2026-08-05
NIST · Post-Quantum Cryptography Project
Current standards, migration guidance, and standardization pipeline.
Evidence register · Reviewed 19 Aug 2026
Every substantive current claim should lead back to a dated source. These are the primary records used in the current release.
Current standards, migration guidance, and standardization pipeline.
Current public overview and migration guidance, including the HAWK withdrawal.
Proposed transition timeline for deprecating quantum-vulnerable algorithms.
The ML-KEM standard and its three parameter sets.
The ML-DSA digital signature standard.
The SLH-DSA hash-based digital signature standard.
Selection of HQC as a backup key-encapsulation mechanism.
Migration practices, discovery, interoperability, and implementation guidance.
A below-threshold surface-code memory demonstration on Google Quantum AI's Willow processors.
A resource estimate under explicit superconducting surface-code assumptions.
A newer resource estimate using changed arithmetic, storage, and distillation assumptions.
A survey of 32 quantum-computing experts, including probability ranges for a CRQC within 10 and 15 years.
The latest expert survey: a CRQC is assessed as 28–49% likely within 10 years and 51–70% likely within 15 years.
Google set 2029 as its company-wide PQC migration deadline in response to progress in hardware, error correction, and factoring estimates.
IBM targets a 200-logical-qubit, 100-million-gate fault-tolerant system for 2029.
Gartner research states an expectation that quantum computing will break public-key cryptographic algorithms by 2029.
IonQ's current roadmap targets 80,000 logical qubits by 2030, with 8,000 logical qubits targeted for 2029.
The foundational published treatment of Shor's algorithm.