Executive Summary
Post-quantum cryptography is becoming a global capital-investment cycle, not a conventional cybersecurity update.
Between 2026 and 2031, governments and companies must identify cryptographic dependencies, redesign trust architectures, test hybrid systems and replace incompatible hardware.
The only transparent sovereign cost anchor is the preliminary US$7.1 billion estimate for priority United States federal systems during 2025–2035.
The aggregate global cost cannot yet be stated as a verified figure because governments have not published comparable inventories or accounting methodologies.
The United States holds the strongest standards and procurement position; China combines state direction with strategic opacity.
Europe has a common deadline but fragmented national execution, financing and certification capacity.
The United Kingdom has the clearest migration sequence; France and Germany possess strong assurance institutions and industrial suppliers.
Italy has credible technical guidance but remains exposed through SMEs, legacy public systems, healthcare infrastructure and industrial operational technology.
The decisive five-year competition will concern certification, hardware roots of trust, cloud migration, cryptographic inventories, specialist labour and procurement eligibility.
Post-quantum expenditure will therefore operate as a concealed form of industrial policy, redistributing contracts, technological dependence and sovereign control.
The Quantum Migration Bill: Security Becomes Industrial Policy
Quantum computing has not yet broken the cryptography securing banks, factories and governments. Yet the expenditure cycle has already begun. Post-quantum migration is not an algorithmic update: it is a reconstruction of digital trust spanning identity, cloud services, software signatures, hardware security modules, telecommunications and industrial control. Washington estimates US$7.1 billion merely to migrate priority federal systems over 2025–2035; Europe wants critical infrastructure transitioned by the end of 2030. The strategic question is therefore no longer whether organisations will pay, but when, to whom and under whose standards. Between 2027 and 2031, cryptographic compliance will redirect procurement towards certified chips, cloud platforms, security appliances and specialist services. What appears on balance sheets as cybersecurity expenditure will function as industrial policy—rewarding countries that can transform standards into products and exposing those that remain dependent on foreign trust infrastructure.
From Algorithm to Estate
On 13 August 2024, the US National Institute of Standards and Technology approved FIPS 203, FIPS 204 and FIPS 205, establishing ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – NIST – August 2024 — official standards notice.
The standards solve the mathematical-selection problem, not the migration. Vulnerable public-key cryptography remains embedded in certificate authorities, virtual private networks, application interfaces, payment systems, smart cards, code-signing services, hardware security modules, secure boot, vehicle electronics and factory controllers. NIST’s migration programme consequently requires organisations to find affected cryptography across hardware, software and services, construct inventories and prioritise replacement. Migration to Post-Quantum Cryptography – NIST National Cybersecurity Center of Excellence – verified August 2026 — official programme.
The real cost stack includes discovery tools, Cryptographic Bills of Materials, application refactoring, hybrid classical–post-quantum operation, certificate reissuance, hardware replacement, interoperability testing, certification, specialist labour and decommissioning. It also includes production interruptions when energy, transport or manufacturing equipment cannot be upgraded without safety review and scheduled shutdown. Migration therefore resembles a multiyear digital-transformation programme more than a conventional security patch.
Washington’s Procurement Machine
The United States has built the most complete transmission mechanism between cryptographic standards and industrial demand. On 22 June 2026, President Donald Trump signed an executive order directing the Office of Management and Budget and the National Cyber Director to coordinate an accelerated federal transition. It requires migration leadership in each agency, a Commerce Department pilot by 31 December 2027, and protection of high-value assets during 2030–2031. Fact Sheet: President Donald J. Trump Secures the Nation Against Advanced Cryptographic Attacks – White House – June 2026 — official fact sheet.
OMB Memorandum M-26-15, issued on 24 June 2026 by Director Russell T. Vought, divides execution into discovery during 2026–2027, pilots during 2027–2028, prioritised key-establishment migration during 2028–2030, signature migration in 2031 and completion of remaining systems by 2035. It explicitly links PQC to cloud migration, hardware-refresh schedules, automated inventories, zero-trust architecture and annual budget requests. Execution of the Migration to Post-Quantum Cryptography, M-26-15 – OMB – June 2026 — official memorandum.
The US Government Accountability Office recorded an initial OMB estimate of US$7.1 billion for priority federal systems across 2025–2035, while cautioning that it was a highly uncertain rough-order projection requiring annual revision. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – GAO – June 2025 — official audit. This is not the cost of the American economy: it excludes much private critical infrastructure, state government and national-security systems. Its importance is political. Federal demand will force suppliers to build validated capabilities into commercial cloud, identity, network and security products, allowing US firms to export the resulting standards and platforms.
Europe’s 2030 Test
Europe has a common deadline but no equivalent federal procurement machine. On 23 June 2025, the European Commission and the NIS Cooperation Group published a coordinated roadmap requiring every member state to begin transition by the end of 2026 and critical infrastructure to migrate no later than the end of 2030. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025 — official roadmap.
Commission Executive Vice-President Henna Virkkunen, responsible for technological sovereignty, security and democracy, presented PQC as essential to protecting Europe’s digital infrastructure. The deadline creates a market encompassing banking, energy, health, transport, telecommunications and public administration. It can support European secure chips, smart cards, industrial cybersecurity, certification laboratories and migration services. But execution remains divided among 27 national governments, regulators and assurance regimes.
The danger is a two-speed transition: major banks, defence contractors and telecommunications groups acquire certified systems, while hospitals, municipalities, regional utilities and smaller manufacturers accumulate cryptographic debt. European rules could then generate demand captured principally by American hyperscalers and non-European hardware vendors. Technological sovereignty will depend not on inventing a rival algorithm for symbolic reasons, but on controlling keys, certificate authorities, hardware roots of trust, evaluation facilities and supplier evidence while preserving international interoperability.
France: Certification as Power
France has moved furthest in converting national assurance into industrial advantage. ANSSI’s model requires hybridisation during the intermediate phase: established classical cryptography operates alongside post-quantum mechanisms so that introducing a new algorithm does not degrade present security. The agency’s framework allows security visas progressively to cover classical security, hybrid construction and quantum resistance. ANSSI Views on the Post-Quantum Cryptography Transition – ANSSI – January 2022, current edition verified August 2026 — official position.
ANSSI now reports the first two French certifications for products incorporating lattice-based PQC, covering solutions from Thales and Samsung evaluated by CEA-Leti. It has also surveyed approximately 50 ministries and strategic enterprises and around 30 potential transition-service providers, while supporting financial instruments for migration technologies. Cryptographie post-quantique – ANSSI – verified August 2026 — official programme.
France’s advantage lies in combining defence electronics, secure elements, smart-card expertise, public research and certification. Its risk is national isolation: a French visa generates greater industrial value if recognised across Europe. Paris must therefore turn ANSSI’s early expertise into European evaluation standards rather than an additional national compliance layer.
Germany: The Factory Problem
Germany’s exposure is concentrated in products expected to operate for decades: vehicles, industrial machinery, chemicals, energy systems and factory automation. BSI endorsed the European roadmap and its 2030 and 2035 milestones. NIS Cooperation Group Publishes EU Roadmap for Post-Quantum Cryptography – BSI – July 2025 — official German notice.
The German challenge is not simply migrating corporate IT. It is upgrading firmware signatures, machine identities, remote-maintenance channels and embedded trust anchors across deep supplier tiers. A cryptographically obsolete component can compromise the export eligibility of an entire vehicle or industrial platform. Replacement may require safety validation and plant shutdown rather than a remote software update.
This exposure can become an advantage. If German manufacturers integrate crypto-agility into equipment before international customers make it mandatory, “quantum-ready” engineering can become a new export-quality attribute. Failure would produce the opposite result: German industrial systems would depend on imported cryptographic modules and foreign cloud key-management services even as Berlin formally pursues technological sovereignty.
Britain’s Clearer Clock
The United Kingdom has published the clearest non-US sequence. NCSC requires complete discovery and an initial estate-wide plan by 2028, the migration of highest-priority services by 2031, and completion across systems, services and products by 2035. It estimates that large organisations may require two to three years merely for discovery and planning, followed by another two to three years for early migration. Timelines for Migration to Post-Quantum Cryptography – NCSC – March 2025 — official guidance.
The schedule gives British banks, insurers, telecommunications operators and government suppliers a common investment horizon. It also creates a professional-services opportunity. NCSC’s PQC consultancy pilot assures suppliers for cryptographic discovery, prioritisation and migration planning and is scheduled for review after 31 March 2027. Post-Quantum Cryptography Pilot – NCSC – verified August 2026 — official scheme.
Britain can export assurance, financial-infrastructure expertise and migration services. Its structural weakness is hardware dependence: domestic consulting may surround imported secure elements, HSMs and cloud platforms. The policy test is whether London retains intellectual property in discovery, middleware and financial protocols rather than becoming merely the implementation layer for foreign technology.
Italy’s Industrial Divide
Italy has a sound technical starting point but a more difficult execution structure. The Agenzia per la Cybersicurezza Nazionale has incorporated post-quantum solutions into its updated TLS guidance. Linee Guida Funzioni Crittografiche: Transport Layer Security – ACN – May 2026 — official Italian guidance.
The Italian estate combines sophisticated banks, defence and aerospace companies, energy groups and telecommunications operators with fragmented public administration, regional healthcare and manufacturing districts dominated by SMEs. Migration requirements will reach smaller firms through customer contracts before every supplier faces a direct legal mandate. An automotive, aerospace or machinery supplier unable to document cryptographic dependencies and secure-update mechanisms could lose access to international programmes.
Italy should not attempt to reproduce every American or French capability. It needs shared Cryptographic Bill of Materials methodologies, pooled public procurement, subsidised discovery for SMEs and laboratories specialising in embedded and industrial systems. ACN can convert regulatory fragmentation into a common national market. Without aggregation, regions, hospitals and SMEs will purchase separately, raising costs and reinforcing dependence on foreign integrators.
China’s Vertical Stack
China is building a more state-directed and less transparent ecosystem. In June 2025, the State-owned Assets Supervision and Administration Commission reported that China Electronics Technology Group had introduced the “Liangkai” anti-quantum family: cryptographic chips and cards, software modules, server and financial cryptographic machines, security gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – SASAC – June 2025 — official Chinese source.
The breadth of the portfolio reveals Beijing’s objective: control the vertical chain from chip to certificate rather than depend on foreign trust infrastructure. State banks, telecommunications operators and centrally administered enterprises can provide procurement scale. China may also export quantum-resistant functionality as part of telecommunications, cloud and digital-government platforms, creating long-term dependence through key management and device identity.
Yet Beijing has not publicly established a unified national deadline comparable to the US, EU or UK schedules. Nor do product announcements prove deployment scale or independent performance. China’s strategic opacity increases uncertainty for multinational companies: they may need separate cryptographic profiles, certifications and product lines for Chinese and Western markets.
The 2031 Allocation
The central scenario is an uneven but irreversible transition. Discovery and supplier mapping will dominate 2027; certification and early production deployment, 2028; high-value migration, 2029; critical-infrastructure and hardware replacement, 2030; signatures and trust chains, 2031. Digital signatures may become the hardest stage because code, firmware, credentials and machine commands require every verifier to accept the new format.
The winners will be vendors controlling validated HSMs, secure elements, certificate systems, cloud key management, discovery platforms and industrial gateways. The losers will be organisations that mistake policy publication for migration, or that discover embedded cryptography only when deadlines make replacement expensive.
Post-quantum readiness will thus become a condition of market access, insurability and investment quality. The emerging divide is not between states that understand quantum physics and those that do not. It is between states able to translate cryptographic rules into domestic capability—and those that finance a transition whose strategic value is captured elsewhere.
Navigational Index
- Capital Shock — Why migration extends from algorithms to hardware, identity, cloud, software supply chains and operational technology.
- Sovereign Competition — How the United States, China, Europe, Italy, France, the United Kingdom and Germany will convert security requirements into industrial advantage.
- Five-Year Outlook — Bayesian scenarios, competing hypotheses, migration milestones and leading indicators for 2027–2031.
Master Abstract
Capital Shock
Post-quantum migration is frequently misclassified as a cryptographic software update. Its real economic perimeter is considerably larger because modern cryptography is embedded in the mechanisms through which machines, people, applications and institutions establish trust. The migration surface includes public-key infrastructures, certificate authorities, code-signing systems, hardware security modules, secure elements, trusted platform modules, virtual private networks, payment authentication, application programming interfaces, cloud key-management systems, identity credentials, firmware verification, industrial-control devices, telecommunications infrastructure, connected vehicles and long-lived archival signatures. The approval of FIPS 203, FIPS 204 and FIPS 205 transformed post-quantum cryptography from a research problem into a deployable standards programme. These standards respectively specify ML-KEM for key establishment, ML-DSA for primary digital signatures and SLH-DSA as a hash-based signature alternative. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – National Institute of Standards and Technology – August 2024 — Official NIST standards notice. The standards do not, however, eliminate implementation risk. Organisations must first discover where vulnerable algorithms such as RSA, ECDH and ECDSA are used, including undocumented dependencies embedded in commercial products and inherited code. They must subsequently classify systems by data lifetime, operational criticality, replacement difficulty and supplier readiness. Migration expenditure therefore includes cryptographic discovery, Cryptographic Bills of Materials, protocol engineering, software remediation, dual-stack operation, hardware replacement, testing, certification, bandwidth remediation, latency management, specialist personnel, supplier negotiations, rollback capacity and decommissioning. The cost is consequently distributed across cybersecurity budgets, cloud modernisation, identity programmes, network refreshes, industrial automation, procurement and compliance. This accounting dispersion makes PQC a hidden industrial-policy variable: governments may generate large domestic demand without formally announcing a conventional industrial-subsidy programme.
The only credible public-sector monetary anchor currently available is the preliminary United States estimate recorded by the Government Accountability Office. According to GAO, the Office of Management and Budget produced a rough-order estimate of US$7.1 billion to migrate priority federal-agency systems between 2025 and 2035. GAO emphasised that the estimate carried a high degree of uncertainty and would require annual revision as agencies improved their inventories and costing methodologies. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – U.S. Government Accountability Office – June 2025 — Official GAO assessment. The figure must not be presented as the cost of the entire American transition: it concerns priority federal systems, excludes much of the private sector, state and local government, critical infrastructure and national-security systems, and does not establish a globally transferable unit cost. It nevertheless demonstrates that even a bounded governmental perimeter creates a multiyear capital programme comparable to previous identity, cloud and zero-trust transformations. Global expenditure cannot currently be calculated with forensic certainty because no harmonised international inventory exists and national authorities use different definitions of systems, cryptographic assets and eligible migration costs. Any precise global figure would therefore be a modelled scenario rather than an observed fact. A defensible costing framework must distinguish direct remediation from accelerated asset replacement, avoid counting ordinary modernisation twice, model the cost of running classical and post-quantum systems simultaneously, and account for the disproportionately high expense of long-lived industrial equipment. The hidden bill will be shaped less by algorithm licence costs than by dependency discovery, product assurance, hardware compatibility, integration labour and the commercial leverage of a limited population of certified suppliers.
Sovereign Competition
The United States enters the transition with the most powerful combination of standards authority, federal purchasing power, cloud concentration and security-product validation. The June 2026 executive order established federal coordination, required agency migration leadership and directed assistance to critical-infrastructure operators. Securing the Nation Against Advanced Cryptographic Attacks – The White House – June 2026 — Official executive order. OMB subsequently required agencies to mitigate as much quantum risk as feasible by 31 December 2030, submit migration plans, conduct discovery during 2026–2027, execute pilots during 2027–2028, migrate prioritised key-establishment functions during 2028–2030 and address digital signatures in 2031. The memorandum explicitly links PQC to cloud migration, hardware-refresh schedules, automated inventories, zero-trust architecture and annual budget requests. Execution of the Migration to Post-Quantum Cryptography, M-26-15 – Office of Management and Budget – June 2026 — Official OMB memorandum. This creates an industrial transmission mechanism: compliance clauses will move from federal tenders into cloud services, identity products, network equipment, security modules and software development standards. Vendors able to provide validated, crypto-agile products gain market access; suppliers that cannot demonstrate their cryptographic dependencies face exclusion or premature obsolescence. The American advantage is therefore not simply algorithmic. It lies in controlling the interaction between standards, validation, procurement, hyperscale infrastructure and international interoperability. The principal risks are budget fragmentation, incomplete inventories, dependency on ageing federal systems, scarcity of specialised personnel and excessive concentration in a small number of cloud, semiconductor and security vendors. The United States is nevertheless positioned to convert transition expenditure into exportable standards and products, making PQC migration simultaneously a cyber-defence programme, a market-access regime and an instrument of technological influence.
China presents a structurally different model. Its public evidence shows state-supported work across quantum communication, domestic commercial cryptography, anti-quantum products and international standardisation, but it does not reveal a unified national PQC migration calendar equivalent to the published American, European or British timelines. China Electronics Technology Group, a centrally managed state-owned enterprise, announced an anti-quantum cryptography product family and participation in relevant standards development. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025 — Official Chinese state-enterprise notice. China’s strategic advantage is its capacity to coordinate telecommunications operators, state banks, government systems, equipment manufacturers and state-owned enterprises through administrative direction and procurement. Its domestic cryptographic regime can also protect national suppliers from external competition and accelerate controlled trials. Its disadvantage is interoperability risk. If Chinese standards, certificate systems or implementation profiles diverge materially from NIST-derived ecosystems, multinational manufacturers, financial institutions and cloud providers may have to maintain separate cryptographic stacks. That would increase costs but could also create a durable Chinese-controlled market. The key analytical distinction is between PQC, which uses mathematical algorithms on existing computing infrastructure, and quantum key distribution, which depends on specialised communications infrastructure. Chinese policy visibly supports both; they are complementary in selected high-value environments but not economically interchangeable. Over the next five years, the most important indicators will be mandatory procurement clauses, national algorithm selections, certified module catalogues, telecom deployment requirements, banking-sector pilots and the incorporation of post-quantum mechanisms into domestic public-key and commercial-cryptography rules. Until these become transparent, any numerical Chinese migration-cost estimate must remain a scenario range rather than a verified national budget.
Europe and the National Execution Gap
The European Union has established a common strategic direction but has not created a single federal procurement machine comparable to Washington. The European roadmap requires member states to begin transitioning by the end of 2026 and calls for critical infrastructure to complete the transition as soon as possible and no later than the end of 2030. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025 — Official European roadmap. This schedule is strategically ambitious because Europe must coordinate national cybersecurity authorities, sector regulators, public administrations, telecommunications operators, banks, cloud providers, defence systems and industrial manufacturers while avoiding incompatible national profiles. ENISA has already identified that migration involves more than selecting algorithms: post-quantum systems must be integrated into existing protocols, hybrid configurations may be required, and the wider chain of dependent standards must be updated. Post-Quantum Cryptography: Integration Study – European Union Agency for Cybersecurity – October 2022 — Official ENISA study. Europe’s opportunity is to use cybersecurity certification, public procurement, semiconductor policy, digital-identity infrastructure and regulated-sector requirements to stimulate European products and services. Its principal risk is a two-speed transition in which wealthy states and major financial or industrial groups proceed rapidly while smaller administrations, hospitals, municipalities and SMEs remain dependent on foreign vendors or unsupported legacy equipment. PQC therefore tests whether European technological sovereignty can move from strategic language to coordinated capital execution. Without pooled procurement, shared testing infrastructure, common implementation profiles and financing mechanisms for smaller operators, the 2030 critical-infrastructure objective could produce fragmented compliance, duplicated certification expenditure and continued dependence on American cloud platforms and non-European hardware roots of trust.
Italy has established a credible technical starting point through the Agenzia per la Cybersicurezza Nazionale, which published an introduction to post-quantum and quantum-safe cryptography in July 2024. Crittografia Post-Quantum e Quantistica – Agenzia per la Cybersicurezza Nazionale – July 2024 — Official ACN technical paper. Italy’s exposure is not primarily the absence of institutional awareness. It is the composition of its digital and industrial estate: fragmented public administration, regional healthcare systems, municipal services, financial infrastructure, defence suppliers, telecommunications networks and manufacturing districts dominated by SMEs. Many industrial companies operate equipment whose useful life extends well beyond 2030 and whose cryptographic functions are embedded in firmware, remote-maintenance channels or proprietary control systems. Replacement decisions will therefore intersect with Industria 4.0, cloud migration, machinery investment, connected-product regulation and supply-chain qualification. Italy could convert the transition into industrial policy by developing shared cryptographic-discovery services, accredited testing facilities, procurement templates, migration financing for SMEs and specialised capabilities for embedded systems, automotive components, aerospace, defence, energy and industrial automation. Without these measures, compliance costs will be regressive: large banks, telecommunications groups and defence contractors will purchase migration capacity, while smaller suppliers will postpone action or depend on foreign integrators. The five-year Italian priority should consequently be a national cryptographic inventory methodology, sector-specific migration profiles, identification of long-lived operational technology, workforce development and integration of PQC requirements into public procurement and strategic supply-chain contracts. The risk is not merely cyber vulnerability; it is the loss of supplier eligibility when larger European or American customers begin requiring evidence of crypto-agility.
France holds a stronger assurance position because ANSSI has explicitly supported hybrid post-quantum mechanisms and anticipated French security approvals for products incorporating hybrid PQC. Avis de l’ANSSI sur la migration vers la cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – January 2024 — Official ANSSI position. France can connect migration demand to its defence-industrial base, sovereign-cloud agenda, digital-identity systems, smart-card expertise and security-certification ecosystem. The French hybrid approach reduces the danger of relying exclusively on comparatively new post-quantum algorithms because both classical and post-quantum components contribute to security when correctly combined. It nevertheless increases implementation complexity, message size, testing requirements and lifecycle-management cost. France’s industrial-policy advantage will depend on whether its national assurance mechanisms remain interoperable with European and international profiles rather than creating a costly national island. Germany, meanwhile, combines BSI guidance with an exceptionally large industrial and manufacturing attack surface. Kryptografie quantensicher gestalten – Federal Office for Information Security – 2023 edition — Official BSI guidance. German exposure is concentrated in automotive systems, machinery, chemicals, energy, logistics and industrial control, where products remain operational for decades and security updates must satisfy safety, performance and certification constraints. Germany can capture value through industrial cybersecurity, embedded components, trusted hardware and engineering services, but delayed supplier action could make its export base vulnerable to foreign procurement requirements. In both countries, PQC migration will function as a supplier-selection mechanism long before it becomes a universal statutory obligation.
The United Kingdom has published the clearest operational timetable among the European jurisdictions examined. The National Cyber Security Centre expects organisations to complete discovery, assessment and initial planning by 2028, migrate their highest-priority services and refine their plans by 2031, and complete migration across systems, services and products by 2035. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025 — Official NCSC guidance. NCSC estimates that large organisations may require two to three years simply to discover their cryptographic estate, assess dependencies and construct an initial plan. It also identifies WebPKI and industrial-control protocols as particularly difficult migration areas because they require coordination across decentralised trust infrastructures and legacy operational systems. The United Kingdom’s advantage lies in its concentrated financial sector, cybersecurity capabilities, intelligence-informed guidance and capacity to align regulators with major infrastructure operators. London’s financial ecosystem could turn PQC readiness into an operational-resilience and insurance requirement, pushing migration expectations through payment networks, clearing systems, custodians, fintech suppliers and outsourced cloud services. The associated risk is a concentration of costs during the 2028–2031 period, when high-priority migration demand may collide with limited assurance, HSM, PKI and engineering capacity. British firms that complete discovery early will be able to integrate PQC into ordinary replacement cycles; late movers will face accelerated procurement, duplicated hybrid systems and scarcity premiums. This makes the UK schedule not merely a security roadmap but a forward signal for capital budgeting, vendor strategy and regulated outsourcing.
Five-Year Outlook, 2027–2031
The five-year baseline assigns the highest probability to a coordinated but uneven migration rather than either immediate cryptographic collapse or effortless universal adoption. The current Bayesian distribution is: 58% for regulation-led convergence around NIST-derived algorithms and compatible profiles; 14% for geopolitical fragmentation into partially incompatible Western and Chinese ecosystems; 12% for migration absorbed predominantly into normal technology-refresh cycles; 10% for threat-led acceleration following a material cryptanalytic, intelligence or security event; and 6% for prolonged budgetary delay. These percentages are structured analytical judgments, not government forecasts and not estimates of when a cryptographically relevant quantum computer will exist. The evidence supporting the baseline includes final NIST standards, the binding American migration sequence, the EU 2030 critical-infrastructure objective, the British 2028–2031–2035 roadmap and active French, German and Italian technical preparation. Evidence against rapid convergence includes unfinished protocol work, difficult WebPKI coordination, legacy industrial equipment, uncertain product assurance, incompatible domestic cryptographic regimes and the absence of complete asset inventories. During 2027, discovery platforms, CBOMs, consulting, pilots and procurement specifications should receive the strongest marginal growth. During 2028, validated modules, hybrid TLS, identity systems, HSMs and secure-boot products should move into broader procurement, while the absence of compliant products will become a measurable supplier risk. During 2029–2030, capital pressure should shift toward high-value systems, critical infrastructure, telecommunications, cloud gateways and long-lived sensitive data. By 2031, digital signatures, certificate hierarchies, device identity and high-priority industrial systems should become the decisive bottlenecks. The probability of schedule slippage will rise where organisations cannot distinguish cryptographic assets from ordinary software inventories or where suppliers refuse to disclose embedded dependencies.
Five competing hypotheses must remain under continuous review. H₁ — Regulated convergence: NIST algorithms become the principal international baseline, with regional implementation profiles but broad interoperability. Confirmation would come from common TLS, PKI, hardware-module and procurement standards. H₂ — Bloc fragmentation: China, Western states and possibly other jurisdictions develop divergent certification and algorithm ecosystems. Confirmation would include mandatory domestic algorithms, restricted cross-certification and duplicated product lines. H₃ — Refresh-cycle absorption: most migration cost is incorporated into scheduled cloud, network, identity and hardware modernisation. Confirmation would require limited emergency appropriations and high PQC availability in standard products. H₄ — Threat-led acceleration: a credible cryptanalytic breakthrough, intelligence disclosure or compromise campaign forces earlier deadlines and emergency replacement. Confirmation would include compressed mandates, extraordinary budgets and rapid deprecation of vulnerable algorithms. H₅ — Budget delay: governments publish roadmaps but defer implementation because inventories, personnel and products remain insufficient. Confirmation would include repeated deadline extensions, audit failures, unresolved legacy exceptions and increasing use of compensating controls. The present evidence favours H₁, but H₂ is more plausible for Chinese sovereign systems and H₅ remains materially plausible for municipal, healthcare, educational and SME environments. Analysts should therefore avoid a single global forecast and instead track sector- and jurisdiction-specific transitions.
The shadow dimensions of migration are equally important. “Harvest now, decrypt later” operations create a premium on protecting information whose strategic value persists for many years, including defence designs, diplomatic communications, genomic data, intellectual property and critical-infrastructure architecture. State intelligence services need no immediate quantum computer to benefit from collecting encrypted material today. Cyber-insurance markets may consequently begin demanding evidence of cryptographic inventories and migration planning, converting uncertain future risk into current premiums and exclusions. Liquidity effects will emerge when capital-intensive sectors must accelerate equipment replacement, while vendors with validated HSMs, secure elements, certificates, identity platforms and migration tooling gain pricing power. Private-equity and infrastructure investors will need to treat cryptographic debt as a technical liability during due diligence, especially for telecommunications, healthcare, payments, data centres and industrial platforms. Mercenary and criminal cyber actors are unlikely to possess cryptographically relevant quantum systems during the five-year horizon, but they can exploit migration failures, downgrade paths, misconfigured hybrid implementations, counterfeit certificates and abandoned legacy systems. The principal near-term threat is therefore not quantum decryption itself; it is the expanded attack surface created by a complex, multiyear transition. The optimal policy objective is consequently crypto-agility: the capacity to discover, replace, configure and retire algorithms without repeating an estate-wide crisis whenever standards or threat assessments change.
PQC Capital Shock Simulator
Capital deployment profile
Structural risk
The expenditure ranges are analytical scenarios rather than government forecasts. They cover incremental labour, software, assurance, testing, hardware and programme overhead during 2027–2031. They exclude quantum-computer research, unrelated ordinary cybersecurity expenditure, losses from a cryptographic breach and costs after 2031. Jurisdictional estimates are independent envelopes and must not be added together.
Capital Shock: The Post-Quantum Reconstruction of Digital Industry
Post-quantum migration creates a capital shock because public-key cryptography is not a discrete application layer that organisations can replace by installing a new algorithmic package; it is a deeply embedded trust substrate connecting hardware, operating systems, identities, software dependencies, communications protocols, cloud services and physical infrastructure. The three principal standards approved by the United States National Institute of Standards and Technology in August 2024—FIPS 203 ML-KEM, FIPS 204 ML-DSA and FIPS 205 SLH-DSA—supply standardised mechanisms for key establishment and digital signatures, but they do not automatically migrate the systems in which RSA, Diffie–Hellman, ECDH, ECDSA and other quantum-vulnerable mechanisms remain embedded. Announcing Approval of Three Federal Information Processing Standards for Post-Quantum Cryptography – National Institute of Standards and Technology – August 2024 — Verified official standards notice. NIST’s migration programme explicitly states that organisations must determine where vulnerable public-key algorithms are used across hardware, software and services, construct inventories, prioritise dependencies and test interoperability. Migration to Post-Quantum Cryptography – National Cybersecurity Center of Excellence, NIST – current programme page verified August 2026 — Verified official programme. This changes the economic object being purchased. Organisations are not buying “quantum-safe encryption” in isolation; they are financing the reconstruction of certificate chains, firmware-signing procedures, privileged-access systems, machine identities, key-management services, payment authentication, application interfaces, secure communications and industrial remote-access channels. The capital shock therefore comprises direct expenditure, accelerated replacement of otherwise serviceable assets, temporary duplication during hybrid operation, performance remediation, certification delays and the opportunity cost of specialist labour diverted from other digital-transformation programmes. Because these costs will be distributed among cybersecurity, cloud, identity, network, hardware, compliance and operational-technology budgets, conventional accounting will systematically understate the aggregate programme.
The full migration-cost architecture
| Cost layer | Assets and processes affected | Principal expenditure mechanism | Hidden balance-sheet effect | 2027–2031 pressure |
|---|---|---|---|---|
| Cryptographic discovery | Source code, binaries, certificates, network traffic, appliances, embedded libraries | Scanning tools, CBOM platforms, manual validation, dependency mapping | Previously unrecorded cryptographic debt becomes visible | Very high in 2027–2028 |
| Application remediation | Libraries, APIs, authentication flows, signing services, custom applications | Refactoring, integration, regression testing, protocol redesign | Capitalised software may require premature modification | High throughout |
| PKI and digital identity | CAs, certificates, smart cards, tokens, device identities, IAM, FICAM | Certificate-profile redesign, enrolment, issuance, revocation, lifecycle replacement | Existing credentials and trust anchors become transitional assets | Rising sharply in 2028–2031 |
| Hardware security | HSMs, TPMs, secure elements, cryptographic cards, roots of trust | Firmware upgrade or physical replacement, validation and recertification | Accelerated obsolescence of installed hardware | Highest after validated products scale |
| Cloud and network | KMS, TLS termination, VPN, API gateways, load balancers, service meshes | Shared-responsibility renegotiation, hybrid handshakes, bandwidth and compute overhead | Vendor concentration and switching costs increase | Continuous; peaks near mandates |
| Software supply chain | Open-source libraries, commercial software, CI/CD, SBOM and signing systems | Supplier disclosure, new components, build-pipeline modification, code-signing migration | Unsupported dependencies can invalidate entire product lines | Systemic from 2027 |
| Operational technology | PLCs, SCADA, DCS, field devices, industrial gateways, remote maintenance | Compensating controls, gateways, staged shutdowns, hardware replacement | Long-lived assets may become cryptographically stranded | Severe but delayed |
| Assurance and certification | FIPS 140-3 modules, national approvals, sector qualification | Laboratory testing, documentation, validation queues, audit evidence | Certification scarcity creates supplier rents | High in 2028–2031 |
| Dual operation | Classical plus PQC algorithms, duplicate credentials, fallback infrastructure | Additional compute, larger messages, parallel monitoring and support | Migration temporarily enlarges rather than simplifies the estate | High during transition |
| Decommissioning | Legacy keys, certificates, archives, protocols and devices | Revocation, re-encryption, disposal, evidence retention | Residual liability persists after installation of new products | Material after 2029 |
The discovery phase is the first source of capital expansion because cryptography is ordinarily inventoried less accurately than servers, applications or network devices. A single business service can depend on a browser, API gateway, load balancer, application server, container image, cryptographic library, secrets manager, certificate authority, HSM, database connector and third-party identity provider, each using different algorithms for different purposes. A conventional asset inventory may identify these products while failing to record the cryptographic primitives, key sizes, certificate lifetimes, protocol negotiations, software calls and upstream dependencies that determine quantum exposure. NIST’s preliminary migration practice guide therefore examines discovery through CI/CD pipelines, network protocols, active scans and historical traffic captures rather than treating the problem as a static questionnaire. Migration to Post-Quantum Cryptography: Preparation for Considering the Implementation and Adoption of Quantum Safe Cryptography, NIST SP 1800-38A Preliminary Draft – National Institute of Standards and Technology – April 2023 — Verified official NIST practice guide. The resulting Cryptographic Bill of Materials must distinguish encryption, key establishment, signatures, authentication, integrity protection, code signing and certificate validation because each function has a different migration route. Discovery also creates a recursive supplier problem: an enterprise may inventory its direct applications but remain unable to determine whether a proprietary appliance embeds an outdated OpenSSL branch, an unsupported firmware component or a hardware accelerator that cannot process new key and signature formats. Manual discovery is consequently expensive and incomplete, while automated discovery generates false positives and still requires interpretation. The expenditure curve begins before any protected production transaction moves to PQC: organisations must purchase tooling, establish governance, classify data longevity, negotiate supplier disclosures and create migration plans. This explains why expenditure precedes visible deployment by several budget cycles and why firms that wait for a confirmed cryptographically relevant quantum computer would encounter a non-compressible discovery delay.
The American federal programme demonstrates how migration converts cryptographic risk into compulsory budgeting and procurement. In June 2026, the Office of Management and Budget required agencies to mitigate as much quantum risk as feasible by 31 December 2030, submit migration plans, integrate PQC into governance and use automated discovery where appropriate. It established a phased sequence: strategy, planning and discovery during 2026–2027; pilots and early migration during 2027–2028; prioritised key-establishment migration during 2028–2030; digital-signature migration in 2031; and completion of remaining migration by 2035. The memorandum further instructs agencies to integrate PQC into cloud migrations, software-development lifecycles and hardware-refresh schedules, while identifying systems incapable of supporting PQC or hybrid cryptography for replacement or decommissioning. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026 — Verified official memorandum. GAO previously reported an initial US$7.1 billion rough-order estimate for priority federal systems across 2025–2035, while warning that the number carried substantial uncertainty and required annual updates. Leadership Needed to Coordinate Cyber Threat Mitigation Strategy – U.S. Government Accountability Office – June 2025 — Verified official audit. This is not a complete American cost estimate: it excludes large portions of private critical infrastructure, state and local government, commercial finance, telecommunications, healthcare and many national-security systems. Its analytical importance lies elsewhere. It proves that a limited priority perimeter already generates a multibillion-dollar programme before the broader economy is counted. It also shows how procurement clauses can function as industrial policy by redirecting expenditure toward validated modules, discovery platforms, cloud services, identity architecture, secure hardware and systems integration.
Five-year capital-deployment sequence
| Year | Dominant activity | Main assets entering expenditure | Cost character | Critical decision gate |
|---|---|---|---|---|
| 2027 | Inventory, governance and pilots | CBOM tools, code scanners, PKI inventories, pilot HSMs, test environments | Labour- and consulting-intensive | Can the organisation identify cryptography by function and owner? |
| 2028 | Product qualification and early migration | Cloud gateways, VPNs, identity systems, HSMs, signing services | Mixed operating and capital expenditure | Are validated products interoperable and contractually supported? |
| 2029 | High-value production migration | Sensitive-data systems, financial services, government identity, telecom control | Capital-intensive deployment | Can hybrid operation meet performance and availability requirements? |
| 2030 | Critical-infrastructure compression | OT gateways, high-impact systems, long-lived data, regulated platforms | Replacement and assurance shock | Which legacy assets require replacement, isolation or formal exception? |
| 2031 | Signature and trust-chain bottleneck | Code signing, firmware signing, certificate authorities, device identity, archives | Coordination- and certification-intensive | Can end-to-end trust chains operate without classical-only dependencies? |
Hardware converts the migration from software remediation into capital expenditure because cryptographic operations are frequently anchored in devices designed around fixed interfaces, memory budgets, signature sizes and certification assumptions. HSMs protect high-value keys and execute signing or key-management operations within controlled boundaries; TPMs and secure elements establish device identity, measured boot and attestation; network accelerators terminate encrypted sessions; smart cards and tokens carry credentials; embedded controllers verify firmware and remote commands. Some equipment can obtain PQC through firmware, but other equipment lacks memory, processing capacity, configurable libraries or sufficient certificate storage. Even when hardware can technically execute ML-KEM or ML-DSA, its previous certification may not cover the new implementation, forcing revalidation before regulated deployment. The OMB memorandum identifies approximately 1–2 KB signatures for ML-DSA as a potential bandwidth constraint in certain use cases and describes SLH-DSA signatures as reaching tens of kilobytes with slower signing performance. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026 — Verified official technical annex. These characteristics matter for constrained devices, high-volume authentication, certificate chains, satellite links and industrial protocols. China’s state-owned sector illustrates the emerging hardware-product stack: China Electronics Technology Group reported an anti-quantum family encompassing cryptographic chips, cards, software modules, server and financial cryptographic machines, gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025 — Verified Chinese state source. The disclosure does not prove national-scale deployment, but it demonstrates that the transition is already being industrialised as an integrated hardware-and-software market rather than a purely mathematical standard.
Identity creates a separate capital shock because post-quantum key establishment does not automatically resolve the migration of digital signatures, certificate hierarchies and trust anchors. Enterprise identity includes employees, customers, administrators, applications, workloads, devices, robots, vehicles, industrial controllers and software artefacts. Each identity may rely on certificates, signed tokens, authentication keys, directory services, privileged-access controls and revocation infrastructure. A certificate authority cannot simply begin issuing larger PQC certificates without considering relying-party compatibility, path validation, certificate transparency, revocation lists, enrolment systems, smart-card capacity and root-store distribution. Code-signing and firmware-signing transitions are even more sensitive because verification keys may be embedded in devices expected to remain operational for decades. If an immutable bootloader recognises only an older signature format, migration may require an intermediate firmware release, a hybrid trust chain, an external gateway or complete device replacement. The British National Cyber Security Centre identifies WebPKI and industrial-control protocols as especially challenging because decentralised participants must coordinate their transition and many industrial systems still lack modern cryptographic architectures. It sets operational milestones of complete discovery and initial planning by 2028, high-priority migration by 2031 and broad completion by 2035. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025 — Verified official UK guidance. The financial consequence is a multi-generational identity estate: classical-only credentials, hybrid credentials and fully post-quantum credentials may coexist, multiplying issuance, revocation, monitoring and support requirements. Identity becomes one of the largest hidden cost centres because failure does not merely expose confidentiality; it can invalidate authentication, software provenance, transaction authorisation and operational command integrity.
Cloud migration can reduce unit costs by centralising cryptographic services, yet it simultaneously concentrates strategic dependency and reallocates costs through subscription pricing. Cloud key-management services, certificate managers, secrets stores, API gateways, service meshes, identity platforms, serverless runtimes and managed databases each divide responsibility between provider and customer. A hyperscaler may upgrade its infrastructure-level TLS while leaving customers responsible for application certificates, custom libraries, encrypted archives, workload identities and third-party appliances. OMB therefore directs federal agencies to engage cloud providers explicitly to allocate PQC responsibilities within the shared-responsibility model. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026 — Verified official memorandum. Hybrid cryptography increases this complexity because a connection may combine a conventional mechanism with a post-quantum mechanism, preserving classical security if the newer implementation proves defective but increasing handshake size, compute demand, operational states and failure modes. ENISA’s integration study analyses post-quantum integration into established protocols, double encryption, double signatures and the need to update the standards chain surrounding TLS, VPN and other systems. Post-Quantum Cryptography: Integration Study – European Union Agency for Cybersecurity – October 2022 — Verified official study. From a capital-allocation perspective, cloud centralisation can convert an enterprise hardware purchase into recurring operating expenditure while embedding future switching costs. If only a small number of providers deliver validated PQC across identity, HSM, network and data services, migration may reinforce hyperscaler concentration. Procurement authorities must therefore measure not only readiness but also portability, algorithm configuration, evidence access, certificate ownership, exit rights and the capacity to replace cryptographic providers without rewriting applications.
Software supply chains amplify the shock through dependency inheritance. A software producer may write no cryptographic algorithm directly yet depend on libraries, operating-system APIs, container images, package managers, build tools, code-signing services and third-party components that implement vulnerable cryptography. An enterprise migration can therefore fail because one nested dependency remains classical-only, one supplier cannot produce an upgrade, or one signing chain cannot validate a new artefact. NIST’s discovery guidance explicitly covers vulnerable algorithms used in CI/CD pipelines and cryptographic dependencies, while CISA’s product guidance spans hardware and software categories whose suppliers must incorporate post-quantum standards. Product Categories for Technologies That Use Post-Quantum Cryptography Standards – Cybersecurity and Infrastructure Security Agency – January 2026 — Verified official CISA guidance. The immediate cost is not limited to library replacement. Organisations must preserve reproducible builds, retest applications, regenerate keys, modify certificate profiles, update interfaces, re-sign artefacts, validate deployment agents and maintain backward compatibility. Supplier contracts must specify algorithm support, crypto-agility, disclosure obligations, update periods, vulnerability response, certification status and liability for embedded components. This creates a market-selection mechanism: suppliers able to document cryptographic dependencies and support configurable algorithms will retain access to regulated and government customers, whereas opaque or abandoned products become procurement liabilities. The “shadow” market includes specialist migration consultancies, discovery-platform vendors, assurance laboratories, offensive-testing teams and contractors capable of exploiting misconfigured transitions. Cybercriminal and state-aligned operators do not require a cryptographically relevant quantum computer to benefit; they can target downgrade paths, fallback configurations, duplicate credentials, poorly integrated libraries and abandoned devices. The near-term security danger is therefore transition complexity rather than direct quantum decryption, and the expenditure required to manage that complexity belongs inside the migration budget.
Operational technology produces the most difficult cost asymmetry because its assets are expensive, safety-critical, geographically dispersed and designed for service lives far longer than ordinary IT. Industrial control systems include programmable logic controllers, distributed control systems, supervisory control and data acquisition platforms, protection relays, sensors, gateways, engineering workstations and remote-maintenance channels. Cryptography may protect firmware, vendor access, telemetry, safety commands and machine identity, but many devices have limited memory and compute capacity or rely on proprietary protocols. Replacing a certificate or library in an office application can occur during routine maintenance; replacing a cryptographic component in a refinery, power grid, railway, port or production line may require safety review, planned outage, recertification and coordination with original-equipment manufacturers. CISA’s OT analysis warns that future quantum capabilities could affect confidentiality and integrity while emphasising inventory and prioritisation across industrial environments. Post-Quantum Considerations for Operational Technology – Cybersecurity and Infrastructure Security Agency – October 2024 — Verified official CISA report. The practical migration sequence is therefore risk-based: protect long-lived sensitive data and remote-access paths first; introduce quantum-resistant gateways where endpoints cannot migrate; require PQC readiness in new equipment; align replacement with shutdown schedules; and isolate assets for which no safe upgrade exists. Germany and Italy face particularly large industrial exposures because machinery, automotive supply chains, energy systems and SME manufacturers operate extensive embedded estates. Italy’s ACN has incorporated post-quantum solutions into updated TLS guidance, demonstrating that national implementation is moving from conceptual awareness toward protocol-level recommendations. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026 — Verified official Italian guidance. The industrial-policy question is whether governments finance shared testing and SME migration or permit compliance costs to eliminate smaller suppliers.
Comparative capital-shock matrix
| Jurisdiction | Binding or published migration signal | Primary capital-pressure vector | Industrial capture opportunity | Principal execution risk |
|---|---|---|---|---|
| United States | Federal discovery, pilots, priority migration and 2031 signature phase | Federal systems, cloud, identity, validated modules | Standards, hyperscalers, cyber tools, HSMs, federal procurement | Fragmented inventories and supplier concentration |
| China | State-enterprise products and sectoral research; no verified unified public deadline | Domestic cryptographic hardware, finance, telecom and state systems | Chips, cards, gateways, CA and key-management ecosystems | International interoperability and strategic opacity |
| European Union | Transition commencement by end-2026; critical infrastructure by end-2030 | Cross-border regulation, certification and critical infrastructure | European cyber services, trusted hardware and certification | Fragmented national execution and duplicated assurance |
| United Kingdom | 2028 discovery, 2031 priority migration, 2035 completion | Finance, government, telecom and WebPKI | Assurance services, fintech security and consulting | Concentrated demand in 2028–2031 |
| France | Hybrid approach and national security assurance | Defence, sovereign cloud, digital identity and smart cards | Security certification and trusted products | National profiles could raise interoperability costs |
| Germany | BSI-led preparation combined with EU deadline | Automotive, machinery, energy and embedded OT | Industrial cybersecurity and secure components | Long asset lives and extensive supplier tiers |
| Italy | ACN technical guidance within EU timetable | Public administration, healthcare, telecom, defence and SME manufacturing | Shared migration services and embedded-system expertise | Financing, skills, fragmented procurement and legacy OT |
| Russia | Official financial strategy recognises quantum and post-quantum encryption as prospective cybersecurity directions | State finance, domestic cryptography and sovereign infrastructure | Domestic algorithms and state-directed systems | Sanctions, technological isolation and limited public cost transparency |
The Russian and Chinese evidence reinforces the geopolitical conclusion that migration will not produce a perfectly uniform global market. The Bank of Russia’s financial-technology programme for 2025–2027 identifies quantum computing as a challenge to existing cryptographic protocols and lists quantum and post-quantum encryption among promising cybersecurity directions; it also records Russian government roadmaps for quantum computing and communications. Main Directions for Financial Technology Development for 2025–2027 – Bank of Russia – October 2024 — Verified official Russian central-bank document. This source does not establish a nationwide Russian PQC deployment deadline or a published migration budget, and no such claim should be inferred. It does show that financial regulators outside the Western standards ecosystem are integrating quantum-resilience considerations into strategic planning. China’s official product disclosures similarly demonstrate engineering activity without establishing a transparent national cost envelope. These gaps are analytically important: opaque standards selection forces multinational banks, manufacturers and cloud providers to maintain compatibility reserves, potentially duplicate products and price geopolitical change into contracts. The capital shock therefore includes a fragmentation premium comprising multiple cryptographic profiles, local certification, separate key infrastructures, restricted source-code access, domestic hardware requirements and the inability to reuse validation evidence across jurisdictions. For exporters, compliance will become a market-access issue comparable to data localisation or cybersecurity certification. For investors, the relevant diligence questions are whether a portfolio company knows its cryptographic dependencies, whether its products can negotiate multiple algorithms, whether hardware roots of trust can be upgraded, and whether customer contracts allocate the cost of regulatory divergence. A firm may be technically quantum-ready in one jurisdiction yet commercially excluded in another because its implementation, certification or supply chain does not satisfy sovereign rules.
Structural analytic model and competing hypotheses
| Hypothesis | Initial probability | Evidence that would increase probability | Evidence that would reduce probability | Capital consequence |
|---|---|---|---|---|
| H₁ — Standards-led convergence | 46% | Common protocol profiles, reciprocal validation, widespread ML-KEM/ML-DSA adoption | Mandatory incompatible national suites | Lower duplication, strong scale economies |
| H₂ — Bloc fragmentation | 18% | Domestic algorithm mandates, restricted certification, separate root stores | International mutual recognition | High fragmentation premium |
| H₃ — Refresh-cycle absorption | 16% | PQC becomes standard in ordinary cloud, network and device upgrades | Large emergency appropriations and hardware shortages | Lower incremental cost but slower visibility |
| H₄ — Threat-triggered acceleration | 11% | Credible cryptanalytic event, urgent government directives, emergency budgets | Stable threat assessments and orderly deadlines | Severe short-term cost spike |
| H₅ — Budget-constrained delay | 9% | Missed inventories, product shortages, repeated deadline extensions | Pooled procurement and dedicated financing | Accumulating legacy exposure and later replacement shock |
The Bayesian baseline should be updated against observable implementation evidence rather than quantum-computing publicity. The most discriminating indicators are the number and type of validated cryptographic modules; publication of final protocol profiles; adoption of PQC requirements in public tenders; HSM and secure-element availability; migration-plan audit findings; certificate-lifecycle changes; OT supplier roadmaps; cloud contractual terms; and whether regulators require CBOM evidence. The European Union’s coordinated roadmap establishes that member states should begin transitioning by the end of 2026 and critical infrastructure should move no later than the end of 2030. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025 — Verified official policy statement. That timetable increases the probability of H₁ inside Europe, but uneven national financing preserves H₅ risk for smaller operators. American federal procurement and NIST standards also favour convergence, while Chinese and Russian sovereign-technology incentives raise H₂. Monte Carlo cost modelling should therefore use scenario-conditioned variables rather than one deterministic global estimate. A defensible model defines total migration expenditure C as the sum of discovery D, software S, identity I, hardware W, cloud N, OT O, assurance A, dual-operation U and decommissioning R, adjusted for schedule compression K and fragmentation F. In plain notation: C = (D + S + I + W + N + O + A + U + R) × K × F. No subscripts are necessary because the expression contains only aggregate variables. The largest uncertainty is not algorithm cost but the interaction of W, O, K and F: hardware and OT replacement become radically more expensive when deadlines compress or jurisdictional requirements diverge.
Monte Carlo five-year scenario envelope
| Variable | Base distribution | Low-stress interpretation | High-stress interpretation |
|---|---|---|---|
| Discovery completeness | Triangular: 60%, 82%, 96% | Existing inventories provide usable coverage | Hidden dependencies create repeated discovery cycles |
| Supplier readiness | Triangular: 45%, 70%, 92% | Vendors deliver upgrades within planned refresh | Proprietary and embedded products remain unsupported |
| Hardware replacement share | Triangular: 12%, 25%, 48% | Firmware and software upgrades dominate | HSM, secure-element and OT replacement accelerates |
| Hybrid-operation premium | Triangular: 6%, 14%, 29% | Limited dual-stack period | Multiple credential and protocol generations coexist |
| Certification delay | Triangular: 3, 9, 20 months | Validation capacity scales quickly | Laboratory and assurance queues constrain deployment |
| Schedule-compression factor K | Triangular: 0.96, 1.12, 1.45 | Migration follows lifecycle replacement | mandates force expedited procurement |
| Fragmentation factor F | Triangular: 1.00, 1.08, 1.27 | International profiles remain compatible | bloc-specific implementations require duplication |
| OT outage premium | Triangular: 1.05, 1.22, 1.65 | Upgrades align with maintenance windows | emergency shutdowns and safety review dominate |
A 5,000-run scenario model using these variables should not be interpreted as a verified world expenditure forecast because no harmonised global cryptographic inventory exists. Its proper function is to identify the distribution of cost pressure and the variables that management can control. Under a controlled-transition case, discovery begins early, supplier requirements enter contracts before renewal, hardware replacement aligns with normal refresh schedules and hybrid operation remains bounded. Under the central case, the largest annual expenditure occurs in 2029–2030, when production migration, certification and high-value hardware replacement converge. Under the stress case, incomplete inventories delay execution until mandates approach, creating simultaneous demand for scarce HSMs, assurance laboratories, identity specialists and OT engineers. This produces liquidity pressure even when the organisation remains solvent because expenditure shifts forward faster than depreciation schedules and contracted customer revenue. Infrastructure investors should therefore request a cryptographic-debt register alongside ordinary cybersecurity assessments; lenders should examine whether migration expenditure is included in capital plans; insurers may seek evidence of inventories and transition governance; and boards should separate avoidable schedule-compression cost from unavoidable technology replacement. The shadow labour market will include offensive researchers, state-aligned contractors, specialist integrators and “migration mercenaries” able to charge scarcity premiums during deadline compression. These actors do not change the mathematics of PQC, but they can materially change execution cost, intelligence exposure and supply-chain trust. The central strategic conclusion is that early inventory and crypto-agile design have an option value: they allow an organisation to postpone irreversible hardware decisions while preserving the ability to switch algorithms, suppliers and protocols when standards mature.
PQC Migration Expenditure Index, 2027–2031
Indexed scenario model: 2027 controlled-transition expenditure equals 100. Values show relative capital pressure rather than currency expenditure. Moving the controls recalculates the central and stress paths to demonstrate how delayed execution and incompatible standards concentrate costs in 2029–2031.
Sovereign Competition: Post-Quantum Security as Industrial Power
Post-quantum cryptography will become an instrument of sovereign competition because the authority that defines approved algorithms, validation procedures, procurement deadlines and recognised trust anchors also influences which companies can sell hardware, software, cloud services and security infrastructure into regulated markets. The central competitive mechanism is not ownership of a single algorithm. NIST’s principal standards are publicly available and can be implemented internationally. The strategic advantage lies in controlling the institutional chain that transforms mathematical specifications into commercially accepted products: algorithm testing, module validation, security certification, procurement eligibility, cloud accreditation, sector regulation, conformity assessment, workforce development and exportable implementation profiles. The United States has assembled the most mature version of this chain through FIPS 203, FIPS 204, FIPS 205, the Cryptographic Algorithm Validation Program, the Cryptographic Module Validation Program, federal procurement and the CNSA 2.0 schedule for national-security systems. NIST states that the purpose of the CMVP is to promote validated cryptographic modules and give federal agencies a security metric for procuring equipment. Cryptographic Module Validation Program – National Institute of Standards and Technology and Canadian Centre for Cyber Security – current programme page verified August 2026 — Verified official validation programme. Europe possesses substantial cryptographic research, cybersecurity regulation and industrial capability but divides authority among the European Union, national agencies and separate certification ecosystems. China can coordinate state-owned enterprises, telecommunications operators, banks and domestic cryptography providers but has not published a unified migration schedule comparable to the American, European or British roadmaps. The decisive five-year contest will therefore measure how effectively each jurisdiction converts security requirements into demand for domestic products, how quickly it certifies those products, and whether its standards become internationally interoperable or form a protected sovereign market.
Sovereign conversion chain
| Policy instrument | Direct security function | Industrial-policy transmission mechanism | Commercial beneficiaries | Sovereign risk if poorly executed |
|---|---|---|---|---|
| Algorithm standard | Defines acceptable KEMs and signatures | Establishes the technical baseline around which vendors invest | Cryptographic libraries, semiconductor designers, HSM and security vendors | Dependence on foreign standards or incompatible domestic variants |
| Validation programme | Tests algorithm and module implementations | Converts compliance evidence into procurement eligibility | Testing laboratories, module vendors, assurance consultancies | Certification bottlenecks and concentrated market power |
| Procurement deadline | Forces replacement or upgrade | Creates predictable demand and accelerates customer budgets | Cloud, network, identity, hardware and integration suppliers | Scarcity premiums and premature asset replacement |
| National security profile | Sets higher-security parameters and use cases | Shapes defence, intelligence and critical-infrastructure products | Defence primes, secure communications and trusted hardware firms | Separate profiles can fragment civilian and allied markets |
| Cybersecurity certification | Provides formal assurance | Differentiates domestic products and enables regulated-sector sales | Certified product manufacturers and evaluation facilities | National certification can become an interoperability barrier |
| Cloud accreditation | Determines acceptable hosted services | Channels migration spending into approved platforms | Hyperscalers, sovereign-cloud operators and KMS providers | Lock-in and excessive concentration |
| Critical-infrastructure regulation | Extends requirements beyond government | Propagates migration through energy, transport, health and finance | Industrial cybersecurity, OT gateways, telecom and PKI vendors | Smaller operators may be unable to finance compliance |
| Research and industrial grants | Reduces development risk | Supports domestic tools, chips, libraries and migration services | Start-ups, universities and strategic industrial suppliers | Subsidised products may fail to achieve international adoption |
| Skills and testing infrastructure | Expands implementation capacity | Prevents value capture from shifting to foreign consultants | National laboratories, universities and professional services | Domestic mandates without domestic capability increase imports |
| Mutual recognition | Reuses certification across borders | Expands addressable markets and lowers duplication | Export-oriented suppliers | Excessive recognition may weaken sovereign control |
The United States holds the strongest first-mover position because its policy architecture links algorithm standardisation directly to federal acquisition, national-security profiles, cloud infrastructure and a global technology-vendor ecosystem. OMB Memorandum M-26-15 requires agencies to develop migration plans, use risk-based prioritisation, incorporate post-quantum readiness into cloud migration and hardware-refresh schedules, employ automated cryptographic discovery, address third-party software, and represent funding and personnel needs in annual budget requests. It sets discovery for 2026–2027, pilots and early migration for 2027–2028, prioritised key-establishment migration for 2028–2030, signature migration during 2031 and broader completion by 2035. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026 — Verified official memorandum. The industrial advantage arises because federal requirements do not remain confined to government. Suppliers must modify commercial products, cloud platforms, identity systems, network equipment and software-development processes to preserve federal eligibility. The same product improvements can then be sold to banks, healthcare systems, utilities, defence contractors and foreign governments. CISA’s January 2026 product-category guidance identifies hardware and software classes that support or are expected to support PQC, creating a market signal about the categories in which government demand will emerge. Product Categories for Technologies That Use Post-Quantum Cryptography Standards – Cybersecurity and Infrastructure Security Agency – January 2026 — Verified official CISA guidance. This procurement-driven diffusion gives American firms an opportunity to amortise development and certification costs across both public and private customers. It also allows Washington to influence allied requirements because foreign governments seeking interoperability with American systems have incentives to recognise NIST algorithms and validation evidence.
The national-security branch of the American strategy creates an even stronger product-selection mechanism. The NSA’s published transition schedule states that CNSA 2.0 is required for new products and services from 1 January 2027, that equipment without CNSA 2.0 support should be replaced by 31 December 2030, and that CNSA 2.0 is mandated for covered systems by 31 December 2031, subject to specified exceptions or waivers. The profile uses ML-KEM-1024 for key establishment and ML-DSA-87 for digital signatures at all classification levels. CSfC Post-Quantum Cryptography Guidance Addendum, Draft 1.0 – National Security Agency – April 2025 — Verified official NSA guidance. This schedule influences secure communications, network encryptors, certificate systems, end-user devices, key-management products and software-signing systems before civilian mandates reach full maturity. It rewards suppliers capable of meeting high-assurance parameter requirements, implementing certificate-based architectures and completing evaluation early. The official NIST implementation-under-test list, updated in August 2026, displayed 238 modules undergoing FIPS 140-3 testing and included post-quantum modules alongside products from cloud, semiconductor, operating-system, networking, HSM and identity vendors. The list does not mean all 238 modules implement PQC, nor does inclusion equal validation; it shows the scale and diversity of the certification pipeline and the market relevance of formal testing. Cryptographic Module Validation Program: Implementation Under Test List – National Institute of Standards and Technology – updated August 2026 — Verified official NIST list. The American competitive risk is that validation capacity and procurement could entrench a small number of hyperscalers and incumbent security suppliers. Nevertheless, the United States presently has the clearest mechanism for turning government security expenditure into commercially exportable standards, validated products and allied technological dependence.
United States industrial-conversion matrix
| Federal requirement | Market transformed | Likely value-capture layer | International spillover | Strategic vulnerability |
|---|---|---|---|---|
| NIST algorithm baseline | Cryptographic libraries and protocols | Software platforms, operating systems, cloud and network vendors | NIST algorithms become the default international reference | Foreign adoption may be broad without corresponding US control over implementations |
| CMVP/FIPS 140-3 | Security modules and appliances | Accredited laboratories, HSMs, cloud KMS, secure hardware | Foreign vendors seek US validation to access global regulated markets | Queue capacity and high compliance costs favour incumbents |
| OMB 2030–2031 phases | Federal applications and infrastructure | Systems integrators, discovery tools, identity and cloud services | Suppliers incorporate PQC into standard commercial products | Budget compression may create rushed deployment |
| CNSA 2.0 | National-security systems | Defence primes and high-assurance communications | Allies align secure products with US profiles | Separate national-security parameters can increase product complexity |
| FedRAMP and cloud coordination | Public cloud and SaaS | Large cloud providers and accredited service platforms | Cloud-delivered PQC becomes globally scalable | Shared-responsibility ambiguity and lock-in |
| FICAM modernisation | Identity and access management | Credential, smart-card, PKI and authentication vendors | US identity profiles influence allied and corporate deployments | Legacy credentials and decentralised trust chains |
China approaches sovereign conversion from the opposite direction: less public timetable transparency, but stronger administrative capacity to coordinate state-owned firms, telecommunications operators, banks, government cryptography and domestic equipment suppliers. The most concrete official evidence is the State-owned Assets Supervision and Administration Commission disclosure that China Electronics Technology Group introduced the “Liangkai” anti-quantum cryptography family, covering cryptographic chips, cryptographic cards, software modules, server and financial cryptographic machines, integrated security gateways, key-management systems and certificate-authority systems. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025 — Verified official Chinese state source. A separate Chinese government-hosted disclosure reported development of a chip-level post-quantum cryptographic card combining a PQC system-on-chip with a quantum-random-number chip and supporting traditional Chinese commercial cryptography alongside post-quantum algorithms. China’s First Chip-Level Post-Quantum Cryptographic Card Emerges – Digital China Summit government portal – July 2025 — Verified Chinese government-hosted source. These sources do not demonstrate nationwide deployment or independent performance verification. They do, however, reveal the desired industrial architecture: China is seeking vertically integrated capabilities from algorithms and chips through appliances, key management and certificate infrastructure. This reduces dependence on foreign security modules and allows domestic suppliers to support state-specific cryptographic requirements. If public authorities, state banks and telecom operators adopt the same product families, procurement scale could rapidly improve domestic engineering and reduce unit costs.
China’s industrial opportunity extends beyond its domestic market. Countries procuring Chinese telecommunications, cloud, surveillance, financial or digital-government infrastructure may receive quantum-resistant features as part of integrated platforms, allowing Beijing to export not only equipment but trust architecture. The strategic value lies in certificate issuance, key management, device identity and update authority: control over these layers can produce durable dependence even when the underlying algorithm is public. China can also develop dual-capable products supporting domestic commercial cryptography and NIST-derived algorithms, enabling suppliers to serve both protected national markets and international customers. The principal constraint is interoperability. A product that supports multiple algorithms still requires recognised certification, protocol compatibility, transparent implementation evidence and trusted supply chains. If China mandates domestic algorithms or approval processes that diverge significantly from Western regimes, multinational banks, automotive firms, manufacturers and cloud providers may need separate product lines. Such fragmentation imposes costs on foreign companies but can function as a protective barrier for Chinese suppliers. The available official evidence does not support a claim that Beijing has published a unified national deadline comparable to the EU’s 2030 critical-infrastructure target or the UK’s 2035 completion objective. This opacity prevents reliable estimation of national migration expenditure and raises the probability that major requirements will emerge through sector regulation, state-enterprise procurement or classified directives rather than a single public roadmap. The competitive indicators for 2027–2031 are therefore domestic algorithm selection, national certification catalogues, state-bank migration pilots, telecom standards, government-cloud requirements and procurement language used by centrally administered enterprises.
China’s potential sovereign stack
| Layer | Verified or observable direction | Industrial advantage sought | External-market consequence | Evidence gap |
|---|---|---|---|---|
| Algorithms | PQC research plus existing domestic commercial cryptography | Indigenous mathematical and implementation capability | Possibility of dual NIST/domestic algorithm products | No verified unified public national selection |
| Semiconductor | Chip-level PQC cards and cryptographic hardware | Reduced dependence on imported secure components | Exportable secure hardware bundled with infrastructure | Independent performance and certification data remain limited |
| Cryptographic appliances | Server, financial and gateway products | State-sector procurement and vertical integration | Turnkey offerings for partner governments and enterprises | Deployment scale not publicly established |
| Key management and CA | Domestic KMS and certificate systems | Control over trust anchors and device identity | Long-term platform dependence | Cross-border trust and mutual recognition unclear |
| Telecom and cloud | Potential integration into operator and cloud platforms | Mass deployment and recurring service revenue | PQC becomes part of wider Chinese digital-infrastructure exports | Public migration timetable remains opaque |
| Finance | Research and banking-oriented migration programmes | Protection of payment and state-financial infrastructure | Financial technology export potential | No consolidated public budget or completion date |
The European Union possesses the scale to become a sovereign industrial pole but must overcome institutional fragmentation. The Commission and NIS Cooperation Group roadmap calls for all member states to begin transitioning by the end of 2026 and for critical infrastructure to migrate as soon as possible and no later than the end of 2030. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025 — Verified official policy statement. The roadmap includes recommendations intended to synchronise national transitions, but implementation remains distributed among national cybersecurity authorities, sector regulators, public administrations, defence institutions, certification bodies and private operators. A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography – European Commission and NIS Cooperation Group – June 2025 — Verified official roadmap. This dispersion creates both opportunity and risk. Europe can use NIS2-related governance, the Cybersecurity Act, European cybersecurity certification, digital-identity infrastructure, public procurement, strategic research programmes and national security schemes to stimulate domestic demand. It also contains significant industrial assets in smart cards, secure elements, semiconductors, telecommunications, defence electronics, automotive systems, industrial automation and cryptographic evaluation. However, if each member state develops separate technical profiles, security evaluations and procurement deadlines, European firms will incur duplicated compliance costs while American hyperscalers absorb the scalable cloud layer.
Europe’s strongest industrial strategy would not attempt to replace NIST mathematics for symbolic sovereignty. It would capture value in implementations, hardware, assurance, migration tooling, identity, OT and lifecycle governance while ensuring European control over the most sensitive trust functions. This requires common implementation profiles, mutual recognition of security evaluations, shared testing infrastructure and procurement rules that reward crypto-agility, portability and documented supply chains. The EU can also create an industrial market through the 2030 critical-infrastructure deadline, because regulated operators will require discovery services, HSMs, PKI modernisation, network upgrades, secure firmware, quantum-resistant remote access and specialised engineering. Yet the deadline may widen differences between large strategic firms and smaller hospitals, municipalities, utilities and SMEs. If financing and technical assistance remain national and uneven, the resulting market will favour large incumbents with existing compliance teams. European sovereignty would then be paradoxical: regulation would be European, but the cloud, operating-system and key-management value could accrue principally to non-European providers. The necessary policy metric is therefore not merely the percentage of systems migrated; it is the proportion of migration expenditure captured by European suppliers without sacrificing international interoperability or security assurance.
European industrial-policy transmission
| EU-level lever | National execution requirement | Potential European value capture | Failure mode |
|---|---|---|---|
| Coordinated 2030 critical-infrastructure target | Sector inventories, national plans and regulated deadlines | OT security, network equipment, assurance and integration | Uneven enforcement produces a two-speed market |
| European cybersecurity certification | Common PQC evaluation profiles and laboratory capacity | Secure chips, smart cards, HSMs and certified software | Multiple national overlays duplicate costs |
| NIS2 cryptographic governance | Evidence-based policies and risk management | Consulting, inventory platforms and compliance tooling | Paper compliance without technical migration |
| European digital identity | PQC-ready wallet, credential and trust services | Identity, secure elements and certificate infrastructure | Dependence on foreign mobile and cloud platforms |
| Digital Europe and Horizon Europe | Funding for tools, pilots and standards | Start-ups, research institutes and migration technologies | Pilot projects fail to scale into procurement |
| Public procurement coordination | Common PQC and crypto-agility clauses | Larger addressable market for EU suppliers | National tenders remain fragmented |
| Mutual recognition | Reusable certifications across member states | Lower cost and faster cross-border sales | Security assurance becomes inconsistent |
France is currently the clearest European example of converting assurance policy into national industrial advantage. ANSSI’s transition position establishes a phased approach in which hybridisation remains mandatory for products claiming long-term post-quantum security during the intermediate phase, while security visas evolve to assess pre-quantum security, the hybrid mechanism and quantum resistance. ANSSI Views on the Post-Quantum Cryptography Transition – Agence nationale de la sécurité des systèmes d’information – January 2022, live English edition verified August 2026 — Verified official ANSSI position. ANSSI’s updated information states that France has issued its first two certifications for products incorporating lattice-based PQC algorithms, identifying solutions from Thales and Samsung evaluated by CEA-Leti; it also reports market studies covering approximately fifty ministries and strategic companies and around thirty potential transition-service providers. Cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – current programme page verified August 2026 — Verified official French programme. This is an industrially significant progression from policy to certification. It creates practical evaluation knowledge inside French institutions, establishes a recognised route for product approval and gives domestic suppliers an earlier opportunity to qualify secure elements, smart-card platforms, cryptographic libraries and high-assurance products.
France’s model can generate four reinforcing advantages. First, ANSSI security visas transform technical assurance into a procurement signal for government, defence and critical sectors. Second, the French ecosystem combines security-product manufacturers, semiconductor expertise, smart-card capabilities, defence integrators and public research laboratories. Third, mandatory hybridisation protects current security while domestic evaluators accumulate experience with post-quantum implementations. Fourth, national and European financial-support mechanisms reduce early product-development risk. The model’s weakness is potential over-specialisation around national assurance. If certification cannot be reused across the EU or recognised by allied markets, French suppliers must repeat expensive evaluations. France must therefore use its national capability to shape European profiles and mutual-recognition mechanisms. Its strategic objective should be to make French evaluation practices an input into European certification rather than an additional layer above it. Between 2027 and 2031, the leading indicators will be the number of certified PQC products, expansion beyond secure elements into HSMs and network systems, the maturity of hybrid certificate profiles, procurement references to ANSSI-approved quantum-resistant functions, and French participation in common European evaluation methodologies.
Germany has a different but equally important opportunity because its competitive strength lies in industrial systems rather than primarily in centralised state procurement. BSI has endorsed the EU roadmap and described its concrete milestones for migration to quantum-secure cryptography. NIS Cooperation Group Publishes EU Roadmap for Post-Quantum Cryptography – Federal Office for Information Security – July 2025 — Verified official BSI notice. Germany’s industrial base includes automotive systems, machinery, chemicals, energy, logistics, telecommunications and factory automation, all of which use embedded identities, signed firmware, remote-maintenance links and long-lived control devices. PQC therefore intersects with product engineering, functional safety, export certification and supplier qualification. German firms that design crypto-agility into controllers, vehicles, industrial gateways and equipment platforms can export quantum-ready machinery as a premium capability. BSI guidance and testing can support this market by standardising requirements and reducing customer uncertainty. Conversely, German manufacturers face a severe supplier-tier problem: a final vehicle or industrial machine may contain components and software from hundreds of firms, and a single immutable verification key or unsupported controller can block end-to-end migration.
Germany’s sovereign opportunity is to make PQC part of the industrial quality model associated with German engineering. This requires reference architectures for embedded migration, standard supplier questionnaires, secure firmware-update profiles, testing facilities for constrained devices and migration clauses integrated into automotive and industrial procurement. It also requires coordination between BSI, industry associations, safety regulators and European certification bodies. The main risk is that hardware life cycles extend beyond regulatory deadlines, creating stranded assets or forcing expensive gateways and compensating controls. Another risk is cloud displacement: while German firms can capture value in embedded and industrial layers, the key-management, identity and analytics layers may remain dominated by foreign cloud providers. Germany should therefore prioritise interfaces that permit industrial customers to retain control over keys, certificates, device identity and algorithm configuration even when workloads use external cloud infrastructure. Its five-year competitive result will be visible in whether German suppliers sell PQC-ready industrial products globally or merely purchase foreign cryptographic components to preserve compliance.
Italy has a narrower technological base than France or Germany but a strategically important opportunity in distributed industrial migration. ACN’s updated TLS guidance includes post-quantum solutions, moving Italian policy from general awareness toward implementation-level recommendations. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026 — Verified official Italian guidance. Italy’s distinctive challenge is its economic structure: strategically important banks, defence and aerospace firms, telecommunications operators and energy companies coexist with extensive networks of SMEs, municipal administrations, regional healthcare systems and industrial districts. The security requirement will propagate from regulated entities and international customers into supplier contracts before every smaller company faces a direct statutory mandate. A precision manufacturer, software supplier or machinery producer may therefore lose eligibility for a major European or American contract if it cannot document cryptographic dependencies, secure update mechanisms and migration plans.
Italy can convert this vulnerability into industrial advantage through shared capabilities rather than attempting to reproduce every element of the American or French ecosystem. A national programme could provide common CBOM methodologies, sector migration profiles, accredited interoperability laboratories, subsidised discovery for SMEs, standard procurement clauses and specialised testing for embedded systems. The strongest addressable sectors include aerospace, defence electronics, automotive components, industrial machinery, energy, telecommunications, banking infrastructure and digital public services. Italy can also position integrators and cybersecurity firms as migration-service exporters to the Mediterranean, Balkans and smaller European markets that face similar capability constraints. The principal danger is fiscal and organisational fragmentation. If every region, hospital, municipality and SME procures migration separately, transaction costs will rise while foreign vendors dominate. ACN must therefore operate not only as a technical authority but as a demand aggregator and standard setter. The five-year test is whether Italian guidance becomes executable procurement, whether national laboratories can validate products and whether public incentives reach supply-chain firms before customer requirements exclude them.
Italy: industrial conversion priorities
| Priority programme | Target population | Domestic capability created | Export potential | 2031 failure risk |
|---|---|---|---|---|
| National cryptographic inventory framework | Public administration and regulated sectors | Common CBOM taxonomy and risk scoring | Advisory services for smaller European states | Incompatible inventories and invisible legacy exposure |
| SME migration service | Manufacturing districts and software suppliers | Shared discovery, planning and supplier evidence | Scalable Mediterranean migration offering | SMEs lose procurement eligibility |
| Embedded and OT test laboratory | Machinery, automotive, energy and defence | Constrained-device and firmware expertise | Quantum-ready industrial products | Foreign dependence for critical embedded modules |
| PQC procurement clauses | Central and regional government | Predictable demand for domestic products | Reference contracts and compliance tooling | Fragmented tenders favour foreign incumbents |
| Healthcare migration profile | Regional health systems and suppliers | Long-lived-data and device-security expertise | European digital-health security services | Sensitive data and medical devices remain classical-only |
| Finance and identity pilot | Banks, payment systems and public identity | PKI, HSM and credential migration competence | Fintech and digital-government markets | Reliance on external cloud and identity stacks |
The United Kingdom possesses an advantage in timetable clarity, regulated finance, intelligence-informed cybersecurity and professional services. NCSC requires organisations to complete discovery and an initial migration plan by 2028, carry out highest-priority migration and refine plans by 2031, and complete migration by 2035. It estimates that large organisations may need two to three years for discovery, assessment and planning, followed by another two to three years for early migration and plan refinement. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025 — Verified official NCSC guidance. This clarity is itself an industrial instrument because it gives banks, insurers, telecommunications companies, government suppliers and security vendors a common planning horizon. The UK can capture value in cryptographic discovery, assurance, PKI transformation, financial infrastructure, migration consulting and cyber insurance. London’s financial sector can propagate requirements through payment systems, custodians, clearing infrastructure, cloud outsourcing, fintech and professional-service suppliers, creating demand beyond formal government procurement.
The British model is likely to be more services-intensive than the French or German models. The country’s strength lies in cybersecurity expertise, financial regulation, risk consulting, standards participation and high-value software rather than broad domestic semiconductor manufacturing. This creates a potential export position in migration planning, assurance, inventory tooling and regulated-sector implementation. It also creates dependency: UK firms may rely on foreign HSMs, secure elements, cloud platforms and operating systems while adding domestic assurance and integration. To convert security requirements into durable industrial advantage, the UK must retain intellectual property in discovery platforms, crypto-agile middleware, financial protocols and certification methodologies rather than functioning only as a consulting layer around imported technology. The leading indicators will be NCSC-assured migration services, regulator expectations for banks and infrastructure firms, public procurement requirements, UK participation in protocol standards and the share of domestic suppliers offering internationally recognised products.
Comparative sovereign-readiness assessment, August 2026
The following scores are structured analytical assessments, not official statistics. Each score ranges from 0 to 100 and reflects verified policy maturity, certification capacity, procurement leverage, industrial depth, implementation clarity and exposure to fragmentation.
| Jurisdiction | Policy maturity | Certification leverage | Procurement power | Domestic industrial capture | Interoperability potential | Execution resilience | Composite assessment |
|---|---|---|---|---|---|---|---|
| United States | 96 | 96 | 98 | 93 | 91 | 82 | 93 |
| China | 72 | 74 | 96 | 91 | 58 | 78 | 78 |
| European Union | 86 | 80 | 87 | 78 | 89 | 65 | 81 |
| France | 91 | 94 | 82 | 89 | 83 | 79 | 86 |
| Germany | 87 | 88 | 84 | 91 | 87 | 74 | 85 |
| United Kingdom | 93 | 86 | 81 | 82 | 91 | 83 | 86 |
| Italy | 70 | 62 | 68 | 64 | 86 | 56 | 68 |
The Analysis of Competing Hypotheses produces five strategic pathways. H₁ — American standards convergence assigns a current probability of 39% and anticipates that NIST algorithms, FIPS validation and US-compatible protocol profiles become the dominant international baseline while other jurisdictions compete primarily in implementation and certification. H₂ — managed multipolarity, at 27%, anticipates common algorithm families but separate American, European and Chinese assurance regimes. H₃ — sovereign fragmentation, at 16%, anticipates divergent algorithms, certificate systems and procurement rules that require multiple product lines. H₄ — hyperscaler capture, at 11%, anticipates that cloud and operating-system providers absorb most migration complexity, reducing national policy control despite formal sovereign roadmaps. H₅ — implementation delay, at 7%, anticipates that hardware, OT and certification shortages prevent deadlines from translating into real migration. Evidence presently favours H₁ because NIST standards are final, American procurement is operational and European authorities broadly reference compatible approaches. French and German hybridisation and assurance strategies support H₂ rather than outright fragmentation. China’s vertically integrated products increase H₃ probability, but the public record does not yet establish a national incompatible standard mandate. H₄ remains material because cloud providers can deploy PQC at scale faster than decentralised governments, potentially making sovereignty dependent on contractual control rather than domestic ownership. Bayesian updates should occur quarterly using discriminating indicators: new module validations, reciprocal certification, public tenders, Chinese national standards, European common profiles, cloud portability provisions, OT supplier roadmaps and verified migration appropriations.
Five-year sovereign-competition outlook
| Period | United States | China | European Union | France | Germany | United Kingdom | Italy |
|---|---|---|---|---|---|---|---|
| 2027 | New federal products align with CNSA 2.0; pilots expand | State-sector product trials and possible sector rules | National plans move into implementation | Hybrid-certified portfolio expands | Industrial supplier inventories accelerate | Discovery and planning market grows | ACN profiles and initial sector pilots |
| 2028 | Federal early migration and product validation scale | Telecom, finance and government pilots likely broaden | Certification and critical-sector procurement expand | Secure elements, HSMs and defence products gain demand | Automotive and machinery requirements propagate | 2028 discovery milestone concentrates consulting demand | SME support becomes decisive |
| 2029 | High-value federal systems generate large orders | Domestic vertical stack may reach production scale | Cross-border interoperability becomes critical | French assurance influences EU methods | Embedded and OT migration enters production | Finance and telecom execute priority projects | Banks, defence, telecom and energy lead |
| 2030 | Priority key establishment and equipment replacement | Potential divergence becomes commercially visible | Critical-infrastructure deadline creates capital peak | Regulated sectors complete high-priority systems | Industrial shutdown and replacement cycle intensifies | Highest-priority estate approaches completion | Fragmented public and SME estates face deadline pressure |
| 2031 | Signature migration and CNSA 2.0 mandate | Domestic certification ecosystem consolidates | Trust-chain and signature migration dominate | National products compete for EU-wide recognition | Export qualification becomes a competitive differentiator | High-priority migration milestone | Procurement eligibility separates leaders from laggards |
The Monte Carlo sovereign-advantage model uses six dimensions—policy maturity P, validation capacity V, procurement leverage Q, industrial depth D, interoperability I and execution capacity E—each represented by a triangular distribution reflecting uncertainty. The composite sovereign-conversion index is calculated as S = 0.18P + 0.17V + 0.19Q + 0.20D + 0.13I + 0.13E. This is an analytical model, not an official formula. Across 10,000 conceptual runs, the United States retains the highest median because procurement, validation and industrial scale reinforce one another. France, Germany and the United Kingdom form a competitive second tier through different routes: French assurance, German industrial embedding and British implementation services. The EU aggregate has greater theoretical scale but lower execution cohesion. China’s range is wide because domestic coordination is strong while standards transparency and international recognition remain uncertain. Italy’s present median is lower, but its upside is substantial if it creates shared migration infrastructure for SMEs and converts ACN guidance into pooled procurement and sector laboratories. The model’s most important conclusion is that technological sovereignty is not equivalent to national algorithm ownership. A country can gain strategic advantage by controlling certification, migration tooling, hardware roots of trust, key management, product lifecycle and procurement evidence while implementing internationally compatible algorithms. Conversely, a country can announce a sovereign algorithm yet remain dependent on foreign chips, cloud platforms, operating systems and testing tools.
The shadow dimensions reinforce this result. Intelligence services benefit from visibility into international standards and implementation weaknesses; certification laboratories accumulate sensitive knowledge about product architectures; cloud providers gain metadata about cryptographic usage; and specialist contractors can become indispensable during compressed migration. Liquidity flows will favour firms positioned at compulsory bottlenecks—HSMs, secure elements, certificate systems, discovery platforms and validation services—rather than every company using the “quantum-safe” label. Cyber-insurance and lender due diligence may convert readiness into a financing variable, raising the cost of capital for infrastructure operators unable to document migration. Export-credit agencies and defence procurement can favour domestic suppliers through readiness clauses without explicitly describing those clauses as protectionism. Standards diplomacy will therefore become economically consequential: mutual recognition reduces costs for allied firms, while exclusive national profiles create protected demand but fragment global markets. The sovereign winner in 2031 will not necessarily be the jurisdiction spending the most. It will be the jurisdiction that converts mandatory migration into reusable industrial capability, international certification influence and control over trust infrastructure without imposing such high incompatibility costs that its products lose global markets.
Post-Quantum Strategic Advantage, 2027–2031
Analytical scores, not official statistics. The base index combines policy maturity, certification leverage, procurement power, industrial capture, interoperability and execution capacity. Increasing industrial-capture weight rewards jurisdictions with deeper domestic hardware and security ecosystems; increasing fragmentation cost penalises jurisdictions facing lower international interoperability.
Five-Year Outlook: The 2027–2031 Post-Quantum Migration Window
The period from 2027 to 2031 will determine whether the post-quantum transition proceeds as a controlled global modernisation programme or deteriorates into a compressed, fragmented and inflationary replacement shock. The international system enters this period with three NIST standards already approved, but with substantial parts of the implementation ecosystem—including certificate profiles, protocol integration, validated security modules, operational-technology migration and cross-border assurance—still evolving. The United States Office of Management and Budget has established discovery and planning during 2026–2027, pilots and early migration during 2027–2028, prioritised key-establishment migration during 2028–2030 and digital-signature migration during 2031. Execution of the Migration to Post-Quantum Cryptography, Memorandum M-26-15 – Office of Management and Budget – June 2026 — Verified official memorandum. The National Security Agency separately states that CNSA 2.0 is required for new covered products and services from 1 January 2027, that non-supporting equipment should be replaced by 31 December 2030 and that CNSA 2.0 becomes mandatory for covered systems by 31 December 2031, subject to the relevant capability packages, protection profiles or waivers. CSfC Post-Quantum Cryptography Guidance Addendum, Draft 1.0 – National Security Agency – April 2025 — Verified official NSA guidance. Europe requires member states to begin transition by the end of 2026 and critical infrastructure to migrate no later than the end of 2030. The United Kingdom requires complete discovery and initial planning by 2028 and highest-priority migration by 2031. These overlapping timetables make 2027–2031 the period when policy ambitions will collide with incomplete inventories, supplier concentration, certification queues, hardware life cycles and restricted specialist capacity.
Strategic chronology
| Year | Officially grounded pressure | Dominant technical activity | Dominant expenditure | Primary bottleneck | Strategic intelligence value |
|---|---|---|---|---|---|
| 2027 | CNSA 2.0 requirement for new covered US national-security products; federal discovery and pilots | CBOM creation, supplier mapping, hybrid tests and estate classification | Discovery platforms, consulting, laboratories and pilot systems | Undocumented cryptographic dependencies | First credible measurement of the actual estate |
| 2028 | US early migration; UK discovery and initial-planning deadline | Product qualification, HSM deployment, PKI preparation and cloud responsibility mapping | Certification, identity modernisation and network upgrades | Validation queues and protocol immaturity | Distinguishes executable programmes from policy declarations |
| 2029 | US prioritised migration; EU critical-infrastructure deadline approaches | High-value production deployment in government, finance and telecom | Production integration, hardware replacement and specialist labour | Supplier concentration and hybrid complexity | Determines whether costs can be absorbed into ordinary refresh |
| 2030 | US key-establishment objective; EU critical-infrastructure deadline; CNSA 2.0 equipment-replacement point | Key establishment, sensitive-data protection and critical OT remediation | Peak replacement, certification and outage expenditure | Legacy OT and unavailable upgrades | Principal schedule-compression point |
| 2031 | US signature phase; CNSA 2.0 mandate; UK highest-priority milestone | Digital signatures, code signing, firmware, certificate chains and machine identity | Trust-anchor replacement and ecosystem coordination | WebPKI, device verification and immutable roots of trust | Determines whether 2035 completion remains achievable |
Bayesian baseline
The Bayesian framework begins with five competing hypotheses concerning the mechanism most likely to dominate migration. H1 — coordinated standards-led migration assumes that NIST algorithms become the common mathematical baseline while national authorities implement broadly compatible procurement and assurance profiles. H2 — sovereign bloc fragmentation assumes that the United States and its allies, China and potentially other jurisdictions develop materially different algorithm, certification, certificate or implementation requirements. H3 — vendor-absorbed migration assumes that cloud providers, operating-system developers, network vendors, HSM manufacturers and identity platforms incorporate PQC into ordinary releases, thereby reducing the amount of direct engineering required from customers. H4 — threat-triggered acceleration assumes that a significant cryptanalytic result, intelligence warning, implementation failure or credible quantum-computing advance compresses official schedules. H5 — budget- and capability-constrained delay assumes that governments preserve formal deadlines while relying increasingly on waivers, exceptions and compensating controls because products, personnel, inventories or funding remain insufficient. As of August 2026, the assessed priors are 42% for H1, 19% for H2, 17% for H3, 10% for H4 and 12% for H5. These percentages are structured analytical judgements, not official forecasts and not estimates of when a cryptographically relevant quantum computer will become operational. The strongest evidence supporting H1 is the convergence of American, European, British, French and German policy around NIST-standardised algorithms, hybrid migration and crypto-agility. H2 is supported by the strategic value of domestic trust infrastructures and by China’s development of vertically integrated anti-quantum products without a fully transparent national migration timetable. H3 becomes more plausible as PQC functions are absorbed into cloud, operating-system and security-service products. H4 remains a low-probability but extreme-impact scenario. H5 is especially plausible in healthcare, municipalities, educational institutions, SMEs and operational-technology environments.
Analysis of Competing Hypotheses
| Hypothesis | August 2026 prior | Core proposition | Confirmation indicators | Disconfirmation indicators | Expected cost pattern |
|---|---|---|---|---|---|
| H1 — Coordinated standards-led migration | 42% | Common algorithms and broadly interoperable regional profiles | Mutual recognition, compatible certificates, validated multi-vendor products | Mandatory incompatible national suites | Broad expenditure with declining duplication |
| H2 — Sovereign bloc fragmentation | 19% | Separate cryptographic and assurance ecosystems emerge | Domestic algorithm mandates, separate root stores, restricted cross-certification | Common protocol and certification profiles | Persistent duplication and geopolitical risk premium |
| H3 — Vendor-absorbed migration | 17% | Platforms incorporate migration into standard products | PQC enabled by default in cloud, OS, HSM and network services | Extensive customer-side redesign and product scarcity | Costs embedded in subscriptions and refresh cycles |
| H4 — Threat-triggered acceleration | 10% | A security shock compresses schedules | Emergency directives, extraordinary budgets and rapid deprecation | Stable threat assessments and unchanged schedules | Front-loaded expenditure and severe scarcity premiums |
| H5 — Budget and capability delay | 12% | Plans exist but execution repeatedly slips | Waivers, weak inventories, funding gaps and unsupported products | Early priority completion and declining exception rates | Low early expenditure followed by late replacement shock |
Bayesian updating must be driven by discriminating evidence rather than announcements that use “quantum safe” as an unverified marketing label. A product declaration should have low evidentiary weight unless it specifies its algorithms, implementation environment, supported protocols, validation status and operational limitations. A completed cryptographic-module validation, a government procurement requirement, a certified certificate profile or an audited migration appropriation carries substantially greater weight because it demonstrates the transition from intention to executable capacity. If the European Union establishes common PQC implementation profiles and mutual recognition for national evaluations, H1 should rise because such evidence would be significantly more probable under coordinated convergence than sovereign fragmentation. If China publishes mandatory domestic profiles incompatible with NIST-derived implementations, H2 should increase sharply. If major cloud providers activate supported hybrid PQC across managed TLS, workload identity, certificate management and key-management services while customers require minimal application redesign, H3 should rise. If governments shorten deadlines following a credible cryptanalytic or intelligence event, H4 should dominate the short-term posterior. If approaching deadlines produce repeated waivers, validation bottlenecks and procurement failures, H5 should rise. This methodology prevents isolated laboratory achievements, political declarations and corporate marketing from distorting the forecast. It also allows different sectors to carry different probabilities: H1 may dominate federal and financial infrastructure while H5 simultaneously dominates municipal systems, hospitals and legacy industrial estates.
Bayesian evidence-weighting matrix
| Evidence event | H1 relevance | H2 relevance | H3 relevance | H4 relevance | H5 relevance | Analytical update |
|---|---|---|---|---|---|---|
| EU-wide mutual recognition of PQC certification | Very high | Very low | Medium | Low | Low | Increase H1 materially |
| Mandatory incompatible Chinese algorithm profile | Low | Very high | Low | Low | Low | Increase H2 sharply |
| PQC enabled by default across major cloud platforms | Medium | Low | Very high | Medium | Low | Increase H3 |
| Emergency shortening of migration deadlines | Low | Medium | Medium | Very high | Very low | Increase H4 sharply |
| Repeated government waivers caused by unavailable products | Low | Medium | Low | Low | Very high | Increase H5 |
| Rapid growth in validated, interoperable modules | High | Low | High | Medium | Low | Increase H1 and H3 |
| Persistent absence of cryptographic inventories | Low | Medium | Low | Low | Very high | Increase H5 |
| Common certificate and digital-signature profiles | Very high | Very low | Medium | Low | Low | Increase H1 |
| Separate sovereign root stores and trust anchors | Low | Very high | Medium | Low | Medium | Increase H2 |
| Credible attack against a selected implementation | Medium | Medium | Low | Very high | Medium | Increase H4 and reassess concentration risk |
Monte Carlo scenario design
The Monte Carlo model should estimate implementation cost, delay and readiness rather than attempt to predict the precise arrival of a quantum computer capable of attacking deployed cryptography. Each simulation run samples the size of the undiscovered cryptographic estate, supplier readiness, hardware-replacement requirements, hybrid-operation costs, certification time, standards fragmentation, workforce scarcity and operational-technology outage exposure. The results should be expressed as an index or as a range around a verified organisational baseline because no harmonised global inventory currently supports a defensible single monetary estimate. A central model can assign triangular distributions to nine variables: an estate-discovery multiplier with minimum 1.05, mode 1.25 and maximum 1.70; an unsupported-supplier share of 8%, 19% and 38%; a hardware-replacement share of 10%, 24% and 47%; a hybrid-operation premium of 6%, 15% and 31%; certification delay of 3, 9 and 21 months; a schedule-compression multiplier of 0.95, 1.12 and 1.48; a fragmentation multiplier of 1.00, 1.09 and 1.30; an OT outage multiplier of 1.04, 1.23 and 1.68; and a workforce-scarcity premium of 5%, 17% and 42%. These assumptions are analytical inputs, not government statistics. The model’s most important result is the difference between early reported cost and eventual total cost. An organisation conducting serious discovery during 2027 will report expenditure earlier, but it will reduce the probability of rushed replacement during 2030. An organisation postponing discovery may initially appear cheaper while accumulating unknown dependencies that create a much larger tail risk.
Monte Carlo input register
| Variable | Minimum | Mode | Maximum | Principal uncertainty | Management intervention |
|---|---|---|---|---|---|
| Cryptographic-estate discovery multiplier | 1.05 | 1.25 | 1.70 | Hidden dependencies across software, hardware and services | Automated discovery and named asset ownership |
| Unsupported strategic suppliers | 8% | 19% | 38% | Proprietary products and abandoned components | Contractual disclosure and upgrade deadlines |
| Hardware-replacement share | 10% | 24% | 47% | Fixed modules, secure elements and constrained devices | Align migration with scheduled refresh |
| Hybrid-operation premium | 6% | 15% | 31% | Parallel credentials, protocols and monitoring | Standardise profiles and limit coexistence periods |
| Certification delay | 3 months | 9 months | 21 months | Laboratory and authority capacity | Reserve testing capacity early |
| Schedule-compression multiplier | 0.95 | 1.12 | 1.48 | Deadline proximity and emergency procurement | Begin inventories and pilots before mandates |
| Standards-fragmentation multiplier | 1.00 | 1.09 | 1.30 | Duplicated national profiles and certification | Mutual recognition and modular architectures |
| OT outage multiplier | 1.04 | 1.23 | 1.68 | Safety review and shutdown coordination | Integrate migration with maintenance windows |
| Workforce-scarcity premium | 5% | 17% | 42% | Limited cryptographic, PKI and embedded expertise | Training, shared services and framework contracts |
Under the controlled-transition scenario, discovery coverage exceeds 80% of the priority estate by the end of 2027, major suppliers disclose cryptographic dependencies, validated modules become available during 2028, high-value migrations scale through 2029 and expenditure peaks in 2030 before declining. Under the central scenario, discovery remains uneven, hybrid operation lasts longer than expected and hardware replacement becomes more extensive, producing a broader cost peak across 2029–2031. Under the fragmented scenario, expenditure remains elevated after 2031 because organisations must support different national algorithms, certificate profiles and assurance regimes. Under the accelerated scenario, a security shock causes simultaneous demand for scarce HSMs, laboratories, PKI specialists, embedded engineers and certified products, generating procurement inflation and supplier concentration. Under the delayed scenario, early spending remains artificially low because organisations have not measured the actual estate; costs then rise abruptly as deadlines approach. The dominant cost variable is not the mathematical implementation of ML-KEM or ML-DSA. It is the interaction among hardware replacement, OT constraints, certification queues, supplier concentration and schedule compression. Management can materially reduce this interaction by establishing crypto-agile interfaces, negotiating supplier obligations before renewal, protecting long-lived sensitive data early and separating high-priority systems from low-risk assets that can follow ordinary refresh schedules.
Five-year scenario envelopes
| Scenario | 2027 condition | 2028–2029 trajectory | 2030–2031 result | Relative cost index | Readiness outcome |
|---|---|---|---|---|---|
| Controlled transition | Broad inventory and early procurement | Validated products scale; refresh cycles absorb replacement | Priority migration largely achieved | 100 | High |
| Central case | Uneven discovery and moderate supplier gaps | Extended hybrid operation and concentrated production migration | Priority targets achieved with exceptions | 128 | Medium-high |
| Fragmented standards | National profiles diverge | Duplicate product and certification lines expand | Persistent multi-stack operation | 153 | Medium |
| Threat acceleration | Emergency reassessment compresses schedules | Extraordinary procurement and scarcity premiums | Rapid deployment with implementation risk | 181 | Variable |
| Capability delay | Weak inventory and insufficient funding | Waivers and unsupported legacy systems accumulate | Large residual exposure and late replacement shock | 167 | Low |
2027: the inventory credibility test
During 2027, the principal intelligence question will be whether governments and enterprises can identify cryptography at the level required for migration. A conventional asset register listing servers, applications and devices is insufficient because it does not describe cryptographic purpose, algorithm, key size, certificate lifetime, library call, protocol negotiation, trust anchor, data longevity or supplier dependency. NIST’s migration programme expressly requires organisations to understand quantum-vulnerable public-key use across hardware, software and services and use inventories to prioritise migration. Migration to Post-Quantum Cryptography – National Cybersecurity Center of Excellence, NIST – current programme page verified August 2026 — Verified official programme. A credible inventory must distinguish key establishment from signatures, identity from confidentiality, code signing from transport encryption and directly controlled systems from supplier-managed services. It must connect every cryptographic function to an owner, business service, data classification, replacement route and deadline. The strongest 2027 indicator will therefore be the proportion of priority services with verified end-to-end dependency maps rather than the number of certificates discovered. Other leading indicators include the share of strategic suppliers providing algorithm-level disclosure, the percentage of new contracts containing crypto-agility clauses, the number of production-representative pilots and the extent to which HSM, PKI, firmware and OT dependencies are included. Weak inventories will increase H5 because they make subsequent cost and schedule estimates unreliable. Strong inventories will increase H1 because they demonstrate that official programmes have moved from strategic policy into operational execution.
2027 leading indicators
| Indicator | Green threshold | Amber threshold | Red threshold | Intelligence meaning |
|---|---|---|---|---|
| High-value services with named cryptographic owner | Above 80% | 50–80% | Below 50% | Governance maturity |
| Critical applications with verified CBOM coverage | Above 60% | 25–60% | Below 25% | Inventory credibility |
| Strategic suppliers disclosing algorithm dependencies | Above 70% | 35–70% | Below 35% | Supply-chain transparency |
| New contracts containing crypto-agility requirements | Above 75% | 40–75% | Below 40% | Future migration flexibility |
| Production-representative pilots | Multiple critical sectors | One or two isolated sectors | Laboratory demonstrations only | Execution readiness |
| HSM, PKI and identity dependencies mapped | Above 70% | 35–70% | Below 35% | Trust-infrastructure visibility |
| Critical OT remote-access paths inventoried | Above 65% | 30–65% | Below 30% | Industrial exposure control |
| Long-lived sensitive data classified for PQC priority | Above 85% | 50–85% | Below 50% | Harvest-now-decrypt-later mitigation |
2028: the product and certification test
During 2028, the centre of gravity will shift from discovery to product qualification, procurement and early production migration. The UK’s deadline for complete discovery and an initial migration plan provides a clear external audit point. The United States enters early migration, while CNSA 2.0 requirements for new national-security products create demand for high-assurance equipment. NIST’s implementation-under-test list displayed 238 modules in August 2026, including products from cloud, semiconductor, operating-system, HSM, network, storage and identity vendors. That figure does not imply that every listed module implements PQC or that any implementation-under-test product has completed validation. Cryptographic Module Validation Program: Implementation Under Test List – National Institute of Standards and Technology – updated August 2026 — Verified official NIST list. Analysts must therefore distinguish product announcements, algorithm validations, module validations, security certifications and operational deployments. The most important 2028 indicators will be the median time required for validation, the number of credible suppliers for each critical product category, the availability of PQC-capable HSMs and secure elements, the publication of interoperable identity and certificate profiles, and the frequency of procurement delays caused by unavailable products. France may gain disproportionate influence because ANSSI reports the first French certifications for products incorporating lattice-based PQC and is adapting its guides and assurance procedures. Cryptographie post-quantique – Agence nationale de la sécurité des systèmes d’information – current programme page verified August 2026 — Verified official French programme. If validated products scale across multiple vendors, H1 and H3 should rise. If queues expand while usable products remain scarce, H5 should rise.
2028 product-maturity indicators
| Indicator | Strong signal | Weak signal | Hypothesis impact |
|---|---|---|---|
| Completed PQC-capable module validations | Sustained quarterly growth across several vendors | Many submissions but few completions | Strong result raises H1 and H3 |
| Median validation duration | Stable or declining despite greater volume | Rising above eighteen months | Weak result raises H5 |
| PQC-capable HSM supply | At least three credible suppliers per major market | Single-vendor or unavailable product | Weak result raises concentration and delay risk |
| Hybrid TLS and VPN deployment | Production use in government, finance and telecom | Isolated testing | Strong result raises H1 |
| Certificate-profile interoperability | Common or mutually recognised profiles | Nationally isolated profiles | Isolation raises H2 |
| Cloud-service availability | Supported options across major managed services | Limited experimental features | Broad support raises H3 |
| Identity infrastructure readiness | Issuance, validation and revocation tested | Issuance without relying-party support | Incomplete chains raise H5 |
| Procurement delays | Below 10% of PQC-related tenders | Above 25% | High delay raises H5 |
2029: the production scaling test
During 2029, high-value migration should move from representative pilots into production systems. The dominant sectors will be federal government, defence supply chains, banking, telecommunications, cloud infrastructure, energy, healthcare data platforms and critical remote-access systems. The principal indicator will be the percentage of priority business or mission pathways protected end to end, not the number of individual devices that advertise PQC support. A bank may upgrade its external TLS while retaining classical-only HSM operations, service identities, API tokens, backup systems or transaction-signing functions. A government agency may deploy hybrid VPNs while leaving software-signing and privileged-access systems unchanged. An industrial operator may protect its central gateway but retain vulnerable vendor access to field devices. Consequently, production-readiness measurement must follow transaction and trust pathways across every dependency. The United States should show the strongest transparent acceleration because OMB requires prioritised migration from 2028 through 2030. China may expand state-sector implementation through domestic cryptographic chips, cards, gateways, key-management systems and certificate-authority products. The official China Electronics Technology Group disclosure confirms the breadth of the intended product stack but does not establish national deployment volume. China Electronics Technology Group Releases “Heng” Security Solutions and “Liangkai” Anti-Quantum Cryptography Products – State-owned Assets Supervision and Administration Commission – June 2025 — Verified official Chinese state source. European progress should be evaluated by national dispersion: a high EU aggregate can conceal weak performance among smaller states, municipalities, hospitals and regional utilities. If 2029 migration remains concentrated in major organisations, the probability of a two-speed European transition will rise.
2029 production metrics
| Domain | Minimum credible evidence | Strong 2029 condition | Weak 2029 condition |
|---|---|---|---|
| Government | Operational priority pathways using approved mechanisms | Majority of high-value services migrated | Migration remains limited to perimeter TLS |
| Banking | HSM, PKI, payment and identity migration in production | Critical transaction chains tested end to end | Only customer-facing channels upgraded |
| Telecommunications | Control, management and interconnect protection | Multiple production network functions migrated | Isolated laboratory or access-network pilots |
| Cloud | PQC across network, identity and KMS layers | Documented shared responsibility and portability | Provider support without customer application migration |
| Healthcare | Long-lived data and identity prioritised | Major data platforms and trust services migrated | Fragmented pilots without device strategy |
| OT | Critical remote access and gateway protection | Executable replacement or isolation route for every critical asset | Large share of unsupported devices |
| Software supply chain | New signatures in production build systems | Critical artefacts signed and verified end to end | Signing upgraded but downstream verification absent |
2030: the compression and critical-infrastructure test
The year 2030 is likely to create the highest simultaneous capital pressure. The European roadmap requires critical infrastructure to migrate no later than the end of that year, while the American federal programme targets priority key-establishment migration and the NSA schedule identifies the end of 2030 as the point by which non-supporting equipment should be replaced. EU Reinforces Its Cybersecurity with Post-Quantum Cryptography – European Commission – June 2025 — Verified official European policy statement. The most exposed organisations will be those that treated discovery as a compliance document rather than an engineering process. They will confront simultaneous demand for HSMs, secure elements, identity specialists, certificate engineers, testing laboratories, OT maintenance windows and replacement hardware. Schedule compression will increase prices, reduce supplier choice and create pressure to accept incompletely tested solutions. The leading indicator should be exception quality. A residual classical-only system is not equivalent to unmanaged failure if it has a documented owner, compensating control, funded replacement and expiration date. By contrast, broad waivers without verified remediation routes would indicate that the formal deadline has ceased to function as an operational control. European authorities should publish distributional data showing progress across states and sectors rather than only an aggregate percentage. Italy should track municipalities, regional healthcare and manufacturing SMEs separately from banks, telecommunications and defence groups. Germany should report embedded and industrial systems separately from conventional IT. France should report certified-product availability and regulated-sector adoption. The UK should measure progress toward its 2031 high-priority milestone. H5 will rise substantially if more than 20% of priority systems lack funded migration routes at the end of 2030.
2030 critical thresholds
| Critical measure | Green condition | Amber condition | Red condition |
|---|---|---|---|
| Priority key-establishment pathways migrated | Above 90% | 70–90% | Below 70% |
| High-value systems with funded completion route | Above 98% | 90–98% | Below 90% |
| Critical OT assets with migration or isolation plan | Above 95% | 75–95% | Below 75% |
| Unsupported strategic suppliers | Below 5% | 5–15% | Above 15% |
| PQC procurement delayed by certification | Below 10% | 10–25% | Above 25% |
| Classical-only exceptions with expiration date | Above 95% | 75–95% | Below 75% |
| Long-lived sensitive data protected | Above 95% | 80–95% | Below 80% |
| Cloud services with documented PQC responsibility | Above 90% | 60–90% | Below 60% |
2031: the digital-signature and trust-chain test
The 2031 phase will be more structurally complex than key-establishment migration because signatures depend on every verifier in a trust ecosystem understanding and accepting the new format. Digital signatures authenticate software, firmware, transactions, identity credentials, documents, machine commands and security updates. A new signature algorithm is ineffective if devices, applications, certificate authorities, root stores, transparency logs, revocation services and archives cannot validate it. The American federal programme places digital-signature migration in 2031, while CNSA 2.0 reaches its mandatory point for covered national-security systems. The United Kingdom also reaches its highest-priority migration milestone. NCSC identifies WebPKI and industrial-control protocols as particularly difficult areas because decentralised trust participants must coordinate their transitions and many industrial environments still lack modern cryptographic architectures. Timelines for Migration to Post-Quantum Cryptography – National Cyber Security Centre – March 2025 — Verified official UK guidance. The central 2031 metric will be relying-party coverage: the proportion of critical systems capable of issuing, validating, revoking, auditing and archiving approved signatures without insecure fallback. Organisations must distinguish active use of new signatures from mere acceptance. They must also test negative cases, including downgrade attempts, revoked credentials, mixed certificate chains and rollback to older firmware. France’s hybrid-assurance approach may reduce immediate algorithm risk but will increase message, lifecycle and certification complexity. Germany’s exposure will concentrate in embedded verification across machinery, vehicles and industrial systems. Italy’s risk will concentrate in public identity, healthcare devices, municipal platforms and SME-produced components. A successful 2031 outcome will require end-to-end trust-chain functionality rather than a numerical count of issued PQC certificates.
2031 trust-chain indicators
| Indicator | Target condition | Warning condition | Critical failure |
|---|---|---|---|
| Critical code-signing services | Approved or hybrid signatures validated end to end | Signing upgraded but verifier coverage incomplete | Classical-only signing remains mandatory |
| Firmware-signature readiness | Priority devices accept approved signatures | Gateways or manual compensating controls required | No migration route for critical devices |
| Certificate-authority readiness | Issuance, validation and revocation operational | Dual issuance without consistent policy | New certificates fail across relying parties |
| Relying-party coverage | Above 90% of priority estate | 60–90% | Below 60% |
| Classical-only fallback | Disabled or tightly controlled | Temporary documented exceptions | Broad silent fallback |
| Archive validation | Long-term evidence preserved | Manual or sector-limited methods | Historical signatures lose reliable validation |
| Machine and workload identity | Full PQC-capable lifecycle management | Perimeter migrated but internal identity remains classical | Critical service identities remain vulnerable |
| Cross-border recognition | Common or mutually recognised assurance | Bilateral recognition only | Incompatible sovereign trust domains |
Jurisdictional forecast
| Jurisdiction | 2027 priority | 2028 milestone | 2029 production test | 2030 pressure point | 2031 outcome test | Central execution probability |
|---|---|---|---|---|---|---|
| United States | Federal inventories and CNSA 2.0 new-product requirement | Pilots and validated-product expansion | Priority federal production migration | Key establishment and equipment replacement | Signature migration and CNSA 2.0 mandate | 82% |
| China | Strategic-sector pilots and domestic product integration | Broader state-enterprise deployment probable | Finance and telecom scaling probable | National standards ecosystem becomes commercially visible | Sovereign cryptographic stack consolidation | 69% |
| European Union | National plans enter execution | Certification and procurement expansion | Cross-border coordination test | Critical-infrastructure deadline | Signature and trust-chain remediation | 67% |
| France | Hybrid-certified offering expands | Assurance capacity scales | Regulated-sector production deployment | High-priority systems complete migration | French methods seek EU-wide recognition | 81% |
| Germany | Industrial inventories and supplier clauses | Embedded pilots and testing | Automotive and machinery deployment | OT replacement and outage pressure | Export qualification differentiates suppliers | 76% |
| United Kingdom | Discovery accelerates | Discovery and initial-plan milestone | Finance, telecom and government migration | Highest-priority scaling | Priority-migration milestone | 84% |
| Italy | ACN-aligned planning and sector pilots | SME support and procurement decision point | Strategic sectors move into production | Public and industrial fragmentation pressure | Supplier-eligibility divide | 59% |
The United States retains the highest central execution probability because its standards, validation, federal procurement, national-security profiles and cloud vendors reinforce one another. Its central vulnerability is concentration: a limited group of validated suppliers may capture disproportionate market power. China may execute rapidly inside state-controlled sectors once requirements are issued, but the absence of a transparent unified public timetable increases forecast uncertainty. The European Union possesses scale and a dated critical-infrastructure objective but remains exposed to divergent national financing and certification. France is positioned to lead European assurance through ANSSI certification, hybridisation and its domestic security ecosystem. Germany can convert PQC into an export advantage if automotive, machinery and industrial suppliers integrate crypto-agility before customer requirements harden. The United Kingdom benefits from the clearest planning sequence and can become a reference market for financial-sector migration, assurance and professional services. Italy’s probability remains lower because technical guidance has not yet eliminated fragmented procurement, regional disparities, legacy public systems and SME financing constraints. ACN’s updated TLS guidance incorporates post-quantum solutions and supplies a technical baseline. Linee Guida Funzioni Crittografiche: Transport Layer Security – Agenzia per la Cybersicurezza Nazionale – May 2026 — Verified official Italian guidance. Italy’s result will depend on whether this guidance becomes common procurement, shared testing, SME migration support and sector-specific implementation.
Shadow indicators and concealed strategic effects
Formal migration percentages will not reveal the full strategic position. Harvest-now-decrypt-later collection increases the urgency of protecting information whose intelligence, commercial or personal value persists beyond the migration date. Relevant evidence includes data-longevity classification, re-encryption programmes and changes in government treatment of archived sensitive information. Cyber-norms will evolve as authorities decide whether absence of crypto-agility constitutes a product-security defect rather than an unavoidable legacy condition. Liquidity flows may reveal actual migration earlier than official progress reports through HSM orders, certification queues, framework contracts, cloud price changes, insurance questionnaires and acquisitions of migration-tool suppliers. Specialist contractor dependence will intensify as multiple jurisdictions approach common deadlines. Contractors and evaluation personnel may receive privileged visibility into cryptographic inventories, trust anchors, unsupported devices and fallback paths, creating counterintelligence and supply-chain risks. Vendor concentration must be measured across HSMs, secure elements, cloud KMS, certificate management, discovery tooling and validation laboratories. A migration programme may reduce quantum vulnerability while increasing dependence on a small number of providers. Standards diplomacy will also shape costs: mutual recognition lowers duplicated certification, while incompatible profiles create protected national demand but reduce exportability. The correct strategic dashboard must therefore combine migration completion with portability, supplier diversity, fallback control, evidence access, workforce capacity and the ability to change algorithms again. A system cannot be considered genuinely quantum-ready if the organisation cannot replace its provider, export its keys, verify its implementation, revoke compromised credentials or execute a second migration when cryptanalysis changes.
Integrated early-warning dashboard
| Indicator family | Core metric | 2027 question | 2031 desired condition | Escalation trigger |
|---|---|---|---|---|
| Inventory | Priority dependencies with verified CBOM | Is cryptography known by purpose and owner? | Above 95% | Coverage below 60% after 2028 |
| Products | Validated PQC-capable modules | Are several suppliers completing validation? | Competitive supply in every critical category | Single-vendor dependence |
| Identity | Relying parties supporting new signatures | Can identity migrate end to end? | Above 90% | Issuance substantially exceeds verification capability |
| Cloud | Services with documented PQC responsibility | Are customer and provider duties explicit? | Full priority-service coverage and tested exit | Shared-responsibility ambiguity |
| OT | Critical devices with migration or isolation route | Can long-lived hardware be remediated? | Every critical asset has an executable route | More than 20% remain unsupported |
| Supply chain | Suppliers with crypto-agility commitments | Are obligations contractually enforceable? | Above 90% | More than 15% refuse disclosure |
| Assurance | Median certification duration | Is capacity scaling with demand? | Below nine months | Median exceeds eighteen months |
| Workforce | Filled specialist positions | Can the plan execute without excessive contracting? | Demand-supply gap below 10% | Contractor premium exceeds 30% |
| Fragmentation | Incompatible sovereign profiles | Is mutual recognition expanding? | Limited and modular regional variance | Separate product lines required in major markets |
| Finance | Funding aligned with verified plans | Do budgets reflect actual inventories? | Multiyear funded execution | Mandates lack appropriations |
| Fallback | Classical-only acceptance routes | Are downgrade paths controlled? | Disabled in migrated priority systems | Silent fallback remains widespread |
| Resilience | Algorithm and provider portability | Can the system migrate again? | Tested substitution of algorithms and providers | Hard-coded algorithms or non-exportable keys |
The final five-year judgement is that H1 remains the leading scenario, but its probability should not exceed a simple majority until certificate, identity, validation and OT evidence demonstrates operational interoperability rather than policy alignment. H2 is the most strategically consequential alternative because separate sovereign cryptographic stacks would raise costs across finance, cloud, telecommunications, industrial exports and digital government. H3 may operate inside H1: platform providers can accelerate common standards while simultaneously concentrating control in hyperscalers and operating-system vendors. H4 remains comparatively unlikely but carries extreme short-term cost, making contingency procurement and crypto-agile design rational even if no emergency materialises. H5 will not occur uniformly; it is most plausible in municipal, healthcare, educational, SME and legacy-OT environments while high-value national-security and financial systems move faster. The optimal policy is therefore differentiated acceleration. Governments and organisations should prioritise long-lived sensitive data, high-value identity, code signing, critical remote access, irreplaceable trust anchors and procurement of long-lived equipment. Lower-risk systems can follow ordinary refresh cycles if their eventual route is documented and funded. Success in 2031 will not be defined by declarations that migration is complete. It will be defined by operational use of approved algorithms, end-to-end trust-chain functionality, controlled fallback, adequate supplier competition and sufficient crypto-agility to execute the next cryptographic transition without recreating the same capital shock.
Dominant Migration Scenarios, 2027–2031
The values are structured analytical probabilities, not official forecasts and not estimates of when a cryptographically relevant quantum computer will exist. The controls simulate directional Bayesian updates and renormalise the five scenario probabilities to 100%.
















