Scope: This dossier assesses the distinct trajectories of quantum computing, quantum communications and cryptography, and quantum sensing through 2031, separating civilian and military applications and examining their technical evidence, institutional ownership, industrial dependencies and consequences for government decisions.
Executive Summary / BLUF
[D/P] The controlling judgment is that quantum policy requires separate investment and assurance decisions for computational experiments, cryptographic migration and sensing systems, because the verified record establishes different kinds of progress across these activities rather than a common transition to operational capability. Quantum error correction below the surface code threshold — Nature — Dec 2024; Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography — NIST — Aug 2024. Nature
[P] The immediate executive obligation is to govern cryptographic migration against data lifetimes and replacement cycles, with European transition milestones extending from initiation by the end of 2026 to critical-infrastructure protection by the end of 2030, while the United Kingdom distinguishes discovery by 2028, priority migration by 2031 and completion by 2035. EU reinforces its cybersecurity with post-quantum cryptography — European Commission — Jun 2025; Timelines for migration to post-quantum cryptography — NCSC — Mar 2025. Shaping Europe’s digital future
[D/R] Error-correction experiments support continued investment in computing, but a demonstrated memory or logical-operation protocol must remain distinct from a vendor commitment to deliver a machine, including IBM’s target of 200 logical qubits and 100 million gates in 2029. A fault-tolerant neutral-atom architecture for universal quantum computation — Nature/NIST — Nov 2025; Quantum 2030 — IBM Technology Atlas — updated Mar 2026. NIST
[C/P] Government-reported navigation flight trials justify further evaluation rather than fleet-readiness claims, while the NSA’s position published on 1 October 2026 continues to reject QKD for national-security transmission unless specified limitations are overcome. Un-jammable quantum tech takes flight to boost UK’s resilience against hostile actors — DSIT/UKRI — May 2024; Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms — NSA — Oct 2026. GOV.UK
Quantum Policy Must Buy Protection and Evidence
Governments should finance quantum policy according to what it can protect or deliver, because the technology’s security timetable has already diverged from its computing timetable. NIST’s adoption of FIPS 203, FIPS 204 and FIPS 205 on 13 August 2024 gave institutions standards for preparing ordinary digital systems against future quantum attacks; it did not demonstrate a quantum computer capable of executing those attacks. That distinction should determine expenditure: ministries must replace vulnerable security dependencies while buying computing progress against verifiable milestones and measurement equipment against defined tasks. Confusing these responsibilities would expose long-lived information, misstate industrial achievement and reward suppliers for a label rather than a delivered function. The governing test is whether each commitment purchases protection, knowledge or an accepted service, with evidence appropriate to that purpose.
A security upgrade cannot certify a quantum computer
Post-quantum cryptography describes mathematical protection performed on conventional systems, rather than quantum processing inside the institution adopting it. ML-KEM establishes shared secret material; ML-DSA and SLH-DSA provide digital signatures. A successful implementation therefore demonstrates a cryptographic operation within its tested scope, while establishing nothing about the reliability of a quantum processor. The distinction matters politically because the phrase “quantum-safe” can make a cybersecurity purchase sound like the acquisition of quantum computing capacity, allowing an accurately described security improvement to become an unsupported industrial claim.
The Willow protected-memory experiment provides evidence of a different kind: physical quantum information preserved through error correction under specified conditions. Its significance lies in the engineering result, whose limits must remain visible, rather than in the adoption of a security algorithm elsewhere. Governments should assess these achievements through separate acceptance tests, because the information-protection programme has to reach the actual services holding sensitive data, while the computing programme has to establish the calculations its equipment can complete.
The figures measure different promises and obligations
Britain’s £2.5 billion quantum research and innovation commitment covers ten years from 2024; France’s May 2026 announcement adds €1 billion for 2026–2030; Australia’s A$940 million commitment concerns a particular computing project. These amounts cannot be ranked as comparable annual expenditure or completed capacity. Their different periods and scopes determine what each government has undertaken, while contract performance and operational acceptance determine what it ultimately receives. India’s March 2026 disclosure makes the distinction concrete: for IIT Bombay, the reported release was ₹114.89 crore and utilisation ₹22.31 crore, within a selected institutional row rather than the whole National Quantum Mission. Authorisation, payment and use remain different financial facts.
The technical calendars are equally incompatible. IBM’s Starling roadmap targets 200 logical qubits and 100 million processing operations in 2029; France’s PROQCIMA programme now targets 1,024 logical qubits in 2032, increased from its earlier target of 128. DARPA’s Quantum Benchmarking Initiative asks whether computational value can exceed cost by 2033. None establishes a completed service within the report’s 2026–2031 horizon. Britain’s National Cyber Security Centre, meanwhile, sets discovery and planning milestones for 2028, highest-priority migration work for 2031 and completion for 2035. Those dates govern organisational preparation rather than predict an attacker’s arrival, so a security deadline can precede computing maturity without contradiction.
The application evidence further narrows what these commitments can promise. The GIRAFE airborne gravimetry study, published in April 2025 from a June–July 2023 campaign, reported approximately 1–2 milligals accuracy for both quantum and conventional instruments; a milligal measures small gravity differences. The comparison supports evaluation of a defined instrument rather than automatic technological superiority. A July 2026 reinforcement-learning study reported approximately 20% additional logical-error suppression in specified Willow experiments, supporting a measured AI contribution to control rather than a claim that AI has completed the engineering of a reliable computing service.
Procurement must follow the result into operation
The Royal Navy’s August 2026 announcement concerning AQlock clocks and Saab radar equipment supports examination of a named timing trial. It does not establish complete navigation independence or fleet-wide readiness, because maintaining time and determining position are different functions. The procurement question is consequently whether the tested instrument can maintain the required service throughout the intended disruption, with supporting equipment, trained users and a workable recovery procedure. Buying a device without specifying that responsibility would leave acceptance dependent on the supplier’s preferred description.
The GIRAFE airborne gravimetry study offers a stronger comparison framework because it examined a quantum instrument alongside conventional equipment in an actual survey campaign. Its lesson for procurement is that the alternative must be competitive and the task explicit: measurement quality, processing requirements and maintenance determine usefulness more directly than the technology label. Quantum computing contracts need the same discipline, with a named calculation, complete execution cost and independent assessment. DARPA’s Quantum Benchmarking Initiative institutionalises that question by testing utility against cost, rather than treating access to equipment as sufficient evidence of value.
Standards open a transition without certifying the estate
FIPS 203, FIPS 204 and FIPS 205 specify mechanisms; they do not certify every product, replace every certificate hierarchy or verify every software-update path. NIST’s migration work distinguishes discovery of cryptographic dependencies from interoperability testing, exposing the management burden that lies between an approved algorithm and a protected service. A ministry has to establish where the older methods operate, which suppliers control replacement and whether both ends of a connection can support the change, while maintaining continuity during deployment. A procurement announcement cannot substitute for those acceptance results.
NSA’s published position on quantum key distribution also limits the claim that special quantum equipment provides a complete security answer. Its objections include authentication, trusted relays, implementation assurance and availability, with conditional rejection for the national-security transmission use discussed. That position should not be turned into a universal prohibition, but it requires a buyer to explain the threat model and the trust arrangement before crediting an additional benefit. Mathematical migration and specialised communications infrastructure need separate business cases, preventing a hardware proposal from inheriting the justification for a different security mechanism.
European coordination cannot replace control of components
The European Commission’s Quantum Europe Strategy, adopted in July 2025, identifies fragmentation and the difficulty of converting scientific strengths into market opportunities. Italy’s strategy adoption that month establishes a coordinating framework, while France’s PROQCIMA programme sets a computing ambition that still requires verified delivery. Germany’s quantum action concept links development to industrial implementation, and Britain’s National Cyber Security Centre gives system owners a staged security transition. These instruments serve different responsibilities; treating them as interchangeable national victories would obscure whether public money is building production, supporting research or changing operational systems.
Japan’s May 2025 ecosystem policy identifies concerns involving specialist lasers, detectors, diamond materials and refrigeration-related equipment, illustrating where industrial dependence can survive the purchase of a finished machine. The EU’s sovereignty objective therefore has to reach design, production, maintenance and replacement options, with contracts identifying indispensable suppliers. Cooperation can improve access, but the buyer still needs to know who repairs the equipment and who controls the components that keep it operating. National installation counts cannot answer those questions, and a domestic research achievement cannot by itself establish continuity of supply.
The next two years will charge delay to system owners
Between October 2026 and October 2028, the practical test should be whether institutions have converted NIST standards and the National Cyber Security Centre’s discovery milestone into funded inventories, tested changes and accountable service plans. Delay would leave the work with security teams, infrastructure operators and future procurement budgets, while long-lived information would continue to depend on the protection already in place. The cost is conditional exposure and a deferred replacement burden, rather than an invented estimate of losses from a quantum attack whose operational arrival remains unestablished.
IBM’s roadmap, PROQCIMA and the Quantum Benchmarking Initiative should face the corresponding industrial test: each next funding decision should identify which uncertainty has been reduced and which capability has been demonstrated. If governments report post-quantum cryptography as proof of quantum computing maturity, taxpayers would finance an overstated achievement and operational users would inherit an unverified promise. The decision over the next 24 months is to complete measurable security preparation and make further industrial commitments conditional on evidence; announcements alone would leave both responsibilities with the institutions expected to operate the result.
Navigational Index
The dossier retains the eleven substantive sections requested in the topic document within the governing protocol’s architecture of exactly three thematic pillars; chapter identifiers are retained in the index, while substantive headings remain unnumbered.
Pillar 0 — Quantum Technologies Explained for Political Leaders and Nontechnical Readers
What Works Today, What Still Prevents Wider Use, and What Governments Should Prepare for by 2031
Pillar I — Mechanisms, Hardware and Computational Evidence
| Dossier section | Required coverage |
|---|---|
| Chapter 1 — Executive Adjudication | Five findings that change ministerial decisions; the evidence supporting each finding; the consequences of confusing a demonstration, programme, roadmap or unsupported claim. |
| Chapter 2 — The Taxonomy | The three technology stacks; mechanism-level interpretation of public terminology; a comparison of technical and institutional readiness; forbidden synonyms and misleading equivalences. |
| Chapter 3 — Quantum Computing: Hardware Truth | Superconducting, trapped-ion, neutral-atom, photonic, silicon-spin and topological platforms; physical and logical resources; fidelity definitions; demonstrated error correction; manufacturing and sovereign supply-chain constraints. |
| Chapter 4 — What Quantum Computers Can and Cannot Do in 2026 | Chemistry, materials, optimisation, sampling, factoring and discrete logarithms, assessed against problem size, classical comparators, verification cost and the resources required for fault tolerance. |
Pillar II — Security Migration and Operational Applications
| Dossier section | Required coverage |
|---|---|
| Chapter 5 — Cryptography | QKD, quantum-secure direct communication, quantum networks, PQC, symmetric cryptography, harvest-now-decrypt-later exposure, named cryptanalytic resource estimates and jurisdiction-specific migration requirements. |
| Chapter 6 — Civilian Uses That Are Real | Finance, telecommunications, pharmaceuticals, energy, metrology and civil positioning, navigation and timing, retaining only applications supported by a named deployment, pilot, experiment or standard. |
| Chapter 7 — Military and Intelligence Uses That Are Real | Sensing and timing, communications and computing assessed separately; contested-spectrum PNT, magnetic-anomaly missions, subsurface detection, distributed timing, national-security cryptographic migration and experimental networks. |
Pillar III — Industrial Power, Conditional Outlook and Decisions
| Dossier section | Required coverage |
|---|---|
| Chapter 8 — The Industrial and Geopolitical Layer | United States, China, European Union, United Kingdom, Japan, India, Israel, Australia and Canada, with separate Italian, French and German lenses; transparent expenditure, hardware sovereignty, standards, talent and operative export controls. |
| Chapter 9 — Five-Year Outlook Under AI Acceleration | Constrained, base and accelerated pathways across 2026–27, 2028–29 and 2030–31, conditional on error correction, logical resources, decoder latency, manufacturing yield and cryptanalytic developments. |
| Chapter 10 — Implications for Decision-Makers | Application-level action matrix for civil government, defence, critical infrastructure and enterprise, distinguishing immediate action, monitored investment, unsuitable procurement and claims requiring retirement. |
| Chapter 11 — Annexes | Glossary and forbidden synonyms; source register with retrieval dates; ten claim corrections; uncertainty register and records capable of changing the assessment. |
Front Matter
Method and Evidentiary Boundary
This assessment treats the supplied text file as the governing report protocol and the supplied Markdown file as the subject-specific specification, admitting peer-reviewed technical papers and explicitly identified preprints where the latter document theoretical estimates rather than experimentally established capability.
The governing question is: which decisions should institutions take between 2026 and 2031 when hardware demonstrations, security requirements, funded programmes and commercial forecasts advance on different schedules?
All sources cited in this opening delivery were retrieved on 4 October 2026; their publication dates identify the age of the evidence rather than implying that the underlying experiment, policy position or roadmap was newly established on the assessment date.
Tag Legend
| Tag | Meaning and application |
|---|---|
| [D] Demonstrated | A peer-reviewed hardware result, bounded by its platform, experimental conditions, measured quantity and limitations; publication does not by itself establish independent reproduction or operational accreditation. |
| [P] Programme | An adopted standard, funded activity, contractual requirement or institutional migration framework, whose existence does not establish that implementation has been completed. |
| [R] Roadmap | A dated future target that remains conditional on milestones and delivery evidence. |
| [C] Claim | An attributed institutional or company assertion, including a theoretical resource projection that has not been demonstrated on the complete proposed hardware. |
| [H] Hype | A proposition that confuses mechanisms, removes a decisive limitation or assigns capability without a corresponding technical basis. |
Where a sentence draws an analytical conclusion from evidence, its tag identifies the underlying evidence category, while wording such as “the assessment therefore” makes clear that the conclusion is a judgment rather than an additional experimental result.
What This Report Will Not Do
The dossier will not assign a universal maturity score to “quantum,” infer cryptanalytic capability from a physical-qubit headline, turn an experimental sensor into a military detection range, count announced investment as expenditure, or present a procurement recommendation without identifying the mechanism, mission, acceptance criteria and responsible institution.
Executive Adjudication
Cryptographic Migration Requires an Owner Before It Requires a Quantum Computer
[P] Finding — Decision changed: establish a funded migration authority, an asset inventory and replacement obligations rather than making preparation conditional on an agreed date for a cryptographically relevant quantum computer. The January 2026 G7 Cyber Expert Group statement addresses the financial sector’s transition as a coordinated governance problem, explicitly incorporating the exposure created when information intercepted before a future quantum capability remains sensitive when that capability becomes available; its timetable is described as non-authoritative and responsive to changing risk, which prevents its use as either a prediction of machine arrival or a universal regulatory deadline. G7 Cyber Expert Group Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector: January 2026 — G7 Cyber Expert Group/HM Treasury — Jan 2026. GOV.UK
The recommended governance response is to assign responsibility for confidentiality, authentication and software-signing dependencies separately, because the replacement plan must account for the lifetime of information, the lifetime of deployed equipment and the authority to change the relevant cryptographic implementation.
Computing Procurement Must Purchase a Workload Result
[D] Finding — Decision changed: condition computing expenditure on reproducible logical performance and a specified workload, with physical-qubit count treated as a hardware descriptor rather than an acceptance test. Google’s Willow paper establishes below-threshold surface-code memory experiments on processors containing 72 and 105 physical qubits, with a distance-5 experiment using an integrated real-time decoder and a distance-7 memory experiment; the authors explicitly identify additional challenges in logical computation, so this result supports an error-correction milestone without establishing a cryptanalytic machine or a general industrial advantage. Quantum error correction below the surface code threshold — Nature — Dec 2024. Nature
The proposed purchasing rule is to require the supplier to identify the computational task, logical operations, complete execution time, verification method and classical comparator before a machine-level performance claim enters an institutional business case.
QKD Requires a Specific Threat Model and Assurance Route
[P] Finding — Decision changed: separate QKD research or specialist-link evaluation from national-security cryptographic migration, rather than allowing a physical-layer security argument to determine system accreditation. In its October 2026 publication, the NSA retains a conditional position against QKD for national-security transmission and identifies absent source authentication, dedicated equipment, trusted-relay exposure, implementation vulnerabilities and denial-of-service sensitivity as material limitations; its wording includes “does not recommend using quantum key distribution,” while its broader position remains conditional on overcoming the listed problems. Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms — NSA — Oct 2026. nsa.gov
The recommended approval test is to require a named authentication mechanism, relay-trust model, physical-security boundary, implementation evaluation and availability requirement, with the approving authority determining whether those properties satisfy the actual mission.
Sensing Investment Should Advance Through Mission Trials
[C/R] Finding — Decision changed: finance instrument integration and mission-relevant evaluation while withholding fleet-capability claims until published performance or accreditation evidence supports them. The British government reported flight trials involving Infleqtion, BAE Systems and QinetiQ at Boscombe Down in May 2024, supported by nearly £8 million in government backing, while describing aircraft deployment by 2030 as a national mission objective; the public announcement therefore establishes an officially reported trial and future target, rather than a disclosed navigation-error envelope or a completed operational deployment. Un-jammable quantum tech takes flight to boost UK’s resilience against hostile actors — DSIT/UKRI — May 2024. GOV.UK
The proposed acceptance programme should specify navigation drift, duration without external correction, environmental tolerance, maintenance burden and integration with existing navigation systems before the instrument is credited with a mission effect.
AI Funding Requires a Named Bottleneck and a Measured Gain
[D] Finding — Decision changed: fund AI as an experimentally evaluated control or decoding tool, with expenditure tied to the bottleneck it addresses rather than to a general claim of accelerated quantum maturity. A July 2026 Nature paper reports approximately 20% additional logical-error suppression from reinforcement-learning fine-tuning after conventional calibration, together with a distance-7 surface-code logical-error rate of 7.72(9) × 10⁻⁴ using the AlphaQubit2 decoder; this supports a specific improvement in the tested control-and-decoding setting, while providing no basis for substituting AI for the physical operations required by the architecture. Reinforcement learning control of quantum error correction — Nature — Jul 2026. Nature
Master Abstract
Three Stacks Require Separate Evidence and Separate Decisions
[D/P] The central distinction is between computing systems that manipulate and protect quantum information, communication systems that distribute quantum states or keying material, and classical cryptographic mechanisms standardised to resist specified classes of quantum attack; NIST’s FIPS 203 establishes a key-encapsulation mechanism, while FIPS 204 and FIPS 205 establish digital-signature mechanisms, so their adoption must be assessed as cryptographic implementation rather than evidence that a quantum communication or computing platform has become operational. Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST, FIPS 203 — Aug 2024; Module-Lattice-Based Digital Signature Standard — NIST, FIPS 204 — Aug 2024; Stateless Hash-Based Digital Signature Standard — NIST, FIPS 205 — Aug 2024. CSRC
The dossier’s recommended institutional architecture therefore assigns computing evaluation to workload and hardware specialists, cryptographic migration to accountable security and infrastructure owners, and sensing acquisition to the organisation that can define and test the intended mission; common scientific foundations do not remove the need for separate acceptance criteria.
Error-Corrected Operations Are Real, While Scale Remains an Engineering Question
[D] Neutral-atom evidence extends beyond a simple memory milestone: the paper published online in November 2025 and appearing in Nature’s January 2026 volume describes reconfigurable arrays of up to 448 atoms, below-threshold behaviour in a four-round characterisation circuit, logical entanglement operations and protocols involving dozens of logical qubits and hundreds of logical teleportations; the demonstrated elements support the feasibility of an architecture, while the experimental scope must remain explicit whenever the result is used to discuss scalable universal processing. A fault-tolerant neutral-atom architecture for universal quantum computation — Nature/NIST — Nov 2025. NIST
[C] The theoretical attraction of quantum low-density parity-check codes is their potential to reduce encoding overhead, but the peer-reviewed bivariate-bicycle work is a code-and-protocol analysis whose benefits depend on the assumed hardware and connectivity, so a favourable encoding rate must not be reported as a fielded processor possessing the complete required gate set, decoding performance and operating reliability. High-threshold and low-overhead fault-tolerant quantum memory — Nature — Mar 2024. Nature
The assessment recommends evaluating fault tolerance through the full execution chain, including state preparation, logical operations, measurement, decoding and the resources consumed by the chosen error-correction architecture, because a result established for one element cannot serve as evidence that all remaining elements have met the same performance standard.
Cryptanalytic Estimates Must Retain Their Complete Assumptions
[C] Gidney’s May 2025 preprint supplies a concrete, architecture-dependent RSA-2048 resource model rather than a demonstrated attack, with the following quantities reported in its logical-cost table and physical-cost analysis. How to factor 2048 bit RSA integers with less than a million noisy qubits — Craig Gidney, arXiv preprint — May 2025. arxiv.org
| Resource or assumption | Value in the cited RSA-2048 model |
|---|---|
| Status | [C] Theoretical resource estimate; no complete attack demonstrated on the proposed hardware. |
| Logical resources | Physical-layout analysis allocates 1,537 logical patches including workspace, while the logical-cost table lists 1,399 algorithmic qubits and the layout text discusses 1,409 active logical qubits; these quantities describe different accounting boundaries. |
| Non-Clifford workload | Approximately 6.5 × 10⁹ expected Toffoli gates per factoring, as reported in Table 5. |
| Error-correction distance | Distance 25 for ordinary hot-storage surface-code patches; cold storage uses a yoked construction. |
| Encoding overhead | 1,352 physical qubits per hot logical patch, approximately 430 per cold logical qubit, with separate computation and factory resources. |
| Complete physical layout | 897,864 physical qubits, with additional slack motivating the headline near one million. |
| Physical noise assumption | Uniform depolarising noise strength of 10⁻³. |
| Timing and connectivity | 1 μs surface-code cycle, 10 μs control reaction time, and a nearest-neighbour square-grid architecture. |
| Runtime | Approximately 4.96 days after the stated logical-error adjustment, rounded upward to less than one week. |
[C] The assessment must also retain newer architectural alternatives: the March 2026 Cain and co-authors preprint examines high-rate codes, logical instruction sets and reconfigurable atomic hardware in an architecture distinct from the surface-code model above, which makes it relevant to the uncertainty register without permitting a lower headline qubit count to be treated as measured attack capability or as a directly comparable revision of the same machine. Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits — Cain et al., arXiv preprint — Mar 2026. arxiv.org
The decision consequence is to keep cryptanalytic resource estimates under technical review while progressing migration against the institution’s exposure, rather than deriving a single arrival year from estimates that assume different codes, connectivity, clock rates and implementation conditions.
Standards Provide a Migration Basis Without Providing Absolute Assurance
[P/R] NIST selected HQC for standardisation in March 2025 as an alternative mathematical basis to ML-KEM, while its announcement described finalisation in 2027 as an expected future milestone; the selection therefore supplies evidence of diversification in the standards programme, while that announcement alone cannot establish the subsequent completion or deployment status of an HQC standard. NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption — NIST — Mar 2025. NIST
[P] Symmetric cryptography requires a separate risk assessment: NIST’s FAQ distinguishes the dramatic algorithmic threat to susceptible public-key schemes from Grover-type search, emphasising the sequential operations and parallelisation constraints that limit the practical interpretation of a quadratic speed-up; consequently, this assessment rejects the use of an RSA resource model as evidence of a comparable attack on AES-256. Post-Quantum Cryptography: FAQs — NIST — undated, retrieved Oct 2026. CSRC
The recommended security case should therefore identify the actual primitive, parameter set, protocol and implementation, with confidentiality migration, signature migration and symmetric-key policy receiving separate acceptance tests.
European Coordination Must Preserve National Assurance Differences
[P] Italy’s institutional baseline includes the adoption of its national quantum strategy by the Interministerial Committee for the Digital Transition, recorded in July 2025, which establishes a coordinating framework without itself demonstrating that every strategic objective has an appropriated budget, awarded contract or delivered capability. Tecnologie quantistiche: una Strategia per l’Italia — Dipartimento per la trasformazione digitale — Jul 2025. innovazione.gov.it
[P/R] France’s ANSSI addendum, dated December 2023 and published through its service portal in January 2024, addresses hybridisation and an accelerated assurance agenda, while the stated expectation of initial security visas around 2024–25 remains a historical target unless a product-specific certificate establishes issuance. Avis de l’ANSSI sur la migration vers la cryptographie post-quantique (suivi 2023) — ANSSI — Dec 2023, p. 1. messervices.cyber.gouv.fr
[P/C] Germany’s government response of July 2025 records support for migration and the development of a national roadmap on the basis of the European framework, so the document supports institutional intent and stated policy without establishing completion of the later roadmap or migration outcomes. Aktuelle und zukünftige Sicherheitsrisiken für Bestände an Kryptowährungen durch Quantencomputer und Hackergruppen — Bundesregierung/Deutscher Bundestag, Drucksache 21/928 — Jul 2025, responses on migration. dserver.bundestag.de
The recommended coordination principle is to compare these jurisdictions through equivalent records—operative guidance, certification, expenditure, procurement and implementation evidence—while preserving differences between a national strategy, an assurance position and a sectoral migration timetable.
Key Evidence Table
| Indicator | Value/status | Reference date | Definition/scope | Issuer | Exact source |
|---|---|---|---|---|---|
| [P] Standardised key establishment | FIPS 203; ML-KEM | August 2024 | Key-encapsulation mechanism; the standard does not establish accreditation of every implementation | NIST | Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST — Aug 2024 |
| [P] Standardised digital signatures | FIPS 204; ML-DSA | August 2024 | Module-lattice signature mechanism | NIST | Module-Lattice-Based Digital Signature Standard — NIST — Aug 2024 |
| [P] Alternative standardised signatures | FIPS 205; SLH-DSA | August 2024 | Stateless hash-based signature mechanism | NIST | Stateless Hash-Based Digital Signature Standard — NIST — Aug 2024 |
| [R] IBM computing target | 200 logical qubits; 100 million gates; target availability in 2029 | June 2025 announcement | Vendor delivery objective, requiring subsequent hardware and performance evidence | IBM | IBM Sets the Course to Build World’s First Large-Scale, Fault-Tolerant Quantum Computer at New IBM Quantum Data Center — IBM — Jun 2025 |
| [P] European transition milestone | Initiation by end-2026; critical infrastructure by end-2030 | June 2025 | Coordinated roadmap expectations; national legal implementation must be examined separately | European Commission/NIS Cooperation Group | EU reinforces its cybersecurity with post-quantum cryptography — European Commission — Jun 2025 |
| [P] UK migration milestones | Discovery and planning by 2028; priority migration by 2031; completion by 2035 | March 2025 | Indicative institutional migration targets, with qualifications in the guidance | NCSC | Timelines for migration to post-quantum cryptography — NCSC — Mar 2025 |
Technical and Institutional Readiness
The following classifications are dossier judgments tied to the cited evidence, rather than numerical scores or a claim that every application within a technology family has reached the same stage.
| Application examined | Technical-readiness judgment | Institutional-readiness judgment | Evidence boundary |
|---|---|---|---|
| [D] Willow surface-code memory | Component demonstrated | Research programme | The experiment establishes protected-memory behaviour; the paper identifies further logical-computation requirements. Quantum error correction below the surface code threshold — Nature — Dec 2024 |
| [D] Neutral-atom logical-processing architecture | Integrated experimental prototype | Research programme | The cited work demonstrates architectural elements and bounded protocols rather than an accredited industrial service. A fault-tolerant neutral-atom architecture for universal quantum computation — Nature/NIST — Nov 2025 |
| [P] PQC standards and migration | Standardised mechanisms; deployment readiness requires implementation-specific evidence | Guidance and requirements established in named jurisdictions | Algorithm approval must remain distinct from product assurance and completed estate migration. Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography — NIST — Aug 2024 |
| [C/R] UK airborne quantum-navigation activity | Officially reported limited flight trial | Funded programme with future deployment objective | Publicly disclosed trial information does not establish a complete operational performance envelope. Un-jammable quantum tech takes flight to boost UK’s resilience against hostile actors — DSIT/UKRI — May 2024 |
Principal Gaps and Watch Indicators
| Assessment-changing gap | Required record or observation | Decision threshold |
|---|---|---|
| [D] Sustained logical-computation performance | Reproducible workload results showing logical operations, complete runtime, error budget and all material overheads | Expand application procurement only when the tested system meets a predeclared workload requirement. |
| [C] Cryptanalytic resource-model feasibility | Architecture-specific validation of the assumed codes, connectivity, timing, logical operations and factory or equivalent resource provision | Reassess exposure when validated engineering evidence materially changes an end-to-end attack estimate. |
| [P] Migration completion | Asset-level evidence covering protocol, algorithm, parameter set, implementation, assurance and retirement of vulnerable dependencies | Report completion against protected assets and functions rather than the number of plans or products purchased. |
| [C/R] Navigation mission performance | Trial reports disclosing drift, duration, environmental conditions, external updates, integration and maintenance | Move from experimental evaluation to acquisition only against mission-specific acceptance criteria. |
| [R] Roadmap delivery | Dated hardware delivery and performance evidence corresponding to the stated milestone | Release later-stage funding against verified achievement rather than elapsed calendar time. |
These collection priorities follow the gaps between demonstrated experiments, theoretical estimates and delivery targets identified above; they are proposed evidence requirements, not assertions that the relevant capabilities are absent outside the public record.
Conditional Pathways to 2031
The opening assessment uses alternatives and indicators rather than assigning probabilities, because a common numerical model for hardware progress, industrial scaling and institutional migration has not been established.
| Pathway | Branch conditions | Decision consequence |
|---|---|---|
| Constrained pathway | Larger systems fail to preserve their demonstrated logical performance, or decoding, interconnection and manufacturing prevent sustained workload execution. | Continue cryptographic migration and mission-specific sensing evaluation while limiting computing expenditure to measurable research and enabling infrastructure. |
| Base pathway | Protected logical operations become more reproducible and systems support selected workloads, while remaining short of a validated cryptanalytic architecture. | Expand computing pilots through independent comparison with classical methods, retaining separate budgets and acceptance criteria for security migration. |
| Accelerated pathway | Error correction, logical operations, control latency, manufacturing and architecture-specific resource reductions succeed together rather than through isolated milestones. | Reassess long-lived information exposure and deployment priorities while demanding complete attack-model evidence before attributing cryptanalytic capability. |
[R] IBM’s current roadmap illustrates the need for this conditional treatment, since it explicitly describes its information as intent subject to change and places Starling availability in 2029, while positioning a larger Blue Jay system at 2033 and beyond; the roadmap is a relevant industrial commitment, but it does not establish which branch will occur or demonstrate a cryptographically relevant computer within the dossier’s window. Quantum 2030 — IBM Technology Atlas — updated Mar 2026.
Cryptographic migration follows an institutional timetable
[P] Calendar-year milestones drawn from published guidance. These dates are migration targets rather than forecasts of cryptographically relevant quantum computing.
UK discovery and planning
Define goals, discover cryptographic dependencies and build an initial migration plan.
EU critical infrastructure
Transition critical-infrastructure protection as soon as possible, no later than the end of this year.
UK highest priorities
Complete early, highest-priority migration activities and refine the route to completion.
UK completion target
Complete migration across systems, services and products, subject to the qualifications in the guidance.
| Jurisdiction | Year | Scope |
|---|---|---|
| United Kingdom | 2028 | Discovery, goals and initial planning |
| European Union | 2030 | Critical-infrastructure protection |
| United Kingdom | 2031 | Highest-priority migration activities |
| United Kingdom | 2035 | Completion target with stated qualifications |
Sources: Timelines for migration to post-quantum cryptography — NCSC — March 2025 ; EU reinforces its cybersecurity with post-quantum cryptography — European Commission — June 2025 . Retrieved 4 October 2026.
Interpretation: the jurisdictions and protected-system scopes differ; no probability, hardware capability or binding national obligation is inferred from this comparison.
Open-source analytical assessment · 4 October 2026
Quantum Technologies, 2026–2031
A Separation of Demonstrated Capability, Funded Programme, and Narrative
Controlling judgment: institutions should govern computing experiments, cryptographic migration and sensing acquisition through distinct evidence and acceptance criteria, because progress in one stack does not establish readiness in another.
Read the evidence before the headline
Tags describe evidentiary status rather than confidence scores. Recommendations and readiness classifications below are analytical judgments; they are not additional hardware demonstrations.
Three stacks, three acceptance tests
Stack A
Quantum computing
[D] Protected-memory experiments and neutral-atom logical-processing elements establish bounded error-correction results rather than a general industrial or cryptanalytic capability.
Acceptance test: require logical operations, complete runtime, error budget, verification and a named classical comparator.
Quantum error correction below the surface code threshold — Nature — Dec 2024; A fault-tolerant neutral-atom architecture for universal quantum computation — Nature/NIST — Nov 2025.
Stack B
Communications & cryptography
[P] NIST standards establish classical key-encapsulation and signature mechanisms; QKD distributes keying material and introduces a different hardware and assurance boundary.
Acceptance test: identify the primitive, authentication, implementation assurance, relay trust and availability requirement.
Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography — NIST — Aug 2024; Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms — NSA — Oct 2026.
Stack C
Sensing, timing & metrology
[C] The UK government reported navigation technology flight trials in May 2024; [R] aircraft deployment by 2030 was described as a future mission objective.
Acceptance test: evaluate drift, mission duration, environment, external updates, maintenance and platform integration.
Five findings that change a decision
| Decision | Action | Evidence and boundary |
|---|---|---|
| Assign migration ownership | Fund discovery and replacement planning against secrecy lifetimes and infrastructure cycles, rather than awaiting a machine-arrival forecast. | [P] G7 Cyber Expert Group Statement on Advancing a Coordinated Roadmap for the Transition to Post-Quantum Cryptography in the Financial Sector: January 2026 — G7/HM Treasury — Jan 2026; planning guidance does not predict a computer’s arrival. |
| Buy a workload result | Condition computing expenditure on reproducible logical performance and complete execution cost. | [D] Quantum error correction below the surface code threshold — Nature — Dec 2024; protected memory is a bounded experimental result. |
| Separate QKD evaluation | Require a specific threat model and accreditation route before crediting national-security protection. | [P] Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms — NSA — Oct 2026; the agency maintains conditional rejection for NSS transmission. |
| Test sensors against missions | Advance trials toward acquisition only after disclosure of a mission-relevant performance envelope. | [C] Un-jammable quantum tech takes flight to boost UK’s resilience against hostile actors — DSIT/UKRI — May 2024; a reported flight trial does not establish fleet readiness. |
| Fund specific AI bottlenecks | Measure improvements in control and decoding while preserving the physical requirements of error correction. | [D] Reinforcement learning control of quantum error correction — Nature — Jul 2026; the reported gain is tied to the tested calibration and decoding conditions. |
Technical reality and institutional readiness are separate axes
These classifications apply to the cited result or programme rather than to an entire technology family.
| Application | Technical readiness | Institutional readiness | Evidence boundary |
|---|---|---|---|
| [D] Willow memory | Component demonstrated | Research programme | Quantum error correction below the surface code threshold — Nature — Dec 2024; protected memory and further logical-computation challenges. |
| [D] Neutral-atom architecture | Integrated experimental prototype | Research programme | A fault-tolerant neutral-atom architecture for universal quantum computation — Nature/NIST — Nov 2025; architectural elements and bounded protocols. |
| [P] PQC migration | Standardised mechanisms; implementation-specific assurance required | Standards and jurisdiction-specific guidance | Announcing Approval of Three Federal Information Processing Standards (FIPS) for Post-Quantum Cryptography — NIST — Aug 2024; approval of mechanisms does not accredit every product. |
| [C] UK airborne navigation | Officially reported limited flight trial | Funded programme and future objective | Un-jammable quantum tech takes flight to boost UK’s resilience against hostile actors — DSIT/UKRI — May 2024; no complete public mission-performance envelope in the announcement. |
Migration milestones are not machine-arrival predictions
[P] Calendar-year milestones have different jurisdictional scopes and are guidance or roadmap expectations rather than a single universal legal deadline.
UK · Discover and plan
Define goals, discover cryptographic dependencies and prepare the initial migration plan.
EU · Critical infrastructure
Transition protection as soon as possible, no later than the end of the year.
UK · Highest priorities
Complete early, highest-priority migration activities and refine the completion roadmap.
UK · Completion target
Complete migration across systems, services and products, with the guidance’s stated qualifications.
Timelines for migration to post-quantum cryptography — NCSC — Mar 2025; EU reinforces its cybersecurity with post-quantum cryptography — European Commission — Jun 2025. Unit: calendar year; categories: jurisdiction-specific milestones; no capability probability is implied.
A cryptanalytic estimate is an architecture, not a qubit headline
[C] The May 2025 RSA-2048 model below is a theoretical preprint estimate whose resource counts depend on the stated error model, code construction, timing and connectivity.
| Resource | Model value | Interpretation |
|---|---|---|
| Logical layout | 1,537 patches including workspace | Accounting differs from Table 5’s 1,399 algorithmic qubits and the layout text’s 1,409 active logical qubits. |
| Toffoli workload | 6.5 × 109 | Expected gates per factoring, as reported in Table 5. |
| Code distance | 25 for ordinary hot patches | Cold storage uses a yoked construction. |
| Physical overhead | 1,352 per hot patch; approximately 430 per cold logical qubit | Additional computation and factory resources are included separately in the complete layout. |
| Physical layout | 897,864 qubits | The headline near one million includes slack. |
| Noise and timing | 10−3 depolarising noise; 1 μs code cycle; 10 μs control reaction | Nearest-neighbour square-grid architecture assumed. |
| Estimated runtime | Approximately 4.96 days | After the stated logical-error adjustment; rounded upward to less than one week. |
[C] The 2026 neutral-atom alternative uses different architectural assumptions and must receive its own complete resource audit before comparison; neither estimate demonstrates a working attack. Shor’s algorithm is possible with as few as 10,000 reconfigurable atomic qubits — Cain et al., arXiv preprint — Mar 2026.
Three conditional pathways through 2031
Analytical alternatives from the opening assessment; no probabilities, invented readiness scores or annual qubit forecasts are assigned.
Constrained
Branch: larger systems fail to retain demonstrated logical performance, or decoding, manufacturing and interconnection constrain sustained execution.
Decision: continue migration and mission-specific sensor evaluation; limit computing procurement to measurable research and enabling infrastructure.
Base
Branch: reproducible protected operations support selected workloads while remaining short of a validated cryptanalytic architecture.
Decision: expand computing pilots through independent classical comparison and retain separate security-migration acceptance criteria.
Accelerated
Branch: error correction, logical operations, control latency, manufacturing and architecture-specific resource reductions succeed together.
Decision: reassess long-lived information exposure and require complete attack-model evidence before attributing cryptanalytic capability.
[R] IBM’s 2029 Starling target remains intent subject to change; Quantum 2030 — IBM Technology Atlas — updated Mar 2026. [D] AI control evidence is bounded by its experiment; Reinforcement learning control of quantum error correction — Nature — Jul 2026.
European coordination preserves national assurance boundaries
| Jurisdiction | Verified institutional baseline | Boundary |
|---|---|---|
| Italy | [P] Strategy adoption recorded in July 2025. Tecnologie quantistiche: una Strategia per l’Italia — DTD — Jul 2025. | A coordinating framework does not establish every appropriation, contract or delivered objective. |
| France | [P] ANSSI’s December 2023 addendum addresses hybrid migration. Avis de l’ANSSI sur la migration vers la cryptographie post-quantique (suivi 2023) — ANSSI — Dec 2023. | Historical expectations for security visas require product-specific issuance evidence. |
| Germany | [P] Government response records migration policy and national-roadmap development. Aktuelle und zukünftige Sicherheitsrisiken für Bestände an Kryptowährungen durch Quantencomputer und Hackergruppen — Bundestag, Drucksache 21/928 — Jul 2025. | The response does not establish later roadmap completion or estate-level migration. |
| United Kingdom | [P] Published staged migration targets. Timelines for migration to post-quantum cryptography — NCSC — Mar 2025. | Discovery, priority migration and completion describe separate tasks. |
The dossier’s three thematic pillars
The eleven requested sections remain within exactly three pillars; expand each pillar to inspect its chapter coverage.
Pillar I — Mechanisms, Hardware and Computational EvidenceChapters 1–4
- Chapter 1 — Executive Adjudication: five ministerial findings, supporting evidence and decision consequences.
- Chapter 2 — The Taxonomy: mechanisms, misleading phrases, three stacks and the two readiness axes.
- Chapter 3 — Quantum Computing: Hardware Truth: superconducting, trapped-ion, neutral-atom, photonic, silicon-spin and topological platforms; logical resources, fidelity, error correction and supply chains.
- Chapter 4 — What Quantum Computers Can and Cannot Do in 2026: chemistry, materials, optimisation, sampling, factoring and discrete logarithms against problem size and complete resources.
Pillar II — Security Migration and Operational ApplicationsChapters 5–7
- Chapter 5 — Cryptography: QKD, direct communication, networks, PQC, symmetric cryptography, retention exposure and migration requirements.
- Chapter 6 — Civilian Uses That Are Real: named deployments, pilots, standards and bounded experiments in finance, telecom, pharma, energy, metrology and civil PNT.
- Chapter 7 — Military and Intelligence Uses That Are Real: mission-specific sensing, timing, communications, migration and experimental networks, supported by trials, contracts or doctrine.
Pillar III — Industrial Power, Conditional Outlook and DecisionsChapters 8–11
- Chapter 8 — The Industrial and Geopolitical Layer: US, China, EU, UK, Japan, India, Israel, Australia and Canada, with Italian, French and German lenses.
- Chapter 9 — Five-Year Outlook Under AI Acceleration: constrained, base and accelerated scenarios for 2026–27, 2028–29 and 2030–31.
- Chapter 10 — Implications for Decision-Makers: application-level action matrix for government, defence, critical infrastructure and enterprise.
- Chapter 11 — Annexes: glossary, forbidden synonyms, source register, ten claim corrections and uncertainty register.
Evidence that would change the assessment
| Gap | Required observation | Decision threshold |
|---|---|---|
| Sustained logical computation | Reproducible workload results, error budgets, complete runtime and overheads. | Expand procurement when a predeclared workload requirement is met. |
| Cryptanalytic feasibility | Validation of code, timing, connectivity, logical operations and resource provision. | Reassess exposure when engineering evidence changes an end-to-end estimate. |
| Migration completion | Asset-level protocol, parameter, implementation and assurance evidence. | Measure protected functions rather than purchased products or written plans. |
| Navigation performance | Disclosed drift, duration, environment, updates, integration and maintenance. | Move toward acquisition against mission-specific acceptance criteria. |
| Roadmap delivery | Dated delivery and performance evidence corresponding to the milestone. | Release later funding against verified achievement. |
Pillar 0 — Quantum Technologies Explained for Political Leaders and Nontechnical Readers
What Works Today, What Still Prevents Wider Use, and What Governments Should Prepare for by 2031
Scope and Method
This opening pillar explains the findings of the report without requiring the reader to understand advanced physics, mathematics or computer engineering. Its purpose is to make the political choices understandable: what deserves immediate implementation, what deserves controlled experimentation, what requires patient research, and what should not be presented to the public as an existing capability.
It introduces the meaning of the technical chapters rather than reproducing their complete inventories of machines, national budgets or cryptographic resource estimates. Where a number is necessary to understand the situation, its source and limitations are stated.
The evidence labels used throughout the report retain their original meaning:
| Label | Meaning in plain English | How the reader should interpret it |
|---|---|---|
| [D] Demonstrated | A result supported by a scientific experiment or independently reproduced technical evidence | Something worked under the stated conditions; wider usefulness still needs to be assessed |
| [P] Programme | A standard, funded programme, contract or formal requirement exists | An institution has authorised or organised work; this does not establish a completed operational service |
| [R] Roadmap | A future target or conditional technical estimate | Something may become possible if the necessary milestones are achieved |
| [C] Claim | A company or public authority reports a result without sufficient independent technical evidence in the cited record | The statement has an identifiable source, but its claimed performance remains to be independently established |
| [H] Hype | A misleading label, unsupported generalisation or confusion between different technologies | The statement should not guide procurement or public policy in its present form |
Definitions, teaching examples and proposed policy controls are identified as explanation, illustration or analytical recommendation. They do not claim that a particular product has achieved a particular performance.
All sources linked in this pillar were retrieved on 4 October 2026. Publication dates and future target dates are distinguished throughout.
0.1 — The Situation in Plain English
The principal political difficulty is that the word “quantum” is used for several different technologies, each with a different state of development. An announcement about a computer, a communications link or a precision clock may sound like evidence of the same technological revolution, although it concerns a different practical problem and a different level of readiness.
The evidence reviewed in this report supports an uneven picture. [P] New standards for protecting information against future quantum attacks already exist. [D] Scientists have demonstrated important improvements in the reliability of quantum information stored in experimental processors. [D] Certain quantum measurement instruments have been tested outside the laboratory. [R] Large, dependable quantum computers capable of carrying out demanding applications remain the subject of future engineering targets. These findings come from different bodies of evidence and should lead to different public decisions. Sources: NIST standards announcement, quantum error-correction experiment, airborne gravity measurements and IBM hardware roadmap. NIST
For a political reader, the essential distinction is between an instrument that can perform a defined task, an experiment that establishes a scientific result, and a future system expected to transform an industry. Each may justify public attention, but each requires a different explanation of what the expenditure will buy.
The present situation at a glance
| Area | Evidence-based position | Practical interpretation for a political reader |
|---|---|---|
| Protection of digital information | [P] NIST finalised ML-KEM, ML-DSA and SLH-DSA standards on 13 August 2024 | Organisations can begin adopting new cryptographic methods without owning a quantum computer |
| Quantum computing reliability | [D] Published experiments show that carefully organised groups of physical qubits can preserve quantum information more reliably than individual components | A necessary engineering step has been demonstrated; a complete industrial service requires much more |
| Large quantum computing systems | [R] Public roadmaps specify future targets for reliable calculations | A target date should be treated as a milestone to verify, rather than as a guaranteed delivery date |
| Quantum communications | [P] Security authorities distinguish special quantum links from software-based protection and identify substantial deployment limitations | A secure communications proposal must explain its actual mechanism and the systems it leaves exposed |
| New quantum measurement instruments | [D] Some instruments have produced results in real surveys and field experiments | Suitability should be assessed application by application, including cost, maintenance and comparison with existing equipment |
| New defence timing applications | [C] Named military authorities report trials with specified equipment | A reported trial supports further evaluation; it does not establish fleet-wide deployment or complete mission independence |
Sources: NIST, Nature: error correction, IBM, NSA: quantum key distribution, Earth System Science Data: airborne gravimetry and Royal Navy: August 2026 clock trials. NIST
Analytical judgment. A government should therefore manage quantum technologies as several connected policy responsibilities, with separate delivery tests. A national strategy can bring these responsibilities together, but a single promotional label should never replace an assessment of whether a particular capability works.
Why Post-Quantum Cryptography Works on Ordinary Computers and Does Not Demonstrate the Maturity of Quantum Computing
| Section | Subject |
|---|---|
| The central distinction | What post-quantum cryptography actually is |
| How the name creates confusion | Why “post-quantum” describes a security objective |
| What happens inside the system | Ordinary computers performing different mathematics |
| What successful implementation proves | Security progress and its evidentiary limits |
| Why preparation precedes the threat | The separate timelines of protection and computing |
| Why quantum communications are different | Distinguishing mathematical protection from quantum equipment |
| The political consequences | Accurate procurement, budgets and public communication |
| Key judgments and open record | What should be verified before making a capability claim |
The Central Distinction
Post-quantum cryptography is cryptography that ordinary computers can perform, designed to resist attacks from both conventional computers and sufficiently powerful future quantum computers. Its successful implementation demonstrates that a particular security mechanism can operate; it does not demonstrate that a quantum computer performed that operation or that quantum computing has reached industrial maturity. [P] NIST’s National Cybersecurity Center of Excellence explicitly describes standards intended to work with current classical computers while resisting future quantum machines. Source: Migration to Post-Quantum Cryptography — NIST NCCoE — maintained programme resource. NCCoE
The misunderstanding arises when the name of the anticipated threat is mistaken for the operating mechanism of the protection. A reader hears that a bank, ministry or telecommunications provider has adopted “post-quantum security” and concludes that the institution is already using quantum computing to secure its information. That conclusion does not follow from the announcement, because a post-quantum implementation can carry out its cryptographic work entirely through conventional digital processing.
The distinction is particularly important when assessing claims that “quantum technology is already working”. That expression needs an identified subject: a computing experiment, a measurement instrument, a communications device or a cryptographic implementation. Evidence for one cannot automatically establish the performance of another, and the adoption of post-quantum cryptography cannot be counted as evidence that a quantum processor has completed a useful calculation.
Analytical judgment. The legitimate achievement is the development and implementation of protection against a class of anticipated attacks. Describing that achievement precisely preserves its value while preventing it from becoming evidence for an unrelated technological claim.
How the Name Creates Confusion
“Post-quantum” describes the intended resistance
[P] In NIST’s explanation, post-quantum cryptographic methods are selected around mathematical problems believed to remain difficult for conventional and quantum attackers. The term therefore concerns the protection sought against an attacker’s capabilities, rather than a requirement that the legitimate user operate a quantum computer. Source: What Is Post-Quantum Cryptography? — NIST — official explanatory resource. NIST
Explanation. A useful analogy is a fire-resistant door: the description identifies a hazard against which the door is designed to provide protection, rather than something the door uses to function. In the same way, the word “quantum” in “post-quantum cryptography” identifies an attacker considered in the security design; it does not identify the machinery required to perform the protective calculation.
The prefix “post” can create a second misunderstanding by suggesting that the technology belongs to a period after powerful quantum computers have already arrived. That interpretation is also unnecessary. A protective method can be developed, standardised and implemented before the threat against which it is designed becomes operational.
Analytical implication. A political briefing should therefore explain the term as “cryptography designed to resist future quantum attacks” before discussing implementation. This wording gives the reader the relevant security objective without implying that the organisation owns quantum hardware.
The adjective does not certify the complete system
A supplier’s description of a product as “post-quantum” also leaves a further question unanswered: which functions have actually been changed? The label alone cannot establish that every connection, identity mechanism, certificate, software update and supporting device has been assessed.
[P] The NCCoE’s migration documentation distinguishes cryptographic discovery from interoperability testing, reflecting the need to understand where protection is used and whether updated components work together. Source: Frequently Asked Questions about Post-Quantum Cryptography — NIST NCCoE — migration documentation. nccoe.nist.gov
Analytical recommendation. The institution should state the scope of its implementation in operational terms, identifying the services covered and the dependencies that remain. An accurate limited claim provides more useful assurance than an expansive label whose coverage cannot be verified.
What Happens Inside the System
Ordinary processing carries out the protective mathematics
Explanation. In a conventional implementation, the legitimate computers execute instructions that generate cryptographic material, establish keys or produce and verify signatures. The calculations use ordinary digital processing; the change concerns the mathematical construction and its implementation within the security system.
[P] NSA makes the mechanism explicit by distinguishing quantum-resistant algorithms implemented on existing platforms from QKD equipment that uses quantum physical signals. For the algorithmic approach, security rests on the difficulty of the relevant mathematical problems. Source: Quantum Key Distribution and Quantum Cryptography — NSA — official agency position. nsa.gov
Consequently, an organisation does not need a quantum processor merely to perform a post-quantum cryptographic operation. It may need updated software, compatible protocols, suitable conventional hardware or replacement products, but those implementation requirements should be identified separately from the engineering requirements of a quantum computer.
The importance of this distinction should not make migration sound effortless. Ordinary computing can still face difficult changes involving performance, compatibility, long-lived equipment and coordinated replacement. The fact that the mechanism is conventional tells the reader what kind of technology is involved; it does not guarantee that every existing product can support it without modification.
Different standards perform different security functions
[P] NIST finalised three initial post-quantum standards on 13 August 2024, providing concrete mechanisms for key establishment and digital signatures. Their publication establishes the standards, while the security and suitability of a particular implementation require their own assessment. Source: NIST Releases First 3 Finalized Post-Quantum Encryption Standards — NIST — Aug 2024. NIST
| Standardised mechanism | Plain-English function | What its use establishes | What it does not establish |
|---|---|---|---|
| [P] ML-KEM | Helps two systems establish shared secret key material | Implementation of a specified key-establishment method | That a quantum computer generated the key |
| [P] ML-DSA | Produces and verifies digital signatures | Implementation of a specified signature method | That quantum processing authenticated the document |
| [P] SLH-DSA | Provides a signature method based on hash constructions | Implementation of another specified signature approach | That the protected service operates through quantum hardware |
Sources: FIPS 203, Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST — Aug 2024, FIPS 204, Module-Lattice-Based Digital Signature Standard — NIST — Aug 2024 and FIPS 205, Stateless Hash-Based Digital Signature Standard — NIST — Aug 2024. CSRC
[P] FIPS 203 describes ML-KEM as a mechanism for establishing a shared secret over a public channel and characterises its security in terms of a mathematical problem believed to be difficult even for quantum computers. This is a security assumption supporting a defined construction, rather than a claim of absolute immunity from every conceivable attack. Source: FIPS 203 — NIST — Aug 2024. CSRC
Analytical implication. Political communication should preserve that qualification. “Designed to resist quantum attacks using a specified standard” identifies an assessable protection objective; “unbreakable quantum security” converts it into a much broader assertion.
What Successful Implementation Proves
A security result has its own evidentiary meaning
Illustration — hypothetical institution. Suppose a ministry updates a communications service and demonstrates that the new key-establishment method works between its approved systems. The test produces relevant evidence about that implementation: the systems can negotiate the specified method and carry out the tested operation.
The same test does not show that the ministry owns a quantum computer, that a quantum processor has overcome its physical error problems or that a future attacker can execute a cryptographic attack. Those propositions concern different equipment and different experiments.
This distinction is logical rather than rhetorical: evidence that a defence operates cannot, by itself, establish the operational maturity of the technology against which it was designed. The protective system and the potential attacking system have separate development requirements.
Quantum computing requires evidence from quantum computing
[D] A Willow experiment first published in December 2024 demonstrated protected quantum memory using a defined superconducting processor arrangement. That evidence concerns physical quantum information and error correction, giving it a different evidentiary meaning from the implementation of a cryptographic algorithm on conventional systems. Source: Quantum error correction below the surface code threshold — Nature — Dec 2024; corrected Apr 2026. Nature
Analytical judgment. A report assessing computing maturity must examine such hardware results against their actual function and limits. A report assessing security migration must examine coverage, interoperability and implementation assurance. Combining the two into a single count of “quantum deployments” would obscure what each result demonstrates.
This correction should also avoid the opposite overstatement. Establishing that post-quantum cryptography uses conventional processing does not show that every quantum technology is unusable or that quantum computing research has produced no results. It establishes a narrower and essential point: post-quantum cryptography is not the evidence needed to substantiate a quantum computing capability claim.
Why Preparation Precedes the Threat
Future resistance can have present value
[P] NIST identifies the possibility of an adversary retaining encrypted information for later exploitation, commonly called “harvest now, decrypt later”. This concern is relevant where information remains sensitive over a long period, even though collecting it does not establish the collector’s present ability to decrypt it through quantum computing. Source: What Is Post-Quantum Cryptography? — NIST — official explanatory resource. NIST
Explanation. An institution therefore has to consider the lifetime of its information alongside the time required to change its systems. The practical question is whether protection can be improved before valuable information is exposed to a future capability, rather than whether a precise arrival date can already be stated.
[P] NCSC treats migration as a substantial organisational change involving discovery, planning, prioritisation, suppliers and continuity. Its guidance reflects the burden of changing a large digital environment, rather than a requirement to acquire a quantum computer. Source: Timelines for migration to post-quantum cryptography — NCSC — Mar 2025. National Cyber Security Centre
Analytical judgment. Early preparation is consequently compatible with uncertainty about quantum computing. A government can justify a security transition because information is long-lived and replacement is slow, while continuing to describe future attacking capability as conditional.
Adoption cannot establish an arrival date
[H] Inferring that an encryption-threatening quantum computer already exists because institutions are adopting post-quantum cryptography reverses the logic of precautionary preparation. The adoption concerns a protection decision, while the existence and performance of an attacking machine require direct evidence.
The opposite inference is equally unsound: the ability to deploy post-quantum cryptography does not establish that all relevant systems have been protected or that every future security risk has been removed. The implementation’s scope remains a separate question, and a completed operation in one service cannot establish coverage across an entire ministry, bank or industrial network.
Why Quantum Communications Are Different
Mathematical resistance and quantum signals are separate mechanisms
[P] QKD uses special-purpose technology and quantum physical signals to generate and distribute key material. NSA’s published discussion separates this mechanism from quantum-resistant algorithms and identifies further requirements involving authentication, equipment, relay trust and implementation security. Source: Quantum Key Distribution and Quantum Cryptography — NSA — official agency position. nsa.gov
Explanation. The distinction can be expressed through the legitimate user’s activity. In post-quantum cryptography, conventional systems perform cryptographic calculations designed around resistance to quantum attacks. In QKD, specialised equipment uses quantum signals for a key-distribution function. Both belong in a discussion of future information protection, but their mechanisms and deployment requirements differ.
Analytical recommendation. When a supplier uses expressions such as “quantum protection” or “quantum-safe communications”, the authority should require it to identify whether the proposal uses post-quantum algorithms, QKD, both, or another specified mechanism. Without that answer, the institution cannot explain accurately what it is buying.
The Political Consequences
Classify the expenditure according to the capability purchased
Analytical recommendation. A programme implementing post-quantum cryptography should be evaluated as a security transition, with success measured through protected functions, verified coverage, compatibility and maintained service. Its association with a quantum-related threat does not justify reporting its expenditure as the acquisition of quantum computing capacity.
Conversely, a quantum computing programme should be evaluated through the performance of its quantum equipment, the calculations it can execute and the conditions under which it delivers useful results. A shared strategic umbrella can coordinate the programmes, but their acceptance criteria must remain distinct.
Failure to preserve this distinction would allow a government to report progress in a category that its expenditure did not actually deliver. It could also mislead legislators into believing that a successful security upgrade has resolved the separate engineering difficulties of quantum computing.
Report what the institution has actually accomplished
Analytical recommendation. A defensible announcement would state that an institution has implemented a specified post-quantum mechanism in identified services, explain the coverage of the change and describe the remaining work. If the deployment uses conventional processing, that fact should be made explicit when there is a risk of confusion.
The question “Which quantum computer performs this protection?” should therefore receive a mechanism-based answer: the post-quantum cryptographic operation does not require one. If the overall product includes some additional quantum component, that component must be identified and assessed independently; its presence cannot be inferred from the name of the algorithm.
For nontechnical audiences, the clearest replacement for the potentially ambiguous definition is:
Post-quantum cryptography: cryptographic methods performed by ordinary computers and designed to resist attacks from conventional computers and future quantum computers; implementing these methods does not demonstrate the maturity of quantum computing.
Key Judgments
Analytical judgments. The first judgment is that post-quantum cryptography should be understood through its operating mechanism: conventional digital processing performs the protective mathematics. The second is that its implementation provides evidence about a security deployment, whose scope and correctness still require verification. The third is that this evidence cannot establish the performance or arrival date of a powerful quantum computer.
These judgments support action rather than postponement. An institution can pursue a justified security transition while demanding separate evidence for quantum computing claims, preserving both the urgency of information protection and the integrity of its technology assessment.
What Would Change the Assessment?
Analytical review criterion. The classification of a particular product would change if its technical documentation established an additional quantum operating mechanism, but that would be a finding about the specified product or component. It would not change the meaning of post-quantum cryptography or make a quantum processor necessary for performing the standardised algorithms.
A broader computing judgment would require direct evidence about the relevant quantum system, while a stronger security judgment would require verified deployment coverage and implementation assurance.
Open Official Record
The record needed to substantiate an institutional claim includes the algorithm and protocol used, the services covered, the implementation tests, the acceptance authority and the unresolved dependencies. A product label, purchase announcement or national programme title cannot supply those details on its own.
Final analytical assessment. Post-quantum cryptography is a concrete means of preparing ordinary digital systems for a potential quantum threat; recognising its conventional operating mechanism allows political leaders to value the security achievement accurately, without presenting it as proof that the separate engineering challenge of powerful quantum computing has been completed.
0.2 — The Different Technologies Hidden Behind the Word “Quantum”
A simple map
| Technology | Plain-English explanation | The question it is intended to answer |
|---|---|---|
| Quantum computing | A different way of carrying out certain calculations using carefully controlled physical systems | Can a particular difficult calculation be performed better than with existing computers? |
| Post-quantum cryptography | New mathematical methods for protecting information, implemented on ordinary digital systems | Can information remain protected if a powerful quantum computer becomes available to an attacker? |
| Quantum key distribution, or QKD | Special equipment that uses quantum signals to help two parties establish secret key material | Can a particular communications link obtain keys under an explicitly defined security arrangement? |
| Quantum networking | Equipment designed to connect systems that store or process quantum information | Can quantum information or shared quantum states be distributed reliably between locations? |
| Quantum sensing | Instruments that use controlled physical effects to measure quantities such as gravity or magnetic fields | Can a measurement become more useful, accurate or dependable for a specific task? |
| Atomic timing | Clocks that use the stable behaviour of atoms as their reference | Can systems maintain the timing accuracy they need? |
Explanation. These definitions identify mechanisms, not product maturity. A clock, a computer and a communications link can all involve quantum physics while performing entirely different functions.
The distinction matters because policy language often moves too quickly from a scientific term to a promised public benefit. “Quantum-safe” may refer to software using post-quantum cryptography. “Quantum communication” may refer to special optical equipment. “Quantum navigation” may refer to a clock, a motion sensor or an experimental combination of several instruments. A proposal that does not identify the mechanism cannot be assessed properly.
How to translate a headline into a useful question
| Headline or phrase | The question a nontechnical decision-maker should ask |
|---|---|
| “The country has acquired a quantum computer” | What calculations can it complete, with what reliability, and who will use the results? |
| “The network is quantum-safe” | Which cryptographic methods protect its connections, identities and software updates? |
| “The link cannot be hacked” | What happens if an endpoint, administrator, relay or software component is compromised? |
| “The ship has quantum navigation” | Does the equipment provide time, position, motion measurements or a complete navigation solution? |
| “Quantum technology will accelerate drug discovery” | Which stage of discovery has been tested, at what scale, against which existing method? |
| “AI has solved the quantum problem” | Which measured engineering problem improved, and which physical obstacles remain? |
| “A national quantum programme is operational” | Is this a research programme, an installed prototype, an accepted service or a maintained deployment? |
Analytical recommendation. Public communications should name the function before using the label. “A clock tested for maintaining timing during a satellite-signal disruption” gives a minister substantially more information than “a breakthrough in quantum defence”.
0.3 — Quantum Computers: Why They Matter and Why They Remain Difficult to Use
What a quantum computer is expected to contribute
Explanation. A quantum computer uses physical behaviour that ordinary digital computers do not use in the same way. Its potential value depends on designing a suitable calculation around that behaviour.
[H] The description that a quantum computer simply tries every answer and then reads out the correct one is misleading. NIST explains that the information available from the final measurement is limited; useful algorithms must arrange the calculation so that the measurement reveals something valuable. Source: NIST, Quantum Computing Explained. NIST
For a political reader, the consequence is straightforward: a new type of computer does not automatically improve every public service. A ministry should ask whether its specific problem has an appropriate algorithm, whether the available machine can execute it reliably, and whether the result improves on the best existing approach.
Why the number of qubits can mislead
Explanation. A physical qubit is a physical component used to hold or process quantum information. A logical qubit is a protected unit of information constructed using an error-correction arrangement. Several physical components may be required to support one protected unit.
An analogy is a public record stored with checks and recovery procedures. Counting the individual storage elements tells us something about the equipment, but it does not tell us whether the record can survive errors or remain usable throughout a long task.
[D] A study first published on 9 December 2024 reported a protected quantum memory on Google’s Willow processors. One arrangement used 101 physical qubits and achieved an error rate of approximately 0.143% per error-correction cycle. Increasing the protection improved reliability under the tested conditions. The demonstrated function was protected memory, which should not be described as an entire industrial computer completing arbitrary long applications. Source: Nature, Quantum error correction below the surface code threshold. Nature
What must be solved before a demanding calculation becomes dependable
| Problem | Plain-English meaning | Why it matters to a user |
|---|---|---|
| Errors in the physical components | The equipment does not always perform exactly as intended | Incorrect operations can undermine the answer |
| Loss of stored quantum information | The useful state changes or becomes disturbed before the task finishes | A long calculation needs information to survive |
| Error correction | The system must repeatedly detect and manage faults | Protection has to work throughout the calculation |
| Protected operations | Reliable information must also be processed reliably | Preserving a record is different from carrying out a long sequence of correct changes |
| Control and feedback | Ordinary electronics and software must direct the quantum equipment | The supporting system must respond within the required time |
| Manufacturing consistency | Many components must meet demanding specifications | A good experimental device does not establish reliable production |
| Operational stability | Performance must remain acceptable over extended periods | Users need repeatable service, rather than an occasional successful run |
| Application performance | The complete workflow must produce a useful result | A scientific milestone may not yet improve a business or public task |
Explanation. This table describes the questions that must be answered. It does not assign the same obstacle or the same cost to every hardware design.
[D] Research published in November 2025 established limits on noisy quantum calculations under specified mathematical models of errors. Its conclusions reinforce the importance of reliability, while its assumptions prevent it from being treated as proof that every near-term quantum application is impossible. Source: npj Quantum Information, Limitations of noisy quantum devices in computing and entangling power. npj Quantum Information
What “usable now” should mean
Analytical recommendation. Ministers should require suppliers and research bodies to distinguish four statements:
| Statement | What it establishes | What remains to be demonstrated |
|---|---|---|
| “Researchers can access the machine” | Access to equipment exists | Whether it improves a particular task |
| “The machine completed an experiment” | A specified experiment ran | Whether the result is useful and repeatable |
| “The result exceeded a stated comparison” | An advantage was reported against that comparison | Whether the comparison remains competitive and the full cost is favourable |
| “The service improves our operation” | A user-facing benefit has been established | Whether it remains dependable as workload and deployment increase |
Analytical judgment. Quantum computing can be worth using for research and carefully designed trials before it becomes a dependable tool for a demanding production task. Public policy should recognise both possibilities and require an honest description of which one public money is purchasing.
0.4 — Protecting Information: Why Action Is Necessary Before the Future Computer Arrives
The two different security clocks
[P] NIST’s explanation of post-quantum cryptography identifies a present planning problem: an adversary can retain protected communications in the hope that future computing capabilities will make some of them readable. This is called “harvest now, decrypt later”. It does not establish that the adversary currently possesses a computer capable of performing the future attack. Source: NIST, What Is Post-Quantum Cryptography?. NIST
Explanation. There are two separate clocks:
| Clock | What it measures | Why a government should care |
|---|---|---|
| The secrecy clock | How long information must remain confidential | Some material could still cause damage many years after collection |
| The migration clock | How long an organisation needs to replace vulnerable protection | Discovery, procurement, testing and replacement may take several budget cycles |
Illustration — hypothetical dates, not a forecast. Suppose information created in 2026 must remain confidential for fifteen years. Its protection matters until 2041. If the institution needs several years to upgrade its systems, beginning only after an attack-capable computer is publicly demonstrated could leave a long period of avoidable exposure.
The political decision therefore concerns the lifetime of the information and the time needed to improve its protection. It cannot sensibly be reduced to a confident prediction of the year in which a future computer will arrive.
What can be implemented without a quantum computer
[P] Post-quantum cryptography consists of mathematical methods intended for ordinary computing platforms. NIST’s final standards include ML-KEM, which helps establish shared secret keys, and ML-DSA and SLH-DSA, which provide digital signatures. Their existence gives organisations a concrete basis for implementation work. Sources: FIPS 203, FIPS 204 and FIPS 205. CSRC
| Security function | Plain-English purpose | What the implementation programme should verify |
|---|---|---|
| Establishing secret keys | Allow legitimate systems to agree on secret material used to protect a connection | Compatible implementations, correct configuration and acceptable performance |
| Digital signatures | Allow a system to verify the origin and integrity of a message, document or software update | The complete chain of trust, including certificates, signing equipment and verification software |
| Replacing older methods | Remove vulnerable dependencies from the service | Whether every relevant connection and component has actually been addressed |
| Keeping future replacement possible | Avoid making the next change unnecessarily difficult | Whether contracts and system designs allow cryptographic methods to be updated |
Analytical recommendation. A standard should be treated as the beginning of an implementation programme. An organisation must still verify that its products, operating procedures and suppliers use the standard correctly.
Why migration is a public-management problem
[P] The UK National Cyber Security Centre’s guidance sets milestones for discovery and planning by 2028, highest-priority migration work by 2031, and completion by 2035. These are migration targets within the guidance, rather than predictions of when an attacker will obtain a powerful quantum computer. Source: NCSC, Timelines for migration to post-quantum cryptography. National Cyber Security Centre
Analytical recommendation. A political authority should require a programme that answers the following questions:
| Management question | Required answer |
|---|---|
| What information is most valuable over time? | A prioritised list with an identified owner |
| Which services depend on vulnerable cryptographic methods? | A documented assessment covering relevant systems and suppliers |
| Which equipment can be updated? | A tested upgrade path |
| Which equipment must be replaced? | A funded replacement plan |
| What happens during the transition? | A continuity plan and tested recovery arrangements |
| Who verifies completion? | A named authority responsible for acceptance |
| How are exceptions handled? | A recorded risk decision with a review date |
The threat should remain specific
[H] “A quantum computer will break all encryption” is an inaccurate generalisation. NIST distinguishes the implications for public-key systems from those for symmetric methods and notes the substantial practical complications in applying quantum search attacks. Source: NIST post-quantum cryptography FAQs. CSRC
Analytical judgment. The appropriate response is a targeted security transition. A dramatic claim about the collapse of every form of encryption can obscure the actual systems that require attention.
0.5 — Quantum Communications: What They Protect and What They Leave Exposed
Understanding quantum key distribution
Explanation. A QKD system uses special physical equipment to help establish secret key material between locations. The resulting keys can be used within a communications security system. This function should be described separately from the protection of computers, users, software and buildings.
[P] NSA’s published position identifies limitations involving authentication, dedicated equipment, trusted relays, implementation security and denial of service. It states: “NSA does not recommend the usage of quantum key distribution and quantum cryptography” for the national-security systems discussed unless the stated limitations are overcome. Source: NSA, Quantum Key Distribution and Quantum Cryptography. nsa.gov
Questions that remain after a quantum link is installed
| Question | Why it still matters |
|---|---|
| Are the communicating parties correctly identified? | A security system must establish who is entitled to participate |
| Are the endpoints protected? | Information can be exposed before protection is applied or after it is removed |
| Are intermediate locations trusted? | Some network designs place sensitive responsibilities in relay sites |
| Can the equipment be maintained and updated? | Security must survive faults, changes and newly discovered weaknesses |
| Can the link be interrupted? | Detecting interference does not guarantee that communication remains available |
| Does the whole system meet the required security standard? | A strong component cannot establish the security of every connected component |
Analytical recommendation. QKD procurement should be justified by a clearly defined need, an explicit trust arrangement and a comparison with alternatives. The decision-maker should receive an explanation of what additional protection is obtained and what operational burden is created.
A quantum network is a different proposition
[D] A paper published in May 2024 demonstrated shared quantum states between experimental memory systems using 35 kilometres of deployed telecommunications fibre. The fibre route was a metropolitan loop; its length should not be presented as the straight-line separation between distant operational users. The result established a networking experiment, rather than a general replacement for ordinary internet services. Source: Nature, Entanglement of nanophotonic quantum memory nodes in a telecom network. Nature
Analytical judgment. Such results can justify research into future networks. They do not, by themselves, justify promising a population that a nationwide “quantum internet” is available or necessary for every public service.
0.6 — Quantum Sensors and Clocks: Where Practical Use Is Further Advanced
Why measuring is a different challenge from computing
Explanation. A sensor measures a physical quantity. A clock provides a timing reference. Neither must necessarily perform the long, complex sequence of protected calculations required by a large quantum computing application.
This distinction explains why a useful measurement instrument can emerge while a much more demanding computing system remains under development. Nevertheless, each instrument still needs to demonstrate that it can perform its intended task under the conditions in which users will operate it.
Established atomic timing and newer instruments should be separated
[D] Germany’s national metrology institute, PTB, operates primary atomic clocks to realise the official unit of time. Its explanation describes the atomic basis of the second and the clocks used for this public measurement responsibility. This is an established metrology function, which should be assessed separately from the readiness of newer compact or mobile instruments. Source: PTB, Realisation of the SI second. PTB.de
What named experiments actually establish
| Application | Evidence | What a nontechnical reader should conclude |
|---|---|---|
| Airborne gravity measurement | [D] A paper published on 17 April 2025 reports flights conducted in Iceland and Greenland during June–July 2023, comparing the GIRAFE cold-atom instrument with a conventional gravimeter | A real airborne measurement campaign took place; the paper describes a technology still at the development stage |
| The same airborne comparison | [D] Both instruments achieved accuracy of approximately 1–2 milligals, a unit used for small gravity differences | The evidence does not support a blanket claim that the quantum instrument was superior in every respect |
| Underground structure measurement | [D] A 2022 study reported detection of a known two-metre tunnel through a defined gravity survey | A specific experiment worked; general discovery of arbitrary underground objects requires separate evidence |
| Defence timing | [C] The Royal Navy reported trials on 14 August 2026 involving two AQlock cold-atom clocks, Saab radar equipment and deliberately disrupted timing conditions | There is a named trial to examine; the announcement does not provide a complete independent account of operational performance |
Sources: Airborne gravimetry study, Nature, Quantum sensing for gravity cartography and Royal Navy clock trials. essd.copernicus.org
Why a better clock does not automatically mean complete navigation
Explanation. Time, position and movement are related but different pieces of information. A clock can support systems that depend on precise timing, but it does not by itself report a vehicle’s complete position and route.
[H] Presenting a clock trial as proof that a ship or aircraft can navigate indefinitely without satellite signals would extend the claim beyond the function tested.
Analytical recommendation. Any proposal for navigation resilience should specify:
| Required specification | Plain-English meaning |
|---|---|
| The service maintained | Timing, position, heading, velocity or a defined combination |
| The duration | How long the required performance can be sustained |
| The operating conditions | Motion, temperature, vibration and relevant interference |
| The supporting equipment | Maps, conventional sensors, communications and external references |
| The acceptable error | How much uncertainty the mission can tolerate |
| The fallback procedure | What the operator does when performance deteriorates |
Civilian and military usefulness must be evaluated separately
Analytical judgment. A civilian survey and a military mission can use related measurement principles while requiring different evidence. A geological survey may tolerate processing after the flight. A navigation task may need a dependable answer immediately. A laboratory sensitivity result does not settle either operational question.
For civilian procurement, the principal test should be whether the instrument improves an identified service at an acceptable cost. For defence procurement, the same test must also address the mission environment, hostile interference, deployment procedures, training and recovery after failure.
0.7 — From an Experiment to a Dependable Public Service
A major source of misunderstanding is the assumption that a successful demonstration is the final step before widespread adoption. Political readers need a more complete picture of delivery.
The delivery stages
Analytical framework.
| Stage | What has been achieved | What the public authority should require next |
|---|---|---|
| Scientific experiment | A result has been obtained under stated conditions | Independent examination and confirmation of the limits |
| Working component | One part of a system performs its intended function | Evidence that it can work with the other required components |
| Integrated prototype | Several parts work together | Testing against the intended user task |
| Limited field trial | Equipment has operated in a relevant setting | Repeatability, failure records and comparison with existing methods |
| Accepted deployment | A user has approved it for a defined responsibility | Maintenance, training, support and continued performance monitoring |
| Repeatable production | Multiple units can be delivered consistently | Quality control, supply continuity and manageable lifetime cost |
Two kinds of readiness
Analytical framework. Technical readiness asks whether the equipment works. Institutional readiness asks whether an organisation can use and sustain it.
| Technical situation | Institutional situation | Policy implication |
|---|---|---|
| Equipment works, but no organisation owns the task | No operator, budget or acceptance authority | Assign responsibility before describing a service as deliverable |
| A programme is authorised, but the equipment remains experimental | An institution has committed to development | Track technical milestones separately from spending |
| A trial succeeds, but maintenance is unresolved | The user cannot yet sustain deployment | Fund operational preparation before expanding installation |
| A service performs reliably and support is established | Operators, procedures and resources are in place | Consider broader adoption against evidence from actual use |
Why the existing alternative remains important
Analytical recommendation. Every proposed application should be compared with the best relevant existing method. The comparison should include:
| Comparison item | Why it matters |
|---|---|
| Accuracy or quality of the result | Establishes whether the new method performs the task better |
| Time to obtain a usable answer | Includes preparation and processing |
| Availability | Shows whether users can depend on access |
| Staffing | Captures training and specialist support |
| Maintenance | Identifies the effort needed to keep equipment working |
| Lifetime expenditure | Includes installation, operations and replacement |
| Failure consequences | Establishes the cost of an incorrect or unavailable result |
| Independent verification | Prevents the supplier’s preferred benchmark from becoming the only measure |
[P] DARPA’s Quantum Benchmarking Initiative explicitly investigates whether quantum computing can reach a scale at which its computational value exceeds its cost, with an assessment horizon of 2033. This is an evaluation objective, rather than a promise that a useful system will necessarily be delivered by that date. Source: DARPA, Quantum Benchmarking Initiative. DARPA
0.8 — What Artificial Intelligence Can Realistically Improve
The useful political question is whether AI improves a particular bottleneck, by a measured amount, under relevant conditions.
A demonstrated contribution
[D] Research published on 8 July 2026 used reinforcement learning to adjust the controls of Google’s Willow processor. For specified error-correction experiments, further tuning reduced logical error rates by approximately 20% beyond the existing calibration. The study also distinguished experiments conducted through repeated runs from simulations exploring uninterrupted operation. Source: Nature, Reinforcement learning control of quantum error correction. Nature
Explanation. This is a practical example of AI helping engineers operate equipment more effectively. It is not evidence that the physical equipment, error correction or manufacturing requirements have become unnecessary.
How to assess an AI contribution
| Proposed role for AI | Plain-English mechanism | Evidence a decision-maker should request |
|---|---|---|
| Adjusting equipment controls | Search for settings that improve measured performance | Improvement on actual hardware, stability and limits |
| Interpreting error signals | Identify likely faults from the information the machine produces | Accuracy and the time required to deliver the decision |
| Searching for materials or designs | Reduce the number of candidates engineers must examine | Physical validation of the suggested design |
| Testing security implementations | Find weaknesses in software or equipment | A reproducible weakness, its scope and a tested correction |
| Combining sensor information | Use several measurements to estimate a useful quantity | Comparison with existing methods in relevant field conditions |
[D] The AlphaQubit study published on 20 November 2024 reported machine-learning improvements in interpreting quantum error information. It included data from physical processors and results from simulations, which must remain separately identified. Source: Nature, Learning high-accuracy error decoding for quantum processors. Nature
Analytical judgment. AI can improve the speed and quality of engineering work. A political authority should still demand evidence that the improvement survives integration into the complete system.
0.9 — What May Change Between 2026 and 2031
Forecasts should be conditional
[R] IBM’s public roadmap targets a system called Starling for 2029, with 200 logical qubits and the ability to run 100 million quantum gates, meaning individual processing operations. These are vendor targets. Their significance depends on whether the complete specified performance is demonstrated and independently assessed. Source: IBM Quantum hardware and roadmap. Hardware and roadmap
Analytical recommendation. Governments should plan around several possible outcomes and identify the evidence that would move the assessment from one outcome to another.
Three possible development paths
[R] Conditional analytical scenarios — not assigned probabilities and not delivery promises.
| Scenario | What happens | What holds it back or enables it | Political response |
|---|---|---|---|
| Constrained development | Research advances, but dependable computing applications remain narrow; some specialised instruments progress | Reliability, manufacturing or integration improvements remain insufficient | Continue security migration, support rigorous research and expand only applications that pass their own acceptance tests |
| Steady development | More protected calculations become possible and selected applications begin to demonstrate useful results | Several engineering milestones are achieved together | Support independent benchmarking and controlled adoption by identified users |
| Accelerated development | Reliability and production improve faster, allowing broader and more demanding trials | Strong components, fast control, reliable operations and a credible application all succeed together | Prepare procurement and governance early while retaining full verification requirements |
The practical questions for each period
[R] Conditional outlook. These are proposed review questions, not claims that particular capabilities will exist in the stated years.
| Period | Quantum computing | Information protection | Sensors and timing | Required evidence |
|---|---|---|---|---|
| 2026–2027 | Can protected components support increasingly demanding integrated experiments? | Have organisations identified vulnerable dependencies and begun tested changes? | Can promising instruments repeat their results in relevant conditions? | Reproducible experiments, implementation tests and field records |
| 2028–2029 | Are roadmap targets achieved as complete systems? | Have priority services removed the relevant vulnerable dependencies? | Can multiple units be maintained by actual users? | Independent acceptance results, reliable operation and production records |
| 2030–2031 | Does a defined application deliver a dependable benefit over a competitive existing method? | Are transition results verified across the intended services? | Does deployment improve the mission throughout its operating conditions? | Measured outcomes, lifetime cost, support performance and accountable ownership |
When might encryption-threatening computing arrive?
[R] A resource estimate first submitted by Craig Gidney on 21 May 2025 models factoring an RSA-2048 number in less than a week using fewer than one million noisy physical qubits. Its logical-cost table gives 1,399 logical qubits and approximately 6.5 billion Toffoli operations, a particular kind of processing operation. The physical model uses surface-code protection, including distance-25 arrangements, with differentiated storage overhead. Assumptions include 0.1% physical gate errors, one-microsecond correction cycles, ten-microsecond control reactions and nearest-neighbour connectivity. This is a clearly identified preprint resource estimate, not an executed attack. Source: Gidney, resource estimate and full technical model. arxiv.org
Explanation. The number of components is only one requirement. The machine would also need to perform the required operations reliably, retain information throughout the task and sustain the assumed control performance.
Analytical judgment. The selected evidence reviewed here does not establish that such an attack will be operational by 2031. It also does not justify a guarantee that the risk lies safely beyond every system’s service life. Governments should manage the uncertainty through migration, monitoring and technical review.
Useful progress can occur without a dramatic headline
[R] Conditional analytical outlook. By 2031, meaningful progress could include better protected information, dependable specialised instruments, more reliable computing experiments, stronger supply chains and better evidence about useful applications. None requires a claim that quantum computers have replaced ordinary computing across the economy.
0.10 — The Political and Industrial Stakes
What a government is really trying to secure
Analytical judgment. The industrial question concerns the ability to obtain, operate, repair and improve technology over time. Ownership of a machine is one part of that ability.
| Form of capability | Plain-English meaning | Political relevance |
|---|---|---|
| Understanding | National institutions can assess performance and limitations | Reduces dependence on promotional claims |
| Design | Engineers can develop important parts of a system | Preserves the ability to adapt technology |
| Production | Suppliers can deliver components consistently | Supports continuity and industrial participation |
| Operation | Users can run equipment and interpret results | Turns an installation into a service |
| Maintenance | Faults can be diagnosed and repaired | Prevents dependence on a fragile support arrangement |
| Security assurance | Qualified bodies can examine protection and implementation | Supports trusted deployment |
| Standards participation | Institutions can contribute to common technical rules | Influences compatibility and future market access |
| Replacement options | Users can change suppliers or components | Reduces long-term dependence |
Why supply chains matter
[P] Japan’s quantum ecosystem policy dated 30 May 2025 addresses dependence on important components and materials, including specialist lasers, detectors, diamond materials and refrigeration-related equipment. The document provides evidence of an official industrial concern; it should not be treated as an independently audited inventory of every global dependency. Source: Japan Cabinet Office, quantum ecosystem measures. www8.cao.go.jp
Analytical recommendation. A public investment proposal should therefore identify the suppliers required to keep the system working and the alternatives available if access is interrupted.
Why scientific strength may not become industrial strength
[P] The European Commission’s Quantum Europe Strategy, adopted on 2 July 2025, identifies difficulty translating scientific strengths into market opportunities and fragmentation across national strategies. Its stated areas include research, infrastructure, industrial development, security and skills. Source: European Commission, Quantum Europe Strategy. Shaping Europe’s digital future
Analytical judgment. For political leaders, this creates a responsibility to connect research with users, production and support. Funding excellent science remains valuable, but the intended public benefit must be described accurately: scientific knowledge, industrial capacity and an operational service are different outputs.
How to understand a funding announcement
Analytical framework.
| Financial statement | What it means | What it does not establish |
|---|---|---|
| A budget is announced | An authority states an intended financial commitment | That all the money has been legally authorised or spent |
| Funding is authorised | Expenditure has an approved basis | That the project has received every payment |
| A contract is awarded | A supplier has an agreed responsibility | That the required performance has been delivered |
| Money is paid | Funds have been transferred | That the system has passed acceptance |
| Equipment is installed | Physical delivery has occurred | That users can depend on the intended service |
| Performance is accepted | The agreed test has been passed | That future maintenance and supply continuity are automatically secured |
Analytical recommendation. National comparisons should identify these categories before adding figures or ranking countries. A large announced envelope and a smaller completed deployment cannot be compared as if they measure the same achievement.
0.11 — Decisions, Public Expenditure and Questions for Suppliers
What deserves immediate action
Analytical recommendations.
| Decision area | Action now | Evidence required before expanding expenditure |
|---|---|---|
| Long-lived confidential information | Identify exposure and establish a cryptographic migration programme | Verified implementation and removal of relevant vulnerable dependencies |
| Public-service digital identities and software trust | Assess signatures, certificates and update mechanisms | End-to-end tests of the replacement trust arrangements |
| Timing resilience | Identify services affected by loss or manipulation of external timing | Performance over the required disruption period |
| New measurement instruments | Commission trials around a clearly stated task | Repeatability, comparison results and support requirements |
| Quantum computing applications | Fund bounded experiments with competitive existing methods as comparators | A useful result with documented reliability and full workflow cost |
| Special quantum communications links | Examine the actual mechanism and trust arrangement | A justified benefit for the specific application |
| Industrial capacity | Map critical dependencies and support justified bottlenecks | Deliverable production or support capability |
| Workforce | Train operators, engineers, security specialists and procurement staff | Evidence that skills can support the intended programme |
How to structure public support
Analytical recommendation. Separate funding into purposes that can be reviewed honestly.
| Purpose | What public money buys | Appropriate success measure |
|---|---|---|
| Research | Knowledge and reduction of scientific uncertainty | Reproducible results and clearly stated unresolved questions |
| Prototype development | Evidence that parts can work together | Integrated performance against a defined task |
| Field evaluation | Evidence under relevant operating conditions | Recorded performance, faults and comparison results |
| Deployment | A service accepted by an identified user | Availability, accuracy, support and lifetime expenditure |
| Security transition | Improved protection across relevant services | Verified coverage and controlled exceptions |
| Industrial development | Production, repair or supply capability | Consistency, lead times and continuity |
Questions a minister should ask before signing
| Question | Why it changes the decision |
|---|---|
| What exact public problem will this address? | Establishes whether there is an identified need |
| What has already been demonstrated? | Separates evidence from intention |
| Under which conditions did it work? | Reveals whether the evidence fits the proposed use |
| What is still missing? | Makes the remaining development responsibility visible |
| What is the best existing alternative? | Prevents comparison with a weak or outdated method |
| Who owns the result and accepts delivery? | Establishes accountability |
| What happens if the principal milestone is missed? | Defines the response to delay or failure |
| What will it cost throughout its service life? | Includes operations and support |
| Which suppliers are indispensable? | Reveals continuity risks |
| Can performance be independently examined? | Protects the authority’s ability to verify claims |
| How will users be trained and equipment repaired? | Tests whether deployment can be sustained |
| How will the public benefit be measured? | Connects technical expenditure with an accountable outcome |
How leaders should communicate the situation
Analytical recommendation. Public statements should describe the capability at its demonstrated level.
| Evidence available | Appropriate public wording |
|---|---|
| A scientific result | “Researchers demonstrated the specified effect under the reported conditions.” |
| An authorised programme | “The government has funded work to develop and evaluate the capability.” |
| A future target | “The programme aims to reach this milestone, subject to the stated technical requirements.” |
| A reported trial | “The authority reports a trial; operational performance remains under evaluation.” |
| An accepted service | “The system has met the specified acceptance requirements for this defined use.” |
A clear statement of limits protects the credibility of the programme. It also allows future progress to be recognised when the next milestone is actually achieved.
0.12 — Key Judgments, Evidence That Would Change Them and Source Register
Key judgments
1. Different quantum technologies require different political decisions.
Analytical judgment. A software security transition, a field instrument and a future computing architecture should have separate owners, budgets and acceptance criteria.
2. Security preparation has a practical basis today.
[P] Final post-quantum standards provide a basis for implementation, while official guidance treats migration as a substantial organisational task. The decision changed is whether to begin discovery, testing and replacement planning now. Sources: NIST standards and NCSC migration guidance. NIST
3. Demonstrated improvement in quantum computing reliability is significant, but it does not establish every promised application.
[D] Protected-memory experiments provide evidence of progress. Analytical judgment. The decision changed is how research milestones should be funded and verified before operational commitments increase. Source: Nature, error correction below threshold. Nature
4. Measurement and timing deserve application-specific assessment.
[D] Established atomic metrology and published field measurements demonstrate concrete functions. Analytical judgment. The decision changed is whether to commission a defined operational comparison rather than wait for quantum computing to mature. Sources: PTB atomic timing and airborne gravimetry. PTB.de
5. Future capability should be governed through evidence and alternative plans.
[R] Roadmaps specify goals rather than guaranteed outcomes. Analytical judgment. The decision changed is whether procurement and national strategies contain independent reviews, staged commitments and responses to missed milestones. Source: IBM roadmap. Hardware and roadmap
What would change this assessment?
Analytical review criteria.
| Area | Evidence that would justify a stronger assessment |
|---|---|
| Quantum computing | An independently assessed application delivering a dependable benefit against a competitive conventional method |
| Reliability | Protected operations sustained at the scale and duration required by the intended task |
| Manufacturing | Multiple systems delivered with consistent performance and manageable support requirements |
| Information protection | Verified migration across the intended services, including identity and software trust |
| Quantum communications | Evidence of a justified security benefit under a complete, tested trust arrangement |
| Sensors | Repeatable performance in the intended environment, with a credible cost and maintenance comparison |
| Defence use | Mission-relevant acceptance evidence, trained operators and established logistics |
| AI assistance | Measured improvements retained within the integrated physical system |
| Industrial capability | Demonstrated production, repair and supply continuity at the required scale |
Open official record
The assessment remains limited to the public evidence cited. A public roadmap cannot establish undisclosed capability, and the absence of an open demonstration cannot prove that no classified activity exists. Equally, speculation about classified activity cannot be used to justify a procurement claim.
A political authority should therefore require the strongest evidence available within the relevant security setting, while ensuring that public statements remain consistent with what can actually be supported.
Source register
Retrieval date for every entry: 4 October 2026.
| Source | Publication or document status | Why it matters in Pillar 0 |
|---|---|---|
| NIST — First three finalised post-quantum standards | Announcement dated 13 August 2024 | Establishes that concrete standards exist |
| NIST — FIPS 203: ML-KEM | Final standard, 13 August 2024 | Defines the key-establishment method |
| NIST — FIPS 204: ML-DSA | Final standard, 13 August 2024 | Defines a digital-signature method |
| NIST — FIPS 205: SLH-DSA | Final standard, 13 August 2024 | Defines a second digital-signature approach |
| NIST — What Is Post-Quantum Cryptography? | Official explanatory resource | Explains early preparation and retained-data exposure |
| NIST — Post-quantum cryptography FAQs | Official technical guidance | Distinguishes different cryptographic risks |
| NIST — Quantum Computing Explained | Official explanatory resource | Corrects the “all answers at once” description |
| NCSC — PQC migration timelines | Guidance published in March 2025 | Establishes planning and migration milestones |
| NSA — QKD and quantum cryptography | Official agency position; some explanatory passages retain older standardisation context | Identifies limitations relevant to national-security procurement |
| Nature — Quantum error correction below the surface code threshold | First published 9 December 2024; corrected in April 2026 | Demonstrates progress in protected quantum memory |
| npj Quantum Information — Limitations of noisy quantum devices | Published 28 November 2025 | Explains limits under specified noise assumptions |
| Nature — Reinforcement learning control of quantum error correction | Published 8 July 2026 | Provides a measured example of AI-assisted control |
| Nature — Learning high-accuracy error decoding | Published 20 November 2024 | Provides evidence on machine-learning interpretation of errors |
| IBM — Quantum hardware and roadmap | Current vendor roadmap, including a 2029 target | Provides a future milestone requiring verification |
| DARPA — Quantum Benchmarking Initiative | Current programme record | Defines evaluation of computational value against cost |
| Gidney — RSA-2048 factoring resource estimate | Preprint first submitted 21 May 2025 | Shows why cryptographic relevance requires a complete resource model |
| Gidney — Full resource model | Technical text retrieved for assumptions and tables | Details logical operations, protection and physical costs |
| PTB — Realisation of the SI second | Official metrology resource | Establishes the existing public role of atomic timing |
| Earth System Science Data — Airborne gravimetry | Published 17 April 2025; measurements from 2023 | Provides field evidence and a conventional comparison |
| Nature — Quantum sensing for gravity cartography | Published February 2022 | Establishes a specific underground-structure experiment |
| Royal Navy — Quantum clock trials | Official announcement, 14 August 2026 | Identifies a reported defence timing trial |
| Nature — Quantum memory nodes in a telecom network | Published May 2024 | Establishes a defined quantum networking experiment |
| European Commission — Quantum Europe Strategy | Adopted 2 July 2025 | Identifies industrial translation and coordination concerns |
| Japan Cabinet Office — Quantum ecosystem measures | Policy document dated 30 May 2025 | Identifies component, supply-chain and industrial-development priorities |
Final political assessment — analytical judgment. Governments can make useful decisions now by improving information protection, testing instruments against real public needs, supporting verifiable computing milestones and strengthening the capacity to operate and maintain technology. The central responsibility through 2031 is to connect each commitment with a measurable result, while preserving the ability to change course as the evidence develops.
Pillar I — Mechanisms, Hardware and Computational Evidence
Evidence cut-off and retrieval date: 4 October 2026. This instalment completes Chapters 1–4 together, following the structure in your supplied prompt and scheme. It develops the technical and computational evidence without reproducing the opening assessment’s migration timetable, national summaries or cryptanalytic resource table.
Classification: [D] demonstrated result, bounded by the experiment; [P] funded, contracted, mandated or standardised programme; [R] roadmap, prospective application or conditional projection; [C] attributed assertion lacking the primary technical evidence required for demonstration status; [H] misleading equivalence, unsupported generalisation or category error. Analytical recommendations below are identified as recommendations rather than presented as demonstrated capabilities.
Chapter 1 — Executive Adjudication
Principal judgment
The appropriate unit of assessment is a verified workload executed under a complete resource and error budget. Qubit numbers, isolated gate fidelities and encoded-state demonstrations each describe part of that capability, but they cannot individually establish useful, sustained computation. The reviewed record contains significant advances in physical processors, logical subroutines and hybrid scientific workflows; the decision problem is determining which missing elements separate each result from its proposed application. This judgment follows from the different experimental scopes of A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Quantinuum and collaborators, Nature, Jun 2026, Experimental Demonstration of Logical Magic State Distillation — author manuscript of the Nature paper, published Jul 2025, and Chemistry Beyond the Scale of Exact Diagonalization on a Quantum-Centric Supercomputer — IBM, RIKEN and collaborators, Science Advances, Jun 2025. Nature
Five actionable findings
| Finding | Evidence and bounded interpretation | Decision consequence |
|---|---|---|
| 1. Buy verified computation rather than a qubit inventory. | [D] The 2026 Helios paper reports an integrated trapped-ion processor with measured component errors and circuit benchmarks. Those measurements support the processor’s documented performance; they do not convert its physical register into an equal-sized fault-tolerant logical register. A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Nature, Jun 2026. | Require the proposed workload, compiled circuit, accepted-result rate, elapsed time, verification method and comparator before approving application procurement. |
| 2. Treat universal fault tolerance as an integration problem. | [D] Neutral-atom logical magic-state distillation demonstrates a necessary resource-generation operation. Its importance lies in improving encoded resource states, rather than establishing an unrestricted production computer. Experimental Demonstration of Logical Magic State Distillation — Nature, Jul 2025; linked author manuscript. | Fund milestones that connect memory, gates, resource-state production, measurement and classical control within one sustained computation. |
| 3. Require classical competition to remain open throughout a pilot. | [D] Subsequent classical work produced fast, converged simulations of the experiment originally presented as evidence of pre-fault-tolerant utility. A benchmark conclusion can change while the quantum hardware remains the same. Fast and converged classical simulations of evidence for the utility of quantum computing before fault tolerance — Caltech author repository, Science Advances, Jan 2024. | Establish an independent classical team and permit updated algorithms; a vendor-selected baseline should not determine the investment case. |
| 4. Assess manufacturing through reproducibility and yield. | [D] Foundry-compatible silicon spin-qubit work reports high-fidelity operations across four characterised devices. This is evidence of repeatable unit-cell performance, not evidence of a large operational processor or production yield at that scale. Industry-compatible silicon spin-qubit unit cells exceeding 99% fidelity — Nature, Sep 2025. | Request distributions across devices, wafers and operating conditions, together with calibration effort, packaging losses and repair procedures. |
| 5. Evaluate AI against a named engineering bottleneck. | [D] Reinforcement learning has been experimentally used to adjust control parameters during error correction. [R] Its extension to larger systems remains a separate scaling proposition. Reinforcement learning control of quantum error correction — Google Quantum AI, Google DeepMind and collaborators, Nature, Jul 2026. | Measure logical performance, drift tolerance, training cost and control latency with and without the intervention; an AI label should not substitute for these results. |
The investment distinction
The recommended investment structure separates research option value, engineering capability and application value. A device may justify research funding because it tests a difficult physical mechanism. A control system may justify engineering funding because it improves reliable operation. An application contract requires additional evidence that the complete workflow produces a useful result under the buyer’s constraints. Moving between these categories should require a new acceptance test.
This distinction is particularly important for hybrid chemistry. [D] Quantum samples can contribute to a workflow whose other stages run on a classical supercomputer. The value question then concerns the incremental contribution of those samples, including the classical processing they require. Independent analysis of quantum-selected configuration interaction identifies sampling and compactness limitations that bear directly on this question. Critical Limitations in Quantum-Selected Configuration Interaction Methods — Reinholdt and collaborators, Journal of Chemical Theory and Computation, Jun 2025; linked author version. arxiv.org
Key judgments
The evidence supports differentiated research and engineering commitments. It supports application procurement only within the demonstrated workload boundary and an independently evaluated comparison. A single score combining physical qubits, fidelity, funding and commercial announcements would conceal the distinctions that matter to the decision.
What would change the assessment
A stronger application assessment would require reproducible, sustained execution of a named useful workload, with disclosed logical resources where applicable, complete elapsed time, output accuracy, unsuccessful attempts and contemporary classical competition. A stronger industrial assessment would require repeatable manufacturing and service performance beyond selected laboratory devices.
Open official record
The principal unresolved records are application-level execution logs, accepted-run statistics, calibration interruptions, manufacturing distributions and independently reproduced comparisons. The linked Helios paper, silicon unit-cell paper and chemistry methods critique provide evidence relevant to these questions without supplying every record required for operational acceptance.
Chapter 2 — The Taxonomy
Principal judgment
Quantum terminology becomes decision-useful only when it identifies a physical mechanism, a delivered function and a bounded assurance claim. The same word can otherwise refer to incompatible systems: classical cryptography designed to resist quantum attacks, optical key distribution, entanglement-assisted processing or a sensor exploiting quantum properties. NIST’s key-encapsulation standard and the experimental optical-network computing paper illustrate this difference directly. Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST, FIPS 203, Aug 2024; Distributed quantum computing across an optical network link — Nature, Feb 2025. CSRC
2.1 Mechanism dictionary and misleading expressions
| Expression | Mechanism that must be identified | Defensible classification | Misleading interpretation to reject | Evidence required |
|---|---|---|---|---|
| “Quantum internet” | Entanglement distribution, quantum memories, interfaces, routing and the accompanying classical control. | [D] for a documented experiment; [R] for a proposed broader network. | [H] A quantum link automatically provides an operational internet, unrestricted quantum computing or instantaneous communication. | Entanglement rate and fidelity, memory lifetime, losses, failure handling and delivered protocol. Distributed quantum computing across an optical network link — Nature, Feb 2025. |
| “Quantum-safe VPN” | Named key establishment, authentication, signatures and symmetric protection within the actual protocol. | [P] for an applicable standard; deployment status needs separate evidence. | [H] Use of one quantum-resistant primitive proves the entire VPN implementation secure. | Complete cryptographic inventory, protocol composition and implementation assurance. Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST, Aug 2024. |
| “Unhackable quantum link” | Usually QKD equipment and key-management infrastructure. | [H] when asserted without qualification. | [H] Protection of key distribution removes endpoint, authentication, equipment or availability vulnerabilities. | Authentication design, implementation testing, relay trust and service continuity. Cryptograph Solutions are Limited Compared to Quantum-Resistant Algorithms — NSA, Oct 2026. |
| “Quantum encryption” | Specify whether the system distributes keys, encapsulates keys, signs messages or protects payloads. | Unresolved until decomposed. | [H] QKD, post-quantum cryptography and payload encryption are interchangeable. | Name the primitive and its exact role. Module-Lattice-Based Key-Encapsulation Mechanism Standard — NIST, Aug 2024. |
| “Quantum radar” | Quantum illumination or another explicitly specified sensing protocol. | [D] for the bounded laboratory result. | [H] Laboratory detection advantage establishes deployable long-range detection of operational targets. | Target model, losses, noise, receiver, temperature, range and equal-resource classical comparison. Demonstration of Quantum Advantage in Microwave Quantum Radar — Nature Physics, 2023; linked author version revised Mar 2023. |
| “AI-powered quantum computer” | Calibration, decoding, control, compilation or another named intervention. | [D] for a measured intervention; [R] for extrapolation. | [H] AI removes the need for physically reliable operations or error correction. | Ablation study, logical outcome, latency and behaviour under drift. Reinforcement learning control of quantum error correction — Nature, Jul 2026. |
| “Logical qubit” | An encoded information unit under a specified code and protocol. | [D] only within the demonstrated operations and correction conditions. | [H] Every encoded register supports the same gates, protection and computation duration. | Code parameters, syndrome procedure, correction, accepted fraction and logical errors. Logical quantum processor based on reconfigurable atom arrays — Nature, Dec 2023. |
| “Fault-tolerant” | A circuit or architecture designed to constrain error propagation under stated assumptions. | [D] for tested operations; [R] for an unbuilt complete architecture. | [H] One fault-tolerant subroutine establishes universal sustained computation. | Tested fault model, logical operations, repeated correction and integration. Fault-tolerant control of an error-corrected qubit — Nature, Oct 2021. |
| “Quantum advantage” | A specified quantum-versus-classical comparison. | [D] for experimental performance, with the comparison’s scope disclosed. | [H] A benchmark separation proves general commercial advantage. | Problem family, accuracy, resources, classical methods and comparison date. Observation of constructive interference at the edge of quantum ergodicity — Nature, Oct 2025. |
| “Topological qubit” | A specified physical encoding, readout and proposed protection mechanism. | [D] for demonstrated device behaviour; [C] for broader unsupported vendor assertions. | [H] Parity readout alone establishes protected universal computation. | Protection tests, coherent operations, error mechanisms and reproducibility. Interferometric single-shot parity measurement in InAs–Al hybrid devices — Nature, Feb 2025. |
2.2 Three stacks with separate acceptance boundaries
The proposed classification below prevents evidence from one stack from being used to certify another.
| Stack | Delivered function | Recommended acceptance boundary | Evidence that cannot substitute for acceptance |
|---|---|---|---|
| A — Computing | A sampled output, observable, energy estimate, optimisation result or other defined computation. | Output accuracy, accepted-result rate, complete runtime, resource accounting and classical comparison. | Security standards, a sensor trial or an announced processor capacity. |
| B — Communications and cryptography | Key establishment, authentication, protected traffic or a specified quantum-network protocol. | Threat model, primitive composition, endpoint assurance, relay assumptions and availability. | A difficult sampling experiment or an encoded logical state. |
| C — Sensing, timing and metrology | A measured physical quantity or mission-relevant estimate. | Sensitivity, bandwidth, bias, drift, environmental tolerance, duration and system integration. | A computing roadmap or an optical key-distribution demonstration. |
[D] The radar experiment is especially instructive: its author record describes a microwave quantum-illumination demonstration performed inside a dilution refrigerator and identifies restricted operating parameters and low-temperature requirements. Its evidentiary value concerns the mechanism and the experimental detection task. [R] Operational radar capability would require additional evidence about propagation, target conditions, receiver integration and environmental operation. Demonstration of Quantum Advantage in Microwave Quantum Radar — Nature Physics, 2023; author version, Mar 2023. arxiv.org
2.3 Two readiness axes
The following is an analytical assessment framework, not an official universal quantum-readiness scale.
| Technical state | What it establishes | Institutional state | What it establishes |
|---|---|---|---|
| Laboratory mechanism | The effect exists under documented experimental conditions. | Research activity | An institution is investigating it. |
| Characterised component | A device has measured interfaces and performance. | Funded programme | Resources have been committed to a specified programme. |
| Integrated prototype | Several components execute the intended function together. | Validated requirement | A user has defined the need and acceptance criteria. |
| Field trial | The system has been tested in a relevant operating environment. | Procurement | A buyer has contracted for specified equipment or services. |
| Repeatable production | Manufacturing and service performance are reproducible. | Accreditation or acceptance | The system has passed the relevant institutional assessment. |
| Operational qualification | The complete system meets its defined mission envelope. | Doctrine or routine use | It has an established role in operational practice. |
A procurement announcement should therefore be recorded on the institutional axis at the level its documents justify. It should not advance the technical axis by implication. Conversely, a technically persuasive experiment can remain a research result without an operational customer or qualification record.
2.4 Metrics that should remain distinct
| Metric | Correct interpretation | Additional information needed |
|---|---|---|
| Gate fidelity | Closeness of an implemented operation to its target under a specified characterisation method. | Method, uncertainty, parallel operation, drift and leakage. |
| SPAM performance | State-preparation-and-measurement performance. | Whether preparation and measurement errors are separated. |
| Logical error per cycle | Encoded performance during the stated correction cycle. | Cycle duration, code, decoder and error correlations. |
| Postselected fidelity | Quality of the accepted subset. | Acceptance probability and cost of rejected attempts. |
| Memory lifetime | Preservation of information under the tested memory protocol. | Logical gates and computation duration are separate questions. |
| Circuit throughput | Completed circuits or outputs over time. | Circuit size, accuracy, calibration and rejected runs. |
| Advantage ratio | Relative performance for the specified comparison. | Classical methods, hardware, precision and resource equality. |
These distinctions have direct experimental consequences. [D] The superconducting magic-state study reports different infidelities for feedforward and postselected procedures, while also measuring their yields; collapsing those results into one fidelity would discard information about usable output production. Encoding a magic state with beyond break-even fidelity — IBM and collaborators, Nature, Jan 2024. Nature
Key judgments
Terminology should identify the mechanism before describing benefit. Readiness should be recorded separately for technical performance and institutional adoption. Metrics should retain their experimental conditions, particularly where postselection, error mitigation or model-based comparison affects interpretation.
What would change the assessment
A term becomes suitable for procurement when its supplier supplies a mechanism-specific specification, a relevant test protocol and an assurance boundary. Greater readiness requires evidence at the next level on the appropriate axis.
Open official record
For security products, request the protocol and assurance documents supporting the advertised property, using NIST FIPS 203 and the NSA assessment of specialised cryptographic solutions as mechanism-specific references. For computing and sensing, request experimental conditions and complete accepted-output records.
Chapter 3 — Quantum Computing: Hardware Truth
Principal judgment
The six hardware families have demonstrated different capabilities and face different integration burdens; the reviewed evidence does not justify a single ranking based on qubit count. A useful comparison must retain the device’s physical register, demonstrated encoding, operation quality, accepted-run conditions and scaling assumptions. The examples below are selected evidence points, not an exhaustive inventory or a claim that these are each platform’s global maximum.
3.1 Comparative hardware evidence
| Platform | Demonstrated evidence | Quantitative detail | Logical or correction boundary | Source |
|---|---|---|---|---|
| Superconducting | [D] Error-suppressed preparation of an encoded magic resource on IBM hardware. | Four data qubits encode two logical qubits; reported logical infidelity 1.87 ± 0.16% with feedforward and 1.23 ± 0.11% with postselection. | Resource-state preparation; an accepted state’s quality and production yield must remain separate. | Encoding a magic state with beyond break-even fidelity — Nature, Jan 2024. |
| Trapped ion | [D] Integrated Helios processor with transport-based connectivity. | 98 physical qubits; mean infidelities: 2.5(1) × 10⁻⁵ for one-qubit gates, 7.9(2) × 10⁻⁴ for two-qubit gates and 3.3(5) × 10⁻⁴ for SPAM. | Physical processor and circuit benchmarks; these counts do not describe 98 error-corrected logical qubits. | A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Nature, Jun 2026. |
| Neutral atom | [D] Reconfigurable encoded processor executing logical circuits. | Up to 280 physical atoms and 48 logical qubits; circuits include 228 logical two-qubit gates and 48 logical CCZ gates. | The highlighted large logical register uses an [[8,3,2]] encoding; error detection and postselection must be distinguished from unrestricted repeated correction. | Logical quantum processor based on reconfigurable atom arrays — Nature, Dec 2023. |
| Photonic | [D] Aurora modular photonic architecture and real-time decoding demonstration. | 35 chips, 84 squeezers, 36 photon-number-resolving detectors, furnishing 12 physical qubit modes per clock cycle. | A distance-2 repetition code; temporal cluster-state size is not a simultaneous logical register. | Scaling and networking a modular photonic quantum computer — Xanadu, Nature, Jan 2025; PMC full text. |
| Silicon spin | [D] Foundry-compatible two-qubit unit cells characterised across four devices. | Controlled-Z fidelities range from 99.04(16)% to 99.56(6)%; paper reports 95% confidence for the characterisation error bars. | Physical operations and manufacturing compatibility; no corresponding large logical register is established by these devices. | Industry-compatible silicon spin-qubit unit cells exceeding 99% fidelity — Nature, Sep 2025. |
| Topological approaches | [D] Single-shot parity measurement in hybrid devices; separate minimal-chain readout experiments. | In the InAs–Al work, optimal readout gives an assignment-error probability of approximately 1%. | The authors explicitly retain ambiguity between the targeted topological interpretation and certain trivial low-energy states. | Interferometric single-shot parity measurement in InAs–Al hybrid devices — Nature, Feb 2025. |
Comparison rule: the entries use different operations, characterisation protocols and correction conditions. Their percentages should not be treated as measurements of the same system-level quantity. Nature
3.2 Superconducting hardware: resource-state production and control
[D] The encoded magic-state experiment illustrates a practical trade-off. Feedforward changes later operations according to intermediate measurements, increasing useful-state production relative to a more restrictive postselection procedure. It also introduces additional control-related waiting during which errors can accumulate. The reported advantage therefore involves both output quality and output yield. Encoding a magic state with beyond break-even fidelity — Nature, Jan 2024.
The recommended procurement quantity is consequently accepted resource states per unit time at the required infidelity, including control delays and rejected attempts. A supplier reporting only the best accepted-state fidelity leaves the buyer unable to determine whether an algorithm’s resource demand can be met.
[D] The July 2026 reinforcement-learning experiment addresses another operational issue: maintaining calibration during error correction. It uses error-detection events as a learning signal for continuous control adjustment. The experiment reports 3.5-fold greater logical stability against injected drift. The larger-code scaling evidence described in the paper is numerical rather than a hardware demonstration at those larger sizes. Reinforcement learning control of quantum error correction — Nature, Jul 2026. Nature
| Control question | Recommended evidence | Decision relevance |
|---|---|---|
| Does calibration interrupt execution? | Time-stamped interruption and recovery logs. | Long computations require continuity. |
| Does performance persist during drift? | Defined drift tests and naturally occurring drift records. | A short stable interval may not represent sustained operation. |
| Does learning improve logical outcomes? | Comparison with the same hardware and fixed control. | Physical calibration scores may conceal logical consequences. |
| What is the learning overhead? | Training samples, compute resources and elapsed time. | Improvement must be assessed with its operating cost. |
| What happens when adaptation fails? | Detection, rollback and run-rejection procedures. | Failed adaptation must not silently invalidate results. |
3.3 Trapped ions: connectivity has a schedule
[D] Helios implements connectivity through physical transport between memory and operating regions. Its paper describes parallel operations, shared optical resources and real-time compilation of dynamic programmes. The entangling-gate operation itself takes approximately 70 microseconds, but a complete programme also involves transport, cooling and other operations. Gate duration alone therefore cannot establish application runtime. A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Nature, Jun 2026.
The architectural question is how effectively movement, cooling and gates overlap under an actual compiled workload. Connectivity may reduce the number of routing gates required by an algorithm, while transport introduces its own scheduling demands. The relevant comparison should measure both effects within the same programme.
[D] Earlier trapped-ion work demonstrated fault-tolerant control of one Bacon–Shor encoded qubit using 13 physical ions. It reported average logical preparation-and-measurement error of 0.6% and Clifford-gate error of 0.3% after offline correction. Those results establish bounded logical operations; the offline qualifier matters when assessing real-time integration. Fault-tolerant control of an error-corrected qubit — Egan and collaborators, Nature, Oct 2021. Nature
| Architecture issue | Recommended test |
|---|---|
| Transport-related performance | Error and duration distributions for the programme’s actual movement operations. |
| Parallel optical control | Gate characterisation under simultaneous execution. |
| Cooling overhead | Full compiled schedule including cooling and waiting. |
| Measurement and feedforward | Latency distribution and its effect on encoded performance. |
| Modular expansion | Measured interface performance and complete distributed operations. |
3.4 Neutral atoms: logical registers and non-Clifford resources
[D] The reconfigurable-array experiment establishes that many encoded qubits can participate in structured logical circuits. Its large-register demonstration combines encoding, logical operations and error-detection-based selection. The retained runs should therefore be evaluated with their acceptance fraction rather than interpreted as an unconditional corrected computation. Logical quantum processor based on reconfigurable atom arrays — Nature, Dec 2023.
[D] Subsequent logical magic-state distillation demonstrated improved output-state fidelity relative to input logical states using distance-3 and distance-5 colour codes. This is a distinct capability: producing resources needed for universal encoded operations. It strengthens the technical pathway without establishing the throughput, integration and sustained runtime required by an arbitrary large algorithm. Experimental Demonstration of Logical Magic State Distillation — Nature, Jul 2025; author manuscript. arxiv.org
| Stage | Function | Evidence required before advancing |
|---|---|---|
| Encoded-state preparation | Creates the logical input. | Preparation error and acceptance statistics. |
| Repeated syndrome extraction | Supplies information about accumulating errors. | Performance over the required number of cycles. |
| Logical entangling operations | Connects encoded registers. | Errors during gates, movement and measurement. |
| Resource-state preparation | Supplies non-Clifford resources. | Input quality and production rate. |
| Distillation | Improves resource-state quality. | Output error, accepted yield and consumed resources. |
| Integrated computation | Uses these elements together. | Complete workload execution with a total error budget. |
This proposed stage structure prevents the presence of one component from being used to certify the others. The next decisive experiment would connect the components under the same control and operating conditions while retaining the complete accepted-run record.
3.5 Photonics: temporal scale, losses and useful outcomes
[D] Aurora generated a cluster state described as containing 86.4 billion modes through temporal operation. The paper simultaneously identifies 12 physical qubit modes per clock cycle and calls the machine a scale model with insufficient component performance for the intended full architecture. The cumulative mode count therefore describes the generated stream, rather than billions of simultaneously available, protected logical qubits. Scaling and networking a modular photonic quantum computer — Nature, Jan 2025. PMC
A useful photonic comparison must report losses alongside fidelity. [C — author preprint] The April 2024 manufacturable-platform manuscript reports high-fidelity component operations, including two-qubit fusion and chip-to-chip transfer, while explicitly excluding loss from the quoted interconnect fidelity. Those numbers support the attributed component claim, not an independently certified operational computer. A manufacturable platform for photonic quantum computing — Alexander and collaborators, author preprint, Apr 2024. arxiv.org
| Quantity | Recommended reporting condition |
|---|---|
| Source quality | State quality and useful-event probability. |
| Transmission | Loss through the complete path, including interfaces. |
| Fusion or entangling operation | Conditional fidelity and success probability. |
| Detector performance | Efficiency, errors, timing and recovery characteristics. |
| Switching and delay | Loss, latency and reliability during the actual schedule. |
| Logical processing | Accepted encoded outputs per unit time at the required error. |
For procurement, a conditional fidelity should always be accompanied by the probability and cost of obtaining the condition. Otherwise a component can appear excellent while delivering too few useful events for the proposed architecture.
3.6 Silicon: three different scaling questions
Silicon evidence should distinguish foundry-compatible electrostatic devices, precision donor processors and mobile-spin interconnection. Their results address different engineering constraints.
| Approach | Demonstrated result | Quantitative boundary | Interpretation |
|---|---|---|---|
| Foundry-compatible unit cells | [D] Characterised high-fidelity two-qubit operations on four devices. | Controlled-Z range 99.04(16)%–99.56(6)%; SPAM exceeds 99.9% on three devices, with 99.33(9)% on the fourth. | Reproducibility evidence at unit-cell scale. Industry-compatible silicon spin-qubit unit cells exceeding 99% fidelity — Nature, Sep 2025. |
| Donor-based processor | [D] An 11-qubit processor using coupled registers. | Reported operation fidelities 99.10%–99.99%, Bell-state fidelity up to 99.5% and an eight-nuclear-spin GHZ state. | A physical processor and entanglement result, rather than 11 protected logical qubits. An 11-qubit atom processor in silicon — Nature, Dec 2025. |
| Mobile spins | [D] Two-qubit logic combined with movement and teleportation. | Approximately 99% two-qubit gate fidelity; 87% conditional, postselected teleportation fidelity over 320 nanometres. | Movement and conditional transfer have separate quality measures. Two-qubit logic and teleportation with mobile spin qubits in silicon — Nature, May 2026. |
The recommended industrial assessment should therefore ask three separate questions: can the unit cell be fabricated reproducibly; can many unit cells be controlled together; and can the complete array execute the required encoded operations? Compatibility with an established manufacturing process materially informs the first question, but does not settle the latter two.
The mobile-spin result also illustrates why a distance measurement needs its physical scale and conditions. Nanometre-scale movement within a device is relevant to processor layout. It should not be described as evidence of a deployable communications network.
3.7 Topological approaches: measurement, protection and vendor claims
[D] The InAs–Al parity paper demonstrates an important measurement capability. Its authors explicitly state that this measurement by itself does not uniquely distinguish Majorana zero modes in a topological phase from certain fine-tuned low-energy Andreev states in a trivial phase. That interpretive boundary should remain attached to the result. Interferometric single-shot parity measurement in InAs–Al hybrid devices — Nature, Feb 2025.
[D] The 2026 minimal-Kitaev-chain paper reports real-time parity readout with switching lifetimes exceeding one millisecond. It identifies the two-site modes as offering limited protection compared with longer chains. The result advances readout and device control while leaving protection and scalable computation as separate evidentiary questions. Single-shot parity readout of a minimal Kitaev chain — Nature, Feb 2026. Nature
[C] Microsoft’s June 2026 Majorana 2 announcement describes improved device reliability and longer-lived states. [R] Its timetable for a scalable future computer remains a company objective. The announcement should be recorded as a first-party claim unless primary technical evidence establishes the relevant operations and protection. Introducing Majorana 2 — Microsoft, Jun 2026. news.microsoft.com
| Claim level | Recommended discriminating evidence |
|---|---|
| Parity readout | Single-shot errors, lifetimes and measurement back-action. |
| Topological interpretation | Tests that constrain competing explanations. |
| Coherent encoded control | Reproducible preparation and operations on the encoding. |
| Protection | Error behaviour under controlled perturbations and scaling. |
| Logical processing | A specified logical gate set and error accounting. |
| Universal sustained computation | Integrated encoded execution at the proposed workload scale. |
This framework permits recognition of real experimental progress while avoiding an unsupported promotion from a readout result to an operational computer.
3.8 Error correction: overhead depends on architecture and assumptions
[R — model-based architectural projection] The bivariate-bicycle-code study estimates preservation of 12 logical qubits using 288 physical qubits, under a stated physical error rate of 0.1%, for nearly one million syndrome cycles. Its comparable surface-code estimate requires nearly 3,000 physical qubits. The result is theoretical and numerical, rather than a hardware demonstration of that memory. High-threshold and low-overhead fault-tolerant quantum memory — Bravyi and collaborators, Nature, Mar 2024. Nature
The comparison shows why a generic “physical qubits per logical qubit” conversion is inadequate. The projected saving depends on the code, noise assumptions, connectivity and correction circuit. Its system value must also account for logical gates and resources beyond memory.
| Resource-estimation field | Recommended disclosure |
|---|---|
| Error-correcting code | Code family, parameters and layout. |
| Physical noise | Gate, measurement, preparation, idle and correlated errors. |
| Connectivity | Required interactions and their implementation. |
| Syndrome cycle | Duration and constituent operations. |
| Decoder | Algorithm, latency, resources and failure behaviour. |
| Logical operations | Gate-specific errors and durations. |
| Non-Clifford resources | Production quality, rate and factory footprint. |
| Complete workload | Logical register, depth, repetitions and success target. |
3.9 Manufacturing and supply-chain acceptance
[C — supplier-reported delivery] Oxford Instruments reported installation of three dilution refrigerators at the UK National Quantum Computing Centre in December 2024. This establishes an attributed enabling-equipment delivery; three refrigerators should not be recorded as three operational quantum computers. Oxford Instruments NanoScience installs dilution refrigerators in the NQCC’s purpose-built research labs — Oxford Instruments, Dec 2024. Oxford Instruments
The proposed diligence matrix below identifies records to collect rather than asserting market shares, national independence or undisclosed supplier concentration.
| Dependency | Records to request | Acceptance question |
|---|---|---|
| Cryogenic equipment | Cooling capacity, load curves, service intervals and recovery time. | Does performance persist with the complete installed system? |
| Lasers and optics | Stability, lifetime, alignment effort, spares and replacement qualification. | Can control performance be reproduced after maintenance? |
| Silicon and fabrication | Material specification, process variation, device distributions and wafer evidence. | How representative are the characterised devices? |
| Photonic packaging | Interface loss, assembly yield and environmental testing. | Does packaging retain component performance? |
| Classical electronics | Channel capacity, timing, latency, firmware and failover. | Can the controller support the required correction cycle? |
| Calibration software | Procedures, access rights, portability and recovery documentation. | Can the buyer operate and diagnose the system? |
| Detectors and readout | Efficiency, errors, throughput and operating requirements. | Is useful-result production limited by measurement? |
| Service and replacement | Repair times, qualified parts and requalification tests. | Can capability be restored within the buyer’s requirement? |
Key judgments
Hardware assessment requires a complete architecture, not a modality label. Logical subroutines are substantial technical achievements, but their integration and throughput determine application feasibility. Manufacturing evidence should describe distributions and reproducibility; supply-chain evidence should describe operational dependencies and recoverability.
What would change the assessment
The strongest upgrade would be repeated, sustained encoded computation with a universal operation set, measured resource-state throughput, real-time correction and demonstrated error performance across the required duration. Industrial readiness would additionally require comparable performance across production units and maintenance cycles.
Open official record
The records most likely to alter the assessment are full error distributions, parallel-operation tests, logical execution logs, accepted yields, decoder latency, fabrication distributions and service evidence. The low-overhead memory study identifies architectural opportunities; the silicon reproducibility study supplies bounded manufacturing evidence; the minimal-chain readout paper defines a narrower demonstrated topological-device milestone.
Chapter 4 — What Quantum Computers Can and Cannot Do in 2026
Principal judgment
The reviewed record supports specified experiments and selected hybrid scientific workflows; it does not establish general superiority across chemistry, optimisation, database search or cryptanalysis. A defensible application claim must identify the mathematical task, its effective size, required accuracy, complete workflow and contemporary classical competition.
4.1 Application evidence matrix
| Application | Evidence class and demonstrated scope | Quantitative anchor | What the evidence does not establish | Appropriate evaluation |
|---|---|---|---|---|
| Electronic structure | [D] Quantum sampling within a hybrid workflow using Heron and Fugaku. | Circuits up to 77 qubits and 10,570 gates. | General superiority over the strongest approximate classical chemistry methods. | Compare energy accuracy and full workflow resources. Chemistry Beyond the Scale of Exact Diagonalization on a Quantum-Centric Supercomputer — Science Advances, Jun 2025. |
| Many-body simulation | [D] Krylov methods demonstrated on specified spin-model sectors. | Up to 56 sites, including restricted particle-number sectors. | Arbitrary simulation of the full 56-qubit state space. | Report effective sector and projected-subspace dimensions. Krylov diagonalization of large many-body Hamiltonians on a quantum processor — Nature Communications, Jun 2025. |
| Quantum dynamics | [D] Higher-order correlation measurements and Hamiltonian-learning example. | Reported 65-qubit circuits in a specified experimental regime. | General commercial chemistry, optimisation or materials advantage. | Evaluate the scientific observable and current simulation methods. Observation of constructive interference at the edge of quantum ergodicity — Nature, Oct 2025. |
| Approximate optimisation | [D] Annealing comparison on a defined spin-glass ensemble. | More than 1,300 error-suppressed logical variables, with a specified classical comparator and approximation criterion. | Universal advantage for logistics, finance or every NP-hard problem. | Preserve instance distribution, embedding and solution quality. Scaling Advantage in Approximate Optimization with Quantum Annealing — Physical Review Letters, Apr 2025. |
| Sampling | [D] Execution of defined random-circuit benchmarks. | Platform-specific register and circuit parameters. | Automatic usefulness of the sampled distribution to a customer. | Define the downstream use and independently test comparison claims. A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Nature, Jun 2026. |
| Search | [D] Small distributed Grover demonstration; [R] useful-scale execution. | Reported distributed-search success of approximately 71%. | A speedup for an ordinary database once oracle construction and data access are included. | Account for the complete oracle and workflow. Distributed quantum computing across an optical network link — Nature, Feb 2025. |
| Factoring and discrete logarithms | Established algorithmic basis; [R] relevant-scale physical execution. | Resources depend on the named cryptographic target and architecture. | A physical-qubit headline proves an operational attack. | Require complete logical circuit, correction, runtime and success accounting. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer — Shor, author manuscript, Aug 1995. |
4.2 Chemistry: what “beyond exact diagonalisation” means
[D] The Heron–Fugaku study prepares quantum samples and uses distributed classical processing to obtain ground-state energy upper bounds and sparse wavefunction approximations for nitrogen and iron–sulphur systems. Its maximum circuit size is a useful scale marker, but the relevant computational object is the complete hybrid workflow. Chemistry Beyond the Scale of Exact Diagonalization on a Quantum-Centric Supercomputer — Science Advances, Jun 2025.
The phrase “beyond exact diagonalisation” identifies a particular comparison boundary. It should not be expanded into “beyond classical chemistry,” because approximate methods are part of the relevant competition. The application judgment should ask whether the quantum contribution improves a useful accuracy–cost trade-off against those methods.
[D — published numerical analysis] Reinholdt and collaborators identify a tension in quantum-selected configuration interaction: repeated sampling can revisit already selected configurations, while avoiding that problem can produce less compact expansions than classical selection heuristics. Their analysis challenges the practical advantage of the method in the examined cases without invalidating every possible future hybrid chemistry approach. Critical Limitations in Quantum-Selected Configuration Interaction Methods — Journal of Chemical Theory and Computation, Jun 2025. arxiv.org
| Chemistry evaluation field | Recommended specification | Why it matters |
|---|---|---|
| Molecular system | Geometry, charge and electronic state. | Defines the physical question. |
| Model | Basis set, active space and Hamiltonian. | Defines the computational approximation. |
| Target quantity | Energy, difference, barrier or other observable. | Determines whether the result is useful. |
| Accuracy | Numerical tolerance and uncertainty. | Prevents comparison at unequal quality. |
| Quantum stage | State preparation, circuit and accepted samples. | Identifies the processor’s contribution. |
| Classical stage | Selection, recovery, diagonalisation and other processing. | Captures hybrid cost. |
| Comparator | Appropriate contemporary classical methods. | Tests incremental value. |
| Total execution | Calibration, sampling, retries and postprocessing. | Supports a practical time comparison. |
| Validation | Independent reference or defensible error bound. | Prevents an internally consistent answer from being mistaken for an accurate one. |
Recommended decision rule: retain chemistry pilots when they produce new scientific information or demonstrate a credible route to a better accuracy–cost trade-off. Do not justify production acquisition solely through active-space size.
4.3 Materials and many-body simulation: count the effective problem
[D] The Krylov study demonstrates calculations in specified particle-number sectors, including cases with 56 sites and one particle, 44 sites and three particles, and 42 sites and five particles. These restrictions materially affect the mathematical size. Krylov diagonalization of large many-body Hamiltonians on a quantum processor — Nature Communications, Jun 2025. Nature Communications
The following dimensions are derived calculations, not additional experimental measurements:
| Reported case | Full binary state-space dimension | Fixed-particle sector dimension | Interpretation |
|---|---|---|---|
| 56 sites, one particle | 256 ≈ 7.21 × 1016 | 56 | The site count greatly exceeds the sector dimension. |
| 44 sites, three particles | 244 ≈ 1.76 × 1013 | 13,244 | Particle-number restriction determines the relevant space. |
| 42 sites, five particles | 242 ≈ 4.40 × 1012 | 850,668 | The restricted sector is larger, but remains distinct from the full space. |
These calculations do not dismiss the experiment. They identify the correct object against which classical difficulty should be assessed. The evaluation should additionally report the Krylov subspace actually constructed, measured observables and accuracy.
A materials application requires another bridge: the simulated Hamiltonian and observable must correspond to a useful materials question. A technically difficult spin-model experiment can have scientific value without yet establishing an industrial materials-design capability.
4.4 Quantum dynamics: difficult observables need bounded claims
[D] The October 2025 study measures second-order out-of-time-order correlators through repeated time-reversal protocols on superconducting hardware. It links the measured interference structure to classical simulation difficulty and includes a Hamiltonian-learning example. This is stronger evidence than a generic claim that “the quantum computer performed a large calculation,” because it identifies the observable and physical mechanism. Observation of constructive interference at the edge of quantum ergodicity — Google Quantum AI and collaborators, Nature, Oct 2025. Nature
The associated application assessment should remain tied to that observable. Extending it to drug discovery, aircraft design or general optimisation would require separate algorithms, error budgets and comparisons. The existence of a hard-to-simulate experiment does not supply those missing demonstrations.
4.5 Optimisation: ensemble, approximation and embedding
[D] The annealing study reports a scaling comparison for approximate optimisation on a defined spin-glass problem family, using quantum annealing correction and a named classical method. Its “logical” variables are error-suppressed annealing variables; they should not be equated with universal fault-tolerant circuit-model qubits. Scaling Advantage in Approximate Optimization with Quantum Annealing — Physical Review Letters, Apr 2025. Phys. Rev. Lett.
| Question | Recommended acceptance requirement |
|---|---|
| Which problems were tested? | Full instance-generation procedure and held-out instances. |
| What solution quality was required? | Objective gap, feasibility and success probability. |
| How was the problem represented? | Variables, interactions, penalties and precision. |
| What did embedding consume? | Physical resources, preprocessing and discarded instances. |
| Which classical methods competed? | Appropriate tuned methods, with disclosed resources. |
| What time was measured? | Complete time to the required valid solution. |
| Does the result transfer? | New evidence on the buyer’s actual problem distribution. |
For a logistics or financial pilot, the recommended test should include all operational constraints and the existing production solver. A favourable result on another ensemble should motivate that test, rather than predetermine its outcome.
4.6 Sampling: computational separation and application value
[D] Random-circuit sampling provides evidence about execution of complex quantum circuits and comparison with classical simulation. Its application value depends on an additional question: what useful output does the sampled distribution enable? The Helios paper’s circuit evidence should be evaluated within its stated benchmark before extending it to customer workloads. A 98-qubit trapped-ion quantum computer with all-to-all connectivity — Nature, Jun 2026.
The recommended assessment separates:
| Question | Record needed |
|---|---|
| Was the intended distribution generated? | Verification protocol, uncertainty and device data. |
| What classical comparison supports the claim? | Methods, resources, precision and comparison date. |
| What useful task consumes the samples? | Named downstream algorithm and measurable benefit. |
The first two can establish an important experimental result. The third establishes the basis for an application investment.
4.7 Why classical competition must remain current
[D] The 2023 IBM utility paper studied a 127-qubit processor and compared error-mitigated results with specified classical approaches. Subsequent published classical work provided fast, converged simulations for the experiment. The original quantum measurements remain experimental evidence, while the interpretation of their comparative difficulty changes. Evidence for the utility of quantum computing before fault tolerance — Nature, Jun 2023; Fast and converged classical simulations of evidence for the utility of quantum computing before fault tolerance — Science Advances, Jan 2024; Caltech repository. Nature
Recommended benchmark governance should therefore freeze the problem definition and output tolerance, while allowing the classical methods to improve. A procurement case that depends on prohibiting improved competition is not a durable application case.
4.8 Search: the oracle is part of the computation
The established Grover algorithm gives a quadratic query improvement for its defined search model. [R] Whether that produces a practical advantage depends on constructing and executing the oracle, supplying the data and accounting for repetitions and errors. A fast quantum mechanical algorithm for database search — Grover, author manuscript, May 1996. arxiv.org
[D] The distributed ion experiment demonstrates a remote controlled-Z gate with fidelity 86.2 ± 0.9% and a small Grover search with approximately 71% success. These results establish a distributed-processing experiment. They do not establish acceleration of a large ordinary database. Distributed quantum computing across an optical network link — Nature, Feb 2025.
| Search proposal field | Recommended disclosure |
|---|---|
| Search space | Number and representation of candidates. |
| Predicate | Exact test defining an acceptable answer. |
| Oracle | Compiled circuit, depth and ancillary resources. |
| Data access | Loading, updates and access assumptions. |
| Repetitions | Success amplification and failed attempts. |
| Classical comparison | Complete incumbent workflow. |
4.9 Factoring and discrete logarithms: relevance requires complete resources
Shor’s algorithm supplies the algorithmic basis for quantum factoring and discrete logarithms. [R] Relevant-scale physical execution requires a sufficiently reliable architecture and complete resource accounting; the mathematical algorithm alone does not establish a fielded attack. Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer — Shor, Aug 1995 author manuscript. arxiv.org
The cryptanalytic estimates from the opening assessment are not repeated here. Chapter 5 will assess the named schemes and complete attack-resource assumptions. For this chapter, the application acceptance boundary is:
| Required field | Why it is indispensable |
|---|---|
| Named cryptographic target | Defines the mathematical problem and parameter size. |
| Logical register | Separates algorithm data from physical inventory. |
| T/Toffoli or equivalent resources | Captures non-Clifford demand. |
| Circuit depth and dependencies | Constrains execution time. |
| Code and distance | Defines protection assumptions. |
| Physical overhead | Includes data, ancillas, factories and routing. |
| Cycle and decoder timing | Determines feasible sustained execution. |
| Success probability | Accounts for failure and repetition. |
| Complete runtime | Connects the architecture to operational relevance. |
4.10 Quantitative illustration: errors accumulate
The following is an illustrative calculation, not measured hardware data or a forecast. Assume independent operations, identical failure probability \(p\), no correction and a requirement that all \(G\) operations succeed:\[ P_{\text{no failure}}=(1-p)^G. \]
| Assumed failure probability per operation | Operations | Probability of no failure |
|---|---|---|
| 1% | 100 | 36.6% |
| 1% | 1,000 | 0.00432% |
| 0.1% | 1,000 | 36.8% |
| 0.1% | 10,000 | 0.00452% |
| 0.01% | 10,000 | 36.8% |
| 0.01% | 100,000 | 0.00454% |
The calculation shows why a high isolated fidelity does not automatically support a deep successful computation. Real devices require richer error models, including correlations, leakage and unequal operations. Error correction changes the analysis; its purpose is to make logical failure compatible with the total workload. Architecture-dependent memory estimates provide a concrete example of that more complete reasoning. High-threshold and low-overhead fault-tolerant quantum memory — Nature, Mar 2024.
4.11 Application claims that should fail the current evidence gate
These are assessment rules for unsupported proposals, rather than statements that the applications can never become feasible.
| Proposed claim | Classification when unsupported | Evidence needed for reconsideration |
|---|---|---|
| “The qubit count proves useful chemistry advantage.” | [H] | Full molecular model, target accuracy and classical comparison. Chemistry workflow; methods critique. |
| “A spin-glass result proves faster operational logistics.” | [H] | Tests on representative logistics instances with all constraints and preprocessing. Annealing study. |
| “A difficult sampling benchmark proves commercial value.” | [H] | A downstream task whose benefit depends on those samples. Helios benchmark paper. |
| “An encoded register is a universal fault-tolerant computer.” | [H] | Integrated universal operations, repeated correction, throughput and runtime. Logical processor; logical distillation. |
| “AI control removes hardware reliability requirements.” | [H] | Sustained logical evidence under the actual physical operating conditions. Reinforcement-learning control. |
| “Parity measurement establishes scalable protected computation.” | [H] | Discriminating physical evidence, protection tests and logical execution. Parity-measurement paper. |
| “A processor announcement establishes a cryptanalytic capability.” | [H] | Named target, complete logical resources and demonstrated or fully specified execution architecture. Algorithmic basis. |
Key judgments
The most defensible computing assessments concern named scientific observables, defined optimisation ensembles and documented hybrid workflows. Problem size should describe the effective mathematical task, rather than only the physical register. Application advantage requires a complete, current comparison, and its validity should remain open to improved classical methods.
What would change the assessment
The decisive evidence would be independent reproduction of a useful workload at the buyer’s required accuracy, with complete elapsed time, accepted-run statistics, classical processing and contemporary comparators. For fault-tolerant applications, it would additionally require the relevant logical operations and resource production to remain reliable throughout execution.
Open official record
The missing records with greatest decision value are full workflow timings, rejected-run costs, effective problem dimensions, independent comparator results and complete logical execution data. The hybrid chemistry study, Krylov study, annealing comparison and published classical re-evaluation provide the starting evidence for those assessments.
Pillar II — Security Migration and Operational Applications
Chapter 5 — Cryptography
5.1. The security decision concerns an entire trust architecture
[P] The principal deployable response to the quantum threat is now anchored in published cryptographic standards: ML-KEM for key encapsulation, ML-DSA for digital signatures and SLH-DSA for stateless hash-based signatures. Their publication establishes interoperable algorithm specifications; it does not certify every product implementing them, migrate an organisation’s certificate hierarchy or establish resistance to implementation attacks.
Sources: NIST, FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard, FIPS 204: Module-Lattice-Based Digital Signature Standard, and FIPS 205: Stateless Hash-Based Digital Signature Standard, August 2024. CSRC
The recommended assessment unit is therefore the security function and its dependencies. For each function, the owner should identify the initiating endpoint, terminating endpoint, intermediate trust boundaries, algorithm, implementation, replacement authority and expected lifetime.
| Security function | Question the migration programme should answer | Required completion evidence |
|---|---|---|
| Session establishment | Can both endpoints establish a session using the authorised replacement mechanism? | Negotiation traces, interoperability results and explicit downgrade tests |
| Endpoint authentication | Does the session authenticate the intended peer through a suitable trust chain? | Certificate-path tests, revocation behaviour and identity-binding verification |
| Bulk confidentiality | Are payload keys generated, stored, rotated and destroyed appropriately? | Key-management design and operational audit |
| Firmware acceptance | Can an installed device verify new signatures throughout its remaining service life? | Tests on deployed bootloaders, recovery paths and update packages |
| Software distribution | Can every build, signing, distribution and installation stage process the new scheme? | End-to-end release rehearsal |
| Archival authenticity | Can a future verifier establish what was signed, when and under which trust state? | Documented preservation, timestamp and renewal procedures |
| Recovery and continuity | What happens when a peer, appliance or certificate is incompatible? | Tested recovery procedures and controlled exception handling |
| Supplier assurance | Who maintains the implementation after initial integration? | Versioned support commitments and replacement procedures |
Recommended interpretation: migration is complete only when the relevant security service works across its actual operational boundary. An algorithm appearing in a product specification should count as a component milestone, not as evidence that the surrounding service has completed its transition.
5.2. ML-KEM parameters: exact sizes and what they mean
[P] FIPS 203 specifies the following encoded sizes. These are cryptographic objects, not complete TLS handshakes, certificate chains, VPN negotiations or application messages.
| Parameter set | NIST security category | Encapsulation key | Decapsulation key | Ciphertext | Shared secret |
|---|---|---|---|---|---|
| ML-KEM-512 | 1 | 800 bytes | 1,632 bytes | 768 bytes | 32 bytes |
| ML-KEM-768 | 3 | 1,184 bytes | 2,400 bytes | 1,088 bytes | 32 bytes |
| ML-KEM-1024 | 5 | 1,568 bytes | 3,168 bytes | 1,568 bytes | 32 bytes |
[P] NIST identifies ML-KEM-768 as its general default recommendation in the standard. That recommendation should not be substituted for a specialised national-security profile or a jurisdiction-specific requirement.
Source: NIST, FIPS 203, Table 3 and parameter-selection guidance, August 2024. nvlpubs.nist.gov
For transport planning, the following arithmetic is useful, provided its scope remains explicit:
| Illustrative object exchange | Calculation | Encoded bytes |
|---|---|---|
| ML-KEM-512 public key plus ciphertext | 800 + 768 | 1,568 |
| ML-KEM-768 public key plus ciphertext | 1,184 + 1,088 | 2,272 |
| ML-KEM-1024 public key plus ciphertext | 1,568 + 1,568 | 3,136 |
These totals are derived from FIPS 203, not measured network traffic. A real protocol may transmit these objects in different messages, reuse keys, add a classical component, include certificates or introduce additional framing.
The recommended performance assessment should distinguish five quantities:
- Encoded object size, determined by the selected algorithm and parameter set.
- Protocol message size, determined by how the objects are packaged.
- Computation time, measured on the actual processor and implementation.
- Network completion time, measured under relevant loss, congestion and connection patterns.
- Service impact, measured as successful transactions, failed negotiations and recovery time.
A larger cryptographic object does not establish a proportional increase in transaction latency. Conversely, acceptable primitive-level benchmarks do not establish acceptable behaviour on a constrained appliance or a lossy communications path.
5.3. Signature parameters: the migration has a different bottleneck
[P] FIPS 204 specifies three ML-DSA parameter sets:
| Parameter set | NIST security category | Public key | Private key | Signature |
|---|---|---|---|---|
| ML-DSA-44 | 2 | 1,312 bytes | 2,560 bytes | 2,420 bytes |
| ML-DSA-65 | 3 | 1,952 bytes | 4,032 bytes | 3,309 bytes |
| ML-DSA-87 | 5 | 2,592 bytes | 4,896 bytes | 4,627 bytes |
Source: NIST, FIPS 204, Table 2, August 2024. nvlpubs.nist.gov
[P] FIPS 205 provides SHA2-based and SHAKE-based variants with the following public-key and signature sizes:
| SLH-DSA parameter suffix | NIST security category | Public key | Signature |
|---|---|---|---|
| 128s | 1 | 32 bytes | 7,856 bytes |
| 128f | 1 | 32 bytes | 17,088 bytes |
| 192s | 3 | 48 bytes | 16,224 bytes |
| 192f | 3 | 48 bytes | 35,664 bytes |
| 256s | 5 | 64 bytes | 29,792 bytes |
| 256f | 5 | 64 bytes | 49,856 bytes |
The listed sizes apply to both hash-family variants for each suffix. Small public keys should not be confused with small signed objects.
Source: NIST, FIPS 205, parameter table, August 2024. nvlpubs.nist.gov
Recommended assessment: treat signature migration as a separate workstream from session establishment. Its acceptance environment includes certificate parsers, update-package formats, verification memory, hardware roots of trust and the installed equipment estate.
| Signature-bearing system | Proposed test | Decision the test should support |
|---|---|---|
| Certificate hierarchy | Validate complete paths with realistic chain lengths | Whether the existing identity infrastructure can support the chosen profile |
| Embedded firmware | Verify representative packages on the oldest supported devices | Whether software updates suffice or hardware replacement is necessary |
| Secure boot | Exercise acceptance, rejection and recovery paths | Whether migration can preserve the device’s trust boundary |
| High-volume signing service | Measure throughput and tail latency under peak demand | Whether signing infrastructure needs additional capacity |
| Offline verifier | Test updates without continuous network access | Whether disconnected operations can sustain the replacement trust model |
| Long-lived signed record | Rehearse future verification and trust renewal | Whether archival procedures preserve evidentiary value |
For an acquisition authority, the difficult question is often whether the installed verifier can be changed safely. Funding a new signing server does not resolve an immutable verifier in equipment expected to remain in service.
5.4. Algorithm diversity and the status of HQC
[P] NIST selected HQC in March 2025 for subsequent standardisation as a backup key-encapsulation mechanism using a different mathematical foundation from ML-KEM. [R] The selection announcement described a prospective final standard in 2027. Selection, a draft and a final standard are separate milestones.
The source does not justify describing HQC as a replacement already required across deployed systems, or postponing migration to the completed standards while waiting for it.
Source: NIST, NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption, March 2025. Here, the announcement’s “encryption” terminology refers specifically to a key-encapsulation mechanism. NIST
Recommended control: maintain algorithm diversity through replaceable implementations, documented interfaces and tested transition procedures. Adding multiple algorithms without a coherent negotiation and authentication design should not count as improved assurance.
A useful procurement requirement is consequently more demanding than “supports PQC.” It should specify:
- The exact algorithm, parameter set and protocol profile.
- The implementation version and applicable validation evidence.
- The mechanism for updating the implementation.
- The supported peer configurations.
- The treatment of incompatible peers and downgrade attempts.
- The operational owner responsible for replacement if an algorithm or implementation is retired.
5.5. Hybrid migration: assurance depends on composition
[P] ANSSI’s follow-up migration guidance supports hybrid approaches and discusses composition requirements. For key establishment, combining mechanisms requires an appropriate construction; for combined signatures, accepting either signature is not equivalent to requiring both. The intended assurance depends on the combiner and verification rule.
Source: ANSSI, Avis sur la migration vers la cryptographie post-quantique — follow-up guidance, 2023 follow-up, official portal publication January 2024. messervices.cyber.gouv.fr
The recommended assurance review should answer the following questions before approving a hybrid deployment:
| Review area | Required question |
|---|---|
| Key combination | What is the security argument for the combiner? |
| Authentication | Which mechanism authenticates the peer and negotiated configuration? |
| Transcript binding | Are identities, algorithms and negotiation results bound into the authenticated exchange? |
| Downgrade handling | Can an active intermediary induce a weaker configuration? |
| Signature acceptance | Must every required signature verify, or can one alone authorise acceptance? |
| Error handling | Do malformed inputs expose secrets, distinguish internal failures or trigger unsafe fallback? |
| Legacy compatibility | Which peers remain outside the intended assurance model? |
| Operational evidence | Can administrators prove which mechanism protected a particular session or signed object? |
[H] “Hybrid” should be rejected as an assurance conclusion when the seller cannot identify the construction and its acceptance rules. The label describes a combination; it does not supply a security proof.
5.6. Confidentiality lifetime and signature lifetime require different clocks
[P] The multinational ANSSI–BSI–NLNCSA–Swedish position paper explicitly recognises the store-now-decrypt-later problem: intercepted material can remain sensitive beyond the period during which its original public-key protection is expected to be adequate. This is a reason to assess retained information now; it is not evidence that an adversary currently possesses a cryptographically relevant quantum computer.
Source: ANSSI, BSI, NLNCSA and Swedish NCSA, Position Paper over Quantum Key Distribution, January 2024. aivd.nl
For planning, define:\[ L=\text{remaining confidentiality lifetime},\qquad M=\text{migration duration},\qquad Q=\text{assumed time until a relevant adversarial capability}. \]
The inequality\[ L+M\geq Q \]
is a scenario-screening rule, not a prediction. It asks whether a chosen scenario leaves enough time to complete migration before newly exposed information outlives the assumed protection horizon.
For illustration only, if an organisation requires ten further years of confidentiality and assumes three years to migrate, its exposure assessment spans thirteen years. This arithmetic establishes no date for the arrival of a quantum computer.
Signature risk should be screened differently. The owner should ask how long equipment will continue accepting a particular signing authority, whether the verifier can be updated, and what procedures preserve the authenticity of historical records.
| Planning clock | Exposure being assessed | Recommended response |
|---|---|---|
| Confidentiality lifetime | Future recovery of information captured during the vulnerable period | Prioritise exposed, long-lived secrets and their key-establishment paths |
| Equipment service life | Future acceptance of unauthorised software or commands | Assess verifier replacement and firmware trust transitions |
| Certificate lifetime | Continued reliance on a retiring trust hierarchy | Plan issuance, validation and revocation changes |
| Archival verification lifetime | Future inability to establish the authenticity of a historical object | Define preservation and renewal procedures |
| Migration duration | Time needed to replace dependencies and incompatible equipment | Begin discovery before selecting a universal completion date |
5.7. A resource estimate is not a demonstrated cryptanalytic service
[R] A published 2017 logical-circuit study estimated the resources below for an elliptic-curve discrete-logarithm computation against NIST P-256. It is a historical model of a particular circuit construction, not a current minimum and not an attack executed on quantum hardware.
Quantum Resource Estimation: NIST P-256 Discrete Logarithm
Logical fault-tolerant resource requirements based on modular arithmetic synthesis and reversible circuit compilation.
| Required resource field | What the cited P-256 study supplies |
|---|---|
| Named target | Elliptic-curve discrete logarithm over P-256 |
| Logical qubits | 2,330 |
| Toffoli count | Approximately 1.26 × 1011 |
| Toffoli depth | Approximately 1.16 × 1011 |
| Error-correcting code and distance | No complete physical implementation specified |
| Physical-qubit overhead | No complete physical implementation specified |
| Fault-tolerant wall-clock runtime | Not established by these logical counts |
| Demonstration status | Circuit construction and classical verification of arithmetic components |
Source: Roetteler, Naehrig, Svore and Lauter, Quantum resource estimates for computing elliptic curve discrete logarithms, ASIACRYPT 2017, Table 2. arxiv.org
Technical Analysis and Architectural Deconstruction of Parameters
Evaluating physical footprint, fault-tolerant overhead, and circuit depth for the cryptanalysis of elliptic curve cryptography.
The data summarized in the reference table belongs to the foundational literature on quantum cryptanalysis applied to elliptic curve public-key cryptosystems, specifically the NIST P-256 standard (also designated as secp256r1 or prime256v1). This elliptic curve underpins the cryptographic security of widespread modern communication standards, including TLS 1.3, X.509 PKI certificates, SSH sessions, digital identity frameworks, and standard ECDSA / Ed25519 signature schemes (with close structural analogy to the secp256k1 curve utilized in Bitcoin).
Deconstructing each operational parameter allows us to quantify with rigorous physical precision how far current experimental prototypes remain from realizing Cryptographically Relevant Quantum Computers (CRQCs) capable of breaking asymmetric public-key infrastructure.
1. The Target Problem: Elliptic-Curve Discrete Logarithm Problem (ECDLP) over P-256
In cryptographic schemes parameterized over prime fields, the abelian group of affine points on a non-singular elliptic curve is governed by the short Weierstrass model:
For the specific NIST P-256 specification, the characteristic modulus p is the generalized 256-bit Mersenne prime:
Given a fixed generator base point G ∈ E(Fp) of prime order n and a published public key point Q = d · G (where scalar multiplication denotes repeated point addition over the chord-and-tangent group law), the Elliptic Curve Discrete Logarithm Problem (ECDLP) consists of computing the private scalar exponent:
- Classical Computational Complexity: The most efficient generic classical attacks—such as Pollard’s ρ algorithm and the parallelized Pollard lambda collision search—exhibit fully exponential asymptotic complexity bounded by O(√n). For an underlying 256-bit prime modulus, evaluating this space requires approximately 2128 point additions, defining a robust classical security threshold of 128 bits.
- Quantum Complexity via Shor’s Reduction: Shor’s algorithm reduces ECDLP to an instance of the Hidden Subgroup Problem (HSP) over the finite abelian product group Zn × Zn. By evaluating quantum phase estimation over a two-dimensional period, Shor collapses the computational complexity from exponential to strictly polynomial time: Õ(n3) or Õ(n2), depending on whether modular arithmetic is synthesized using ripple-carry or carry-lookahead architectures.
2. Logical Qubit Requirements: 2,330 Qubits
A logical qubit represents an ideal, fault-tolerant macroscopic quantum state synthesized across an ensemble of physical qubits protected by quantum error correction (QEC) codes. The benchmark of 2,330 logical qubits to resolve the P-256 discrete logarithm reflects several decades of compiler optimization and register reallocation:
- Early Shor Formulations: Canonical formulations of Shor’s algorithm required two distinct operational registers to execute the Quantum Fourier Transform (QFT) spanning 2 × ⌈log2 n⌉ ≈ 512 qubits, alongside dedicated auxiliary work registers for point arithmetic in projective coordinates (X : Y : Z). Early implementations consequently required between 5,000 and 9,000 logical qubits.
-
The Ekerå-Håstad Algorithmic Paradigm: By leveraging semi-classical phase estimation alongside short-period modifications developed by Martin Ekerå and Johan Håstad, modern implementations replace wide parallel QFT registers with iterative single-qubit semiclassical readouts. Combined with space-optimized reversible modular adders (such as Cuccaro ripple-carry networks and Montgomery inversion circuits refined by Roetteler, Naehrig, Svore, Lauter, Litinski, and Gidney), circuit designers successfully compressed spatial demands down to:
- Base coordinate registers representing field elements in Fp (256 logical qubits per coordinate register).
- Reversible modular multiplication and inversion ancilla pools.
- Clean uncomputation registers that dynamically recycle intermediate values, entirely preventing the persistent accumulation of dirty “garbage bits.”
3. Toffoli Count: ≈ 1.26 × 1011 and the Dominant Cost of Non-Clifford Gates
In fault-tolerant quantum computation, gates are divided into two operational classes: transversal operations within the Clifford group (X, Y, Z, H, S, and CNOT) and non-Clifford operations, represented by either the single-qubit T gate (where T = diag(1, eiπ/4)) or the three-qubit Toffoli (Controlled-Controlled-NOT) gate.
- The Eastin-Knill Restriction: The Eastin-Knill Theorem proves that no quantum error-correcting code can realize a continuous, universal gate set using exclusively transversal operations. While Clifford gates are executed with low latency using topological braid operations or lattice surgery in standard 2D surface codes, non-Clifford gates cannot be implemented natively on logical codewords.
-
Toffoli Decomposition via Magic State Distillation: To execute a Toffoli gate without destroying code distance, the processor must inject high-fidelity resource states known as magic states:
|T〉 = cos(π/8)|0〉 + sin(π/8)|1〉Synthesizing a single Toffoli gate requires decomposing it into 4 T gates (with auxiliary measurement lines) or 7 T gates in unassisted layouts.
- Cumulative Computational Footprint: An aggregate count of ≈ 1.26 × 1011 Toffoli gates indicates that an attacking quantum processor must reliably distill and inject over half a trillion magic states (4 × 1.26 × 1011 ≈ 5.04 × 1011 |T〉 states). In any physical surface-code architecture, magic state distillation factories account for over 90% of the entire hardware footprint and energy consumption.
4. Toffoli Depth: ≈ 1.16 × 1011 and Circuit Critical Path Serialization
While the total gate count dictates total computational energy, the Toffoli depth dictates the absolute minimum execution latency by defining the longest serial dependency chain of gates that cannot be evaluated in parallel:
The fact that the depth (1.16 × 1011) is nearly identical to the overall count (1.26 × 1011)—representing a serial occupancy ratio exceeding 92%—highlights the core architectural bottleneck of quantum cryptanalysis on elliptic curves:
- Point multiplication k · G proceeds through deeply serialized chains of elliptic point doubling and additions (P ← 2P and P ← P + Gi).
- Each point addition necessitates field inversion and modular multiplication over Fp, which rely on arithmetic carry chains that enforce linear sequential execution.
- Architectural Consequence: Even if a quantum supercomputer were provisioned with millions of additional data qubits, Amdahl’s law prevents parallelization. The execution time of an attack on P-256 is entirely bounded by the sequential execution speed of these 1.16 × 1011 serialized Toffoli layers.
5. Error-Correcting Code and Code Distance (d): Why Specifications Are Hardware-Agnostic
The classification “No complete physical implementation specified” reflects the standard methodological boundary between high-level logical circuit compilation and physical microarchitecture implementation:
- Algorithmic synthesis papers optimize reversible Boolean networks to minimize abstract logical costs without anchoring calculations to a specific hardware family.
-
Establishing code distance d requires defining both the physical error rate per native gate (pphys) and the maximum allowable total algorithm failure probability (Ptarget):
Ptarget ≈ 1 − (1 − Plogical)N ≈ N · PlogicalFor an attack executing N ≈ 1011 to 1012 total gate operations with an overall target success rate > 50%, the per-gate logical failure rate must be suppressed to:Plogical ≤ 0.5 / 1012 = 5 × 10−13
Under standard 2D rotated surface codes operating with physical error rates pphys ≈ 10−3 (well beneath the approximate 1% fault tolerance threshold), suppressing errors to 10−13 requires a code distance between d = 27 and d = 31.
6. Physical Qubit Overhead: From Abstract Theory to Hardware Scaling
Physical overhead quantifies the number of raw physical qubits (e.g., superconducting Josephson junctions, trapped ions, or neutral Rydberg atoms) required to protect a single logical qubit against decoherence:
In rotated surface codes, spatial qubit allocation scales quadratically with distance:
- Selecting a conservative distance d = 27 yields: 2 × (27)2 = 1,458 physical qubits per logical qubit.
- Multiplying this across the 2,330 logical data qubits gives: 2,330 × 1,458 ≈ 3.4 × 106 physical qubits purely dedicated to data memory and arithmetic routing.
- Magic State Factory Scaling: Continuous distillation using 15-to-1 schemes or multi-tier Bravyi-Kitaev pipelines introduces substantial footprint demands. To supply a steady stream of T states to the execution pipeline without starvation stalls, distillation modules require an additional 1 to 5 million physical qubits.
7. Real Runtime (Fault-Tolerant Wall-Clock Latency)
Physical runtime cannot be derived from logical gate counts alone without specifying the hardware cycle frequency of the Quantum Error Correction (QEC) stabilization loop:
- Superconducting Circuits (e.g., Transmon Qubits): Stabilizer syndrome measurement cycles execute within 200 ns to 1 μs. Executing a logical operation via lattice surgery over distance d = 27 requires d stabilizer rounds (≈ 27 μs). Multiplying this latency across a critical path of 1.16 × 1011 sequential cycles establishes a continuous wall-clock runtime ranging from several days to roughly 3 to 4 weeks.
- Trapped-Ion and Neutral-Atom Processors: These architectures exhibit superior physical gate fidelities (allowing lower code distances d), but their physical two-qubit gate operations and fluorescence detection cycles are significantly slower (spanning hundreds of microseconds to milliseconds). Executing 1011 sequential operations on slow-cycle platforms results in runtimes spanning decades to centuries, rendering serial attacks infeasible on those modalities absent substantial algorithmic parallelization.
8. Demonstration Status: Circuit Construction and Classical Verification
The formal status designation “Circuit construction and classical verification of arithmetic components” precisely defines the Technology Readiness Level (TRL) of current research:
- Circuit Construction: The complete gate topology (CNOT, Toffoli, Hadamard, and phase rotations) has been synthetically constructed down to the exact gate level, including reversible Montgomery point adders and modular inversion circuits.
- Classical Verification: Because no quantum computer with thousands of logical qubits exists today, the end-to-end circuit has never executed on physical quantum processors. Instead, arithmetic subcomponents (e.g., 256-bit modular reversible adders and lookup tables) are formally verified on classical supercomputers using Binary Decision Diagrams (BDDs) and stabilizer simulation frameworks.
Scalability Comparison: Elliptic Curves (ECDLP) vs. RSA Factorization
Comparing the resource profiles of NIST P-256 against RSA-2048 reveals how distinct cryptographic hardness assumptions stress physical quantum hardware in opposing dimensions:
| Cryptographic Parameter | NIST P-256 (ECDLP) | RSA-2048 (Factoring) | Key Architectural Difference |
|---|---|---|---|
| Classical Security Level | 128-bit | 112-bit | P-256 provides higher resistance against classical algorithms. |
| Required Logical Qubits | ≈ 2,330 | ≈ 4,096 | P-256 requires nearly half the logical memory space of RSA-2048. |
| Toffoli Gate Count | ≈ 1.26 × 1011 | ≈ 2.9 × 109 | RSA requires nearly two orders of magnitude fewer Toffoli operations. |
| Circuit Depth | Extremely High (≈ 1.16 × 1011) | Lower & Parallelizable | Elliptic curve point operations are strictly serialized along carry paths. |
| Physical Hardware Impact | Requires fewer qubits, but extreme coherence times. | Requires more qubits, but finishes in far less real time. | The two targets stress quantum architectures in opposite dimensions. |
[H] Interpreting the table as evidence that a processor containing 2,330 physical qubits can recover a P-256 private key is a category error. The physical architecture, logical error budget, non-Clifford implementation and execution schedule are unresolved in that translation.
Recommended reporting rule: any newer attack estimate should replace the complete resource row, including its assumptions. A reduced logical-qubit count should not be reported as a reduced operational attack cost unless the associated gate count, error correction, physical resources and runtime have also been assessed.
5.8. Symmetric cryptography should not inherit the RSA/ECC risk model
[R] NIST’s PQC FAQ cautions against translating Grover’s theoretical query reduction directly into a practical attack estimate. It discusses sequential execution costs and the limited benefit of parallelisation, and permits continued use of AES-128, AES-192 and AES-256 subject to applicable guidance.
Source: NIST, Post-Quantum Cryptography FAQs, maintained page, retrieved October 2026. CSRC
[H] “Quantum computers halve every key length” is an inadequate security statement. It suppresses the attack model, reversible implementation, error-correction cost and elapsed time.
Recommended control: select symmetric parameters through the applicable security profile, confidentiality horizon and implementation environment. For new systems protecting long-lived secrets, AES-256 can be considered within that profile; it should not be presented as a substitute for migrating vulnerable public-key establishment or signature functions.
| Proposed assessment | Evidence to require |
|---|---|
| Adequacy of a symmetric parameter set | Applicable policy and a named attack model |
| Quality of key management | Generation, storage, rotation, access and destruction procedures |
| Adequacy of session establishment | Evidence that payload keys are not exposed through an obsolete establishment mechanism |
| Integrity protection | Correct authenticated-encryption or message-authentication implementation |
| Long-term storage protection | Protection of wrapping keys, backups and recovery copies |
5.9. QKD: physical key distribution and system assurance remain separate questions
[P] NSA’s published position states:
“NSA does not recommend the usage of quantum key distribution and quantum cryptography for securing the transmission of data in National Security Systems (NSS)”
The position retains a condition: the identified limitations would need to be overcome. NSA identifies missing source authentication, specialised infrastructure, trusted-relay exposure, implementation-validation difficulties and denial-of-service risk. This is a scoped position on national-security systems, not a denial that QKD experiments produce keys.
Source: NSA, Post-Quantum Cybersecurity Resources — QKD and quantum-cryptography guidance, maintained institutional guidance, retrieved October 2026. nsa.gov
[P] ANSSI’s QKD guidance allows consideration of a limited niche involving fixed optical links and defence in depth, while favouring PQC for broad modern-system migration. It warns against allowing QKD expenditure to displace more immediate cybersecurity work.
Source: ANSSI, Should Quantum Key Distribution be Used for Secure Communications?, May 2020. MesServicesCyber
[P] The January 2024 joint European position prioritises PQC and suitable symmetric-key approaches, and identifies practical assurance work still required for QKD protocols and devices. Its discussion includes finite-key security, physical attacks and evaluation methods. It also recognises existing ISO/IEC evaluation standards and BSI-supported protection-profile work; standards activity should therefore be distinguished from certification of a particular installed network.
Source: ANSSI, BSI, NLNCSA and Swedish NCSA, Joint position paper, official Dutch publication, January 2024. aivd.nl
The recommended QKD acquisition review should examine the following boundaries:
| Assurance boundary | Required evidence before acceptance |
|---|---|
| Peer identity | How the classical channel is authenticated |
| Device model | Which source, detector and calibration assumptions underpin the proof |
| Finite-key operation | Security parameters for the actual block sizes and operating conditions |
| Intermediate nodes | Which locations must remain trusted and physically protected |
| Payload protection | Whether keys feed AES or another specified mechanism |
| Availability | Behaviour under fibre interruption, optical disturbance and key exhaustion |
| Maintenance | How firmware, calibration and defective components are replaced |
| Endpoint security | How plaintext and keys are protected after delivery |
| Accreditation | The authority, evaluation scope and approved configuration |
[H] A claim of an “unhackable link” should be retired when it substitutes a protocol-level theoretical property for evidence covering these boundaries.
5.10. QSDC and quantum networks: measured results, bounded interpretations
[D] A 2022 quantum-secure direct communication experiment reported the following results using time-bin and phase states:
| Experimental configuration | Reported loss | Reported secure communication rate |
|---|---|---|
| 30 km commercial fibre | 6 dB | 22.4 kbit/s |
| 100 km ultralow-loss fibre | 15.8 dB | 0.54 bit/s |
The protocol carries information through a quantum communication construction rather than merely distributing keys. These results establish operation under the paper’s conditions; they do not establish a general-purpose replacement for high-throughput communications.
Source: Long and colleagues, Realization of quantum secure direct communication over 100 km fiber with time-bin and phase quantum states, Light: Science & Applications, April 2022. PMC
[D] A separate 2024 experiment entangled diamond-based quantum-memory nodes through a 35 km deployed telecom fibre loop, reporting nuclear-spin Bell-state fidelity of 0.69(7) after error detection. Fibre-path length should not be recast as straight-line separation between the nodes.
Source: Knaut and colleagues, Entanglement of nanophotonic quantum memory nodes in a telecom network, Nature, May 2024. Nature
Recommended interpretation: assess three different deliverables separately:
| Deliverable | Appropriate acceptance question |
|---|---|
| QKD key service | Does the installed system deliver usable keys with the required assurance and availability? |
| QSDC communication service | Does the protocol provide the required protected payload rate under its stated assumptions? |
| Memory-based quantum network | Can nodes establish, retain and use entanglement across the intended architecture? |
[H] Evidence for one deliverable does not establish the other two. In particular, a long trusted-node QKD route is not evidence of a memory-based quantum repeater network.
5.11. Migration governance: the instrument and its scope matter
[P] The June 2026 US executive order introduces differentiated requirements and prospective implementation actions:
| Provision | Specified action or target | Scope distinction |
|---|---|---|
| Section 4(b) | OMB guidance requiring PQC key establishment by 31 December 2030 | Federal HVAs and high-impact systems; excludes NSS |
| Section 4(b) | PQC digital signatures by 31 December 2031 | Same specified system categories |
| Section 4(c) | NIST migration pilot completed by 31 December 2027 | Appropriate subset of NIST systems |
| Section 5(c) | NSA migration reporting within 180 days and annually thereafter | Separate national-security-system reporting path |
| Section 5(d) | Public cryptographic-bill-of-materials guidance within 270 days | CISA-led guidance action |
| Section 6(c) | Proposed FAR rule within 180 days, addressing covered-contractor compliance by 2030 | Direction to propose a rule, not evidence of an already effective contract clause |
Source: White House, Executive Order 14412: Securing the Nation Against Advanced Cryptographic Attacks, June 2026. The White House
[P] The European Commission’s coordinated roadmap provides a framework for member-state transition planning. It should be read as a coordination instrument, with implementation responsibilities assessed through the relevant national authorities.
Source: European Commission, Una tabella di marcia coordinata per l’attuazione della transizione alla crittografia post-quantistica, June 2025, page updated September 2026. Plasmare il futuro digitale dell’Europa
[P] NCSC’s migration guidance describes discovery and planning as substantial work, potentially taking two to three years in large organisations. That supports beginning dependency discovery early; it does not establish an identical project duration for every owner.
Source: UK NCSC, Timelines for migration to post-quantum cryptography, March 2025. National Cyber Security Centre
Recommended governance rule: keep an instrument register recording jurisdiction, system category, issuing authority, binding status, implementation milestones and permitted exceptions. A deadline without its scope should not enter an acquisition specification.
5.12. Asset-class decision table
The following is a recommended decision framework, not a claim that every organisation has the same secrecy periods or legal obligations. Lifetimes must be supplied by the information and system owners.
| Asset class | Lifetime to establish | Migration priority | Recommended control | QKD consideration |
|---|---|---|---|---|
| Intelligence identities and relationships | Period during which disclosure can endanger people or operations | Highest where exposed traffic carries enduring secrets | Approved PQC or symmetric arrangements; reduce unnecessary retained copies | Only within an explicitly authorised threat model |
| Genomic and longitudinal health records | Remaining period of personal and institutional sensitivity | High where records or transfers have long retention | PQC establishment, suitable symmetric protection and storage-key governance | Requires a specific fixed-link justification |
| Strategic research and industrial designs | Remaining commercial or strategic value | High for valuable material exposed across organisational boundaries | PQC transfer paths and protected archival keys | Possible additional control on a bounded link |
| Firmware roots of trust | Remaining equipment life | High for devices with difficult or immutable verifier replacement | Signature migration or hardware replacement plan | Does not replace firmware-signature work |
| Payment infrastructure | Transaction security and infrastructure service life | High because transition must preserve continuity | PQC signatures and establishment with interoperability testing | Does not replace signature migration |
| Critical-infrastructure administration | Service life and consequences of unauthorised control | High where cryptographic dependencies support remote administration | Approved migration, segmentation and controlled recovery | Assess only as a supplementary channel |
| Routine short-lived sessions | Actual sensitivity beyond session completion | Prioritise through exposure and policy | Supported PQC protocol implementation | Requires evidence of additional value |
| Fixed inter-site links | Information lifetime and accepted endpoint/node trust | Case-specific | PQC and authenticated symmetric payload protection | Consider only after assurance and availability review |
| Offline archives | Retention and future verification requirements | Separate confidentiality and authenticity assessments | Key rewrapping, preservation and trust-renewal procedures | Does not resolve offline archival verification |
5.13. AI-assisted cryptanalysis: assess the named scheme
[C] NIST’s maintained PQC page reports a July 2026 announcement that an AI model helped identify a vulnerability in the candidate signature scheme HAWK. [P] It records the candidate’s subsequent withdrawal. NIST explicitly states that this finding does not affect its finalised ML-KEM and ML-DSA standards.
Source: NIST, Post-quantum cryptography — current standards and HAWK notice, notice concerning July 2026, retrieved October 2026. NIST
Recommended interpretation: demand the attacked scheme, parameter set, vulnerability class, reproducibility and attack cost. An algorithmic weakness, a coding error and a side-channel attack should produce different corrective actions.
[H] “AI has broken PQC” is an unsupported generalisation when the evidence concerns one named candidate or implementation. The appropriate institutional response is to review the affected dependency and preserve replacement capability.
Chapter 5 — Key judgments
- [P] Completed standards provide an actionable migration foundation, while deployment assurance remains a separate obligation. The decision changed is whether to begin integration work now. See NIST FIPS 203.
- [P] Agency positions support broad PQC migration and impose substantial qualifications on QKD use. The decision changed is whether a proposed QKD acquisition can satisfy the owner’s actual assurance requirements. See NSA’s scoped position.
- [R] Logical-circuit estimates establish conditional computational requirements, not a functioning adversarial service. The decision changed is how to report cryptanalytic risk without equating physical-qubit counts with attack capability. See the P-256 resource study.
What would change the assessment
A reproducible attack against a finalised scheme at relevant parameters; an implementation vulnerability affecting a widely deployed product; a complete physical attack estimate with validated error-correction assumptions; or a QKD deployment demonstrating assurance and continuity adequate for the relevant authority.
Open official record
The important unresolved questions concern inventory completeness, installed-verifier replacement, implementation validation, exception management and independently audited migration completion. The instruments cited above do not establish that their covered organisations have already completed those tasks.
Chapter 6 — Civilian Uses That Are Real
6.1. Civilian evidence should be evaluated at the level of the named service
Recommended assessment: distinguish scientific performance, integration into an existing workflow and evidence that the workflow produces a useful operational outcome. A sector partnership should enter the register as a partnership; a hardware experiment as an experiment; and an accredited service only when its authorisation and operating scope are documented.
| Civilian application | Named evidence | Technical readiness assessment | Institutional readiness assessment |
|---|---|---|---|
| Payment-system PQC | BIS Project Leap phase 2 | Integrated pilot in an operating payment environment | Central-bank and infrastructure-owner participation |
| Metropolitan QKD service | Toshiba–BT trial involving HSBC | Named service trial; technical assurance requires separate evidence | Commercial operator and named customer |
| Pharmaceutical computation | IBM–Moderna mRNA study | Hardware research experiment | Research collaboration; no clinical-service conclusion |
| Utility communications | Published trusted-node QKD experiment | Limited field demonstration on utility fibre | Research and utility integration |
| Airborne gravity surveying | GIRAFE/iMAR Iceland–Greenland campaign | Field experiment with classical comparison | Scientific survey programme |
| Biomedical sensing | Wearable optically pumped MEG | Integrated human research prototype | Research use; accreditation not established by the paper |
| Magnetic navigation | April 2025 author preprint | Author-reported airborne and ground trials | Development activity; operational authorisation not established |
| Time metrology | PTB realisation and dissemination of the second | Established atomic-metrology function | Statutory national-metrology responsibility |
The supporting records and limitations are examined below. These classifications should not be read as official technology-readiness-level assignments.
6.2. Finance: migration testing has a clearer operational purpose than a generic quantum-computing pilot
[P] Project Leap phase 2 involved the BIS Innovation Hub, Banca d’Italia, Banque de France, Deutsche Bundesbank and infrastructure participants. [C] Its December 2025 report describes testing PQC signatures in an operational payment system while sending liquidity transfers, and reports integration and performance differences requiring attention.
The evidence is significant because the experiment addresses a concrete security function inside payment infrastructure. It does not establish system-wide production migration or quantum-computing advantage in financial optimisation.
Source: BIS Innovation Hub, Project Leap phase 2: quantum-proofing payment systems, December 2025. “Quantum-proofing” here means migration to post-quantum cryptography. bis.org
Recommended next-stage financial assessment:
| Test area | Measurement to request | Acceptance purpose |
|---|---|---|
| Transaction completion | Success and failure rates under representative load | Establish continuity of the payment service |
| Signature verification | Median and tail latency on each receiving platform | Detect heterogeneous implementation bottlenecks |
| Message handling | Actual signed-message sizes and parser behaviour | Identify incompatible interfaces |
| Peak demand | Throughput during stress periods | Establish capacity requirements |
| Recovery | Behaviour after partial upgrade or signing-service failure | Establish controlled continuity |
| Participant interoperability | Results across institutions and implementations | Avoid a pilot that works only within one configuration |
| Auditability | Ability to reconstruct algorithm and key use | Preserve security accountability |
The recommended financial decision is to expand bounded migration pilots into representative operational testing. Claims about portfolio optimisation, pricing or settlement acceleration should require their own computational evidence and should not inherit credibility from a successful cryptographic trial.
6.3. Telecom: service availability, security assurance and quantum networking are different deliverables
[C] Toshiba’s Japanese-language announcement identifies HSBC as a participant in the Toshiba–BT metropolitan QKD commercial trial service in London. The announcement describes a named operator, customer and fibre-based service arrangement. It does not independently establish every security or availability property of the installed service.
Source: Toshiba, 東芝とBTによる量子暗号通信の商用メトロネットワークのトライアルサービスに金融大手HSBCが参画, July 2023. The mechanism is QKD supplying cryptographic keys. 東芝デジタルソリューションズ
Recommended operator evidence package:
| Service dimension | Required documentation |
|---|---|
| Physical route | Actual optical path, attenuation, permitted switching and maintenance conditions |
| Key delivery | Delivered secret-key rate, buffer behaviour and exhaustion policy |
| Customer isolation | Separation of key material and management interfaces |
| Endpoint trust | Protection of key-management systems and customer encryptors |
| Intermediate trust | Named trusted nodes and their protection requirements |
| Availability | Scheduled maintenance, failure modes and recovery results |
| Security evaluation | Applicable protocol proof and installed-device assessment |
| Commercial support | Replacement times, spares, software support and liability allocation |
The recommended purchasing question is whether the additional key service improves the customer’s defined assurance case at an acceptable operational cost. It should not be reduced to whether the operator can use the word “quantum” in a service description.
6.4. Pharma: hardware experiments should retain their actual problem size
[D] The IBM–Moderna mRNA secondary-structure study, recorded as a QCE 2025 conference paper, reports IBM hardware experiments using up to 156 qubits and 950 nonlocal gates for sequences up to 60 nucleotides. Its workflow combines quantum sampling with classical training or post-processing.
[C] The publication record describes noiseless tensor-network simulations up to 358 qubits, while the May 2025 preprint states 354 qubits. These are separately versioned simulation statements, not a larger hardware experiment.
Sources: IBM Research, Towards secondary structure prediction of longer mRNA sequences using a quantum-centric optimization scheme, August 2025; and May 2025 author preprint. IBM Research
| Evidence item | Classification | Permitted interpretation |
|---|---|---|
| Quantum-processor experiment | [D] | The stated hybrid workflow ran at the reported hardware scale |
| Noiseless tensor-network calculation | [C], reported simulation | A classical simulation explored a larger representation |
| Biological usefulness | [R], further validation required | Must be assessed against experimentally relevant structure and function |
| Clinical benefit | [R], not established here | Requires evidence connecting the workflow to a therapeutic outcome |
| General drug-discovery acceleration | [H] if inferred from this experiment alone | Exceeds the demonstrated task and problem size |
Recommended continuation: require competitive classical baselines, full elapsed workflow time, sampling costs, reproducibility and biological validation. The research question is whether the quantum component improves a relevant endpoint once the entire hybrid process is counted.
| Proposed benchmark | Why it matters |
|---|---|
| Best available classical method for the same formulation | Establishes the actual comparison |
| Alternative biological formulations | Tests whether the chosen optimisation objective is useful |
| Total wall-clock time | Includes training, queueing, execution and post-processing |
| Solution quality distribution | Prevents selection of only favourable runs |
| Scaling with sequence length | Tests whether the demonstrated regime extends usefully |
| Laboratory biological validation | Connects computational output to the intended scientific purpose |
6.5. Energy: the utility network is a deployment environment, not evidence of grid optimisation
[D] A published trusted-node QKD study integrated three QKD systems on real electrical-utility fibre and examined interoperability and key-rate behaviour. It is evidence for field integration of communication-security components.
It does not establish quantum-computing advantage for dispatch, state estimation or power-system optimisation.
Source: ORNL, Trusted Node QKD at an Electrical Utility, IEEE Access, 2021. ORNL
Recommended energy-sector separation:
| Proposed activity | Security or operational endpoint to assess |
|---|---|
| QKD-assisted utility communications | Assured key delivery and acceptable availability |
| PQC migration of administrative access | Authorised remote access across the installed estate |
| Quantum optimisation experiment | Improved solution quality or time against competitive classical methods |
| Quantum materials calculation | Validated prediction relevant to a specified material |
| Quantum sensing near infrastructure | Reliable measurement under the actual environmental conditions |
For a utility, a communication-security experiment should advance only after examining outage behaviour, maintenance access, trusted sites and compatibility with operational equipment. A computational experiment should advance through a separate performance and usefulness review.
6.6. Gravity surveying: field data support a bounded application
[D] The Iceland–Greenland airborne campaign used the GIRAFE cold-atom gravimeter alongside an iMAR classical strapdown instrument, with flights conducted in June–July 2023. The 2025 publication reports accuracy around 1–2 mGal, depending on flight conditions, for both systems. The campaign also used GNSS receivers.
Source: Jensen and colleagues, Airborne gravimetry with quantum technology: observations from Iceland and Greenland, Earth System Science Data, April 2025. essd.copernicus.org
| Reported feature | Assessment |
|---|---|
| Airborne cold-atom instrument | [D] Field operation under survey conditions |
| Classical instrument in the campaign | [D] Relevant comparative evidence |
| Approximately 1–2 mGal accuracy | [D] Campaign-specific result, affected by conditions |
| GNSS-supported survey | [D] Navigation support present |
| Autonomous navigation without GNSS | [H] Not established by this campaign |
For scale, 1 mGal equals \(10^{-5}\,\mathrm{m\,s^{-2}}\). This is a unit conversion, not an additional experimental result.
Recommended interpretation: evaluate where the instruments’ differing error characteristics improve a combined survey product. Require repeatability, calibration burden, spatial resolution, operating cost and comparison across representative flight conditions before asserting a commercial advantage.
6.7. Biomedical sensing: a human research instrument has been demonstrated
[D] A 2018 wearable magnetoencephalography experiment combined optically pumped quantum sensors with background-field control and measured brain activity while participants moved naturally. It established a human research prototype with capabilities different from a fixed superconducting-sensor arrangement.
Source: Boto and colleagues, Moving magnetoencephalography towards real-world applications with a wearable system, Nature, March 2018. Nature
Recommended clinical assessment: distinguish the ability to record a signal from the ability to support a validated diagnostic or treatment decision.
| Clinical-development gate | Required evidence |
|---|---|
| Measurement repeatability | Consistent results across sessions and operators |
| Patient suitability | Performance across the intended population |
| Environmental tolerance | Defined shielding and field-control requirements |
| Diagnostic relevance | Validation against the intended clinical endpoint |
| Workflow integration | Setup, acquisition, interpretation and cleaning procedures |
| Regulatory status | Authorisation for the specified use and configuration |
| Supportability | Calibration, maintenance and fault-detection arrangements |
[H] A demonstrated wearable MEG research system should not automatically be described as an accredited routine clinical service.
6.8. Civil PNT: magnetic-navigation reports merit testing, not universal performance claims
[C] An April 2025 author preprint reports airborne and ground magnetic-navigation trials using quantum magnetometers, denoising and map matching. It reports a best final airborne positioning result of 22 m, flights up to 19,000 feet, and improvements relative to the specified velocity-aided inertial comparator.
These remain author-reported results in the retrieved preprint. They do not establish certification for civil aviation or performance across every route and platform.
Source: Muradoglu and colleagues, Quantum-assured magnetic navigation achieves positioning accuracy better than a strategic-grade INS in airborne and ground-based field trials, April 2025 preprint. arxiv.org
Recommended PNT acceptance framework:
| Dimension | Proposed measurement |
|---|---|
| Accuracy | Position-error distribution across the complete route |
| Integrity | Ability to detect and report misleading position estimates |
| Continuity | Duration and frequency of lost or unreliable fixes |
| Map dependence | Sensitivity to coverage, resolution and map uncertainty |
| Platform interference | Performance under representative payload and configuration changes |
| Route diversity | Results over terrain with different magnetic characteristics |
| Reference truth | Independent reconstruction of the trial trajectory |
| Recovery | Behaviour after prolonged ambiguity or sensor interruption |
The fusion and map-matching contribution should be measured separately from the sensor contribution where feasible. This is the appropriate place to test algorithmic acceleration; it does not remove the need to validate the physical measurement or reference map.
6.9. Metrology: established atomic timing and deployable advanced clocks have different readiness
[P] PTB documents its national responsibility for realising and disseminating the SI second through its time-metrology work. That established institutional function should be distinguished from the readiness of a particular transportable optical or cold-atom clock.
Source: PTB, Realisation of the SI second, maintained institutional page, retrieved October 2026. PTB.de
Recommended assessment: require the complete uncertainty and dissemination chain. A clock’s internal performance is only one part of the service delivered to a telecommunications node, financial timestamping system or remote instrument.
| Metrology layer | Evidence to request |
|---|---|
| Frequency reference | Calibration and uncertainty budget |
| Clock output | Stability and accuracy over relevant averaging periods |
| Time transfer | Distribution-path uncertainty |
| Customer interface | Delivered timing performance |
| Environmental operation | Temperature, vibration and power sensitivity |
| Maintenance | Recalibration and intervention requirements |
| Service continuity | Holdover and recovery behaviour |
Chapter 6 — Key judgments
- [P]/[C] Named financial and telecom pilots show institutional engagement with concrete security services. They do not establish migration of an entire sector. See Project Leap phase 2.
- [D] Selected sensing and surveying applications have physical field or human-system evidence. Their useful operating envelopes must remain attached to the result. See the airborne gravity campaign.
- [D] Pharmaceutical computation has identifiable hardware experiments, but the cited study does not establish a clinical outcome. See the QCE 2025 publication record.
What would change the assessment
Independent operational replication; representative baseline comparisons; published service-level performance; documented accreditation; and evidence that the quantum component improves the intended outcome after integration and maintenance costs are included.
Open official record
The major missing items are often outside the scientific paper: sustained availability, total ownership cost, installed-base compatibility, authorisation scope and measured outcomes under ordinary operating conditions.
Chapter 7 — Military and Intelligence Uses That Are Real
7.1. Mission evidence must connect the component to an operational decision
Recommended assessment: organise defence applications around the mission effect, then examine the sensor or cryptographic mechanism. Each programme should state what the operator can do differently, under which conditions and with what confidence.
The technical and institutional axes must remain separate:
| Technical evidence | Institutional evidence needed for a stronger operational conclusion |
|---|---|
| Laboratory sensitivity | Written mission requirement |
| Integrated prototype | Representative platform and environmental testing |
| Limited field trial | Operator evaluation and acceptance criteria |
| Repeated mission trial | Acquisition decision and support arrangements |
| Series equipment | Training, calibration, spares and configuration control |
| Accredited deployment | Authorised operating scope and continuing assurance |
This is a proposed evidentiary progression, not a claim that every programme must follow an identical procurement sequence.
7.2. Timing: current naval evidence includes integration trials
[C] The Royal Navy’s August 2026 report describes trials involving cold-atom clocks, Saab Giraffe 1X radar equipment, testing at Portsdown Hill and associated industry sites, and rebroadcast activity involving XV Patrick Blackett. It describes simulated GNSS interference and investigation of timestamp alignment.
The report does not publish a complete holdover specification, establish fleet deployment or demonstrate immunity to every form of timing disruption.
Source: Royal Navy, Royal Navy’s technology experts work with industry to test quantum clock in milestone trials, August 2026. royalnavy.mod.uk
[C] A separate June 2025 report describes AQlock trials aboard HMS Puncher. It establishes a named maritime trial, rather than a publicly specified operational timing service.
Source: Royal Navy, Quantum navigation technology takes next step after trial on Royal Navy P2000, June 2025. royalnavy.mod.uk
[C] Dstl’s February 2026 report describes extended unattended operation in conditions intended to be more representative of deployment. [R] It identifies further trials as a prospective development step.
Source: Dstl, Trial speeds up next generation of atomic clocks, February 2026. GOV.UK
| Named evidence | Technical readiness judgment | Institutional readiness judgment | Limitation |
|---|---|---|---|
| Royal Navy radar-clock trial | Limited integration trial | Service-owned evaluation | Public performance specification incomplete |
| HMS Puncher clock trial | Limited maritime field trial | Named naval platform and partners | No fleet-wide acceptance conclusion |
| Dstl unattended-operation work | Component and device evaluation | Defence research ownership | Operational endurance specification not established |
7.3. Distributed radar and SIGINT: delivered timing is the relevant metric
[R] The cited clock trials support further evaluation of timing services for distributed sensing. They do not, by themselves, establish the accuracy of a complete radar or signals-intelligence network.
Recommended acceptance tests:
| Timing function | Proposed requirement to measure |
|---|---|
| Local frequency stability | Performance over mission-relevant averaging intervals |
| Holdover | Time error accumulated after external-reference loss |
| Node synchronisation | Relative timing error between deployed nodes |
| Distribution | Delay variation and asymmetry in the transfer path |
| Timestamp generation | Error at the actual sensor or receiver interface |
| Recovery | Behaviour when the external reference returns |
| Fault indication | Whether operators receive timely warning of degraded assurance |
| Sustainment | Calibration interval and required technical intervention |
A useful physical conversion is
For a one-way propagation interpretation, one nanosecond corresponds to approximately 0.30 m. A monostatic round-trip radar interpretation introduces the appropriate factor of two. These are arithmetic relationships, not performance specifications for the naval trials.
Recommended decision: define the required error at the measurement endpoint before selecting a clock. The acquisition should demonstrate that the distribution architecture preserves the necessary performance under representative disruption.
7.4. Contested-spectrum PNT: robust integration is a funded research problem
[P] DARPA’s Robust Quantum Sensors — RoQS programme explicitly addresses the difficulty of operating quantum sensors under motion, vibration and electromagnetic disturbance. Its programme instrument includes solicitation DARPA-PS-25-11.
[R] The phase-one announcement describes prospective testing with a government-provided helicopter and platform-integration studies, including ground vehicles, submarines, satellites and uncrewed aircraft. Planned testing should not be reported as a completed mission demonstration.
Sources: DARPA, RoQS: Robust Quantum Sensors, maintained programme page; and RoQS launches first phase, August 2025. DARPA
Recommended contested-PNT review:
| Navigation dependency | Proposed stress test |
|---|---|
| Inertial sensor | Representative motion, vibration and thermal transitions |
| Magnetic sensor | Platform-generated fields and changing configuration |
| Reference map | Missing, inaccurate and spatially ambiguous data |
| Fusion software | Sensor disagreement and misleading inputs |
| Timing source | External-reference loss and recovery |
| Position solution | Long routes with independent ground truth |
| Operator interface | Clear indication of degraded confidence |
| Support system | Field recalibration and replacement procedures |
[H] “GNSS-independent” should not be accepted as proof of immunity to navigation deception, environmental interference or estimation failure. The acquisition authority should identify which external dependencies have been removed and which remain.
7.5. ASW and magnetic anomaly detection: a candidate mission requires its own target evidence
[R] RoQS identifies submarine platform-integration studies as a prospective area. That is evidence of programme interest in platform suitability; it does not establish an anti-submarine detection capability or a detection range.
Source: DARPA, RoQS launches first phase, August 2025. DARPA
Recommended ASW evidence package:
| Mission question | Required trial information |
|---|---|
| What was detected? | Target class, configuration and relevant signature |
| At what geometry? | Sensor–target relationship and trajectory |
| Against what background? | Environmental and platform interference |
| With what detection probability? | Results at a specified false-alarm rate |
| With what localisation quality? | Position uncertainty and track continuity |
| Against which comparator? | Relevant conventional sensor and processing chain |
| Under what disclosure limits? | Publicly releasable scope of the conclusion |
| With what sustainment burden? | Calibration, platform compensation and maintenance |
[H] A laboratory magnetometer sensitivity cannot be converted directly into an ASW range. Sensitivity is an instrument property; detection and classification require a target signature, background model and decision threshold.
Recommended decision: fund blinded, representative target trials before assigning mission capability. Where target details cannot be released, public reporting should still distinguish a research milestone from an accepted operational system.
7.6. Tunnel and void detection: civil proof of measurement is not military target identification
[D] The Birmingham gravity-cartography experiment demonstrated outdoor detection of a two-metre tunnel, reporting 20 E statistical uncertainty and 0.5 m spatial resolution across an 8.5 m survey line. The published result also includes substantial uncertainty in inferred depth.
Source: Stray and colleagues, Quantum sensing for gravity cartography, Nature, February 2022. University of Birmingham
[R] This supports further evaluation for subsurface survey missions. It does not establish reliable military identification of arbitrary underground structures.
Recommended military trial design:
| Trial element | Purpose |
|---|---|
| Blinded target inventory | Prevent prior knowledge from determining interpretation |
| Multiple depths and geometries | Test the usable operating envelope |
| Geological variation | Measure background ambiguity |
| Non-target anomalies | Establish false-alarm performance |
| Survey-time constraint | Test whether the method fits the mission |
| Competing instruments | Establish comparative value |
| Independent excavation or reference survey | Confirm the inferred structure |
| Operator replication | Test dependence on specialist interpretation |
The acceptance endpoint should be a specified detection or classification outcome with uncertainty. A successful measurement of a gravity anomaly should not automatically count as identification of its cause.
7.7. RF reception: a programme target must not become a claimed deployed capability
[P] DARPA’s Quantum Apertures programme investigated Rydberg-atom RF receivers. Its current reference page identifies the programme as complete, but does not publish evidence that every stated performance objective was achieved.
[R] The 2021 team-selection announcement described targets including reception over 10 MHz to 40 GHz or more, directionality, sensitivity and compact packaging. Those numbers are programme objectives, not a verified specification for a fielded SIGINT receiver.
Sources: DARPA, QA: Quantum Apertures, completed-programme reference page; and DARPA Selects Research Teams to Enable Quantum Shift in Spectrum Sensing, 2021. DARPA
Recommended RF evaluation:
| Performance dimension | Required distinction |
|---|---|
| Frequency coverage | Tunable coverage versus instantaneous bandwidth |
| Sensitivity | Performance for the stated modulation and integration time |
| Dynamic range | Behaviour with strong nearby signals |
| Direction finding | Angular performance of the complete receiver architecture |
| Waveform recovery | Successful demodulation of representative signals |
| Retuning | Time needed to change operating frequency |
| Packaging | Complete optical, control, power and thermal system |
| Field operation | Temperature, vibration and electromagnetic tolerance |
[H] A statement that a receiver can be tuned across a broad range should not be restated as simultaneous interception of that entire range.
7.8. Quantum radar: prospective defence work is not an operational radar record
[P] Canada’s Quantum 2030 implementation plan identifies defence research missions including quantum radar, quantum lidar, algorithms and networking. [R] It states a TRL 7 by 2030 ambition. This is a programme objective, not a completed capability.
Source: Canadian Department of National Defence, Quantum S&T Strategy Implementation Plan, March 2023. Canada.ca
Recommended radar assessment: carry forward the mechanism analysis from Pillar I, then require evidence at the full-system boundary. Relevant tests should specify transmitted energy, bandwidth, target, range, background, integration time, detection probability and false alarms.
| Claimed result | Evidence required |
|---|---|
| Improved sensitivity | Matched-resource comparison with a suitable classical receiver |
| Improved target detection | Representative target and clutter trial |
| Resistance to countermeasures | Named countermeasure and measured outcome |
| Operational range | Full link budget and field evidence |
| Compact deployable equipment | Complete system size, weight, power and environmental results |
| Mission readiness | Acceptance authority, operating scope and support arrangements |
[H] A defence research mission labelled “quantum radar” does not establish long-range detection of stealth platforms. Such a conclusion requires its own system and target evidence.
7.9. Communications: migration authority and network experimentation serve different purposes
[P] NSA’s current resource page identifies CNSS Policy 15, released in March 2025, and the CNSA Suite 2.0 materials as the relevant national-security cryptographic instruments. National-security owners should use those applicable profiles rather than assume that general-purpose NIST defaults satisfy their requirements.
Source: NSA, Post-Quantum Cybersecurity Resources, maintained page, retrieved October 2026. nsa.gov
[P] NATO’s quantum strategy identifies transition toward quantum-resistant cryptography as an alliance concern. [R] Its desired outcomes and possible future quantum-communications contributions should not be read as evidence that allied systems have already completed migration.
Source: NATO, Summary of NATO’s Quantum Technologies Strategy, January 2024. NATO Official text
Recommended national-security migration controls:
| Control area | Evidence to require |
|---|---|
| Governing profile | Applicable authority and approved algorithms |
| Equipment inventory | Cryptographic dependencies by device and service |
| Tactical constraints | Representative bandwidth, loss and disconnection tests |
| Coalition interoperability | Authorised peer configurations and transition arrangements |
| Trust anchors | Verifier replacement and certificate-hierarchy plan |
| Key management | Approved provisioning, storage and destruction procedures |
| Configuration assurance | Evidence that installed equipment uses the approved profile |
| Exceptions | Named owner, residual risk and retirement date |
| Sustainment | Support for long-lived and difficult-to-access equipment |
[R] Early memory-based quantum-network experiments remain relevant to future network research, but the Chapter 5 demonstration does not establish an accredited military communications service. Its evidence should remain attached to the physical experiment, not multiplied into a mission claim.
7.10. Intelligence exposure: retained secrets and operational trust require separate priorities
Recommended intelligence assessment: divide the exposure register into three classes:
| Exposure class | Assessment question | Proposed priority |
|---|---|---|
| Retained confidentiality | What intercepted information would remain valuable years later? | Protect enduring identities, relationships and strategic information |
| Live operational authentication | Which future messages, software or authorities must remain trustworthy? | Migrate signatures, identities and verification paths |
| Archived evidentiary authenticity | How will historical records retain verifiable provenance? | Preserve trust state and define renewal procedures |
The recommended collection-risk review should identify which communications are plausibly obtainable, how long their contents remain consequential, and whether the vulnerable cryptographic dependency lies in session establishment, storage or an upstream key-wrapping layer.
The response should then match the exposure. Re-encrypting a local archive cannot recall copies already intercepted. Replacing a network establishment mechanism does not update an offline firmware verifier. Reducing unnecessary retention can lower exposure, but it does not establish secure authentication.
These are planning distinctions, not claims about a particular intelligence service’s holdings or computing capability.
7.11. Computing: a defence owner does not establish mission advantage
[P] Canada’s implementation plan includes a quantum-algorithms mission. [R] Its prospective application objectives require later technical and operational validation; the programme’s existence does not demonstrate a useful military optimisation service.
Source: Canadian Department of National Defence, Quantum S&T Strategy Implementation Plan, March 2023. Canada.ca
Recommended computational evidence package:
| Field | Required content |
|---|---|
| Mission problem | Exact decision or calculation being supported |
| Instance size | Full problem dimensions and constraints |
| Encoding | Reduction and data-preparation costs |
| Hardware | Processor, qubit type and execution conditions |
| Resources | Circuit depth, samples and applicable error correction |
| Comparator | Competitive classical algorithm on relevant hardware |
| Total time | Complete workflow elapsed time |
| Output quality | Objective value, accuracy or useful decision metric |
| Robustness | Behaviour across representative instances |
| Reproducibility | Data, code and sufficient methodological detail |
[H] A small scheduling demonstration, a synthetic optimisation instance or a defence-funded processor should not be described as a mission advantage without this comparison.
The recommended defence investment should pursue well-defined research questions and preserve the ability to stop work when improved classical methods remove the hypothesised advantage.
7.12. Military readiness register
This register consolidates the assessment without treating research ownership as procurement or doctrine.
| Application | Best evidence examined in this block | Technical readiness judgment | Institutional readiness judgment | Current claim boundary |
|---|---|---|---|---|
| Naval advanced clocks | [C] Named sea and integration trials | Limited field and integration trials | Service-owned evaluation | No fleet-wide timing specification established |
| Distributed radar timing | [C] Radar-clock trial | Integration trial | Named defence and industry participants | No complete operational-network result established |
| Robust quantum sensing | [P] RoQS | Research and prospective platform testing | Funded programme and solicitation | Planned test is not a completed trial |
| ASW-related sensing | [R] Candidate mission inference | Mission performance not established | Platform-study interest | No justified detection-range claim |
| Tunnel detection | [D] Civil outdoor experiment | Demonstrated survey experiment | Military acceptance not established by cited evidence | No general target-identification capability |
| Rydberg RF reception | [P] Quantum Apertures | Programme research; field specification unresolved | Completed research programme | Objectives are not an accredited receiver specification |
| Quantum radar | [P]/[R] Canadian programme and target | Operational mission result not established here | Defence research ownership | No operational long-range radar conclusion |
| NSS cryptographic migration | [P] Applicable policy instruments | Implementation depends on system | Formal security authority | Policy does not establish completed estate migration |
| Experimental quantum networks | [D] Physical experiment discussed in Chapter 5 | Experimental network integration | Military service ownership not established | No accredited military network conclusion |
| Military quantum algorithms | [P]/[R] Named research mission | Application-specific validation required | Defence research ownership | No general mission advantage established |
7.13. The next funding gate should require evidence that resolves a mission uncertainty
Recommended acquisition discipline:
| Funding gate | Evidence to request | Decision enabled |
|---|---|---|
| Component continuation | Repeatable performance under specified conditions | Whether the physical mechanism warrants integration |
| Platform integration | Representative motion, noise and environmental testing | Whether the device is suitable for the platform |
| Mission experiment | Blinded targets and relevant comparators | Whether the system changes an operational outcome |
| Pre-procurement evaluation | Reliability, maintainability and reproducibility | Whether acquisition is justified |
| Operational acceptance | Authorised configuration, training and logistics | Whether the service can be relied upon |
| Expansion | Repeated performance across platforms and locations | Whether initial success generalises |
For timing, the gate should resolve delivered holdover and synchronisation performance. For navigation, it should resolve position integrity across representative routes. For subsurface sensing, it should resolve detection and false alarms. For RF reception, it should resolve waveform recovery and dynamic range. For cryptography, it should resolve approved interoperability and installed configuration.
A programme should receive additional funding because the proposed experiment can settle a material uncertainty, rather than because its terminology fits a strategic theme.
Chapter 7 — Key judgments
- [C] The strongest current naval evidence examined here concerns named timing trials and integration work. It supports continued evaluation, with operational specifications still required. See the August 2026 Royal Navy trial report.
- [P] Robustness under platform conditions is an explicit funded research objective. The decision changed is whether to require representative testing before procurement. See DARPA RoQS.
- [P]/[R] Defence strategies and target dates establish institutional intent. They do not establish ASW range, operational quantum radar or computational mission advantage. See Canada’s implementation plan.
- [P] National-security cryptographic migration has identified policy authorities and should proceed through the applicable profiles and assurance processes. See NSA’s resource guidance.
What would change the assessment
Published representative mission trials; independent replication; detection results at specified false-alarm rates; delivered timing and navigation specifications; accredited communications configurations; series-production evidence; or computational results that outperform competitive classical methods on relevant mission instances.
Open official record
The decisive unresolved questions are performance under operational disturbance, sustained availability, maintenance burden, acceptance authority and transition from research ownership to procurement and doctrine. Public evidence examined here supports several concrete experiments and programmes; it does not support assigning them a common operational maturity.
Pillar III — Industrial Power, Conditional Outlook and Decisions
Chapter 8 — The Industrial and Geopolitical Layer
8.1. Industrial position should be assessed through control, reproducibility and continuity
The recommended unit of industrial assessment is the capability that a country, institution or supplier can reproduce, maintain and improve under realistic constraints. A national laboratory, an installed processor and a domestic company represent different forms of participation; none alone establishes control of the complete production chain.
For a cabinet office, the consequential question is whether the national programme can retain access to the technologies and people required for its chosen applications when commercial conditions, ownership, export permissions or technical requirements change. For an investor or acquisition authority, the corresponding question is whether the supplier can sustain the promised service beyond its initial demonstration.
| Assessment axis | Evidence to collect | Conclusion the evidence can support |
|---|---|---|
| Hardware design authority | Ownership or licensed control of architecture and design files | Ability to modify the system |
| Fabrication access | Qualified production process, contractual access and alternative capacity | Ability to produce additional devices |
| Component continuity | Supplier map, replacement paths and maintenance arrangements | Ability to sustain installed equipment |
| Integration competence | Repeated assembly, calibration and commissioning results | Ability to reproduce a working system |
| Software and control authority | Access to firmware, control interfaces, decoders and update procedures | Ability to maintain performance and security |
| Standards participation | Contributions, evaluation facilities and implementation experience | Ability to influence and implement interoperable requirements |
| Workforce continuity | Relevant skills, retention and succession arrangements | Ability to operate and improve the capability |
| Financial durability | Funds available against milestones and continuing operating costs | Ability to complete the programme and support its outputs |
| Mission ownership | Named user, requirement and acceptance authority | Ability to convert research into an adopted service |
Recommended interpretation: industrial sovereignty should be reported as a set of controlled dependencies. The phrase “sovereign quantum computer” should trigger an examination of design authority, production access, operating rights and supportability, rather than close that examination.
8.2. Public funding figures require an accounting classification before comparison
The financial register should distinguish at least six categories:
| Financial category | Meaning for the assessment | Error to avoid |
|---|---|---|
| Authorised envelope | Amount approved or permitted for a programme | Treating the entire envelope as expenditure |
| Budget request | Funding sought for a fiscal period | Treating a request as enacted funding |
| Budget authority or allocation | Funding made available under the relevant process | Treating it as money already used |
| Contracted commitment | Obligation under a specified agreement | Treating every commitment as an immediate cash payment |
| Released funds | Resources transferred to the implementing body | Treating transfer as completed technical work |
| Reported expenditure or utilisation | Resources recorded as spent or used | Treating spending as proof of capability |
[P] The US National Quantum Initiative’s FY2025 supplement explicitly separates historical expenditure, FY2024 enacted budget authority and the FY2025 request. Its reporting structure demonstrates why the categories should remain visible in an international comparison.
Source: US National Science and Technology Council, National Quantum Initiative Supplement to the President’s FY2025 Budget, December 2024. quantum.gov
8.3. Selected financial instruments: amounts, periods and limits
The following table records selected public instruments, not exhaustive national spending. The amounts are deliberately retained in their original currencies; converting them into dollars would not resolve differences in time horizon, scope or accounting status.
| Jurisdiction | Amount and period in the cited record | Accounting interpretation | Evidence classification and source |
|---|---|---|---|
| United States | US$1,036 million, FY2023; US$1,006 million, FY2024; US$998 million, FY2025 | Respectively reported expenditure, enacted budget authority and requested authority | [P] Historical federal QIS series, not a verified FY2026 total. FY2025 supplement, December 2024 |
| United Kingdom | £2.5 billion, ten years from 2024 | Strategy funding commitment across a multiyear programme | [P] Commitment does not establish expenditure to date. National Quantum Strategy, March 2023 |
| European Union | €1 billion for the Quantum Technologies Flagship | Long-term EU research initiative | [P] Programme scope differs from aggregate member-state spending. Commission quantum policy record |
| France | Additional €1 billion, announced for 2026–2030 | New investment announcement within the national strategy | [C] Announcement is not an independently audited disbursement record. DGE update, May 2026 |
| Germany | €2.18 billion federal funding, plus €282 million from scientific organisations, described in the 2023 parliamentary discussion | Financing associated with the action concept | [C] Parliamentary description; not a consolidated 2026 expenditure statement. Bundestag committee record, May 2023 |
| India | ₹6,003.65 crore, eight-year National Quantum Mission | Approved mission outlay | [P] Envelope must be separated from released and utilised amounts. Parliamentary response, February 2026, Hindi |
| Israel | NIS100 million, July 2026 infrastructure call | Named national R&D infrastructure initiative | [P] Call for proposals, not evidence that the proposed facility is already operational. Israel Innovation Authority, July 2026, Hebrew |
| Australia | A$940 million, joint Commonwealth–Queensland investment announced in April 2024 | Project-specific support for PsiQuantum in Brisbane | [P] Financial support; delivery of the intended computer remains a separate technical milestone. Government progress report, 2024 |
| Canada | C$360 million, seven years beginning in 2021–2022 | Incremental funding supporting the national strategy | [P] Does not encompass every related federal or provincial programme. National Quantum Strategy, French official version |
The cited records support the amounts and their classifications, but do not support adding the rows into a global expenditure total. quantum.gov
For China, Japan and Italy, the policy records examined below establish strategic direction or programme architecture. They do not supply a directly comparable, consolidated quantum-only expenditure series for this table. That is a limitation of the comparison, rather than a finding that the countries spend nothing.
8.4. India provides a useful example of financial implementation visibility
[P] A March 2026 parliamentary response distinguishes sanctioned, released and utilised funds for selected implementing institutions:
| Institution | Sanctioned through March 2031 | Released | Utilised | Utilised ÷ released |
|---|---|---|---|---|
| IISER Pune | ₹30.61 crore | ₹18.14 crore | ₹4.71 crore | 25.96% |
| IIT Bombay | ₹558.76 crore | ₹114.89 crore | ₹22.31 crore | 19.42% |
| TIFR Mumbai | ₹71.03 crore | ₹36.15 crore | ₹3.63 crore | 10.04% |
The percentages are this report’s arithmetic, calculated from the published amounts. The rows are not the complete mission budget.
Source: Government of India, Parliament question: women’s participation in quantum research and entrepreneurship, including fellowships, March 2026. Press Information Bureau
Recommended interpretation: these ratios should trigger an implementation review, rather than an automatic performance judgment. Funds sanctioned through 2031 cannot be compared with expenditure recorded in 2026 as if all technical deliverables were already due.
The review should examine procurement timing, facility construction, hiring, grant-release conditions and the relationship between expenditure and completed milestones. Financial visibility is valuable precisely because it permits those questions to be asked without substituting a headline envelope for evidence of implementation.
8.5. United States: evaluate the connection between research, verification and production
[P] The NQI budget supplement describes activities across federal agencies and records work on supply-chain analysis, enabling technologies and workforce development. Its scope is wider than the activities specifically authorised under the original NQI legislation.
Source: NSTC, FY2025 National Quantum Initiative supplement, December 2024. quantum.gov
[P] DARPA’s Quantum Benchmarking Initiative provides a separate verification mechanism. It seeks to determine whether an approach can achieve utility-scale operation by 2033, defining utility in terms of computational value exceeding cost. Its stages move from a system concept, through an R&D plan, to government verification and validation.
Source: DARPA, Quantum Benchmarking Initiative, maintained programme record, retrieved October 2026. DARPA
Analytical judgment: the important US policy distinction is between financing an approach and validating its complete economics. An acquisition authority should preserve that separation even when the supplier has a substantial private balance sheet or extensive scientific publications.
Recommended national assessment: examine whether verification findings can influence funding decisions, whether component suppliers have sustainable production paths, and whether trained personnel can move between research, manufacturing and operational support.
8.6. United Kingdom: mission targets are useful only when intermediate evidence remains visible
[P] The UK strategy commits funding to research hubs, accelerators and challenge-led innovation. [R] Its mission framework includes a 2035 computing objective of one trillion operations, with intermediate computing milestones in 2028 and 2032.
Sources: UK government, National Quantum Strategy, March 2023; and National Quantum Strategy Missions, November 2023. GOV.UK
Analytical judgment: a mission framework can connect scientific work with users, but its value depends on how “operations” are defined and whether intermediate systems meet complete workload requirements.
For the 2026–2031 assessment, the 2035 objective belongs outside the reporting window. The nearer milestones should be evaluated through gate definitions, supported logical register size, success probability and elapsed execution time.
Recommended national assessment: retain separate scorecards for mission progress, manufacturing capability, user adoption and standards implementation. A successful field trial should advance the relevant sensing mission without being counted as progress toward fault-tolerant computation.
8.7. European Union: coordination and industrialisation are explicit policy objectives
[P] The July 2025 Quantum Europe Strategy identifies research, infrastructure, ecosystem development, space and dual-use applications, and skills as interconnected areas of action. It also identifies fragmentation and the conversion of innovation into market opportunities as policy problems.
Source: European Commission, Quantum Europe Strategy, July 2025. Shaping Europe’s digital future
[P] The Commission’s maintained policy record describes a €100 million EuroHPC investment associated with six selected quantum-computing sites, financed equally by the EU and participating countries. [R] The same record describes the Quantum Act as a forthcoming initiative scheduled for adoption in 2026; that wording does not establish an already enacted and effective Act.
Source: European Commission, Quantum policy, infrastructure and Quantum Act record, maintained page, retrieved October 2026. Shaping Europe’s digital future
Analytical judgment: EU-level infrastructure can provide shared access and common testing environments. Its industrial contribution should be judged through utilisation, qualified supply chains, retained design authority and the ability to support equipment across national boundaries.
Recommended comparison rule: do not add EU funding to member-state envelopes unless co-financing and overlapping allocations have been reconciled. The same project can appear in several policy narratives without representing several independent investments.
8.8. France: a larger target changes the verification burden
[C] The May 2026 DGE update reports €1 billion mobilised by the state since 2021, €1.8 billion in cumulative public and private commitments, and €610 million invested through France 2030. These categories should not be added together.
[P] The update identifies PROQCIMA as a programme intended to develop a fault-tolerant computer for state requirements. [R] It raises the stated 2032 objective to 1,024 logical qubits, compared with an initial 128.
Source: French Directorate-General for Enterprise, France 2030 : la France accélère sa stratégie quantique pour renforcer sa souveraineté technologique, May 2026. Direction générale des Entreprises
Analytical judgment: the target revision increases the importance of intermediate acceptance criteria. It is a change in ambition, not evidence that the larger system exists, and should not be described as schedule slippage without evidence of a missed milestone.
Recommended national assessment: request the logical-operation specification, production architecture and milestone verification process. Because the revised endpoint lies in 2032, progress within 2026–2031 should be evaluated through the components and integrated prototypes required to reach it.
8.9. Germany: the 2026 transition should be evaluated through usable systems
[P] Germany’s 2023 action concept established a policy framework through 2026. [R] It included a target for a system with at least 100 individually controllable qubits, scalable to 500, alongside sensing and communications objectives.
Source: German federal government, Handlungskonzept Quantentechnologien, April 2023. quantensysteme.info
[P] The 2026 federal research and innovation report emphasises moving quantum computing, sensing and communications from demonstrators toward usable systems.
Source: German federal government, Bundesbericht Forschung und Innovation 2026 — research and innovation policy guidelines, 2026. BuFI
Analytical judgment: the relevant industrial test is whether demonstrators become reproducible products with defined operating envelopes and support arrangements. A physical-qubit target should remain separate from logical-computing performance.
Recommended national assessment: examine the continuity between the expiring action concept and its successor measures, especially manufacturing qualification, user requirements and evaluation of systems intended for industrial environments.
8.10. China: strategic priority is visible; a comparable expenditure total remains unresolved
[P] The published Fifteenth Five-Year Plan places quantum technologies among strategic frontier fields and identifies quantum technology within the development of future industries.
Source: 中华人民共和国国民经济和社会发展第十五个五年规划纲要, official Chinese publication of the 2026–2030 plan, March 2026. zyshgzb.gov.cn
Analytical judgment: this establishes policy priority and a national planning context. It does not establish a consolidated quantum-only budget, the technical performance of a processor or the operational security of a communications network.
The recommended comparison should therefore retain two separate records: one for policy instruments and disclosed expenditure, and another for reproducible technical evidence. Institutional claims of indigenous production should remain [C] until supported by an auditable production record or appropriate technical evidence.
Recommended national assessment: examine named institutions, procurement, fabrication routes and qualified components. Do not infer a quantum budget by assigning an unspecified portion of broader science, semiconductor or strategic-industry expenditure to the sector.
8.11. Japan: its own policy record identifies international dependencies
[P] Japan’s May 2025 ecosystem measures explicitly address component supply chains, industrialisation and international cooperation. [C] The document identifies import dependencies for some high-end lasers and single-photon detectors and discusses supply risks involving materials and advanced measurement equipment.
Source: Japanese Cabinet Office, 量子エコシステム構築に向けた推進方策, May 2025. www8.cao.go.jp
[P] The Cabinet Office’s current record also lists 2026 cooperation instruments involving the Netherlands, Australia and India.
Source: Japanese Cabinet Office, 量子技術イノベーション — strategy and international-cooperation register, maintained page, retrieved October 2026. 内閣府
Analytical judgment: the Japanese record supports an assessment based on strategic autonomy combined with reliable international access. Domestic integration does not require every component to be domestically manufactured, but dependence should be visible and manageable.
Recommended national assessment: identify which component technologies are intended to become nationally indispensable, which remain internationally sourced, and how qualification or replacement would proceed if a supply path were interrupted.
8.12. India: institutional architecture and physical-qubit targets should remain distinct
[P] India’s National Quantum Mission has four thematic hubs covering computing, communication, sensing and metrology, and materials and devices. The official Hindi parliamentary record describes their governance and implementation arrangements.
[R] The mission specifies physical-qubit development bands of 20–50, 50–100, and 50–1,000 at its three-, five- and eight-year stages.
Source: Government of India, राष्ट्रीय क्वांटम मिशन — parliamentary response, February 2026. Press Information Bureau
Analytical judgment: the hub structure provides identifiable institutional owners. Its physical-qubit milestones do not establish a future logical register or cryptanalytic capability.
Recommended national assessment: connect hub financing to commissioned facilities, qualified production processes, trained personnel and independently evaluated devices. The financial implementation table above offers a starting point, but technical milestones require their own evidence.
8.13. Israel: multi-platform infrastructure is an integration instrument
[P] The Israel Innovation Authority’s July 2026 call proposes national R&D infrastructure integrating at least three quantum-processing technologies. It describes services spanning benchmarking, integration, control, error correction, software, applications and workforce development.
Source: Israel Innovation Authority, רשות החדשנות מקימה תשתית מו״פ לאומית למחשוב קוונטי בהשקעה של 100 מיליון שקלים, July 2026. רשות החדשנות
Analytical judgment: a multi-platform facility can improve comparative testing and reduce premature commitment to one architecture. Its value should be measured through the quality of evaluation, access, integration and technology transfer.
The call does not establish that every platform will be domestically fabricated or that the infrastructure already delivers the proposed services.
Recommended national assessment: require a clear distinction between ownership of equipment, access to control interfaces, rights to experimental data and the ability to modify or replace the underlying platform.
8.14. Australia: project concentration makes delivery verification consequential
[P] The Australian government’s progress report identifies the joint PsiQuantum investment and support for other activities, including Silicon Quantum Computing and feasibility projects.
Source: Australian Department of Industry, Science and Resources, State of Australian Quantum report — progress, 2024. Department of Industry Science and Resources
Analytical judgment: substantial project-specific support creates a concentrated exposure to that project’s technical and contractual execution. The assessment should separately examine construction progress, manufacturing qualification, system acceptance, continuing operating costs and the domestic capabilities retained through the arrangement.
Recommended national assessment: define what remains useful if the central computing milestone arrives late or changes technically. Relevant retained assets may include qualified processes, integration knowledge, facilities and personnel, but their existence and transferability must be documented rather than assumed.
8.15. Canada: research, talent and commercialisation have identified programme roles
[P] Canada’s national strategy organises support around research, talent and commercialisation, with missions covering computing, communications and sensing. Its funding mechanisms include support for research collaboration and operational prototype testing.
Source: Innovation, Science and Economic Development Canada, Stratégie quantique nationale du Canada, official French strategy record. Stratégie quantique nationale
Analytical judgment: the commercialisation test is whether an enterprise can repeatedly deliver and support a product at an acceptable cost. Scientific participation and prototype funding should remain visible as inputs, rather than be recorded as completed industrial output.
Recommended national assessment: examine production access, market concentration, skilled-worker retention and the transition from prototype evaluation into recurring procurement.
8.16. Italy: coordination should be connected to funded implementation
[P] Italy adopted its national quantum-technology strategy through the Interministerial Committee for Digital Transition in July 2025. The government record describes coordination between the digital-transformation and university-research policy structures.
Source: Italian Department for Digital Transformation, Tecnologie quantistiche: una Strategia per l’Italia, July 2025. innovazione.gov.it
Analytical judgment: the central evaluation question is how coordination becomes a funded and accountable implementation chain. An assessment should identify programme owners, facilities, industrial contributions, user access and acceptance criteria.
Recommended national assessment: distinguish capabilities developed domestically, capabilities accessed through European infrastructure and capabilities bought from international suppliers. Each can contribute to national resilience, but they confer different forms of control.
8.17. Sovereignty should be tested at the dependency level
The following is a recommended dependency audit. It identifies potential bottlenecks to investigate; it does not assert a verified shortage or export restriction for every item.
| Dependency | Exposure to examine | Required continuity evidence |
|---|---|---|
| Dilution refrigeration | Cooling capacity, installation and specialist maintenance | Qualified alternatives, spares and service arrangements |
| Precision lasers | Required noise, stability and wavelength performance | Replacement qualification and long-term support |
| Isotopically tailored materials | Purity, reproducibility and production access | Specification, batch acceptance and alternate source |
| Photonic components | Loss, detector performance and packaging | Process qualification and reproducible assembly |
| Control electronics | Timing, noise, scaling and firmware access | Supported interfaces and replaceable implementation |
| Fabrication equipment | Access to suitable processes and tolerances | Production agreements and transfer feasibility |
| Vacuum and packaging | Reliability and reproducible integration | Environmental tests and manufacturing documentation |
| Decoder infrastructure | Throughput, latency and control-system integration | Performance at the intended logical scale |
| Calibration knowledge | Dependence on individual specialists | Documented procedures and trained replacement staff |
| Software infrastructure | Licensing, portability and update continuity | Data export, reproducible workflows and transition rights |
[P] Japan’s ecosystem measures expressly include refrigerators, electronics, optical systems, detectors and control systems among component areas for policy attention.
Source: Cabinet Office, Quantum ecosystem measures, component and supply-chain sections, May 2025. www8.cao.go.jp
A practical sovereignty test should ask three questions for each dependency: who can alter it, who can reproduce it, and how long replacement takes. The answers should determine resilience measures and procurement rights.
8.18. Export controls: the legal choke point must be identified precisely
[P] The September 2024 US rule introduced quantum-computing controls including:
| Classification | Scope described in the 2024 instrument |
|---|---|
| 4A906 | Specified quantum computers and related assemblies or components |
| 4D906 | Specified software for development or production of covered components |
| 4E906 | Specified technology for development, production or relevant software use |
The rule combines controllable physical-qubit count with gate-error criteria and includes technical definitions and notes. It does not establish that every product marketed as quantum falls within the same classification.
Source: US Department of Commerce, Commerce Control List additions and revisions: advanced technologies consistent with international-partner controls, September 2024. federalregister.gov
[P] BIS also described exclusions and a general-licence mechanism concerning certain deemed exports and reexports, with reporting conditions.
Source: BIS, Department of Commerce Implements Controls on Quantum Computing and Other Advanced Technologies Alongside International Partners, September 2024. bis.gov
Recommended assessment: maintain a classification record at item and technology level, including the relevant transaction, recipient, destination and current consolidated provisions. The BIS Interactive Commerce Control List provides the current-reference entry point; the historical rule explains the introduction of the controls.
8.19. Standards influence and talent should be evaluated through outputs
A recommended standards scorecard should examine technical contributions, reference implementations, test methods, evaluation laboratories and adoption support. Committee membership alone should not be treated as demonstrated influence over a final specification.
A recommended workforce scorecard should distinguish scientific research from the engineering and operational skills needed to reproduce systems:
| Workforce category | Capability to measure |
|---|---|
| Device scientists | Understanding and improvement of the physical mechanism |
| Fabrication engineers | Repeatable process and yield |
| Integration engineers | Assembly, packaging and commissioning |
| Control specialists | Calibration, feedback and performance maintenance |
| Software and decoder engineers | Reliable execution and classical-system integration |
| Validation specialists | Independent testing and uncertainty analysis |
| Field-service personnel | Repair, recalibration and sustained operation |
| Application specialists | Connection between the technology and user requirements |
Analytical judgment: the industrial programme should fund these roles according to its intended outputs. A research workforce can establish scientific strength while leaving manufacturing or service continuity unresolved.
Chapter 8 — Key judgments
[P] National programmes are identifiable, but their financial instruments differ materially. The decision changed is how to compare investment without equating requests, commitments and expenditure. The US budget supplement and Indian implementation response provide useful accounting distinctions.
[R] Larger logical-qubit targets increase the verification burden; they do not resolve it. France’s revised PROQCIMA objective should be assessed through intermediate operational specifications.
Analytical judgment: the most useful sovereignty measures concern controlled dependencies, reproducible production and sustained access. Funding an installed system should be accompanied by evidence of the rights and capabilities retained.
What would change the assessment
Audited expenditure reconciled across programmes; qualified production and yield records; documented component substitution; completed acceptance tests; and evidence that industrial outputs remain supportable beyond their initial demonstrations.
Open official record
Comparable national expenditure, complete dependency maps, production yields and maintenance costs remain unevenly disclosed. These gaps prevent a defensible single ranking of national quantum power.
Chapter 9 — Five-Year Outlook, 2026–2031, Under AI Acceleration
9.1. Scenarios should branch on measurable conditions
The recommended outlook uses three branches:
- Constrained: component progress continues, but integrated reliability, manufacturing or operational adoption remains limiting.
- Base: several approaches establish useful integrated systems within defined operating envelopes, while fault-tolerant computing remains workload-limited.
- Accelerated: coordinated improvements in physical performance, error correction, classical control and production permit substantially deeper logical computation and wider adoption.
These are [R] analytical scenarios, not assigned probabilities. Their purpose is to connect decisions with evidence that can confirm or reject a branch.
| Branch variable | Evidence needed to advance the assessment |
|---|---|
| Error correction | Repeated suppression under relevant operations and conditions |
| Logical register | Simultaneously usable logical qubits executing the required operations |
| Decoder | Sustained throughput, decision latency and integration into feedback |
| Manufacturing | Repeatable yield and commissioned-system consistency |
| Cryptanalysis | Updated complete resource estimates or reproducible attacks against named schemes |
| Application value | End-to-end comparison against a competitive conventional alternative |
| Institutional adoption | Acceptance, support, ownership and operational authorisation |
9.2. Public roadmaps provide targets with different scopes
[R] The following targets are prospective and should retain their original definitions:
| Roadmap or programme | Stated target | Relationship to 2026–2031 |
|---|---|---|
| IBM Starling | 2029, 200 logical qubits, 100 million quantum gates | Inside the window; performance remains prospective |
| Quantinuum Apollo | Updated company record identifies 2029 launch | Inside the window; complete application resources require verification |
| French PROQCIMA | 1,024 logical qubits by 2032 | Endpoint lies beyond the window |
| UK computing mission | 2032 billion-operation intermediate milestone; 2035 trillion-operation objective | Both endpoints lie beyond the window |
| DARPA QBI | Assess utility-scale feasibility by 2033 | Verification horizon extends beyond the window |
Sources: IBM, Hardware and roadmap, maintained record; Quantinuum, Stage B announcement and roadmap update, November 2025; DGE, PROQCIMA update, May 2026; UK government, Quantum Missions, November 2023; DARPA, QBI. Hardware and roadmap
[R] Quantinuum’s September 2024 announcement used a “by 2030” framing and described circuits with millions of gates. The subsequent 2029 statement is an earlier target, rather than evidence of delay.
Source: Quantinuum, Accelerated roadmap announcement, September 2024. quantinuum.com
Recommended reporting rule: retain dated versions and record changes in metric, scope and delivery date. A roadmap revision should be classified accurately as acceleration, delay, increased ambition or redefinition.
9.3. AI-assisted decoding has demonstrated value, with an execution constraint
[D] The 2024 AlphaQubit paper evaluated neural decoding on experimental Sycamore surface-code data at distances three and five. It reported improved decoding accuracy relative to the evaluated comparators. Larger-distance results used simulation.
The paper distinguishes throughput from final-decision latency and states that its design had not been optimised for inference speed. Consequently, better retrospective decoding does not alone establish the feedback performance required for a long algorithm.
Source: Bausch and colleagues, Learning high-accuracy error decoding for quantum processors, Nature, November 2024. Nature
Recommended next-stage test: require the decoder to meet both a throughput requirement and a decision deadline under the intended code, noise regime and number of logical blocks. Average throughput should not conceal a persistent backlog or unacceptable latency tail.
9.4. A 2026 control result supports acceleration through calibration
[D] A July 2026 study applied reinforcement-learning fine-tuning to Google’s Willow processor after conventional calibration. It reported approximately 20% additional logical-error suppression in repeated distance-five surface- and colour-code runs. Its distance-seven surface-code result reached a logical error rate of using AlphaQubit2.
The paper distinguishes experimental repeated-shot control from simulated steering during a long logical computation. It also identifies fast drift that its current steering cannot follow.
Source: Sivak and colleagues, Reinforcement learning control of quantum error correction, Nature, July 2026. Nature
Analytical judgment: this is evidence for a specific acceleration mechanism—using error-detection information to improve control. It is not evidence that learning removes irreducible physical noise or supplies an entire fault-tolerant architecture.
9.5. AI should enter the outlook through identifiable bottlenecks
| AI contribution | Mechanism to assess | Evidence classification | Ceiling that remains |
|---|---|---|---|
| QEC decoding | Infer corrections from syndrome history and analogue information | [D] Selected decoding results; [R] broader deployment | Latency, scale and physical-noise behaviour |
| Calibration and control | Search and adapt control parameters using measured outcomes | [D] Selected 2026 hardware result | Irreducible noise, fast drift and unsafe exploration |
| Materials and device search | Prioritise candidate structures or fabrication parameters | [R] Proposed acceleration pathway here | Fabrication, measurement and reproducibility |
| PQC cryptanalysis and implementation testing | Search for weaknesses in a named construction or implementation | [R] Scheme-specific continuation | Proof, attack cost and independent reproduction |
| Sensor fusion | Combine sensor streams, maps and uncertainty estimates | [R] Application-specific development | Measurement quality, map ambiguity and integrity |
The recommended programme should measure the improvement at the bottleneck and then measure the complete system. An improvement in one stage can be useful without determining the total rate of progress.
9.6. Long computations require an explicit failure budget
The following is an illustrative analytical calculation, rather than a device forecast.
Let K be the number of relevant failure opportunities and pi the probability of failure at opportunity i. The union bound gives:
If each probability is bounded by p, a sufficient condition for total failure probability no greater than ε is:
For an illustrative 1% total failure budget:
| Counted failure opportunities (K) | Sufficient uniform bound (p) |
|---|---|
| 106 | 10−8 |
| 108 | 10−10 |
| 1011 | 10−13 |
These rows require a defined opportunity count. It may include logical operations, memory rounds, state preparation and other events. A published memory-error rate cannot be substituted directly for a complete logical-operation failure model.
[R] Surface-code resource analysis explicitly connects fault-tolerant operations with physical space and execution requirements.
Source: Fowler and colleagues, Surface codes: Towards practical large-scale quantum computation, published in Physical Review A, 2012. arxiv.org
Recommended interpretation: ask whether the processor meets the failure budget of the intended computation, rather than whether its logical qubits are better than its physical qubits under one experiment.
9.7. Decoder capacity requires two separate inequalities
For planning, define:
- Rs: syndrome-information arrival rate.
- Rd: sustained decoding-processing rate.
- Ld: decision latency.
- Lmax: maximum latency tolerated by the relevant feedback operation.
The proposed acceptance conditions are:
with sufficient operating margin, and
at the required tail probability.
| Decoder indicator | Proposed management use |
|---|---|
| Sustained processing rate | Establish whether backlog remains bounded |
| Median latency | Describe ordinary operation |
| High-percentile latency | Test deadline reliability |
| Maximum tested block count | Establish demonstrated scale |
| Response to noise changes | Test robustness outside the training distribution |
| Resource consumption | Assess classical compute, power and cooling |
| Recovery behaviour | Establish what happens after interruption or overload |
Recommended interpretation: a fast average decoder can still fail an operational requirement if a small fraction of decisions arrive too late. The scenario should advance only when both conditions are met at the intended scale.
9.8. Manufacturing yield can become a system-level constraint
The following is an illustrative manufacturing model, not an estimate of any supplier’s yield.
Assume a module requires m independent elements, each acceptable with probability y, and that all must pass:
For m = 1,000:
| Assumed element pass probability | Derived all-pass module yield |
|---|---|
| 99.9% | 36.77% |
| 99.99% | 90.48% |
| 99.999% | 99.00% |
The calculation assumes independent failures and no defect tolerance, repair or redundancy. Real architectures may violate every one of those assumptions.
Recommended industrial test: request the actual acceptance model. The decisive data are qualified module yield, repair success, calibration time and the distribution of performance across commissioned systems.
| Production indicator | Question it resolves |
|---|---|
| Device yield | How frequently fabrication produces an acceptable device |
| Module yield | How frequently assembly meets the specification |
| Commissioning time | How much specialist effort is needed to reach operation |
| Inter-system variation | Whether one demonstration generalises to production |
| Repairability | Whether failed parts can be replaced economically |
| Long-duration availability | Whether acceptable initial performance persists |
9.9. Constrained scenario: progress continues without broad integrated capability
The numerical thresholds below are [R] planning tests selected for this report. They are not vendor promises or consensus forecasts.
| Year-band | Error correction and logical register | Decoder condition | Manufacturing condition | Cryptanalytic condition | Resulting assessment |
|---|---|---|---|---|---|
| 2026–2027 | Ten simultaneously usable logical qubits with sustained universal operations remain difficult to reproduce across systems | Accuracy gains do not consistently meet feedback deadlines | Commissioning remains heavily specialist-dependent | Complete estimates continue to rely on unvalidated integration assumptions | Fund components and bounded experiments |
| 2028–2029 | Registers expand, but a 100-logical-qubit deep workload remains limited by cumulative error or operation cost | Backlog, latency or adaptation limits usable depth | Yield and calibration impede expansion | No demonstrated named cryptographic target; estimates remain conditional | Restrict adoption claims to measured workloads |
| 2030–2031 | A reproducible 200-logical-qubit system at the required depth remains unestablished | Classical processing remains an architectural constraint | Support costs limit replication | No complete operational attack chain established | Broad cryptanalytic capability is not assumed within this window |
[R] Scenario consequence: sensing and security migration can still produce substantial institutional outputs because their delivery paths are separate from deep logical computation. Computing investment should remain tied to specific unresolved integration problems.
9.10. Base scenario: selected systems become useful within defined limits
| Year-band | Error correction and logical register | Decoder condition | Manufacturing condition | Cryptanalytic condition | Resulting assessment |
|---|---|---|---|---|---|
| 2026–2027 | At least ten usable logical qubits support reproducible, bounded universal-operation experiments | Feedback succeeds for the demonstrated code and scale | Repeat commissioning produces similar performance | Resource models improve but retain physical assumptions | Expand well-defined research workloads |
| 2028–2029 | Systems in the approximately 200-logical-qubit class reach independently verified workload specifications | Sustained throughput and latency meet the relevant control budget | Qualified modules and replacement procedures emerge | Roadmap resources remain distinct from attack resources | Evaluate application value end to end |
| 2030–2031 | At least one deep logical application demonstrates reproducible value at its stated register size | Decoding scales without unacceptable classical overhead | Useful systems can be replicated and maintained | A named attack still requires its complete architecture and execution schedule | Adopt selected services; retain cryptanalytic uncertainty |
[R] Scenario consequence: this branch permits early fault-tolerant services without assuming general-purpose economic advantage. The defining evidence is a completed workload with a meaningful conventional comparison.
9.11. Accelerated scenario: several bottlenecks improve together
| Year-band | Error correction and logical register | Decoder condition | Manufacturing condition | Cryptanalytic condition | Resulting assessment |
|---|---|---|---|---|---|
| 2026–2027 | At least 100 logical qubits execute an appropriate universal-operation workload with documented success probability | AI and conventional decoding meet tested feedback deadlines | Repeated modules retain the demonstrated performance | Algorithmic improvements reduce complete resource requirements | Reassess the pace of integration |
| 2028–2029 | At least 1,000 usable logical qubits are available for deep computation, including necessary ancillary resources | Decoder capacity scales across simultaneous blocks | Production, interconnect and calibration meet system requirements | Complete named-scheme models become consistent with a credible architecture | Accelerate verification and security reviews |
| 2030–2031 | At least 2,000 usable logical qubits support the required deep workload; factory and memory resources are separately accounted for | Sustained operation meets throughput and latency requirements | Large systems remain stable over the required execution duration | Cryptanalytic capability becomes credible only if every target-specific resource condition is satisfied | Treat earlier arrival as a contingency requiring direct evidence |
[R] Scenario consequence: this is a demanding conjunction of assumptions. A larger logical register alone does not activate the branch. Error budgets, non-Clifford production, interconnects, control and sustained operation must improve together.
These thresholds are designed to test institutional preparedness against faster progress. They should not be published as expected delivery dates.
9.12. Cryptographic relevance is a target-specific resource test
The previously established RSA and ECC estimates should be used as workload tests, without repeating their introductory resource tables here.
[R] Gidney’s RSA-2048 analysis explicitly includes distinct compute, hot-storage and cold-storage regions, state-production resources and physical timing assumptions. It also leaves detailed cold-storage workload analysis as future work.
Source: Gidney, How to factor 2048 bit RSA integers with less than a million noisy qubits, author preprint first submitted May 2025, retrieved version inspected October 2026. arxiv.org
A roadmap should pass the following mapping before receiving a cryptanalytic interpretation:
| Attack-resource field | Required roadmap correspondence |
|---|---|
| Named scheme and parameter | Exact target represented by the estimate |
| Logical algorithm register | Simultaneously available algorithm qubits |
| Ancillary resources | Workspace, routing, preparation and verification |
| T/Toffoli requirement | Demonstrated production and consumption schedule |
| Error correction | Applicable code, distances and noise assumptions |
| Physical overhead | Complete allocation rather than one encoding ratio |
| Runtime | Timing, repetition and control delays |
| Success probability | Combined algorithmic and physical failure treatment |
| Sustained operation | Availability across the required execution period |
[R] Assessment: the selected roadmaps examined here announce important prospective capabilities, but do not establish a verified operational attack against a named standard-sized cryptographic target by 2031. That finding does not prove such an attack is impossible within the window; it means its arrival cannot be treated as demonstrated or scheduled fact.
9.13. Migration deadlines can precede the adversarial computer
[P] Cryptographic transition instruments impose institutional work independently of a demonstrated adversarial quantum computer. The applicable US and UK records establish migration planning and implementation responsibilities.
Sources: White House, Executive Order 14412, June 2026; UK NCSC, Timelines for migration to post-quantum cryptography, March 2025. www.whitehouse.gov
Analytical judgment: the ordering is coherent because an owner must discover dependencies, replace incompatible equipment, preserve service continuity and protect information whose confidentiality extends beyond the transition period.
The recommended scenario response should therefore avoid tying migration funding to a forecast of a particular machine’s arrival. Slower computing progress may alter the assessed urgency of some exposures, but does not erase applicable requirements or make unmaintained cryptographic dependencies acceptable.
9.14. Branch-switching indicators
| Observation | Recommended assessment change |
|---|---|
| Logical-error suppression stalls under representative operations | Move the computing outlook toward constrained |
| Decoder meets accuracy but misses control deadlines | Hold the scale assessment |
| Several commissioned systems reproduce performance | Strengthen the manufacturing branch |
| Deep application result survives a stronger classical comparison | Strengthen the useful-computing branch |
| Complete attack estimate becomes materially cheaper | Reassess cryptanalytic contingency |
| Widely deployed PQC implementation has a reproducible vulnerability | Initiate scheme- or implementation-specific remediation |
| Field sensor demonstrates mission value across environments | Advance that application independently |
| Programme funding is released but milestone delivery remains unclear | Review execution before expanding commitments |
Chapter 9 — Key judgments
[D] AI has demonstrated improvements in decoding and control under specified conditions. The decision changed is whether to fund those bottlenecks with explicit latency, robustness and integration tests. See AlphaQubit and the July 2026 control study.
[R] Roadmaps inside the window describe different metrics and levels of integration. The decision changed is whether a target can be mapped onto a complete workload, rather than compared through headline qubit counts.
Analytical judgment: the base planning position should permit useful selected systems while retaining “not within this window” for a verified cryptanalytic service. Preparedness for the accelerated branch should come through migration and monitoring, without treating the branch as a forecast.
What would change the assessment
Independent deep-circuit validation; scalable low-latency control; reproducible manufacturing; complete named-target attack resources; or a useful application result that persists against improved conventional alternatives.
Open official record
The unresolved variables include simultaneous usable logical capacity, complete operation costs, decoder scaling, production yield and sustained availability. Assigning precise probabilities to the scenarios would exceed the evidence examined here.
Chapter 10 — Implications for Decision-Makers
10.1. Action matrix
The matrix is prescriptive:
- ACT NOW: undertake authorised implementation or readiness work.
- FUND AND WATCH: support a bounded experiment that resolves a material uncertainty.
- DO NOT BUY: withhold capability procurement until the required evidence exists.
- RETIRE THE CLAIM: remove an unsupported assertion from planning or communication.
| Application or claim | Civil government | Defence | Critical infrastructure | Enterprise |
|---|---|---|---|---|
| PQC dependency discovery | ACT NOW: establish owners and inventory | ACT NOW: use applicable national-security profiles | ACT NOW: identify operational and supplier dependencies | ACT NOW: map services and installed verifiers |
| PQC integration | ACT NOW: test priority services | ACT NOW: test authorised interoperability | ACT NOW: preserve continuity and recovery | ACT NOW: coordinate platform and supplier transitions |
| Advanced timing | FUND AND WATCH: test delivered service | FUND AND WATCH: representative holdover and synchronisation | FUND AND WATCH: endpoint timing and continuity | FUND AND WATCH: only for defined requirements |
| Magnetic or inertial navigation | FUND AND WATCH: integrity and authorisation | FUND AND WATCH: representative contested conditions | FUND AND WATCH: route-specific trials | DO NOT BUY: universal performance claims |
| Gravity surveying | FUND AND WATCH: benchmark the survey product | FUND AND WATCH: blinded target trials | FUND AND WATCH: site-specific comparison | FUND AND WATCH: complete ownership-cost test |
| Biomedical quantum sensing | FUND AND WATCH: clinical endpoint and authorisation | FUND AND WATCH: defined medical requirement | DO NOT BUY: unsupported diagnostic benefit | DO NOT BUY: research result sold as clinical service |
| Fixed-link QKD | FUND AND WATCH: bounded assurance case | DO NOT BUY: absent applicable approval | FUND AND WATCH: availability and trusted-node review | FUND AND WATCH: incremental value against alternatives |
| Memory-based quantum networks | FUND AND WATCH: research infrastructure | FUND AND WATCH: defined experimental requirement | DO NOT BUY: claimed operational protection without evidence | DO NOT BUY: production-service claims from experiments |
| Rydberg RF receivers | FUND AND WATCH: complete receiver performance | FUND AND WATCH: waveform and platform trials | FUND AND WATCH: specific monitoring need | DO NOT BUY: range substituted for instantaneous bandwidth |
| Deep logical computing | FUND AND WATCH: verifiable workloads | FUND AND WATCH: mission comparator | FUND AND WATCH: bounded useful problem | FUND AND WATCH: total workflow value |
| Operational quantum radar | DO NOT BUY: absent system evidence | DO NOT BUY: absent representative acceptance | DO NOT BUY: unsupported range claims | DO NOT BUY: laboratory analogy sold as service |
| “Unhackable quantum link” | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM |
| “AI solves fault tolerance” | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM |
| Physical qubits equated with cryptanalytic capacity | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM | RETIRE THE CLAIM |
[P] The standards and agency guidance provide the foundation for the security rows; [D]/[C] the experiments and trial reports in Chapters 6–7 provide the application boundaries.
Reference points: NIST FIPS 203, NSA guidance, DARPA RoQS, and DARPA QBI. csrc.nist.gov
10.2. A decision should identify the owner, the uncertainty and the exit condition
The recommended decision memorandum should contain six fields:
| Field | Required content |
|---|---|
| Decision owner | Person or body authorised to accept the outcome |
| Intended outcome | Security function, scientific result or mission effect |
| Present evidence | Demonstration, instrument, roadmap or claim |
| Uncertainty to resolve | Question the next expenditure will answer |
| Acceptance condition | Measurable evidence required to continue or adopt |
| Exit condition | Circumstance requiring redesign, pause or termination |
This structure permits ambitious work while preserving accountability. A programme can continue despite uncertainty when its next experiment is designed to resolve that uncertainty and the decision owner understands the remaining exposure.
10.3. Proposed first-year implementation sequence
The following periods are recommended management intervals, not statutory deadlines.
| Interval | Work to complete | Reviewable output |
|---|---|---|
| First 90 days | Identify decision owners, priority exposures and active quantum commitments | Portfolio register with evidence tags and applicable authorities |
| Months 3–6 | Define migration dependencies, pilot questions and supplier information requirements | Approved test plans and dependency maps |
| Months 6–9 | Execute representative tests and inspect financial implementation | Results linked to acceptance criteria |
| Months 9–12 | Decide expansion, redesign or termination | Updated investment and acquisition decisions |
For cryptography, the sequence should be aligned with applicable mandates. For research, its purpose is to prevent indefinite continuation without a measurable question.
10.4. Expenditure should purchase evidence or an accepted service
| Expenditure type | Recommended contracting focus |
|---|---|
| Research grant | Reproducible result and uncertainty resolved |
| Prototype contract | Integrated performance under stated conditions |
| Infrastructure investment | Access, utilisation, support and retained capability |
| Capability procurement | Accepted operating envelope and service continuity |
| Supplier-development support | Qualified production and replacement capacity |
| Migration expenditure | Verified transition of a defined security function |
Recommended financial discipline: record capital expenditure, operating cost, specialist staffing and replacement obligations separately. A low initial equipment price should not determine the choice when calibration, support or infrastructure dominate the service.
10.5. Proposed portfolio indicators
| Indicator | Numerator or measurement | Denominator or reference |
|---|---|---|
| Cryptographic inventory coverage | Assessed priority systems | Defined priority-system population |
| Migration completion | Services passing approved transition tests | Services scheduled for transition |
| Exception exposure | Unresolved exceptions weighted by consequence | Complete exception register |
| Demonstration reproducibility | Successful independent repetitions | Planned relevant repetitions |
| Manufacturing consistency | Commissioned systems passing specification | Commissioned systems tested |
| Operational availability | Time delivering the required service | Required service time |
| Evidence conversion | Experiments resolving their stated uncertainty | Experiments completed |
| Adoption conversion | Systems accepted by a named owner | Systems proposed for adoption |
These indicators are intended to measure implementation. Publication counts, partnerships and announced investment can remain contextual measures, but should not replace them.
10.6. Capability contracts should preserve evaluation and transition rights
The recommended contract should define access to the data needed to verify performance, the accepted configuration, changes requiring re-evaluation and the rights needed to transition if the supplier or architecture changes.
| Contract provision | Purpose |
|---|---|
| Performance-data access | Permit independent assessment |
| Configuration identification | Establish what was tested and accepted |
| Change notification | Prevent unsupported extrapolation after modification |
| Support commitment | Preserve service continuity |
| Calibration and maintenance documentation | Reduce dependence on undocumented expertise |
| Interoperability specification | Define supported peers and interfaces |
| Data portability | Preserve institutional work and evidence |
| Failure and recovery procedure | Establish a controlled response |
| Replacement or transition provision | Preserve options if the service becomes unsuitable |
10.7. Public reporting should preserve epistemic status
A recommended public statement should name the experiment or instrument, describe what it establishes and retain the relevant limit. A technical milestone can be communicated strongly without upgrading it into an operational capability.
[H] Statements that turn a programme objective into a completed deployment, or convert a component result into a whole-system guarantee, should be removed from official reporting.
Chapter 10 — Key judgments
Recommended decision: act on cryptographic migration through the relevant authorities, fund bounded application trials, and make capability procurement depend on representative acceptance evidence.
Recommended investment rule: the next expenditure should purchase an accepted service, a reproducible production capability or an answer to a material uncertainty.
Recommended reporting rule: preserve the distinction between delivered capability and funded ambition in every decision memorandum.
What would change the assessment
Accepted service-level results, repeated production performance, clarified operating costs or evidence that a programme’s intended advantage no longer survives comparison with conventional alternatives.
Open official record
Portfolio-level spending and programme announcements are often easier to obtain than acceptance results and continuing costs. Acquisition authorities should make those latter records part of the delivery requirement.
Chapter 11 — Annexes
11.1. Glossary and terminology controls
The definitions below establish the report’s usage. They are not capability claims.
| Term | Meaning in this report | Terminology to reject or qualify |
|---|---|---|
| Physical qubit | Physical degree of freedom used to encode quantum information | “Qubit” without identifying the physical or logical level |
| Logical qubit | Encoded information protected under a specified error-correction construction | Equating one logical qubit with a fixed universal physical overhead |
| Error-corrected memory | Protected storage of a quantum state under stated conditions | Describing storage alone as universal computation |
| Fault-tolerant operation | Operation designed to limit error propagation under stated assumptions | Assuming a complete machine from one protected gate |
| Fault-tolerant computer | Integrated system meeting the error budget of its computations | Undefined “fully error-free computer” |
| Code distance | Parameter associated with the protection of a specified code | Comparing distances across different architectures without context |
| Decoder | Classical process inferring an appropriate response from error information | Equating decoding accuracy with feedback suitability |
| Syndrome | Information obtained from checks used in error correction | Treating it as a direct measurement of the protected logical state |
| T/Toffoli resources | Non-Clifford computational resources counted under a stated model | Comparing them directly with an undefined total gate count |
| Magic-state production | Preparation and processing supporting relevant logical operations | Omitting its space, time and error costs |
| Quantum advantage | Better performance on a stated task against a specified comparator | Unqualified “faster than every classical computer” |
| Useful advantage | Advantage relevant to an intended outcome after full workflow costs | Inferring economic value from a benchmark alone |
| QKD | Quantum key distribution under a specified protocol and device model | “Unhackable communications” |
| QSDC | Quantum-secure direct communication under a stated construction | Treating it as interchangeable with QKD |
| PQC | Classical cryptographic constructions designed for quantum resistance | Describing PQC as requiring quantum hardware |
| KEM | Key-encapsulation mechanism | Calling a KEM the complete payload-encryption service |
| Digital signature | Mechanism supporting authenticity and integrity under a trust model | Equating signature protection with confidentiality |
| Trusted node | Intermediate node whose security forms part of the assurance assumptions | Claiming unconditional end-to-end protection without addressing it |
| Quantum repeater | Architecture for extending quantum-network functionality | Calling every trusted QKD relay a repeater in this sense |
| Quantum sensing | Measurement using an identified quantum mechanism | Assuming every sensor has the same maturity or operational advantage |
| Holdover | Timing performance after loss of an external reference | “GNSS independence” without a duration and error specification |
| Quantum radar | Label requiring an identified sensing and receiver mechanism | Assuming long-range target capability from the label |
| Crypto-agility | Controlled ability to replace cryptographic dependencies | Unrestricted algorithm negotiation |
| Sovereignty | Specified control over design, production, operation or continuity | Treating installation location as complete technological control |
Foundational references: NIST FIPS 203, FIPS 204, FIPS 205, and Fowler et al., Surface-code architecture and operations. csrc.nist.gov
11.2. Claim-correction log
The statements below are assertions to test and correct; the table does not quantify their prevalence.
| Assertion | Classification | Precise correction | Evidence reference |
|---|---|---|---|
| “A processor with thousands of physical qubits can recover a standard ECC key.” | [H] | Requires a complete logical and physical attack implementation, not a physical-qubit count | P-256 resource study |
| “A published PQC standard means the organisation has migrated.” | [H] | Publication specifies the algorithm; migration requires implementation and system verification | FIPS 203 |
| “QKD removes the need for authentication.” | [H] | Authentication remains part of the assurance architecture | NSA QKD guidance |
| “A long QKD route is a quantum-repeater network.” | [H] | Trusted relaying and memory-based entanglement networking are distinct architectures | Joint European QKD position |
| “A noiseless simulation is a larger quantum-hardware demonstration.” | [H] | Preserve the distinction between simulated representation and executed hardware | mRNA conference record |
| “An airborne gravimeter survey demonstrates navigation without GNSS.” | [H] | The cited survey used GNSS support and measured gravity-survey performance | Iceland–Greenland campaign |
| “A naval clock trial establishes fleet-wide operational capability.” | [H] | A trial report requires subsequent performance specification and acceptance evidence | Royal Navy August 2026 trials |
| “AI has solved fault tolerance.” | [H] | Selected decoding and control improvements do not establish the complete architecture | 2026 reinforcement-learning study |
| “The largest announced programme budget identifies the leading nation.” | [H] | Compare accounting status, period, outputs and controlled dependencies | US financial reporting categories |
| “A 2029 fault-tolerant roadmap is a scheduled cryptanalytic service.” | [H] | Match the roadmap to the named attack’s complete resources and sustained execution | IBM roadmap and RSA resource model |
11.3. Uncertainty register
| Uncertainty | Consequence for decisions | Evidence that would reduce it | Interim treatment |
|---|---|---|---|
| Complete logical-operation error budget | Limits credible deep workload size | Representative integrated operations | Retain workload-specific qualification |
| Simultaneous usable logical capacity | Limits roadmap interpretation | Execution with the claimed active register | Separate memory and computation |
| Non-Clifford resource production | Limits runtime and physical allocation | Sustained production with accepted error | Require explicit factory accounting |
| Decoder tail latency | Can constrain feedback | Relevant latency distribution at scale | Hold scale claims pending testing |
| Noise outside the evaluated model | Can invalidate resource projections | Representative correlated-error tests | Preserve model assumptions |
| Production yield | Determines replication cost and pace | Qualified multi-device and module records | Treat one device as insufficient |
| Calibration and maintenance burden | Determines sustainable availability | Long-duration service records | Include specialist costs |
| Critical-component continuity | Affects industrial resilience | Qualified alternative supply paths | Maintain dependency register |
| Comparative application value | Affects adoption and investment | Strong conventional benchmark | Fund bounded comparisons |
| Target-specific cryptanalytic resources | Affects contingency planning | Complete reproducible estimate or attack | Avoid a single arrival date |
| PQC implementation assurance | Affects present cybersecurity | Validation and reproducible testing | Maintain update and replacement paths |
| National financial comparability | Affects geopolitical rankings | Reconciled fiscal and programme series | Do not publish an aggregate ranking |
| Operational accreditation | Affects procurement authority | Named acceptance and approved scope | Retain trial classification |
| Financial execution | Affects programme completion | Released and utilised funds linked to milestones | Review implementation separately |
11.4. Readiness recording template
Every application entry should preserve both axes:
| Field | Required entry |
|---|---|
| Application | Specific service or mission |
| Mechanism | Computing, QKD, QSDC, PQC, symmetric cryptography or identified sensor |
| Evidence tag | D, P, R, C or H |
| Date and source | Publication and retrieval dates |
| Platform | Named hardware or infrastructure |
| Metric | Measured performance or explicit programme target |
| Conditions | Environment, comparator and assumptions |
| Technical readiness | Laboratory phenomenon; component; integrated prototype; limited field trial; series or accredited deployment |
| Institutional readiness | No owner; research programme; requirement; procurement; doctrine and logistics |
| Acceptance authority | Named body or unresolved status |
| Limitation | What the evidence does not establish |
| Next decision | Continue, test, adopt, redesign or stop |
This template prevents technical results and institutional status from being collapsed into a single maturity score.
11.5. Source register — industrial programmes, scenarios and policy instruments
All records below were retrieved on 4 October 2026. Dates describe the source or instrument, rather than the date on which the claimed future capability will exist.
| ID | Source | Date / status | Principal use |
|---|---|---|---|
| I-01 | NSTC — NQI FY2025 budget supplement | December 2024 | Federal financial categories and programme scope |
| I-02 | UK — National Quantum Strategy | March 2023 | Funding commitment and national framework |
| I-03 | UK — National Quantum Strategy Missions | November 2023 | Prospective mission milestones |
| I-04 | European Commission — Quantum Europe Strategy | July 2025 | Industrial coordination and policy objectives |
| I-05 | European Commission — Quantum policy record | Maintained page | Flagship, EuroHPC and forthcoming Act |
| I-06 | France DGE — national strategy acceleration | May 2026 | Financial announcement and PROQCIMA revision |
| I-07 | Germany — Handlungskonzept Quantentechnologien | April 2023 | Framework and prospective milestones |
| I-08 | Bundestag — action-concept committee discussion | May 2023 | Reported financing categories |
| I-09 | Germany — federal research and innovation report | 2026 | Transition toward usable systems |
| I-10 | China — Fifteenth Five-Year Plan | March 2026 | Quantum policy priority |
| I-11 | Japan — quantum ecosystem measures | May 2025 | Industrialisation and dependencies |
| I-12 | Japan — strategy and cooperation register | Maintained page | Current policy and cooperation instruments |
| I-13 | India — National Quantum Mission, Hindi parliamentary response | February 2026 | Mission governance and targets |
| I-14 | India — institution-level financial response | March 2026 | Sanctioned, released and utilised funds |
| I-15 | Israel Innovation Authority — national infrastructure call | July 2026 | Multi-platform R&D infrastructure |
| I-16 | Australia — State of Australian Quantum, progress | 2024 | Project support and programme activities |
| I-17 | Canada — national strategy, French version | Official strategy record | Funding, talent and commercialisation |
| I-18 | Italy — national quantum strategy adoption | July 2025 | National coordination framework |
| I-19 | US Federal Register — advanced-technology controls | September 2024 | Introduction of specified quantum controls |
| I-20 | BIS — control implementation announcement | September 2024 | Deemed-export and reporting context |
| I-21 | BIS — Interactive Commerce Control List | Maintained reference | Consolidated classification entry point |
| S-01 | IBM — hardware and roadmap | Maintained record | Starling target |
| S-02 | Quantinuum — accelerated roadmap | September 2024 | Original Apollo framing |
| S-03 | Quantinuum — Stage B announcement | November 2025 | Updated roadmap statement |
| S-04 | DARPA — Quantum Benchmarking Initiative | Maintained programme | Verification and value-versus-cost test |
| S-05 | Bausch et al. — high-accuracy decoding | November 2024 | AI decoder evidence and speed limits |
| S-06 | Sivak et al. — reinforcement-learning control | July 2026 | Hardware control improvement |
| S-07 | Fowler et al. — surface-code computation | Published 2012 | Fault-tolerant architecture |
| S-08 | Gidney — RSA-2048 resource analysis | Preprint first submitted May 2025 | Complete resource-model inspection |
11.6. Source register — security and application evidence carried forward from Pillar II
This register consolidates the principal security and application records from the supplied block. Their original experimental conditions and numerical results remain in Chapters 5–7.
| ID | Source | Date / status | Evidence role |
|---|---|---|---|
| C-01 | NIST FIPS 203 — ML-KEM | August 2024 | Final standard |
| C-02 | NIST FIPS 204 — ML-DSA | August 2024 | Final standard |
| C-03 | NIST FIPS 205 — SLH-DSA | August 2024 | Final standard |
| C-04 | NIST — HQC selection | March 2025 | Selection and prospective standardisation |
| C-05 | NIST — PQC current record | Maintained page | Standards and candidate status |
| C-06 | NIST — PQC FAQs | Maintained page | Symmetric-cryptography assessment |
| C-07 | NSA — post-quantum resources | Maintained guidance | NSS instruments and QKD position |
| C-08 | ANSSI — QKD guidance | May 2020 | Scoped communications guidance |
| C-09 | ANSSI — PQC follow-up guidance | 2023 follow-up | Hybrid migration |
| C-10 | Joint European QKD position | January 2024 | Assurance and migration priorities |
| C-11 | White House — Executive Order 14412 | June 2026 | Scoped transition instrument |
| C-12 | European Commission — coordinated PQC roadmap | June 2025 | Member-state coordination |
| C-13 | NCSC — migration timelines | March 2025 | Discovery and transition planning |
| C-14 | Roetteler et al. — ECC resources | Published 2017 | Logical-circuit resource model |
| C-15 | Long et al. — QSDC fibre experiment | April 2022 | Physical communication experiment |
| C-16 | Knaut et al. — memory nodes in telecom fibre | May 2024 | Quantum-network experiment |
| A-01 | BIS — Project Leap phase 2 | December 2025 | Payment-system migration pilot |
| A-02 | Toshiba — HSBC metropolitan QKD trial | July 2023 | Named commercial-trial announcement |
| A-03 | IBM Research — mRNA conference paper | August 2025 | Hardware and simulation distinction |
| A-04 | mRNA author preprint | May 2025 | Version-specific research record |
| A-05 | ORNL — trusted-node QKD at a utility | Published 2021 | Field integration |
| A-06 | Jensen et al. — airborne gravimetry | April 2025 | Survey field evidence |
| A-07 | Boto et al. — wearable MEG | March 2018 | Human research prototype |
| A-08 | Magnetic-navigation author preprint | April 2025 | Author-reported field results |
| A-09 | PTB — realisation of the SI second | Maintained record | National time-metrology function |
| M-01 | Royal Navy — radar-clock trials | August 2026 | Institutional trial report |
| M-02 | Royal Navy — P2000 clock trial | June 2025 | Named maritime trial |
| M-03 | Dstl — atomic-clock development | February 2026 | Unattended-operation report |
| M-04 | DARPA — RoQS | Maintained programme | Robust sensor development |
| M-05 | DARPA — RoQS first phase | August 2025 | Prospective platform testing |
| M-06 | Stray et al. — gravity cartography | February 2022 | Outdoor subsurface experiment |
| M-07 | DARPA — Quantum Apertures | Completed-programme reference | RF-receiver research |
| M-08 | DARPA — spectrum-sensing team selection | 2021 | Programme targets |
| M-09 | NATO — quantum strategy summary | January 2024 | Alliance objectives |
| M-10 | Canada DND — Quantum S&T implementation plan | March 2023 | Defence research missions and targets |
11.7. Quantitative provenance rules
| Number type | Required treatment |
|---|---|
| Measured performance | Date, platform, conditions, uncertainty and comparator |
| Programme budget | Currency, period, accounting status and scope |
| Roadmap target | Named owner, publication version and prospective status |
| Resource estimate | Target scheme, architecture, code, overhead and runtime assumptions |
| Derived arithmetic | Formula and input values |
| Illustrative scenario | Explicit assumptions and analytical purpose |
| National comparison | Reconciled scope and avoidance of double counting |
| Operational claim | Trial, contract, acceptance or doctrine evidence |
The manufacturing-yield calculation, utilisation percentages and failure-budget examples in this block are identified as derived or illustrative. They should not enter an empirical database without those labels.
11.8. Closing adjudication
Analytical judgment: the strategic task for 2026–2031 is to protect enduring information, convert bounded experiments into accepted services, and retain the industrial capabilities needed to reproduce those services. Progress in computing, communications and sensing should be evaluated through their separate technical and institutional requirements.
[R] Public roadmaps permit serious consideration of early fault-tolerant computing within the window, but do not establish a verified cryptanalytic service by its end. [P] Security-transition instruments already provide responsibilities that can be acted upon. [D] Selected experiments establish real technical progress, while leaving application-specific adoption questions to be resolved.
The resulting decision standard is demanding but usable: finance the work that resolves a consequential uncertainty, procure the service that passes its acceptance conditions, and preserve the distinction between what has been demonstrated and what remains an ambition.


















