterprises.

1 program · view detail

Canada

North America64

CCCS aligned with NIST standards; federal roadmap targets high-priority systems by 2031.

1 program · view detail

China

Asia-Pacific62

China is on a parallel and deliberately independent track. The Institute of Commercial Cryptography Standards ran a national next-generation commercial cryptography competition and shortlisted domestic lattice and hash based schemes rather than adopting the NIST portfolio, and the Cryptography Law plus GM/T commercial standards give Beijing a mandate lever most states lack. Public research output on reducing qubit and circuit requirements for factoring, including hybrid quantum-classical and annealing based attempts, is unusually heavy relative to its published hardware, which is why China is the hardest actor to score.

3 programs · view detail

Australia

Asia-Pacific62

ASD set an aggressive 2030 deadline to remove RSA, ECDH and ECDSA from government systems.

1 program · view detail

Japan

Asia-Pacific58

CRYPTREC evaluating PQC for the next e-Government recommended ciphers list.

0 programs · view detail

South Korea

Asia-Pacific52

KpqC competition selected domestic PQC algorithms; migration master plan targets 2035.

1 program · view detail

Singapore

Asia-Pacific50

MAS advisory requires financial institutions to build crypto inventories and pilot PQC.

1 program · view detail

India

Asia-Pacific40

Early-stage national roadmap; RBI and MeitY issuing preparatory guidance.

0 programs · view detail

Deep dive: the United States, China and the qubit question

Every migration deadline is really a bet on one number: how many qubits it takes to break RSA-2048. That number is not fixed. It has fallen by more than an order of magnitude in six years because the algorithms and error-correction schemes improved, not because the hardware did. Both the United States and China fund work aimed at pushing it lower.

United States

Standardize in the open, mandate hard dates
  • NIST published FIPS 203 (ML-KEM), 204 (ML-DSA) and 205 (SLH-DSA) in August 2024, with HQC selected in March 2025 as a code-based backup.
  • NIST IR 8547 deprecates RSA and ECC at 112-bit security after 2030 and disallows them after 2035.
  • NSA CNSA 2.0 binds national security systems to exclusively quantum-resistant algorithms by 2033, with browser, server and firmware milestones earlier.
  • OMB M-23-02 and NSM-10 force annual cryptographic inventories and funded migration plans across federal agencies.
  • Federal money also flows to the attack side: DARPA Quantum Benchmarking Initiative, IARPA and DOE work exists to find out how few qubits a real attack needs.

Scoring note

High mandate clarity, high standards leverage, uneven execution below the federal level.

China

Build a sovereign stack, disclose selectively
  • The Institute of Commercial Cryptography Standards ran a national next-generation commercial cryptography competition and shortlisted domestic lattice and hash based public-key schemes instead of adopting the NIST portfolio.
  • The Cryptography Law plus GM/T standards let the state require approved domestic algorithms in critical information infrastructure once selection is final.
  • Hardware programs are public and credible: the Zuchongzhi superconducting line and the Jiuzhang photonic line, both from CAS and USTC.
  • Published Chinese research leans unusually hard on reducing the resource cost of attacks: hybrid quantum-classical factoring, quantum annealing approaches to lattice and factoring problems, and Schnorr-style sublinear-qubit claims.
  • Verification is the problem. Capability disclosure is partial, so readiness scoring here carries a wider error bar than for any other tracked state.

Scoring note

Lower published mandate clarity, but a distinct standards path and heavy investment on both sides of the problem.

How many qubits does RSA-2048 actually need?

Planning implication: do not anchor your timeline to a qubit count. Anchor it to the length of time your data must stay confidential plus the time your migration will take. If that sum crosses any credible Q-Day estimate, the harvest-now-decrypt-later exposure already exists today.