Executive Summary

Post-quantum cryptography is becoming a global capital-investment cycle, not a conventional cybersecurity update.
Between 2026 and 2031, governments and companies must identify cryptographic dependencies, redesign trust architectures, test hybrid systems and replace incompatible hardware.
The only transparent sovereign cost anchor is the preliminary US$7.1 billion estimate for priority United States federal systems during 2025–2035.
The aggregate global cost cannot yet be stated as a verified figure because governments have not published comparable inventories or accounting methodologies.
The United States holds the strongest standards and procurement position; China combines state direction with strategic opacity.
Europe has a common deadline but fragmented national execution, financing and certification capacity.
The United Kingdom has the clearest migration sequence; France and Germany possess strong assurance institutions and industrial suppliers.
Italy has credible technical guidance but remains exposed through SMEs, legacy public systems, healthcare infrastructure and industrial operational technology.
The decisive five-year competition will concern certification, hardware roots of trust, cloud migration, cryptographic inventories, specialist labour and procurement eligibility.
Post-quantum expenditure will therefore operate as a concealed form of industrial policy, redistributing contracts, technological dependence and sovereign control.

The Quantum Migration Bill: Security Becomes Industrial Policy

Quantum computing has not yet broken the cryptography securing banks, factories and governments. Yet the expenditure cycle has already begun. Post-quantum migration is not an algorithmic update: it is a reconstruction of digital trust spanning identity, cloud services, software signatures, hardware security modules, telecommunications and industrial control. Washington estimates US$7.1 billion merely to migrate priority federal systems over 2025–2035; Europe wants critical infrastructure transitioned by the end of 2030. The strategic question is therefore no longer whether organisations will pay, but when, to whom and under whose standards. Between 2027 and 2031, cryptographic compliance will redirect procurement towards certified chips, cloud platforms, security appliances and specialist services. What appears on balance sheets as cybersecurity expenditure will function as industrial policy—rewarding countries that can transform standards into products and exposing those that remain dependent on foreign trust infrastructure.

From Algorithm to Estate

On 13 August 2024, the US National Institute of Standards and Technology approved FIPS 203, FIPS 204 and FIPS 205, establishing ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – NIST – August 2024official standards notice.

The standards solve the mathematical-selection problem, not the migration. Vulnerable public-key cryptography remains embedded in certificate authorities, virtual private networks, application interfaces, payment systems, smart cards, code-signing services, hardware security modules, secure boot, vehicle electronics and factory controllers. NIST’s migration programme consequently requires organisations to find affected cryptography across hardware, software and services, construct inventories and prioritise replacement. Migration to Post-Quantum Cryptography – NIST National Cybersecurity Center of Excellence – verified August 2026official programme.

The real cost stack includes discovery tools, Cryptographic Bills of Materials, application refactoring, hybrid classical–post-quantum operation, certificate reissuance, hardware replacement, interoperability testing, certification, specialist labour and decommissioning. It also includes production interruptions when energy, transport or manufacturing equipment cannot be upgraded without safety review and scheduled shutdown. Migration therefore resembles a multiyear digital-transformation programme more than a conventional security patch.

Washington’s Procurement Machine

The United States has built the most complete transmission mechanism between cryptographic standards and industrial demand. On 22 June 2026, President Donald Trump signed an executive order directing the Office of Management and Budget and the National Cyber Director to coordinate an accelerated federal transition. It requires migration leadership in each agency, a Commerce Department pilot by 31 December 2027, and protection of high-value assets during 2030–2031. Fact Sheet: President Donald J. Trump Secures the Nation Against Advanced Cryptographic Attacks – White House – June 2026official fact sheet.

OMB Memorandum M-26-15, issued on 24 June 2026 by Director Russell T. Vought, divides execution into discovery during 2026–2027, pilots during 2027–2028, prioritised key-establishment migration during 2028–2030, signature migration in 2031 and completion of remaining systems by 2035. It explicitly links PQC to cloud migration, hardware-refresh schedules, automated inventories, zero-trust architecture and annual budget requests. Execution of the Migration to Post-Quantum Cryptography, M-26-15 – OMB – June 2026official memorandum.

The US Government Accountability Office recorded an initial OMB estimate of US$7.1 billion for priority federal systems across 2025–2035, while cautioning that it was a highly uncertain rough-order projection requiring annual revision. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – GAO – June 2025official audit. This is not the cost of the American economy: it excludes much private critical infrastructure, state government and national-security systems. Its importance is political. Federal demand will force suppliers to build validated capabilities into commercial cloud, identity, network and security products, allowing US firms to export the resulting standards and platforms.

Europe’s 2030 Test

Europe has a common deadline but no equivalent federal procurement machine. On 23 June 2025, the European Commission and the NIS Cooperation Group published a coordinated roadmap requiring every member state to begin transition by the end of 2026 and critical infrastructure to migrate no later than the end of 2030. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025official roadmap.

Commission Executive Vice-President Henna Virkkunen, responsible for technological sovereignty, security and democracy, presented PQC as essential to protecting Europe’s digital infrastructure. The deadline creates a market encompassing banking, energy, health, transport, telecommunications and public administration. It can support European secure chips, smart cards, industrial cybersecurity, certification laboratories and migration services. But execution remains divided among 27 national governments, regulators and assurance regimes.

The danger is a two-speed transition: major banks, defence contractors and telecommunications groups acquire certified systems, while hospitals, municipalities, regional utilities and smaller manufacturers accumulate cryptographic debt. European rules could then generate demand captured principally by American hyperscalers and non-European hardware vendors. Technological sovereignty will depend not on inventing a rival algorithm for symbolic reasons, but on controlling keys, certificate authorities, hardware roots of trust, evaluation facilities and supplier evidence while preserving international interoperability.

France: Certification as Power

France has moved furthest in converting national assurance into industrial advantage. ANSSI’s model requires hybridisation during the intermediate phase: established classical cryptography operates alongside post-quantum mechanisms so that introducing a new algorithm does not degrade present security. The agency’s framework allows security visas progressively to cover classical security, hybrid construction and quantum resistance. ANSSI Views on the Post-Quantum Cryptography Transition – ANSSI – January 2022, current edition verified August 2026official position.

ANSSI now reports the first two French certifications for products incorporating lattice-based PQC, covering solutions from Thales and Samsung evaluated by CEA-Leti. It has also surveyed approximately 50 ministries and strategic enterprises and around 30 potential transition-service providers, while supporting financial instruments for migration technologies. Cryptographie post-quantique – ANSSI – verified August 2026official programme.

France’s advantage lies in combining defence electronics, secure elements, smart-card expertise, public research and certification. Its risk is national isolation: a French visa generates greater industrial value if recognised across Europe. Paris must therefore turn ANSSI’s early expertise into European evaluation standards rather than an additional national compliance layer.

Germany: The Factory Problem

Germany’s exposure is concentrated in products expected to operate for decades: vehicles, industrial machinery, chemicals, energy systems and factory automation. BSI endorsed the European roadmap and its 2030 and 2035 milestones. NIS Cooperation Group Publishes EU Roadmap for Post-Quantum Cryptography – BSI – July 2025official German notice.

The German challenge is not simply migrating corporate IT. It is upgrading firmware signatures, machine identities, remote-maintenance channels and embedded trust anchors across deep supplier tiers. A cryptographically obsolete component can compromise the export eligibility of an entire vehicle or industrial platform. Replacement may require safety validation and plant shutdown rather than a remote software update.

This exposure can become an advantage. If German manufacturers integrate crypto-agility into equipment before international customers make it mandatory, “quantum-ready” engineering can become a new export-quality attribute. Failure would produce the opposite result: German industrial systems would depend on imported cryptographic modules and foreign cloud key-management services even as Berlin formally pursues technological sovereignty.

Britain’s Clearer Clock

The United Kingdom has published the clearest non-US sequence. NCSC requires complete discovery and an initial estate-wide plan by 2028, the migration of highest-priority services by 2031, and completion across systems, services and products by 2035. It estimates that large organisations may require two to three years merely for discovery and planning, followed by another two to three years for early migration. Timelines for Migration to Post-Quantum Cryptography – NCSC – March 2025official guidance.

The schedule gives British banks, insurers, telecommunications operators and government suppliers a common investment horizon. It also creates a professional-services opportunity. NCSC’s PQC consultancy pilot assures suppliers for cryptographic discovery, prioritisation and migration planning and is scheduled for review after 31 March 2027. Post-Quantum Cryptography Pilot – NCSC – verified August 2026official scheme.

Britain can export assurance, financial-infrastructure expertise and migration services. Its structural weakness is hardware dependence: domestic consulting may surround imported secure elements, HSMs and cloud platforms. The policy test is whether London retains intellectual property in discovery, middleware and financial protocols rather than becoming merely the implementation layer for foreign technology.

Italy’s Industrial Divide

Italy has a sound technical starting point but a more difficult execution structure. The Agenzia per la Cybersicurezza Nazionale has incorporated post-quantum solutions into its updated TLS guidance. Linee Guida Funzioni Crittografiche: Transport Layer Security – ACN – May 2026official Italian guidance.

The Italian estate combines sophisticated banks, defence and aerospace companies, energy groups and telecommunications operators with fragmented public administration, regional healthcare and manufacturing districts dominated by SMEs. Migration requirements will reach smaller firms through customer contracts before every supplier faces a direct legal mandate. An automotive, aerospace or machinery supplier unable to document cryptographic dependencies and secure-update mechanisms could lose access to international programmes.

Italy should not attempt to reproduce every American or French capability. It needs shared Cryptographic Bill of Materials methodologies, pooled public procurement, subsidised discovery for SMEs and laboratories specialising in embedded and industrial systems. ACN can convert regulatory fragmentation into a common national market. Without aggregation, regions, hospitals and SMEs will purchase separately, raising costs and reinforcing dependence on foreign integrators.

China’s Vertical Stack

China is building a more state-directed and less transparent ecosystem. In June 2025, the State-owned Assets Supervision and Administration Commission reported that China Electronics Technology Group had introduced the “Liangkai” anti-quantum family: cryptographic chips and cards, software modules, server and financial cryptographic machines, security gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – SASAC – June 2025official Chinese source.

The breadth of the portfolio reveals Beijing’s objective: control the vertical chain from chip to certificate rather than depend on foreign trust infrastructure. State banks, telecommunications operators and centrally administered enterprises can provide procurement scale. China may also export quantum-resistant functionality as part of telecommunications, cloud and digital-government platforms, creating long-term dependence through key management and device identity.

Yet Beijing has not publicly established a unified national deadline comparable to the US, EU or UK schedules. Nor do product announcements prove deployment scale or independent performance. China’s strategic opacity increases uncertainty for multinational companies: they may need separate cryptographic profiles, certifications and product lines for Chinese and Western markets.

The 2031 Allocation

The central scenario is an uneven but irreversible transition. Discovery and supplier mapping will dominate 2027; certification and early production deployment, 2028; high-value migration, 2029; critical-infrastructure and hardware replacement, 2030; signatures and trust chains, 2031. Digital signatures may become the hardest stage because code, firmware, credentials and machine commands require every verifier to accept the new format.

The winners will be vendors controlling validated HSMs, secure elements, certificate systems, cloud key management, discovery platforms and industrial gateways. The losers will be organisations that mistake policy publication for migration, or that discover embedded cryptography only when deadlines make replacement expensive.

Post-quantum readiness will thus become a condition of market access, insurability and investment quality. The emerging divide is not between states that understand quantum physics and those that do not. It is between states able to translate cryptographic rules into domestic capability—and those that finance a transition whose strategic value is captured elsewhere.


Navigational Index

  1. Capital Shock — Why migration extends from algorithms to hardware, identity, cloud, software supply chains and operational technology.
  2. Sovereign Competition — How the United States, China, Europe, Italy, France, the United Kingdom and Germany will convert security requirements into industrial advantage.
  3. Five-Year Outlook — Bayesian scenarios, competing hypotheses, migration milestones and leading indicators for 2027–2031.

Master Abstract

Capital Shock

Post-quantum migration is frequently misclassified as a cryptographic software update. Its real economic perimeter is considerably larger because modern cryptography is embedded in the mechanisms through which machines, people, applications and institutions establish trust. The migration surface includes public-key infrastructures, certificate authorities, code-signing systems, hardware security modules, secure elements, trusted platform modules, virtual private networks, payment authentication, application programming interfaces, cloud key-management systems, identity credentials, firmware verification, industrial-control devices, telecommunications infrastructure, connected vehicles and long-lived archival signatures. The approval of FIPS 203, FIPS 204 and FIPS 205 transformed post-quantum cryptography from a research problem into a deployable standards programme. These standards respectively specify ML-KEM for key establishment, ML-DSA for primary digital signatures and SLH-DSA as a hash-based signature alternative. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – National Institute of Standards and Technology – August 2024Official NIST standards notice. The standards do not, however, eliminate implementation risk. Organisations must first discover where vulnerable algorithms such as RSA, ECDH and ECDSA are used, including undocumented dependencies embedded in commercial products and inherited code. They must subsequently classify systems by data lifetime, operational criticality, replacement difficulty and supplier readiness. Migration expenditure therefore includes cryptographic discovery, Cryptographic Bills of Materials, protocol engineering, software remediation, dual-stack operation, hardware replacement, testing, certification, bandwidth remediation, latency management, specialist personnel, supplier negotiations, rollback capacity and decommissioning. The cost is consequently distributed across cybersecurity budgets, cloud modernisation, identity programmes, network refreshes, industrial automation, procurement and compliance. This accounting dispersion makes PQC a hidden industrial-policy variable: governments may generate large domestic demand without formally announcing a conventional industrial-subsidy programme.

The only credible public-sector monetary anchor currently available is the preliminary United States estimate recorded by the Government Accountability Office. According to GAO, the Office of Management and Budget produced a rough-order estimate of US$7.1 billion to migrate priority federal-agency systems between 2025 and 2035. GAO emphasised that the estimate carried a high degree of uncertainty and would require annual revision as agencies improved their inventories and costing methodologies. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – U.S. Government Accountability Office – June 2025Official GAO assessment. The figure must not be presented as the cost of the entire American transition: it concerns priority federal systems, excludes much of the private sector, state and local government, critical infrastructure and national-security systems, and does not establish a globally transferable unit cost. It nevertheless demonstrates that even a bounded governmental perimeter creates a multiyear capital programme comparable to previous identity, cloud and zero-trust transformations. Global expenditure cannot currently be calculated with forensic certainty because no harmonised international inventory exists and national authorities use different definitions of systems, cryptographic assets and eligible migration costs. Any precise global figure would therefore be a modelled scenario rather than an observed fact. A defensible costing framework must distinguish direct remediation from accelerated asset replacement, avoid counting ordinary modernisation twice, model the cost of running classical and post-quantum systems simultaneously, and account for the disproportionately high expense of long-lived industrial equipment. The hidden bill will be shaped less by algorithm licence costs than by dependency discovery, product assurance, hardware compatibility, integration labour and the commercial leverage of a limited population of certified suppliers.

Sovereign Competition

The United States enters the transition with the most powerful combination of standards authority, federal purchasing power, cloud concentration and security-product validation. The June 2026 executive order established federal coordination, required agency migration leadership and directed assistance to critical-infrastructure operators. Securing the Nation Against Advanced Cryptographic Attacks – The White House – June 2026Official executive order. OMB subsequently required agencies to mitigate as much quantum risk as feasible by 31 December 2030, submit migration plans, conduct discovery during 2026–2027, execute pilots during 2027–2028, migrate prioritised key-establishment functions during 2028–2030 and address digital signatures in 2031. The memorandum explicitly links PQC to cloud migration, hardware-refresh schedules, automated inventories, zero-trust architecture and annual budget requests. Execution of the Migration to Post-Quantum Cryptography, M-26-15 – Office of Management and Budget – June 2026Official OMB memorandum. This creates an industrial transmission mechanism: compliance clauses will move from federal tenders into cloud services, identity products, network equipment, security modules and software development standards. Vendors able to provide validated, crypto-agile products gain market access; suppliers that cannot demonstrate their cryptographic dependencies face exclusion or premature obsolescence. The American advantage is therefore not simply algorithmic. It lies in controlling the interaction between standards, validation, procurement, hyperscale infrastructure and international interoperability. The principal risks are budget fragmentation, incomplete inventories, dependency on ageing federal systems, scarcity of specialised personnel and excessive concentration in a small number of cloud, semiconductor and security vendors. The United States is nevertheless positioned to convert transition expenditure into exportable standards and products, making PQC migration simultaneously a cyber-defence programme, a market-access regime and an instrument of technological influence.

China presents a structurally different model. Its public evidence shows state-supported work across quantum communication, domestic commercial cryptography, anti-quantum products and international standardisation, but it does not reveal a unified national PQC migration calendar equivalent to the published American, European or British timelines. China Electronics Technology Group, a centrally managed state-owned enterprise, announced an anti-quantum cryptography product family and participation in relevant standards development. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025Official Chinese state-enterprise notice. China’s strategic advantage is its capacity to coordinate telecommunications operators, state banks, government systems, equipment manufacturers and state-owned enterprises through administrative direction and procurement. Its domestic cryptographic regime can also protect national suppliers from external competition and accelerate controlled trials. Its disadvantage is interoperability risk. If Chinese standards, certificate systems or implementation profiles diverge materially from NIST-derived ecosystems, multinational manufacturers, financial institutions and cloud providers may have to maintain separate cryptographic stacks. That would increase costs but could also create a durable Chinese-controlled market. The key analytical distinction is between PQC, which uses mathematical algorithms on existing computing infrastructure, and quantum key distribution, which depends on specialised communications infrastructure. Chinese policy visibly supports both; they are complementary in selected high-value environments but not economically interchangeable. Over the next five years, the most important indicators will be mandatory procurement clauses, national algorithm selections, certified module catalogues, telecom deployment requirements, banking-sector pilots and the incorporation of post-quantum mechanisms into domestic public-key and commercial-cryptography rules. Until these become transparent, any numerical Chinese migration-cost estimate must remain a scenario range rather than a verified national budget.

Europe and the National Execution Gap

The European Union has established a common strategic direction but has not created a single federal procurement machine comparable to Washington. The European roadmap requires member states to begin transitioning by the end of 2026 and calls for critical infrastructure to complete the transition as soon as possible and no later than the end of 2030. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025Official European roadmap. This schedule is strategically ambitious because Europe must coordinate national cybersecurity authorities, sector regulators, public administrations, telecommunications operators, banks, cloud providers, defence systems and industrial manufacturers while avoiding incompatible national profiles. ENISA has already identified that migration involves more than selecting algorithms: post-quantum systems must be integrated into existing protocols, hybrid configurations may be required, and the wider chain of dependent standards must be updated. Post-Quantum Cryptography: Integration Study – European Union Agency for Cybersecurity – October 2022Official ENISA study. Europe’s opportunity is to use cybersecurity certification, public procurement, semiconductor policy, digital-identity infrastructure and regulated-sector requirements to stimulate European products and services. Its principal risk is a two-speed transition in which wealthy states and major financial or industrial groups proceed rapidly while smaller administrations, hospitals, municipalities and SMEs remain dependent on foreign vendors or unsupported legacy equipment. PQC therefore tests whether European technological sovereignty can move from strategic language to coordinated capital execution. Without pooled procurement, shared testing infrastructure, common implementation profiles and financing mechanisms for smaller operators, the 2030 critical-infrastructure objective could produce fragmented compliance, duplicated certification expenditure and continued dependence on American cloud platforms and non-European hardware roots of trust.

Italy has established a credible technical starting point through the Agenzia per la Cybersicurezza Nazionale, which published an introduction to post-quantum and quantum-safe cryptography in July 2024. Crittografia Post-Quantum e Quantistica – Agenzia per la Cybersicurezza Nazionale – July 2024Official ACN technical paper. Italy’s exposure is not primarily the absence of institutional awareness. It is the composition of its digital and industrial estate: fragmented public administration, regional healthcare systems, municipal services, financial infrastructure, defence suppliers, telecommunications networks and manufacturing districts dominated by SMEs. Many industrial companies operate equipment whose useful life extends well beyond 2030 and whose cryptographic functions are embedded in firmware, remote-maintenance channels or proprietary control systems. Replacement decisions will therefore intersect with Industria 4.0, cloud migration, machinery investment, connected-product regulation and supply-chain qualification. Italy could convert the transition into industrial policy by developing shared cryptographic-discovery services, accredited testing facilities, procurement templates, migration financing for SMEs and specialised capabilities for embedded systems, automotive components, aerospace, defence, energy and industrial automation. Without these measures, compliance costs will be regressive: large banks, telecommunications groups and defence contractors will purchase migration capacity, while smaller suppliers will postpone action or depend on foreign integrators. The five-year Italian priority should consequently be a national cryptographic inventory methodology, sector-specific migration profiles, identification of long-lived operational technology, workforce development and integration of PQC requirements into public procurement and strategic supply-chain contracts. The risk is not merely cyber vulnerability; it is the loss of supplier eligibility when larger European or American customers begin requiring evidence of crypto-agility.

France holds a stronger assurance position because ANSSI has explicitly supported hybrid post-quantum mechanisms and anticipated French security approvals for products incorporating hybrid PQC. Avis de l’ANSSI sur la migration vers la cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – January 2024Official ANSSI position. France can connect migration demand to its defence-industrial base, sovereign-cloud agenda, digital-identity systems, smart-card expertise and security-certification ecosystem. The French hybrid approach reduces the danger of relying exclusively on comparatively new post-quantum algorithms because both classical and post-quantum components contribute to security when correctly combined. It nevertheless increases implementation complexity, message size, testing requirements and lifecycle-management cost. France’s industrial-policy advantage will depend on whether its national assurance mechanisms remain interoperable with European and international profiles rather than creating a costly national island. Germany, meanwhile, combines BSI guidance with an exceptionally large industrial and manufacturing attack surface. Kryptografie quantensicher gestalten – Federal Office for Information Security – 2023 editionOfficial BSI guidance. German exposure is concentrated in automotive systems, machinery, chemicals, energy, logistics and industrial control, where products remain operational for decades and security updates must satisfy safety, performance and certification constraints. Germany can capture value through industrial cybersecurity, embedded components, trusted hardware and engineering services, but delayed supplier action could make its export base vulnerable to foreign procurement requirements. In both countries, PQC migration will function as a supplier-selection mechanism long before it becomes a universal statutory obligation.

The United Kingdom has published the clearest operational timetable among the European jurisdictions examined. The National Cyber Security Centre expects organisations to complete discovery, assessment and initial planning by 2028, migrate their highest-priority services and refine their plans by 2031, and complete migration across systems, services and products by 2035. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025Official NCSC guidance. NCSC estimates that large organisations may require two to three years simply to discover their cryptographic estate, assess dependencies and construct an initial plan. It also identifies WebPKI and industrial-control protocols as particularly difficult migration areas because they require coordination across decentralised trust infrastructures and legacy operational systems. The United Kingdom’s advantage lies in its concentrated financial sector, cybersecurity capabilities, intelligence-informed guidance and capacity to align regulators with major infrastructure operators. London’s financial ecosystem could turn PQC readiness into an operational-resilience and insurance requirement, pushing migration expectations through payment networks, clearing systems, custodians, fintech suppliers and outsourced cloud services. The associated risk is a concentration of costs during the 2028–2031 period, when high-priority migration demand may collide with limited assurance, HSM, PKI and engineering capacity. British firms that complete discovery early will be able to integrate PQC into ordinary replacement cycles; late movers will face accelerated procurement, duplicated hybrid systems and scarcity premiums. This makes the UK schedule not merely a security roadmap but a forward signal for capital budgeting, vendor strategy and regulated outsourcing.

Five-Year Outlook, 2027–2031

The five-year baseline assigns the highest probability to a coordinated but uneven migration rather than either immediate cryptographic collapse or effortless universal adoption. The current Bayesian distribution is: 58% for regulation-led convergence around NIST-derived algorithms and compatible profiles; 14% for geopolitical fragmentation into partially incompatible Western and Chinese ecosystems; 12% for migration absorbed predominantly into normal technology-refresh cycles; 10% for threat-led acceleration following a material cryptanalytic, intelligence or security event; and 6% for prolonged budgetary delay. These percentages are structured analytical judgments, not government forecasts and not estimates of when a cryptographically relevant quantum computer will exist. The evidence supporting the baseline includes final NIST standards, the binding American migration sequence, the EU 2030 critical-infrastructure objective, the British 2028–2031–2035 roadmap and active French, German and Italian technical preparation. Evidence against rapid convergence includes unfinished protocol work, difficult WebPKI coordination, legacy industrial equipment, uncertain product assurance, incompatible domestic cryptographic regimes and the absence of complete asset inventories. During 2027, discovery platforms, CBOMs, consulting, pilots and procurement specifications should receive the strongest marginal growth. During 2028, validated modules, hybrid TLS, identity systems, HSMs and secure-boot products should move into broader procurement, while the absence of compliant products will become a measurable supplier risk. During 2029–2030, capital pressure should shift toward high-value systems, critical infrastructure, telecommunications, cloud gateways and long-lived sensitive data. By 2031, digital signatures, certificate hierarchies, device identity and high-priority industrial systems should become the decisive bottlenecks. The probability of schedule slippage will rise where organisations cannot distinguish cryptographic assets from ordinary software inventories or where suppliers refuse to disclose embedded dependencies.

Five competing hypotheses must remain under continuous review. H₁ — Regulated convergence: NIST algorithms become the principal international baseline, with regional implementation profiles but broad interoperability. Confirmation would come from common TLS, PKI, hardware-module and procurement standards. H₂ — Bloc fragmentation: China, Western states and possibly other jurisdictions develop divergent certification and algorithm ecosystems. Confirmation would include mandatory domestic algorithms, restricted cross-certification and duplicated product lines. H₃ — Refresh-cycle absorption: most migration cost is incorporated into scheduled cloud, network, identity and hardware modernisation. Confirmation would require limited emergency appropriations and high PQC availability in standard products. H₄ — Threat-led acceleration: a credible cryptanalytic breakthrough, intelligence disclosure or compromise campaign forces earlier deadlines and emergency replacement. Confirmation would include compressed mandates, extraordinary budgets and rapid deprecation of vulnerable algorithms. H₅ — Budget delay: governments publish roadmaps but defer implementation because inventories, personnel and products remain insufficient. Confirmation would include repeated deadline extensions, audit failures, unresolved legacy exceptions and increasing use of compensating controls. The present evidence favours H₁, but H₂ is more plausible for Chinese sovereign systems and H₅ remains materially plausible for municipal, healthcare, educational and SME environments. Analysts should therefore avoid a single global forecast and instead track sector- and jurisdiction-specific transitions.

The shadow dimensions of migration are equally important. “Harvest now, decrypt later” operations create a premium on protecting information whose strategic value persists for many years, including defence designs, diplomatic communications, genomic data, intellectual property and critical-infrastructure architecture. State intelligence services need no immediate quantum computer to benefit from collecting encrypted material today. Cyber-insurance markets may consequently begin demanding evidence of cryptographic inventories and migration planning, converting uncertain future risk into current premiums and exclusions. Liquidity effects will emerge when capital-intensive sectors must accelerate equipment replacement, while vendors with validated HSMs, secure elements, certificates, identity platforms and migration tooling gain pricing power. Private-equity and infrastructure investors will need to treat cryptographic debt as a technical liability during due diligence, especially for telecommunications, healthcare, payments, data centres and industrial platforms. Mercenary and criminal cyber actors are unlikely to possess cryptographically relevant quantum systems during the five-year horizon, but they can exploit migration failures, downgrade paths, misconfigured hybrid implementations, counterfeit certificates and abandoned legacy systems. The principal near-term threat is therefore not quantum decryption itself; it is the expanded attack surface created by a complex, multiyear transition. The optimal policy objective is consequently crypto-agility: the capacity to discover, replace, configure and retire algorithms without repeating an estate-wide crisis whenever standards or threat assessments change.

Five-Year Intelligence Model · 2027–2031

PQC Capital Shock Simulator

5,000 MODEL RUNS
Modelled 2027–31 expenditure 90% simulation interval
2031 priority readiness Conditional analytical estimate
Industrial-policy intensity Procurement and certification leverage
Peak annual pressure Largest annual capital share

Capital deployment profile

Structural risk

H₁ · 58%Regulated convergence
H₂ · 14%Bloc fragmentation
H₃ · 12%Refresh-cycle absorption
H₄ · 10%Threat-led acceleration
H₅ · 6%Budgetary delay

The expenditure ranges are analytical scenarios rather than government forecasts. They cover incremental labour, software, assurance, testing, hardware and programme overhead during 2027–2031. They exclude quantum-computer research, unrelated ordinary cybersecurity expenditure, losses from a cryptographic breach and costs after 2031. Jurisdictional estimates are independent envelopes and must not be added together.

Capital Shock: The Post-Quantum Reconstruction of Digital Industry

Post-quantum migration creates a capital shock because public-key cryptography is not a discrete application layer that organisations can replace by installing a new algorithmic package; it is a deeply embedded trust substrate connecting hardware, operating systems, identities, software dependencies, communications protocols, cloud services and physical infrastructure. The three principal standards approved by the United States National Institute of Standards and Technology in August 2024—FIPS 203 ML-KEM, FIPS 204 ML-DSA and FIPS 205 SLH-DSA—supply standardised mechanisms for key establishment and digital signatures, but they do not automatically migrate the systems in which RSA, Diffie–Hellman, ECDH, ECDSA and other quantum-vulnerable mechanisms remain embedded. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – National Institute of Standards and Technology – August 2024Verified official standards notice. NIST’s migration programme explicitly states that organisations must determine where vulnerable public-key algorithms are used across hardware, software and services, construct inventories, prioritise dependencies and test interoperability. Migration to Post-Quantum Cryptography – National Cybersecurity Center of Excellence, NIST – current programme page verified August 2026Verified official programme. This changes the economic object being purchased. Organisations are not buying “quantum-safe encryption” in isolation; they are financing the reconstruction of certificate chains, firmware-signing procedures, privileged-access systems, machine identities, key-management services, payment authentication, application interfaces, secure communications and industrial remote-access channels. The capital shock therefore comprises direct expenditure, accelerated replacement of otherwise serviceable assets, temporary duplication during hybrid operation, performance remediation, certification delays and the opportunity cost of specialist labour diverted from other digital-transformation programmes. Because these costs will be distributed among cybersecurity, cloud, identity, network, hardware, compliance and operational-technology budgets, conventional accounting will systematically understate the aggregate programme.

The full migration-cost architecture

Cost layerAssets and processes affectedPrincipal expenditure mechanismHidden balance-sheet effect2027–2031 pressure
Cryptographic discoverySource code, binaries, certificates, network traffic, appliances, embedded librariesScanning tools, CBOM platforms, manual validation, dependency mappingPreviously unrecorded cryptographic debt becomes visibleVery high in 2027–2028
Application remediationLibraries, APIs, authentication flows, signing services, custom applicationsRefactoring, integration, regression testing, protocol redesignCapitalised software may require premature modificationHigh throughout
PKI and digital identityCAs, certificates, smart cards, tokens, device identities, IAM, FICAMCertificate-profile redesign, enrolment, issuance, revocation, lifecycle replacementExisting credentials and trust anchors become transitional assetsRising sharply in 2028–2031
Hardware securityHSMs, TPMs, secure elements, cryptographic cards, roots of trustFirmware upgrade or physical replacement, validation and recertificationAccelerated obsolescence of installed hardwareHighest after validated products scale
Cloud and networkKMS, TLS termination, VPN, API gateways, load balancers, service meshesShared-responsibility renegotiation, hybrid handshakes, bandwidth and compute overheadVendor concentration and switching costs increaseContinuous; peaks near mandates
Software supply chainOpen-source libraries, commercial software, CI/CD, SBOM and signing systemsSupplier disclosure, new components, build-pipeline modification, code-signing migrationUnsupported dependencies can invalidate entire product linesSystemic from 2027
Operational technologyPLCs, SCADA, DCS, field devices, industrial gateways, remote maintenanceCompensating controls, gateways, staged shutdowns, hardware replacementLong-lived assets may become cryptographically strandedSevere but delayed
Assurance and certificationFIPS 140-3 modules, national approvals, sector qualificationLaboratory testing, documentation, validation queues, audit evidenceCertification scarcity creates supplier rentsHigh in 2028–2031
Dual operationClassical plus PQC algorithms, duplicate credentials, fallback infrastructureAdditional compute, larger messages, parallel monitoring and supportMigration temporarily enlarges rather than simplifies the estateHigh during transition
DecommissioningLegacy keys, certificates, archives, protocols and devicesRevocation, re-encryption, disposal, evidence retentionResidual liability persists after installation of new productsMaterial after 2029

The discovery phase is the first source of capital expansion because cryptography is ordinarily inventoried less accurately than servers, applications or network devices. A single business service can depend on a browser, API gateway, load balancer, application server, container image, cryptographic library, secrets manager, certificate authority, HSM, database connector and third-party identity provider, each using different algorithms for different purposes. A conventional asset inventory may identify these products while failing to record the cryptographic primitives, key sizes, certificate lifetimes, protocol negotiations, software calls and upstream dependencies that determine quantum exposure. NIST’s preliminary migration practice guide therefore examines discovery through CI/CD pipelines, network protocols, active scans and historical traffic captures rather than treating the problem as a static questionnaire. Migration to Post-Quantum Cryptography: Preparation for Considering the Implementation and Adoption of Quantum Safe Cryptography, NIST SP 1800-38A Preliminary Draft – National Institute of Standards and Technology – April 2023Verified official NIST practice guide. The resulting Cryptographic Bill of Materials must distinguish encryption, key establishment, signatures, authentication, integrity protection, code signing and certificate validation because each function has a different migration route. Discovery also creates a recursive supplier problem: an enterprise may inventory its direct applications but remain unable to determine whether a proprietary appliance embeds an outdated OpenSSL branch, an unsupported firmware component or a hardware accelerator that cannot process new key and signature formats. Manual discovery is consequently expensive and incomplete, while automated discovery generates false positives and still requires interpretation. The expenditure curve begins before any protected production transaction moves to PQC: organisations must purchase tooling, establish governance, classify data longevity, negotiate supplier disclosures and create migration plans. This explains why expenditure precedes visible deployment by several budget cycles and why firms that wait for a confirmed cryptographically relevant quantum computer would encounter a non-compressible discovery delay.

The American federal programme demonstrates how migration converts cryptographic risk into compulsory budgeting and procurement. In June 2026, the Office of Management and Budget required agencies to mitigate as much quantum risk as feasible by 31 December 2030, submit migration plans, integrate PQC into governance and use automated discovery where appropriate. It established a phased sequence: strategy, planning and discovery during 2026–2027; pilots and early migration during 2027–2028; prioritised key-establishment migration during 2028–2030; digital-signature migration in 2031; and completion of remaining migration by 2035. The memorandum further instructs agencies to integrate PQC into cloud migrations, software-development lifecycles and hardware-refresh schedules, while identifying systems incapable of supporting PQC or hybrid cryptography for replacement or decommissioning. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026Verified official memorandum. GAO previously reported an initial US$7.1 billion rough-order estimate for priority federal systems across 2025–2035, while warning that the number carried substantial uncertainty and required annual updates. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – U.S. Government Accountability Office – June 2025Verified official audit. This is not a complete American cost estimate: it excludes large portions of private critical infrastructure, state and local government, commercial finance, telecommunications, healthcare and many national-security systems. Its analytical importance lies elsewhere. It proves that a limited priority perimeter already generates a multibillion-dollar programme before the broader economy is counted. It also shows how procurement clauses can function as industrial policy by redirecting expenditure toward validated modules, discovery platforms, cloud services, identity architecture, secure hardware and systems integration.

Five-year capital-deployment sequence

YearDominant activityMain assets entering expenditureCost characterCritical decision gate
2027Inventory, governance and pilotsCBOM tools, code scanners, PKI inventories, pilot HSMs, test environmentsLabour- and consulting-intensiveCan the organisation identify cryptography by function and owner?
2028Product qualification and early migrationCloud gateways, VPNs, identity systems, HSMs, signing servicesMixed operating and capital expenditureAre validated products interoperable and contractually supported?
2029High-value production migrationSensitive-data systems, financial services, government identity, telecom controlCapital-intensive deploymentCan hybrid operation meet performance and availability requirements?
2030Critical-infrastructure compressionOT gateways, high-impact systems, long-lived data, regulated platformsReplacement and assurance shockWhich legacy assets require replacement, isolation or formal exception?
2031Signature and trust-chain bottleneckCode signing, firmware signing, certificate authorities, device identity, archivesCoordination- and certification-intensiveCan end-to-end trust chains operate without classical-only dependencies?

Hardware converts the migration from software remediation into capital expenditure because cryptographic operations are frequently anchored in devices designed around fixed interfaces, memory budgets, signature sizes and certification assumptions. HSMs protect high-value keys and execute signing or key-management operations within controlled boundaries; TPMs and secure elements establish device identity, measured boot and attestation; network accelerators terminate encrypted sessions; smart cards and tokens carry credentials; embedded controllers verify firmware and remote commands. Some equipment can obtain PQC through firmware, but other equipment lacks memory, processing capacity, configurable libraries or sufficient certificate storage. Even when hardware can technically execute ML-KEM or ML-DSA, its previous certification may not cover the new implementation, forcing revalidation before regulated deployment. The OMB memorandum identifies approximately 1–2 KB signatures for ML-DSA as a potential bandwidth constraint in certain use cases and describes SLH-DSA signatures as reaching tens of kilobytes with slower signing performance. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026Verified official technical annex. These characteristics matter for constrained devices, high-volume authentication, certificate chains, satellite links and industrial protocols. China’s state-owned sector illustrates the emerging hardware-product stack: China Electronics Technology Group reported an anti-quantum family encompassing cryptographic chips, cards, software modules, server and financial cryptographic machines, gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025Verified Chinese state source. The disclosure does not prove national-scale deployment, but it demonstrates that the transition is already being industrialised as an integrated hardware-and-software market rather than a purely mathematical standard.

Identity creates a separate capital shock because post-quantum key establishment does not automatically resolve the migration of digital signatures, certificate hierarchies and trust anchors. Enterprise identity includes employees, customers, administrators, applications, workloads, devices, robots, vehicles, industrial controllers and software artefacts. Each identity may rely on certificates, signed tokens, authentication keys, directory services, privileged-access controls and revocation infrastructure. A certificate authority cannot simply begin issuing larger PQC certificates without considering relying-party compatibility, path validation, certificate transparency, revocation lists, enrolment systems, smart-card capacity and root-store distribution. Code-signing and firmware-signing transitions are even more sensitive because verification keys may be embedded in devices expected to remain operational for decades. If an immutable bootloader recognises only an older signature format, migration may require an intermediate firmware release, a hybrid trust chain, an external gateway or complete device replacement. The British National Cyber Security Centre identifies WebPKI and industrial-control protocols as especially challenging because decentralised participants must coordinate their transition and many industrial systems still lack modern cryptographic architectures. It sets operational milestones of complete discovery and initial planning by 2028, high-priority migration by 2031 and broad completion by 2035. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025Verified official UK guidance. The financial consequence is a multi-generational identity estate: classical-only credentials, hybrid credentials and fully post-quantum credentials may coexist, multiplying issuance, revocation, monitoring and support requirements. Identity becomes one of the largest hidden cost centres because failure does not merely expose confidentiality; it can invalidate authentication, software provenance, transaction authorisation and operational command integrity.

Cloud migration can reduce unit costs by centralising cryptographic services, yet it simultaneously concentrates strategic dependency and reallocates costs through subscription pricing. Cloud key-management services, certificate managers, secrets stores, API gateways, service meshes, identity platforms, serverless runtimes and managed databases each divide responsibility between provider and customer. A hyperscaler may upgrade its infrastructure-level TLS while leaving customers responsible for application certificates, custom libraries, encrypted archives, workload identities and third-party appliances. OMB therefore directs federal agencies to engage cloud providers explicitly to allocate PQC responsibilities within the shared-responsibility model. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026Verified official memorandum. Hybrid cryptography increases this complexity because a connection may combine a conventional mechanism with a post-quantum mechanism, preserving classical security if the newer implementation proves defective but increasing handshake size, compute demand, operational states and failure modes. ENISA’s integration study analyses post-quantum integration into established protocols, double encryption, double signatures and the need to update the standards chain surrounding TLS, VPN and other systems. Post-Quantum Cryptography: Integration Study – European Union Agency for Cybersecurity – October 2022Verified official study. From a capital-allocation perspective, cloud centralisation can convert an enterprise hardware purchase into recurring operating expenditure while embedding future switching costs. If only a small number of providers deliver validated PQC across identity, HSM, network and data services, migration may reinforce hyperscaler concentration. Procurement authorities must therefore measure not only readiness but also portability, algorithm configuration, evidence access, certificate ownership, exit rights and the capacity to replace cryptographic providers without rewriting applications.

Software supply chains amplify the shock through dependency inheritance. A software producer may write no cryptographic algorithm directly yet depend on libraries, operating-system APIs, container images, package managers, build tools, code-signing services and third-party components that implement vulnerable cryptography. An enterprise migration can therefore fail because one nested dependency remains classical-only, one supplier cannot produce an upgrade, or one signing chain cannot validate a new artefact. NIST’s discovery guidance explicitly covers vulnerable algorithms used in CI/CD pipelines and cryptographic dependencies, while CISA’s product guidance spans hardware and software categories whose suppliers must incorporate post-quantum standards. Product Categories for Technologies That Use Post-Quantum Cryptography Standards – Cybersecurity and Infrastructure Security Agency – January 2026Verified official CISA guidance. The immediate cost is not limited to library replacement. Organisations must preserve reproducible builds, retest applications, regenerate keys, modify certificate profiles, update interfaces, re-sign artefacts, validate deployment agents and maintain backward compatibility. Supplier contracts must specify algorithm support, crypto-agility, disclosure obligations, update periods, vulnerability response, certification status and liability for embedded components. This creates a market-selection mechanism: suppliers able to document cryptographic dependencies and support configurable algorithms will retain access to regulated and government customers, whereas opaque or abandoned products become procurement liabilities. The “shadow” market includes specialist migration consultancies, discovery-platform vendors, assurance laboratories, offensive-testing teams and contractors capable of exploiting misconfigured transitions. Cybercriminal and state-aligned operators do not require a cryptographically relevant quantum computer to benefit; they can target downgrade paths, fallback configurations, duplicate credentials, poorly integrated libraries and abandoned devices. The near-term security danger is therefore transition complexity rather than direct quantum decryption, and the expenditure required to manage that complexity belongs inside the migration budget.

Operational technology produces the most difficult cost asymmetry because its assets are expensive, safety-critical, geographically dispersed and designed for service lives far longer than ordinary IT. Industrial control systems include programmable logic controllers, distributed control systems, supervisory control and data acquisition platforms, protection relays, sensors, gateways, engineering workstations and remote-maintenance channels. Cryptography may protect firmware, vendor access, telemetry, safety commands and machine identity, but many devices have limited memory and compute capacity or rely on proprietary protocols. Replacing a certificate or library in an office application can occur during routine maintenance; replacing a cryptographic component in a refinery, power grid, railway, port or production line may require safety review, planned outage, recertification and coordination with original-equipment manufacturers. CISA’s OT analysis warns that future quantum capabilities could affect confidentiality and integrity while emphasising inventory and prioritisation across industrial environments. Post-Quantum Considerations for Operational Technology – Cybersecurity and Infrastructure Security Agency – October 2024Verified official CISA report. The practical migration sequence is therefore risk-based: protect long-lived sensitive data and remote-access paths first; introduce quantum-resistant gateways where endpoints cannot migrate; require PQC readiness in new equipment; align replacement with shutdown schedules; and isolate assets for which no safe upgrade exists. Germany and Italy face particularly large industrial exposures because machinery, automotive supply chains, energy systems and SME manufacturers operate extensive embedded estates. Italy’s ACN has incorporated post-quantum solutions into updated TLS guidance, demonstrating that national implementation is moving from conceptual awareness toward protocol-level recommendations. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026Verified official Italian guidance. The industrial-policy question is whether governments finance shared testing and SME migration or permit compliance costs to eliminate smaller suppliers.

Comparative capital-shock matrix

JurisdictionBinding or published migration signalPrimary capital-pressure vectorIndustrial capture opportunityPrincipal execution risk
United StatesFederal discovery, pilots, priority migration and 2031 signature phaseFederal systems, cloud, identity, validated modulesStandards, hyperscalers, cyber tools, HSMs, federal procurementFragmented inventories and supplier concentration
ChinaState-enterprise products and sectoral research; no verified unified public deadlineDomestic cryptographic hardware, finance, telecom and state systemsChips, cards, gateways, CA and key-management ecosystemsInternational interoperability and strategic opacity
European UnionTransition commencement by end-2026; critical infrastructure by end-2030Cross-border regulation, certification and critical infrastructureEuropean cyber services, trusted hardware and certificationFragmented national execution and duplicated assurance
United Kingdom2028 discovery, 2031 priority migration, 2035 completionFinance, government, telecom and WebPKIAssurance services, fintech security and consultingConcentrated demand in 2028–2031
FranceHybrid approach and national security assuranceDefence, sovereign cloud, digital identity and smart cardsSecurity certification and trusted productsNational profiles could raise interoperability costs
GermanyBSI-led preparation combined with EU deadlineAutomotive, machinery, energy and embedded OTIndustrial cybersecurity and secure componentsLong asset lives and extensive supplier tiers
ItalyACN technical guidance within EU timetablePublic administration, healthcare, telecom, defence and SME manufacturingShared migration services and embedded-system expertiseFinancing, skills, fragmented procurement and legacy OT
RussiaOfficial financial strategy recognises quantum and post-quantum encryption as prospective cybersecurity directionsState finance, domestic cryptography and sovereign infrastructureDomestic algorithms and state-directed systemsSanctions, technological isolation and limited public cost transparency

The Russian and Chinese evidence reinforces the geopolitical conclusion that migration will not produce a perfectly uniform global market. The Bank of Russia’s financial-technology programme for 2025–2027 identifies quantum computing as a challenge to existing cryptographic protocols and lists quantum and post-quantum encryption among promising cybersecurity directions; it also records Russian government roadmaps for quantum computing and communications. Main Directions for Financial Technology Development for 2025–2027 – Bank of Russia – October 2024Verified official Russian central-bank document. This source does not establish a nationwide Russian PQC deployment deadline or a published migration budget, and no such claim should be inferred. It does show that financial regulators outside the Western standards ecosystem are integrating quantum-resilience considerations into strategic planning. China’s official product disclosures similarly demonstrate engineering activity without establishing a transparent national cost envelope. These gaps are analytically important: opaque standards selection forces multinational banks, manufacturers and cloud providers to maintain compatibility reserves, potentially duplicate products and price geopolitical change into contracts. The capital shock therefore includes a fragmentation premium comprising multiple cryptographic profiles, local certification, separate key infrastructures, restricted source-code access, domestic hardware requirements and the inability to reuse validation evidence across jurisdictions. For exporters, compliance will become a market-access issue comparable to data localisation or cybersecurity certification. For investors, the relevant diligence questions are whether a portfolio company knows its cryptographic dependencies, whether its products can negotiate multiple algorithms, whether hardware roots of trust can be upgraded, and whether customer contracts allocate the cost of regulatory divergence. A firm may be technically quantum-ready in one jurisdiction yet commercially excluded in another because its implementation, certification or supply chain does not satisfy sovereign rules.

Structural analytic model and competing hypotheses

HypothesisInitial probabilityEvidence that would increase probabilityEvidence that would reduce probabilityCapital consequence
H₁ — Standards-led convergence46%Common protocol profiles, reciprocal validation, widespread ML-KEM/ML-DSA adoptionMandatory incompatible national suitesLower duplication, strong scale economies
H₂ — Bloc fragmentation18%Domestic algorithm mandates, restricted certification, separate root storesInternational mutual recognitionHigh fragmentation premium
H₃ — Refresh-cycle absorption16%PQC becomes standard in ordinary cloud, network and device upgradesLarge emergency appropriations and hardware shortagesLower incremental cost but slower visibility
H₄ — Threat-triggered acceleration11%Credible cryptanalytic event, urgent government directives, emergency budgetsStable threat assessments and orderly deadlinesSevere short-term cost spike
H₅ — Budget-constrained delay9%Missed inventories, product shortages, repeated deadline extensionsPooled procurement and dedicated financingAccumulating legacy exposure and later replacement shock

The Bayesian baseline should be updated against observable implementation evidence rather than quantum-computing publicity. The most discriminating indicators are the number and type of validated cryptographic modules; publication of final protocol profiles; adoption of PQC requirements in public tenders; HSM and secure-element availability; migration-plan audit findings; certificate-lifecycle changes; OT supplier roadmaps; cloud contractual terms; and whether regulators require CBOM evidence. The European Union’s coordinated roadmap establishes that member states should begin transitioning by the end of 2026 and critical infrastructure should move no later than the end of 2030. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025Verified official policy statement. That timetable increases the probability of H₁ inside Europe, but uneven national financing preserves H₅ risk for smaller operators. American federal procurement and NIST standards also favour convergence, while Chinese and Russian sovereign-technology incentives raise H₂. Monte Carlo cost modelling should therefore use scenario-conditioned variables rather than one deterministic global estimate. A defensible model defines total migration expenditure C as the sum of discovery D, software S, identity I, hardware W, cloud N, OT O, assurance A, dual-operation U and decommissioning R, adjusted for schedule compression K and fragmentation F. In plain notation: C = (D + S + I + W + N + O + A + U + R) × K × F. No subscripts are necessary because the expression contains only aggregate variables. The largest uncertainty is not algorithm cost but the interaction of W, O, K and F: hardware and OT replacement become radically more expensive when deadlines compress or jurisdictional requirements diverge.

Monte Carlo five-year scenario envelope

VariableBase distributionLow-stress interpretationHigh-stress interpretation
Discovery completenessTriangular: 60%, 82%, 96%Existing inventories provide usable coverageHidden dependencies create repeated discovery cycles
Supplier readinessTriangular: 45%, 70%, 92%Vendors deliver upgrades within planned refreshProprietary and embedded products remain unsupported
Hardware replacement shareTriangular: 12%, 25%, 48%Firmware and software upgrades dominateHSM, secure-element and OT replacement accelerates
Hybrid-operation premiumTriangular: 6%, 14%, 29%Limited dual-stack periodMultiple credential and protocol generations coexist
Certification delayTriangular: 3, 9, 20 monthsValidation capacity scales quicklyLaboratory and assurance queues constrain deployment
Schedule-compression factor KTriangular: 0.96, 1.12, 1.45Migration follows lifecycle replacementmandates force expedited procurement
Fragmentation factor FTriangular: 1.00, 1.08, 1.27International profiles remain compatiblebloc-specific implementations require duplication
OT outage premiumTriangular: 1.05, 1.22, 1.65Upgrades align with maintenance windowsemergency shutdowns and safety review dominate

A 5,000-run scenario model using these variables should not be interpreted as a verified world expenditure forecast because no harmonised global cryptographic inventory exists. Its proper function is to identify the distribution of cost pressure and the variables that management can control. Under a controlled-transition case, discovery begins early, supplier requirements enter contracts before renewal, hardware replacement aligns with normal refresh schedules and hybrid operation remains bounded. Under the central case, the largest annual expenditure occurs in 2029–2030, when production migration, certification and high-value hardware replacement converge. Under the stress case, incomplete inventories delay execution until mandates approach, creating simultaneous demand for scarce HSMs, assurance laboratories, identity specialists and OT engineers. This produces liquidity pressure even when the organisation remains solvent because expenditure shifts forward faster than depreciation schedules and contracted customer revenue. Infrastructure investors should therefore request a cryptographic-debt register alongside ordinary cybersecurity assessments; lenders should examine whether migration expenditure is included in capital plans; insurers may seek evidence of inventories and transition governance; and boards should separate avoidable schedule-compression cost from unavoidable technology replacement. The shadow labour market will include offensive researchers, state-aligned contractors, specialist integrators and “migration mercenaries” able to charge scarcity premiums during deadline compression. These actors do not change the mathematics of PQC, but they can materially change execution cost, intelligence exposure and supply-chain trust. The central strategic conclusion is that early inventory and crypto-agile design have an option value: they allow an organisation to postpone irreversible hardware decisions while preserving the ability to switch algorithms, suppliers and protocols when standards mature.

Figure 1 · Five-Year Capital-Pressure Projection

PQC Migration Expenditure Index, 2027–2031

INTERACTIVE MODEL

Indexed scenario model: 2027 controlled-transition expenditure equals 100. Values show relative capital pressure rather than currency expenditure. Moving the controls recalculates the central and stress paths to demonstrate how delayed execution and incompatible standards concentrate costs in 2029–2031.

Sovereign Competition: Post-Quantum Security as Industrial Power

Post-quantum cryptography will become an instrument of sovereign competition because the authority that defines approved algorithms, validation procedures, procurement deadlines and recognised trust anchors also influences which companies can sell hardware, software, cloud services and security infrastructure into regulated markets. The central competitive mechanism is not ownership of a single algorithm. NIST’s principal standards are publicly available and can be implemented internationally. The strategic advantage lies in controlling the institutional chain that transforms mathematical specifications into commercially accepted products: algorithm testing, module validation, security certification, procurement eligibility, cloud accreditation, sector regulation, conformity assessment, workforce development and exportable implementation profiles. The United States has assembled the most mature version of this chain through FIPS 203, FIPS 204, FIPS 205, the Cryptographic Algorithm Validation Program, the Cryptographic Module Validation Program, federal procurement and the CNSA 2.0 schedule for national-security systems. NIST states that the purpose of the CMVP is to promote validated cryptographic modules and give federal agencies a security metric for procuring equipment. Cryptographic Module Validation Program – National Institute of Standards and Technology and Canadian Centre for Cyber Security – current programme page verified August 2026Verified official validation programme. Europe possesses substantial cryptographic research, cybersecurity regulation and industrial capability but divides authority among the European Union, national agencies and separate certification ecosystems. China can coordinate state-owned enterprises, telecommunications operators, banks and domestic cryptography providers but has not published a unified migration schedule comparable to the American, European or British roadmaps. The decisive five-year contest will therefore measure how effectively each jurisdiction converts security requirements into demand for domestic products, how quickly it certifies those products, and whether its standards become internationally interoperable or form a protected sovereign market.

Sovereign conversion chain

Policy instrumentDirect security functionIndustrial-policy transmission mechanismCommercial beneficiariesSovereign risk if poorly executed
Algorithm standardDefines acceptable KEMs and signaturesEstablishes the technical baseline around which vendors investCryptographic libraries, semiconductor designers, HSM and security vendorsDependence on foreign standards or incompatible domestic variants
Validation programmeTests algorithm and module implementationsConverts compliance evidence into procurement eligibilityTesting laboratories, module vendors, assurance consultanciesCertification bottlenecks and concentrated market power
Procurement deadlineForces replacement or upgradeCreates predictable demand and accelerates customer budgetsCloud, network, identity, hardware and integration suppliersScarcity premiums and premature asset replacement
National security profileSets higher-security parameters and use casesShapes defence, intelligence and critical-infrastructure productsDefence primes, secure communications and trusted hardware firmsSeparate profiles can fragment civilian and allied markets
Cybersecurity certificationProvides formal assuranceDifferentiates domestic products and enables regulated-sector salesCertified product manufacturers and evaluation facilitiesNational certification can become an interoperability barrier
Cloud accreditationDetermines acceptable hosted servicesChannels migration spending into approved platformsHyperscalers, sovereign-cloud operators and KMS providersLock-in and excessive concentration
Critical-infrastructure regulationExtends requirements beyond governmentPropagates migration through energy, transport, health and financeIndustrial cybersecurity, OT gateways, telecom and PKI vendorsSmaller operators may be unable to finance compliance
Research and industrial grantsReduces development riskSupports domestic tools, chips, libraries and migration servicesStart-ups, universities and strategic industrial suppliersSubsidised products may fail to achieve international adoption
Skills and testing infrastructureExpands implementation capacityPrevents value capture from shifting to foreign consultantsNational laboratories, universities and professional servicesDomestic mandates without domestic capability increase imports
Mutual recognitionReuses certification across bordersExpands addressable markets and lowers duplicationExport-oriented suppliersExcessive recognition may weaken sovereign control

The United States holds the strongest first-mover position because its policy architecture links algorithm standardisation directly to federal acquisition, national-security profiles, cloud infrastructure and a global technology-vendor ecosystem. OMB Memorandum M-26-15 requires agencies to develop migration plans, use risk-based prioritisation, incorporate post-quantum readiness into cloud migration and hardware-refresh schedules, employ automated cryptographic discovery, address third-party software, and represent funding and personnel needs in annual budget requests. It sets discovery for 2026–2027, pilots and early migration for 2027–2028, prioritised key-establishment migration for 2028–2030, signature migration during 2031 and broader completion by 2035. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026Verified official memorandum. The industrial advantage arises because federal requirements do not remain confined to government. Suppliers must modify commercial products, cloud platforms, identity systems, network equipment and software-development processes to preserve federal eligibility. The same product improvements can then be sold to banks, healthcare systems, utilities, defence contractors and foreign governments. CISA’s January 2026 product-category guidance identifies hardware and software classes that support or are expected to support PQC, creating a market signal about the categories in which government demand will emerge. Product Categories for Technologies That Use Post-Quantum Cryptography Standards – Cybersecurity and Infrastructure Security Agency – January 2026Verified official CISA guidance. This procurement-driven diffusion gives American firms an opportunity to amortise development and certification costs across both public and private customers. It also allows Washington to influence allied requirements because foreign governments seeking interoperability with American systems have incentives to recognise NIST algorithms and validation evidence.

The national-security branch of the American strategy creates an even stronger product-selection mechanism. The NSA’s published transition schedule states that CNSA 2.0 is required for new products and services from 1 January 2027, that equipment without CNSA 2.0 support should be replaced by 31 December 2030, and that CNSA 2.0 is mandated for covered systems by 31 December 2031, subject to specified exceptions or waivers. The profile uses ML-KEM-1024 for key establishment and ML-DSA-87 for digital signatures at all classification levels. CSfC Post-Quantum Cryptography Guidance Addendum, Draft 1.0 – National Security Agency – April 2025Verified official NSA guidance. This schedule influences secure communications, network encryptors, certificate systems, end-user devices, key-management products and software-signing systems before civilian mandates reach full maturity. It rewards suppliers capable of meeting high-assurance parameter requirements, implementing certificate-based architectures and completing evaluation early. The official NIST implementation-under-test list, updated in August 2026, displayed 238 modules undergoing FIPS 140-3 testing and included post-quantum modules alongside products from cloud, semiconductor, operating-system, networking, HSM and identity vendors. The list does not mean all 238 modules implement PQC, nor does inclusion equal validation; it shows the scale and diversity of the certification pipeline and the market relevance of formal testing. Cryptographic Module Validation Program: Implementation Under Test List – National Institute of Standards and Technology – updated August 2026Verified official NIST list. The American competitive risk is that validation capacity and procurement could entrench a small number of hyperscalers and incumbent security suppliers. Nevertheless, the United States presently has the clearest mechanism for turning government security expenditure into commercially exportable standards, validated products and allied technological dependence.

United States industrial-conversion matrix

Federal requirementMarket transformedLikely value-capture layerInternational spilloverStrategic vulnerability
NIST algorithm baselineCryptographic libraries and protocolsSoftware platforms, operating systems, cloud and network vendorsNIST algorithms become the default international referenceForeign adoption may be broad without corresponding US control over implementations
CMVP/FIPS 140-3Security modules and appliancesAccredited laboratories, HSMs, cloud KMS, secure hardwareForeign vendors seek US validation to access global regulated marketsQueue capacity and high compliance costs favour incumbents
OMB 2030–2031 phasesFederal applications and infrastructureSystems integrators, discovery tools, identity and cloud servicesSuppliers incorporate PQC into standard commercial productsBudget compression may create rushed deployment
CNSA 2.0National-security systemsDefence primes and high-assurance communicationsAllies align secure products with US profilesSeparate national-security parameters can increase product complexity
FedRAMP and cloud coordinationPublic cloud and SaaSLarge cloud providers and accredited service platformsCloud-delivered PQC becomes globally scalableShared-responsibility ambiguity and lock-in
FICAM modernisationIdentity and access managementCredential, smart-card, PKI and authentication vendorsUS identity profiles influence allied and corporate deploymentsLegacy credentials and decentralised trust chains

China approaches sovereign conversion from the opposite direction: less public timetable transparency, but stronger administrative capacity to coordinate state-owned firms, telecommunications operators, banks, government cryptography and domestic equipment suppliers. The most concrete official evidence is the State-owned Assets Supervision and Administration Commission disclosure that China Electronics Technology Group introduced the “Liangkai” anti-quantum cryptography family, covering cryptographic chips, cryptographic cards, software modules, server and financial cryptographic machines, integrated security gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025Verified official Chinese state source. A separate Chinese government-hosted disclosure reported development of a chip-level post-quantum cryptographic card combining a PQC system-on-chip with a quantum-random-number chip and supporting traditional Chinese commercial cryptography alongside post-quantum algorithms. China’s First Chip-Level Post-Quantum Cryptographic Card Emerges – Digital China Summit government portal – July 2025Verified Chinese government-hosted source. These sources do not demonstrate nationwide deployment or independent performance verification. They do, however, reveal the desired industrial architecture: China is seeking vertically integrated capabilities from algorithms and chips through appliances, key management and certificate infrastructure. This reduces dependence on foreign security modules and allows domestic suppliers to support state-specific cryptographic requirements. If public authorities, state banks and telecom operators adopt the same product families, procurement scale could rapidly improve domestic engineering and reduce unit costs.

China’s industrial opportunity extends beyond its domestic market. Countries procuring Chinese telecommunications, cloud, surveillance, financial or digital-government infrastructure may receive quantum-resistant features as part of integrated platforms, allowing Beijing to export not only equipment but trust architecture. The strategic value lies in certificate issuance, key management, device identity and update authority: control over these layers can produce durable dependence even when the underlying algorithm is public. China can also develop dual-capable products supporting domestic commercial cryptography and NIST-derived algorithms, enabling suppliers to serve both protected national markets and international customers. The principal constraint is interoperability. A product that supports multiple algorithms still requires recognised certification, protocol compatibility, transparent implementation evidence and trusted supply chains. If China mandates domestic algorithms or approval processes that diverge significantly from Western regimes, multinational banks, automotive firms, manufacturers and cloud providers may need separate product lines. Such fragmentation imposes costs on foreign companies but can function as a protective barrier for Chinese suppliers. The available official evidence does not support a claim that Beijing has published a unified national deadline comparable to the EU’s 2030 critical-infrastructure target or the UK’s 2035 completion objective. This opacity prevents reliable estimation of national migration expenditure and raises the probability that major requirements will emerge through sector regulation, state-enterprise procurement or classified directives rather than a single public roadmap. The competitive indicators for 2027–2031 are therefore domestic algorithm selection, national certification catalogues, state-bank migration pilots, telecom standards, government-cloud requirements and procurement language used by centrally administered enterprises.

China’s potential sovereign stack

LayerVerified or observable directionIndustrial advantage soughtExternal-market consequenceEvidence gap
AlgorithmsPQC research plus existing domestic commercial cryptographyIndigenous mathematical and implementation capabilityPossibility of dual NIST/domestic algorithm productsNo verified unified public national selection
SemiconductorChip-level PQC cards and cryptographic hardwareReduced dependence on imported secure componentsExportable secure hardware bundled with infrastructureIndependent performance and certification data remain limited
Cryptographic appliancesServer, financial and gateway productsState-sector procurement and vertical integrationTurnkey offerings for partner governments and enterprisesDeployment scale not publicly established
Key management and CADomestic KMS and certificate systemsControl over trust anchors and device identityLong-term platform dependenceCross-border trust and mutual recognition unclear
Telecom and cloudPotential integration into operator and cloud platformsMass deployment and recurring service revenuePQC becomes part of wider Chinese digital-infrastructure exportsPublic migration timetable remains opaque
FinanceResearch and banking-oriented migration programmesProtection of payment and state-financial infrastructureFinancial technology export potentialNo consolidated public budget or completion date

The European Union possesses the scale to become a sovereign industrial pole but must overcome institutional fragmentation. The Commission and NIS Cooperation Group roadmap calls for all member states to begin transitioning by the end of 2026 and for critical infrastructure to migrate as soon as possible and no later than the end of 2030. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025Verified official policy statement. The roadmap includes recommendations intended to synchronise national transitions, but implementation remains distributed among national cybersecurity authorities, sector regulators, public administrations, defence institutions, certification bodies and private operators. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025Verified official roadmap. This dispersion creates both opportunity and risk. Europe can use NIS2-related governance, the Cybersecurity Act, European cybersecurity certification, digital-identity infrastructure, public procurement, strategic research programmes and national security schemes to stimulate domestic demand. It also contains significant industrial assets in smart cards, secure elements, semiconductors, telecommunications, defence electronics, automotive systems, industrial automation and cryptographic evaluation. However, if each member state develops separate technical profiles, security evaluations and procurement deadlines, European firms will incur duplicated compliance costs while American hyperscalers absorb the scalable cloud layer.

Europe’s strongest industrial strategy would not attempt to replace NIST mathematics for symbolic sovereignty. It would capture value in implementations, hardware, assurance, migration tooling, identity, OT and lifecycle governance while ensuring European control over the most sensitive trust functions. This requires common implementation profiles, mutual recognition of security evaluations, shared testing infrastructure and procurement rules that reward crypto-agility, portability and documented supply chains. The EU can also create an industrial market through the 2030 critical-infrastructure deadline, because regulated operators will require discovery services, HSMs, PKI modernisation, network upgrades, secure firmware, quantum-resistant remote access and specialised engineering. Yet the deadline may widen differences between large strategic firms and smaller hospitals, municipalities, utilities and SMEs. If financing and technical assistance remain national and uneven, the resulting market will favour large incumbents with existing compliance teams. European sovereignty would then be paradoxical: regulation would be European, but the cloud, operating-system and key-management value could accrue principally to non-European providers. The necessary policy metric is therefore not merely the percentage of systems migrated; it is the proportion of migration expenditure captured by European suppliers without sacrificing international interoperability or security assurance.

European industrial-policy transmission

EU-level leverNational execution requirementPotential European value captureFailure mode
Coordinated 2030 critical-infrastructure targetSector inventories, national plans and regulated deadlinesOT security, network equipment, assurance and integrationUneven enforcement produces a two-speed market
European cybersecurity certificationCommon PQC evaluation profiles and laboratory capacitySecure chips, smart cards, HSMs and certified softwareMultiple national overlays duplicate costs
NIS2 cryptographic governanceEvidence-based policies and risk managementConsulting, inventory platforms and compliance toolingPaper compliance without technical migration
European digital identityPQC-ready wallet, credential and trust servicesIdentity, secure elements and certificate infrastructureDependence on foreign mobile and cloud platforms
Digital Europe and Horizon EuropeFunding for tools, pilots and standardsStart-ups, research institutes and migration technologiesPilot projects fail to scale into procurement
Public procurement coordinationCommon PQC and crypto-agility clausesLarger addressable market for EU suppliersNational tenders remain fragmented
Mutual recognitionReusable certifications across member statesLower cost and faster cross-border salesSecurity assurance becomes inconsistent

France is currently the clearest European example of converting assurance policy into national industrial advantage. ANSSI’s transition position establishes a phased approach in which hybridisation remains mandatory for products claiming long-term post-quantum security during the intermediate phase, while security visas evolve to assess pre-quantum security, the hybrid mechanism and quantum resistance. ANSSI Views on the Post-Quantum Cryptography Transition – Agence nationale de la sécurité des systèmes d’information – January 2022, live English edition verified August 2026Verified official ANSSI position. ANSSI’s updated information states that France has issued its first two certifications for products incorporating lattice-based PQC algorithms, identifying solutions from Thales and Samsung evaluated by CEA-Leti; it also reports market studies covering approximately fifty ministries and strategic companies and around thirty potential transition-service providers. Cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – current programme page verified August 2026Verified official French programme. This is an industrially significant progression from policy to certification. It creates practical evaluation knowledge inside French institutions, establishes a recognised route for product approval and gives domestic suppliers an earlier opportunity to qualify secure elements, smart-card platforms, cryptographic libraries and high-assurance products.

France’s model can generate four reinforcing advantages. First, ANSSI security visas transform technical assurance into a procurement signal for government, defence and critical sectors. Second, the French ecosystem combines security-product manufacturers, semiconductor expertise, smart-card capabilities, defence integrators and public research laboratories. Third, mandatory hybridisation protects current security while domestic evaluators accumulate experience with post-quantum implementations. Fourth, national and European financial-support mechanisms reduce early product-development risk. The model’s weakness is potential over-specialisation around national assurance. If certification cannot be reused across the EU or recognised by allied markets, French suppliers must repeat expensive evaluations. France must therefore use its national capability to shape European profiles and mutual-recognition mechanisms. Its strategic objective should be to make French evaluation practices an input into European certification rather than an additional layer above it. Between 2027 and 2031, the leading indicators will be the number of certified PQC products, expansion beyond secure elements into HSMs and network systems, the maturity of hybrid certificate profiles, procurement references to ANSSI-approved quantum-resistant functions, and French participation in common European evaluation methodologies.

Germany has a different but equally important opportunity because its competitive strength lies in industrial systems rather than primarily in centralised state procurement. BSI has endorsed the EU roadmap and described its concrete milestones for migration to quantum-secure cryptography. NIS Cooperation Group Publishes EU Roadmap for Post-Quantum Cryptography – Federal Office for Information Security – July 2025Verified official BSI notice. Germany’s industrial base includes automotive systems, machinery, chemicals, energy, logistics, telecommunications and factory automation, all of which use embedded identities, signed firmware, remote-maintenance links and long-lived control devices. PQC therefore intersects with product engineering, functional safety, export certification and supplier qualification. German firms that design crypto-agility into controllers, vehicles, industrial gateways and equipment platforms can export quantum-ready machinery as a premium capability. BSI guidance and testing can support this market by standardising requirements and reducing customer uncertainty. Conversely, German manufacturers face a severe supplier-tier problem: a final vehicle or industrial machine may contain components and software from hundreds of firms, and a single immutable verification key or unsupported controller can block end-to-end migration.

Germany’s sovereign opportunity is to make PQC part of the industrial quality model associated with German engineering. This requires reference architectures for embedded migration, standard supplier questionnaires, secure firmware-update profiles, testing facilities for constrained devices and migration clauses integrated into automotive and industrial procurement. It also requires coordination between BSI, industry associations, safety regulators and European certification bodies. The main risk is that hardware life cycles extend beyond regulatory deadlines, creating stranded assets or forcing expensive gateways and compensating controls. Another risk is cloud displacement: while German firms can capture value in embedded and industrial layers, the key-management, identity and analytics layers may remain dominated by foreign cloud providers. Germany should therefore prioritise interfaces that permit industrial customers to retain control over keys, certificates, device identity and algorithm configuration even when workloads use external cloud infrastructure. Its five-year competitive result will be visible in whether German suppliers sell PQC-ready industrial products globally or merely purchase foreign cryptographic components to preserve compliance.

Italy has a narrower technological base than France or Germany but a strategically important opportunity in distributed industrial migration. ACN’s updated TLS guidance includes post-quantum solutions, moving Italian policy from general awareness toward implementation-level recommendations. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026Verified official Italian guidance. Italy’s distinctive challenge is its economic structure: strategically important banks, defence and aerospace firms, telecommunications operators and energy companies coexist with extensive networks of SMEs, municipal administrations, regional healthcare systems and industrial districts. The security requirement will propagate from regulated entities and international customers into supplier contracts before every smaller company faces a direct statutory mandate. A precision manufacturer, software supplier or machinery producer may therefore lose eligibility for a major European or American contract if it cannot document cryptographic dependencies, secure update mechanisms and migration plans.

Italy can convert this vulnerability into industrial advantage through shared capabilities rather than attempting to reproduce every element of the American or French ecosystem. A national programme could provide common CBOM methodologies, sector migration profiles, accredited interoperability laboratories, subsidised discovery for SMEs, standard procurement clauses and specialised testing for embedded systems. The strongest addressable sectors include aerospace, defence electronics, automotive components, industrial machinery, energy, telecommunications, banking infrastructure and digital public services. Italy can also position integrators and cybersecurity firms as migration-service exporters to the Mediterranean, Balkans and smaller European markets that face similar capability constraints. The principal danger is fiscal and organisational fragmentation. If every region, hospital, municipality and SME procures migration separately, transaction costs will rise while foreign vendors dominate. ACN must therefore operate not only as a technical authority but as a demand aggregator and standard setter. The five-year test is whether Italian guidance becomes executable procurement, whether national laboratories can validate products and whether public incentives reach supply-chain firms before customer requirements exclude them.

Italy: industrial conversion priorities

Priority programmeTarget populationDomestic capability createdExport potential2031 failure risk
National cryptographic inventory frameworkPublic administration and regulated sectorsCommon CBOM taxonomy and risk scoringAdvisory services for smaller European statesIncompatible inventories and invisible legacy exposure
SME migration serviceManufacturing districts and software suppliersShared discovery, planning and supplier evidenceScalable Mediterranean migration offeringSMEs lose procurement eligibility
Embedded and OT test laboratoryMachinery, automotive, energy and defenceConstrained-device and firmware expertiseQuantum-ready industrial productsForeign dependence for critical embedded modules
PQC procurement clausesCentral and regional governmentPredictable demand for domestic productsReference contracts and compliance toolingFragmented tenders favour foreign incumbents
Healthcare migration profileRegional health systems and suppliersLong-lived-data and device-security expertiseEuropean digital-health security servicesSensitive data and medical devices remain classical-only
Finance and identity pilotBanks, payment systems and public identityPKI, HSM and credential migration competenceFintech and digital-government marketsReliance on external cloud and identity stacks

The United Kingdom possesses an advantage in timetable clarity, regulated finance, intelligence-informed cybersecurity and professional services. NCSC requires organisations to complete discovery and an initial migration plan by 2028, carry out highest-priority migration and refine plans by 2031, and complete migration by 2035. It estimates that large organisations may need two to three years for discovery, assessment and planning, followed by another two to three years for early migration and plan refinement. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025Verified official NCSC guidance. This clarity is itself an industrial instrument because it gives banks, insurers, telecommunications companies, government suppliers and security vendors a common planning horizon. The UK can capture value in cryptographic discovery, assurance, PKI transformation, financial infrastructure, migration consulting and cyber insurance. London’s financial sector can propagate requirements through payment systems, custodians, clearing infrastructure, cloud outsourcing, fintech and professional-service suppliers, creating demand beyond formal government procurement.

The British model is likely to be more services-intensive than the French or German models. The country’s strength lies in cybersecurity expertise, financial regulation, risk consulting, standards participation and high-value software rather than broad domestic semiconductor manufacturing. This creates a potential export position in migration planning, assurance, inventory tooling and regulated-sector implementation. It also creates dependency: UK firms may rely on foreign HSMs, secure elements, cloud platforms and operating systems while adding domestic assurance and integration. To convert security requirements into durable industrial advantage, the UK must retain intellectual property in discovery platforms, crypto-agile middleware, financial protocols and certification methodologies rather than functioning only as a consulting layer around imported technology. The leading indicators will be NCSC-assured migration services, regulator expectations for banks and infrastructure firms, public procurement requirements, UK participation in protocol standards and the share of domestic suppliers offering internationally recognised products.

Comparative sovereign-readiness assessment, August 2026

The following scores are structured analytical assessments, not official statistics. Each score ranges from 0 to 100 and reflects verified policy maturity, certification capacity, procurement leverage, industrial depth, implementation clarity and exposure to fragmentation.

JurisdictionPolicy maturityCertification leverageProcurement powerDomestic industrial captureInteroperability potentialExecution resilienceComposite assessment
United States96969893918293
China72749691587878
European Union86808778896581
France91948289837986
Germany87888491877485
United Kingdom93868182918386
Italy70626864865668

The Analysis of Competing Hypotheses produces five strategic pathways. H₁ — American standards convergence assigns a current probability of 39% and anticipates that NIST algorithms, FIPS validation and US-compatible protocol profiles become the dominant international baseline while other jurisdictions compete primarily in implementation and certification. H₂ — managed multipolarity, at 27%, anticipates common algorithm families but separate American, European and Chinese assurance regimes. H₃ — sovereign fragmentation, at 16%, anticipates divergent algorithms, certificate systems and procurement rules that require multiple product lines. H₄ — hyperscaler capture, at 11%, anticipates that cloud and operating-system providers absorb most migration complexity, reducing national policy control despite formal sovereign roadmaps. H₅ — implementation delay, at 7%, anticipates that hardware, OT and certification shortages prevent deadlines from translating into real migration. Evidence presently favours H₁ because NIST standards are final, American procurement is operational and European authorities broadly reference compatible approaches. French and German hybridisation and assurance strategies support H₂ rather than outright fragmentation. China’s vertically integrated products increase H₃ probability, but the public record does not yet establish a national incompatible standard mandate. H₄ remains material because cloud providers can deploy PQC at scale faster than decentralised governments, potentially making sovereignty dependent on contractual control rather than domestic ownership. Bayesian updates should occur quarterly using discriminating indicators: new module validations, reciprocal certification, public tenders, Chinese national standards, European common profiles, cloud portability provisions, OT supplier roadmaps and verified migration appropriations.

Five-year sovereign-competition outlook

PeriodUnited StatesChinaEuropean UnionFranceGermanyUnited KingdomItaly
2027New federal products align with CNSA 2.0; pilots expandState-sector product trials and possible sector rulesNational plans move into implementationHybrid-certified portfolio expandsIndustrial supplier inventories accelerateDiscovery and planning market growsACN profiles and initial sector pilots
2028Federal early migration and product validation scaleTelecom, finance and government pilots likely broadenCertification and critical-sector procurement expandSecure elements, HSMs and defence products gain demandAutomotive and machinery requirements propagate2028 discovery milestone concentrates consulting demandSME support becomes decisive
2029High-value federal systems generate large ordersDomestic vertical stack may reach production scaleCross-border interoperability becomes criticalFrench assurance influences EU methodsEmbedded and OT migration enters productionFinance and telecom execute priority projectsBanks, defence, telecom and energy lead
2030Priority key establishment and equipment replacementPotential divergence becomes commercially visibleCritical-infrastructure deadline creates capital peakRegulated sectors complete high-priority systemsIndustrial shutdown and replacement cycle intensifiesHighest-priority estate approaches completionFragmented public and SME estates face deadline pressure
2031Signature migration and CNSA 2.0 mandateDomestic certification ecosystem consolidatesTrust-chain and signature migration dominateNational products compete for EU-wide recognitionExport qualification becomes a competitive differentiatorHigh-priority migration milestoneProcurement eligibility separates leaders from laggards

The Monte Carlo sovereign-advantage model uses six dimensions—policy maturity P, validation capacity V, procurement leverage Q, industrial depth D, interoperability I and execution capacity E—each represented by a triangular distribution reflecting uncertainty. The composite sovereign-conversion index is calculated as S = 0.18P + 0.17V + 0.19Q + 0.20D + 0.13I + 0.13E. This is an analytical model, not an official formula. Across 10,000 conceptual runs, the United States retains the highest median because procurement, validation and industrial scale reinforce one another. France, Germany and the United Kingdom form a competitive second tier through different routes: French assurance, German industrial embedding and British implementation services. The EU aggregate has greater theoretical scale but lower execution cohesion. China’s range is wide because domestic coordination is strong while standards transparency and international recognition remain uncertain. Italy’s present median is lower, but its upside is substantial if it creates shared migration infrastructure for SMEs and converts ACN guidance into pooled procurement and sector laboratories. The model’s most important conclusion is that technological sovereignty is not equivalent to national algorithm ownership. A country can gain strategic advantage by controlling certification, migration tooling, hardware roots of trust, key management, product lifecycle and procurement evidence while implementing internationally compatible algorithms. Conversely, a country can announce a sovereign algorithm yet remain dependent on foreign chips, cloud platforms, operating systems and testing tools.

The shadow dimensions reinforce this result. Intelligence services benefit from visibility into international standards and implementation weaknesses; certification laboratories accumulate sensitive knowledge about product architectures; cloud providers gain metadata about cryptographic usage; and specialist contractors can become indispensable during compressed migration. Liquidity flows will favour firms positioned at compulsory bottlenecks—HSMs, secure elements, certificate systems, discovery platforms and validation services—rather than every company using the “quantum-safe” label. Cyber-insurance and lender due diligence may convert readiness into a financing variable, raising the cost of capital for infrastructure operators unable to document migration. Export-credit agencies and defence procurement can favour domestic suppliers through readiness clauses without explicitly describing those clauses as protectionism. Standards diplomacy will therefore become economically consequential: mutual recognition reduces costs for allied firms, while exclusive national profiles create protected demand but fragment global markets. The sovereign winner in 2031 will not necessarily be the jurisdiction spending the most. It will be the jurisdiction that converts mandatory migration into reusable industrial capability, international certification influence and control over trust infrastructure without imposing such high incompatibility costs that its products lose global markets.

Figure 1 · Sovereign Industrial Conversion

Post-Quantum Strategic Advantage, 2027–2031

INTERACTIVE SCENARIO

Analytical scores, not official statistics. The base index combines policy maturity, certification leverage, procurement power, industrial capture, interoperability and execution capacity. Increasing industrial-capture weight rewards jurisdictions with deeper domestic hardware and security ecosystems; increasing fragmentation cost penalises jurisdictions facing lower international interoperability.

Five-Year Outlook: The 2027–2031 Post-Quantum Migration Window

The period from 2027 to 2031 will determine whether the post-quantum transition proceeds as a controlled global modernisation programme or deteriorates into a compressed, fragmented and inflationary replacement shock. The international system enters this period with three NIST standards already approved, but with substantial parts of the implementation ecosystem—including certificate profiles, protocol integration, validated security modules, operational-technology migration and cross-border assurance—still evolving. The United States Office of Management and Budget has established discovery and planning during 2026–2027, pilots and early migration during 2027–2028, prioritised key-establishment migration during 2028–2030 and digital-signature migration during 2031. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026Verified official memorandum. The National Security Agency separately states that CNSA 2.0 is required for new covered products and services from 1 January 2027, that non-supporting equipment should be replaced by 31 December 2030 and that CNSA 2.0 becomes mandatory for covered systems by 31 December 2031, subject to the relevant capability packages, protection profiles or waivers. CSfC Post-Quantum Cryptography Guidance Addendum, Draft 1.0 – National Security Agency – April 2025Verified official NSA guidance. Europe requires member states to begin transition by the end of 2026 and critical infrastructure to migrate no later than the end of 2030. The United Kingdom requires complete discovery and initial planning by 2028 and highest-priority migration by 2031. These overlapping timetables make 2027–2031 the period when policy ambitions will collide with incomplete inventories, supplier concentration, certification queues, hardware life cycles and restricted specialist capacity.

Strategic chronology

YearOfficially grounded pressureDominant technical activityDominant expenditurePrimary bottleneckStrategic intelligence value
2027CNSA 2.0 requirement for new covered US national-security products; federal discovery and pilotsCBOM creation, supplier mapping, hybrid tests and estate classificationDiscovery platforms, consulting, laboratories and pilot systemsUndocumented cryptographic dependenciesFirst credible measurement of the actual estate
2028US early migration; UK discovery and initial-planning deadlineProduct qualification, HSM deployment, PKI preparation and cloud responsibility mappingCertification, identity modernisation and network upgradesValidation queues and protocol immaturityDistinguishes executable programmes from policy declarations
2029US prioritised migration; EU critical-infrastructure deadline approachesHigh-value production deployment in government, finance and telecomProduction integration, hardware replacement and specialist labourSupplier concentration and hybrid complexityDetermines whether costs can be absorbed into ordinary refresh
2030US key-establishment objective; EU critical-infrastructure deadline; CNSA 2.0 equipment-replacement pointKey establishment, sensitive-data protection and critical OT remediationPeak replacement, certification and outage expenditureLegacy OT and unavailable upgradesPrincipal schedule-compression point
2031US signature phase; CNSA 2.0 mandate; UK highest-priority milestoneDigital signatures, code signing, firmware, certificate chains and machine identityTrust-anchor replacement and ecosystem coordinationWebPKI, device verification and immutable roots of trustDetermines whether 2035 completion remains achievable

Bayesian baseline

The Bayesian framework begins with five competing hypotheses concerning the mechanism most likely to dominate migration. H1 — coordinated standards-led migration assumes that NIST algorithms become the common mathematical baseline while national authorities implement broadly compatible procurement and assurance profiles. H2 — sovereign bloc fragmentation assumes that the United States and its allies, China and potentially other jurisdictions develop materially different algorithm, certification, certificate or implementation requirements. H3 — vendor-absorbed migration assumes that cloud providers, operating-system developers, network vendors, HSM manufacturers and identity platforms incorporate PQC into ordinary releases, thereby reducing the amount of direct engineering required from customers. H4 — threat-triggered acceleration assumes that a significant cryptanalytic result, intelligence warning, implementation failure or credible quantum-computing advance compresses official schedules. H5 — budget- and capability-constrained delay assumes that governments preserve formal deadlines while relying increasingly on waivers, exceptions and compensating controls because products, personnel, inventories or funding remain insufficient. As of August 2026, the assessed priors are 42% for H1, 19% for H2, 17% for H3, 10% for H4 and 12% for H5. These percentages are structured analytical judgements, not official forecasts and not estimates of when a cryptographically relevant quantum computer will become operational. The strongest evidence supporting H1 is the convergence of American, European, British, French and German policy around NIST-standardised algorithms, hybrid migration and crypto-agility. H2 is supported by the strategic value of domestic trust infrastructures and by China’s development of vertically integrated anti-quantum products without a fully transparent national migration timetable. H3 becomes more plausible as PQC functions are absorbed into cloud, operating-system and security-service products. H4 remains a low-probability but extreme-impact scenario. H5 is especially plausible in healthcare, municipalities, educational institutions, SMEs and operational-technology environments.

Analysis of Competing Hypotheses

HypothesisAugust 2026 priorCore propositionConfirmation indicatorsDisconfirmation indicatorsExpected cost pattern
H1 — Coordinated standards-led migration42%Common algorithms and broadly interoperable regional profilesMutual recognition, compatible certificates, validated multi-vendor productsMandatory incompatible national suitesBroad expenditure with declining duplication
H2 — Sovereign bloc fragmentation19%Separate cryptographic and assurance ecosystems emergeDomestic algorithm mandates, separate root stores, restricted cross-certificationCommon protocol and certification profilesPersistent duplication and geopolitical risk premium
H3 — Vendor-absorbed migration17%Platforms incorporate migration into standard productsPQC enabled by default in cloud, OS, HSM and network servicesExtensive customer-side redesign and product scarcityCosts embedded in subscriptions and refresh cycles
H4 — Threat-triggered acceleration10%A security shock compresses schedulesEmergency directives, extraordinary budgets and rapid deprecationStable threat assessments and unchanged schedulesFront-loaded expenditure and severe scarcity premiums
H5 — Budget and capability delay12%Plans exist but execution repeatedly slipsWaivers, weak inventories, funding gaps and unsupported productsEarly priority completion and declining exception ratesLow early expenditure followed by late replacement shock

Bayesian updating must be driven by discriminating evidence rather than announcements that use “quantum safe” as an unverified marketing label. A product declaration should have low evidentiary weight unless it specifies its algorithms, implementation environment, supported protocols, validation status and operational limitations. A completed cryptographic-module validation, a government procurement requirement, a certified certificate profile or an audited migration appropriation carries substantially greater weight because it demonstrates the transition from intention to executable capacity. If the European Union establishes common PQC implementation profiles and mutual recognition for national evaluations, H1 should rise because such evidence would be significantly more probable under coordinated convergence than sovereign fragmentation. If China publishes mandatory domestic profiles incompatible with NIST-derived implementations, H2 should increase sharply. If major cloud providers activate supported hybrid PQC across managed TLS, workload identity, certificate management and key-management services while customers require minimal application redesign, H3 should rise. If governments shorten deadlines following a credible cryptanalytic or intelligence event, H4 should dominate the short-term posterior. If approaching deadlines produce repeated waivers, validation bottlenecks and procurement failures, H5 should rise. This methodology prevents isolated laboratory achievements, political declarations and corporate marketing from distorting the forecast. It also allows different sectors to carry different probabilities: H1 may dominate federal and financial infrastructure while H5 simultaneously dominates municipal systems, hospitals and legacy industrial estates.

Bayesian evidence-weighting matrix

Evidence eventH1 relevanceH2 relevanceH3 relevanceH4 relevanceH5 relevanceAnalytical update
EU-wide mutual recognition of PQC certificationVery highVery lowMediumLowLowIncrease H1 materially
Mandatory incompatible Chinese algorithm profileLowVery highLowLowLowIncrease H2 sharply
PQC enabled by default across major cloud platformsMediumLowVery highMediumLowIncrease H3
Emergency shortening of migration deadlinesLowMediumMediumVery highVery lowIncrease H4 sharply
Repeated government waivers caused by unavailable productsLowMediumLowLowVery highIncrease H5
Rapid growth in validated, interoperable modulesHighLowHighMediumLowIncrease H1 and H3
Persistent absence of cryptographic inventoriesLowMediumLowLowVery highIncrease H5
Common certificate and digital-signature profilesVery highVery lowMediumLowLowIncrease H1
Separate sovereign root stores and trust anchorsLowVery highMediumLowMediumIncrease H2
Credible attack against a selected implementationMediumMediumLowVery highMediumIncrease H4 and reassess concentration risk

Monte Carlo scenario design

The Monte Carlo model should estimate implementation cost, delay and readiness rather than attempt to predict the precise arrival of a quantum computer capable of attacking deployed cryptography. Each simulation run samples the size of the undiscovered cryptographic estate, supplier readiness, hardware-replacement requirements, hybrid-operation costs, certification time, standards fragmentation, workforce scarcity and operational-technology outage exposure. The results should be expressed as an index or as a range around a verified organisational baseline because no harmonised global inventory currently supports a defensible single monetary estimate. A central model can assign triangular distributions to nine variables: an estate-discovery multiplier with minimum 1.05, mode 1.25 and maximum 1.70; an unsupported-supplier share of 8%, 19% and 38%; a hardware-replacement share of 10%, 24% and 47%; a hybrid-operation premium of 6%, 15% and 31%; certification delay of 3, 9 and 21 months; a schedule-compression multiplier of 0.95, 1.12 and 1.48; a fragmentation multiplier of 1.00, 1.09 and 1.30; an OT outage multiplier of 1.04, 1.23 and 1.68; and a workforce-scarcity premium of 5%, 17% and 42%. These assumptions are analytical inputs, not government statistics. The model’s most important result is the difference between early reported cost and eventual total cost. An organisation conducting serious discovery during 2027 will report expenditure earlier, but it will reduce the probability of rushed replacement during 2030. An organisation postponing discovery may initially appear cheaper while accumulating unknown dependencies that create a much larger tail risk.

Monte Carlo input register

VariableMinimumModeMaximumPrincipal uncertaintyManagement intervention
Cryptographic-estate discovery multiplier1.051.251.70Hidden dependencies across software, hardware and servicesAutomated discovery and named asset ownership
Unsupported strategic suppliers8%19%38%Proprietary products and abandoned componentsContractual disclosure and upgrade deadlines
Hardware-replacement share10%24%47%Fixed modules, secure elements and constrained devicesAlign migration with scheduled refresh
Hybrid-operation premium6%15%31%Parallel credentials, protocols and monitoringStandardise profiles and limit coexistence periods
Certification delay3 months9 months21 monthsLaboratory and authority capacityReserve testing capacity early
Schedule-compression multiplier0.951.121.48Deadline proximity and emergency procurementBegin inventories and pilots before mandates
Standards-fragmentation multiplier1.001.091.30Duplicated national profiles and certificationMutual recognition and modular architectures
OT outage multiplier1.041.231.68Safety review and shutdown coordinationIntegrate migration with maintenance windows
Workforce-scarcity premium5%17%42%Limited cryptographic, PKI and embedded expertiseTraining, shared services and framework contracts

Under the controlled-transition scenario, discovery coverage exceeds 80% of the priority estate by the end of 2027, major suppliers disclose cryptographic dependencies, validated modules become available during 2028, high-value migrations scale through 2029 and expenditure peaks in 2030 before declining. Under the central scenario, discovery remains uneven, hybrid operation lasts longer than expected and hardware replacement becomes more extensive, producing a broader cost peak across 2029–2031. Under the fragmented scenario, expenditure remains elevated after 2031 because organisations must support different national algorithms, certificate profiles and assurance regimes. Under the accelerated scenario, a security shock causes simultaneous demand for scarce HSMs, laboratories, PKI specialists, embedded engineers and certified products, generating procurement inflation and supplier concentration. Under the delayed scenario, early spending remains artificially low because organisations have not measured the actual estate; costs then rise abruptly as deadlines approach. The dominant cost variable is not the mathematical implementation of ML-KEM or ML-DSA. It is the interaction among hardware replacement, OT constraints, certification queues, supplier concentration and schedule compression. Management can materially reduce this interaction by establishing crypto-agile interfaces, negotiating supplier obligations before renewal, protecting long-lived sensitive data early and separating high-priority systems from low-risk assets that can follow ordinary refresh schedules.

Five-year scenario envelopes

Scenario2027 condition2028–2029 trajectory2030–2031 resultRelative cost indexReadiness outcome
Controlled transitionBroad inventory and early procurementValidated products scale; refresh cycles absorb replacementPriority migration largely achieved100High
Central caseUneven discovery and moderate supplier gapsExtended hybrid operation and concentrated production migrationPriority targets achieved with exceptions128Medium-high
Fragmented standardsNational profiles divergeDuplicate product and certification lines expandPersistent multi-stack operation153Medium
Threat accelerationEmergency reassessment compresses schedulesExtraordinary procurement and scarcity premiumsRapid deployment with implementation risk181Variable
Capability delayWeak inventory and insufficient fundingWaivers and unsupported legacy systems accumulateLarge residual exposure and late replacement shock167Low

2027: the inventory credibility test

During 2027, the principal intelligence question will be whether governments and enterprises can identify cryptography at the level required for migration. A conventional asset register listing servers, applications and devices is insufficient because it does not describe cryptographic purpose, algorithm, key size, certificate lifetime, library call, protocol negotiation, trust anchor, data longevity or supplier dependency. NIST’s migration programme expressly requires organisations to understand quantum-vulnerable public-key use across hardware, software and services and use inventories to prioritise migration. Migration to Post-Quantum Cryptography – National Cybersecurity Center of Excellence, NIST – current programme page verified August 2026Verified official programme. A credible inventory must distinguish key establishment from signatures, identity from confidentiality, code signing from transport encryption and directly controlled systems from supplier-managed services. It must connect every cryptographic function to an owner, business service, data classification, replacement route and deadline. The strongest 2027 indicator will therefore be the proportion of priority services with verified end-to-end dependency maps rather than the number of certificates discovered. Other leading indicators include the share of strategic suppliers providing algorithm-level disclosure, the percentage of new contracts containing crypto-agility clauses, the number of production-representative pilots and the extent to which HSM, PKI, firmware and OT dependencies are included. Weak inventories will increase H5 because they make subsequent cost and schedule estimates unreliable. Strong inventories will increase H1 because they demonstrate that official programmes have moved from strategic policy into operational execution.

2027 leading indicators

IndicatorGreen thresholdAmber thresholdRed thresholdIntelligence meaning
High-value services with named cryptographic ownerAbove 80%50–80%Below 50%Governance maturity
Critical applications with verified CBOM coverageAbove 60%25–60%Below 25%Inventory credibility
Strategic suppliers disclosing algorithm dependenciesAbove 70%35–70%Below 35%Supply-chain transparency
New contracts containing crypto-agility requirementsAbove 75%40–75%Below 40%Future migration flexibility
Production-representative pilotsMultiple critical sectorsOne or two isolated sectorsLaboratory demonstrations onlyExecution readiness
HSM, PKI and identity dependencies mappedAbove 70%35–70%Below 35%Trust-infrastructure visibility
Critical OT remote-access paths inventoriedAbove 65%30–65%Below 30%Industrial exposure control
Long-lived sensitive data classified for PQC priorityAbove 85%50–85%Below 50%Harvest-now-decrypt-later mitigation

2028: the product and certification test

During 2028, the centre of gravity will shift from discovery to product qualification, procurement and early production migration. The UK’s deadline for complete discovery and an initial migration plan provides a clear external audit point. The United States enters early migration, while CNSA 2.0 requirements for new national-security products create demand for high-assurance equipment. NIST’s implementation-under-test list displayed 238 modules in August 2026, including products from cloud, semiconductor, operating-system, HSM, network, storage and identity vendors. That figure does not imply that every listed module implements PQC or that any implementation-under-test product has completed validation. Cryptographic Module Validation Program: Implementation Under Test List – National Institute of Standards and Technology – updated August 2026Verified official NIST list. Analysts must therefore distinguish product announcements, algorithm validations, module validations, security certifications and operational deployments. The most important 2028 indicators will be the median time required for validation, the number of credible suppliers for each critical product category, the availability of PQC-capable HSMs and secure elements, the publication of interoperable identity and certificate profiles, and the frequency of procurement delays caused by unavailable products. France may gain disproportionate influence because ANSSI reports the first French certifications for products incorporating lattice-based PQC and is adapting its guides and assurance procedures. Cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – current programme page verified August 2026Verified official French programme. If validated products scale across multiple vendors, H1 and H3 should rise. If queues expand while usable products remain scarce, H5 should rise.

2028 product-maturity indicators

IndicatorStrong signalWeak signalHypothesis impact
Completed PQC-capable module validationsSustained quarterly growth across several vendorsMany submissions but few completionsStrong result raises H1 and H3
Median validation durationStable or declining despite greater volumeRising above eighteen monthsWeak result raises H5
PQC-capable HSM supplyAt least three credible suppliers per major marketSingle-vendor or unavailable productWeak result raises concentration and delay risk
Hybrid TLS and VPN deploymentProduction use in government, finance and telecomIsolated testingStrong result raises H1
Certificate-profile interoperabilityCommon or mutually recognised profilesNationally isolated profilesIsolation raises H2
Cloud-service availabilitySupported options across major managed servicesLimited experimental featuresBroad support raises H3
Identity infrastructure readinessIssuance, validation and revocation testedIssuance without relying-party supportIncomplete chains raise H5
Procurement delaysBelow 10% of PQC-related tendersAbove 25%High delay raises H5

2029: the production scaling test

During 2029, high-value migration should move from representative pilots into production systems. The dominant sectors will be federal government, defence supply chains, banking, telecommunications, cloud infrastructure, energy, healthcare data platforms and critical remote-access systems. The principal indicator will be the percentage of priority business or mission pathways protected end to end, not the number of individual devices that advertise PQC support. A bank may upgrade its external TLS while retaining classical-only HSM operations, service identities, API tokens, backup systems or transaction-signing functions. A government agency may deploy hybrid VPNs while leaving software-signing and privileged-access systems unchanged. An industrial operator may protect its central gateway but retain vulnerable vendor access to field devices. Consequently, production-readiness measurement must follow transaction and trust pathways across every dependency. The United States should show the strongest transparent acceleration because OMB requires prioritised migration from 2028 through 2030. China may expand state-sector implementation through domestic cryptographic chips, cards, gateways, key-management systems and certificate-authority products. The official China Electronics Technology Group disclosure confirms the breadth of the intended product stack but does not establish national deployment volume. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025Verified official Chinese state source. European progress should be evaluated by national dispersion: a high EU aggregate can conceal weak performance among smaller states, municipalities, hospitals and regional utilities. If 2029 migration remains concentrated in major organisations, the probability of a two-speed European transition will rise.

2029 production metrics

DomainMinimum credible evidenceStrong 2029 conditionWeak 2029 condition
GovernmentOperational priority pathways using approved mechanismsMajority of high-value services migratedMigration remains limited to perimeter TLS
BankingHSM, PKI, payment and identity migration in productionCritical transaction chains tested end to endOnly customer-facing channels upgraded
TelecommunicationsControl, management and interconnect protectionMultiple production network functions migratedIsolated laboratory or access-network pilots
CloudPQC across network, identity and KMS layersDocumented shared responsibility and portabilityProvider support without customer application migration
HealthcareLong-lived data and identity prioritisedMajor data platforms and trust services migratedFragmented pilots without device strategy
OTCritical remote access and gateway protectionExecutable replacement or isolation route for every critical assetLarge share of unsupported devices
Software supply chainNew signatures in production build systemsCritical artefacts signed and verified end to endSigning upgraded but downstream verification absent

2030: the compression and critical-infrastructure test

The year 2030 is likely to create the highest simultaneous capital pressure. The European roadmap requires critical infrastructure to migrate no later than the end of that year, while the American federal programme targets priority key-establishment migration and the NSA schedule identifies the end of 2030 as the point by which non-supporting equipment should be replaced. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025Verified official European policy statement. The most exposed organisations will be those that treated discovery as a compliance document rather than an engineering process. They will confront simultaneous demand for HSMs, secure elements, identity specialists, certificate engineers, testing laboratories, OT maintenance windows and replacement hardware. Schedule compression will increase prices, reduce supplier choice and create pressure to accept incompletely tested solutions. The leading indicator should be exception quality. A residual classical-only system is not equivalent to unmanaged failure if it has a documented owner, compensating control, funded replacement and expiration date. By contrast, broad waivers without verified remediation routes would indicate that the formal deadline has ceased to function as an operational control. European authorities should publish distributional data showing progress across states and sectors rather than only an aggregate percentage. Italy should track municipalities, regional healthcare and manufacturing SMEs separately from banks, telecommunications and defence groups. Germany should report embedded and industrial systems separately from conventional IT. France should report certified-product availability and regulated-sector adoption. The UK should measure progress toward its 2031 high-priority milestone. H5 will rise substantially if more than 20% of priority systems lack funded migration routes at the end of 2030.

2030 critical thresholds

Critical measureGreen conditionAmber conditionRed condition
Priority key-establishment pathways migratedAbove 90%70–90%Below 70%
High-value systems with funded completion routeAbove 98%90–98%Below 90%
Critical OT assets with migration or isolation planAbove 95%75–95%Below 75%
Unsupported strategic suppliersBelow 5%5–15%Above 15%
PQC procurement delayed by certificationBelow 10%10–25%Above 25%
Classical-only exceptions with expiration dateAbove 95%75–95%Below 75%
Long-lived sensitive data protectedAbove 95%80–95%Below 80%
Cloud services with documented PQC responsibilityAbove 90%60–90%Below 60%

2031: the digital-signature and trust-chain test

The 2031 phase will be more structurally complex than key-establishment migration because signatures depend on every verifier in a trust ecosystem understanding and accepting the new format. Digital signatures authenticate software, firmware, transactions, identity credentials, documents, machine commands and security updates. A new signature algorithm is ineffective if devices, applications, certificate authorities, root stores, transparency logs, revocation services and archives cannot validate it. The American federal programme places digital-signature migration in 2031, while CNSA 2.0 reaches its mandatory point for covered national-security systems. The United Kingdom also reaches its highest-priority migration milestone. NCSC identifies WebPKI and industrial-control protocols as particularly difficult areas because decentralised trust participants must coordinate their transitions and many industrial environments still lack modern cryptographic architectures. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025Verified official UK guidance. The central 2031 metric will be relying-party coverage: the proportion of critical systems capable of issuing, validating, revoking, auditing and archiving approved signatures without insecure fallback. Organisations must distinguish active use of new signatures from mere acceptance. They must also test negative cases, including downgrade attempts, revoked credentials, mixed certificate chains and rollback to older firmware. France’s hybrid-assurance approach may reduce immediate algorithm risk but will increase message, lifecycle and certification complexity. Germany’s exposure will concentrate in embedded verification across machinery, vehicles and industrial systems. Italy’s risk will concentrate in public identity, healthcare devices, municipal platforms and SME-produced components. A successful 2031 outcome will require end-to-end trust-chain functionality rather than a numerical count of issued PQC certificates.

2031 trust-chain indicators

IndicatorTarget conditionWarning conditionCritical failure
Critical code-signing servicesApproved or hybrid signatures validated end to endSigning upgraded but verifier coverage incompleteClassical-only signing remains mandatory
Firmware-signature readinessPriority devices accept approved signaturesGateways or manual compensating controls requiredNo migration route for critical devices
Certificate-authority readinessIssuance, validation and revocation operationalDual issuance without consistent policyNew certificates fail across relying parties
Relying-party coverageAbove 90% of priority estate60–90%Below 60%
Classical-only fallbackDisabled or tightly controlledTemporary documented exceptionsBroad silent fallback
Archive validationLong-term evidence preservedManual or sector-limited methodsHistorical signatures lose reliable validation
Machine and workload identityFull PQC-capable lifecycle managementPerimeter migrated but internal identity remains classicalCritical service identities remain vulnerable
Cross-border recognitionCommon or mutually recognised assuranceBilateral recognition onlyIncompatible sovereign trust domains

Jurisdictional forecast

Jurisdiction2027 priority2028 milestone2029 production test2030 pressure point2031 outcome testCentral execution probability
United StatesFederal inventories and CNSA 2.0 new-product requirementPilots and validated-product expansionPriority federal production migrationKey establishment and equipment replacementSignature migration and CNSA 2.0 mandate82%
ChinaStrategic-sector pilots and domestic product integrationBroader state-enterprise deployment probableFinance and telecom scaling probableNational standards ecosystem becomes commercially visibleSovereign cryptographic stack consolidation69%
European UnionNational plans enter executionCertification and procurement expansionCross-border coordination testCritical-infrastructure deadlineSignature and trust-chain remediation67%
FranceHybrid-certified offering expandsAssurance capacity scalesRegulated-sector production deploymentHigh-priority systems complete migrationFrench methods seek EU-wide recognition81%
GermanyIndustrial inventories and supplier clausesEmbedded pilots and testingAutomotive and machinery deploymentOT replacement and outage pressureExport qualification differentiates suppliers76%
United KingdomDiscovery acceleratesDiscovery and initial-plan milestoneFinance, telecom and government migrationHighest-priority scalingPriority-migration milestone84%
ItalyACN-aligned planning and sector pilotsSME support and procurement decision pointStrategic sectors move into productionPublic and industrial fragmentation pressureSupplier-eligibility divide59%

The United States retains the highest central execution probability because its standards, validation, federal procurement, national-security profiles and cloud vendors reinforce one another. Its central vulnerability is concentration: a limited group of validated suppliers may capture disproportionate market power. China may execute rapidly inside state-controlled sectors once requirements are issued, but the absence of a transparent unified public timetable increases forecast uncertainty. The European Union possesses scale and a dated critical-infrastructure objective but remains exposed to divergent national financing and certification. France is positioned to lead European assurance through ANSSI certification, hybridisation and its domestic security ecosystem. Germany can convert PQC into an export advantage if automotive, machinery and industrial suppliers integrate crypto-agility before customer requirements harden. The United Kingdom benefits from the clearest planning sequence and can become a reference market for financial-sector migration, assurance and professional services. Italy’s probability remains lower because technical guidance has not yet eliminated fragmented procurement, regional disparities, legacy public systems and SME financing constraints. ACN’s updated TLS guidance incorporates post-quantum solutions and supplies a technical baseline. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026Verified official Italian guidance. Italy’s result will depend on whether this guidance becomes common procurement, shared testing, SME migration support and sector-specific implementation.

Shadow indicators and concealed strategic effects

Formal migration percentages will not reveal the full strategic position. Harvest-now-decrypt-later collection increases the urgency of protecting information whose intelligence, commercial or personal value persists beyond the migration date. Relevant evidence includes data-longevity classification, re-encryption programmes and changes in government treatment of archived sensitive information. Cyber-norms will evolve as authorities decide whether absence of crypto-agility constitutes a product-security defect rather than an unavoidable legacy condition. Liquidity flows may reveal actual migration earlier than official progress reports through HSM orders, certification queues, framework contracts, cloud price changes, insurance questionnaires and acquisitions of migration-tool suppliers. Specialist contractor dependence will intensify as multiple jurisdictions approach common deadlines. Contractors and evaluation personnel may receive privileged visibility into cryptographic inventories, trust anchors, unsupported devices and fallback paths, creating counterintelligence and supply-chain risks. Vendor concentration must be measured across HSMs, secure elements, cloud KMS, certificate management, discovery tooling and validation laboratories. A migration programme may reduce quantum vulnerability while increasing dependence on a small number of providers. Standards diplomacy will also shape costs: mutual recognition lowers duplicated certification, while incompatible profiles create protected national demand but reduce exportability. The correct strategic dashboard must therefore combine migration completion with portability, supplier diversity, fallback control, evidence access, workforce capacity and the ability to change algorithms again. A system cannot be considered genuinely quantum-ready if the organisation cannot replace its provider, export its keys, verify its implementation, revoke compromised credentials or execute a second migration when cryptanalysis changes.

Integrated early-warning dashboard

Indicator familyCore metric2027 question2031 desired conditionEscalation trigger
InventoryPriority dependencies with verified CBOMIs cryptography known by purpose and owner?Above 95%Coverage below 60% after 2028
ProductsValidated PQC-capable modulesAre several suppliers completing validation?Competitive supply in every critical categorySingle-vendor dependence
IdentityRelying parties supporting new signaturesCan identity migrate end to end?Above 90%Issuance substantially exceeds verification capability
CloudServices with documented PQC responsibilityAre customer and provider duties explicit?Full priority-service coverage and tested exitShared-responsibility ambiguity
OTCritical devices with migration or isolation routeCan long-lived hardware be remediated?Every critical asset has an executable routeMore than 20% remain unsupported
Supply chainSuppliers with crypto-agility commitmentsAre obligations contractually enforceable?Above 90%More than 15% refuse disclosure
AssuranceMedian certification durationIs capacity scaling with demand?Below nine monthsMedian exceeds eighteen months
WorkforceFilled specialist positionsCan the plan execute without excessive contracting?Demand-supply gap below 10%Contractor premium exceeds 30%
FragmentationIncompatible sovereign profilesIs mutual recognition expanding?Limited and modular regional varianceSeparate product lines required in major markets
FinanceFunding aligned with verified plansDo budgets reflect actual inventories?Multiyear funded executionMandates lack appropriations
FallbackClassical-only acceptance routesAre downgrade paths controlled?Disabled in migrated priority systemsSilent fallback remains widespread
ResilienceAlgorithm and provider portabilityCan the system migrate again?Tested substitution of algorithms and providersHard-coded algorithms or non-exportable keys

The final five-year judgement is that H1 remains the leading scenario, but its probability should not exceed a simple majority until certificate, identity, validation and OT evidence demonstrates operational interoperability rather than policy alignment. H2 is the most strategically consequential alternative because separate sovereign cryptographic stacks would raise costs across finance, cloud, telecommunications, industrial exports and digital government. H3 may operate inside H1: platform providers can accelerate common standards while simultaneously concentrating control in hyperscalers and operating-system vendors. H4 remains comparatively unlikely but carries extreme short-term cost, making contingency procurement and crypto-agile design rational even if no emergency materialises. H5 will not occur uniformly; it is most plausible in municipal, healthcare, educational, SME and legacy-OT environments while high-value national-security and financial systems move faster. The optimal policy is therefore differentiated acceleration. Governments and organisations should prioritise long-lived sensitive data, high-value identity, code signing, critical remote access, irreplaceable trust anchors and procurement of long-lived equipment. Lower-risk systems can follow ordinary refresh cycles if their eventual route is documented and funded. Success in 2031 will not be defined by declarations that migration is complete. It will be defined by operational use of approved algorithms, end-to-end trust-chain functionality, controlled fallback, adequate supplier competition and sufficient crypto-agility to execute the next cryptographic transition without recreating the same capital shock.

Figure 1 · Bayesian Five-Year Outlook

Dominant Migration Scenarios, 2027–2031

INTERACTIVE UPDATE

The values are structured analytical probabilities, not official forecasts and not estimates of when a cryptographically relevant quantum computer will exist. The controls simulate directional Bayesian updates and renormalise the five scenario probabilities to 100%.


Copyright of debuglies.com - Even partial reproduction of the contents is not permitted without prior authorization – Reproduction reserved

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Questo sito utilizza Akismet per ridurre lo spam. Scopri come vengono elaborati i dati derivati dai commenti.