Skip to content
← Back to Briefings
technology

Quantum Computing Progress: Commercial Readiness and Cryptography Risk Timeline

The quantum threat to current encryption is no longer a distant planning horizon: Google's March 2026 declaration of a 2029 internal migration deadline, driven by faster-than-expected advances in hardware and error correction.

Key Takeaway

Organizations that wait for the 2035 regulatory deadline to begin migration will find themselves executing a multi-year engineering project with no remaining runway.

Executive Summary

The quantum threat to current encryption is no longer a distant planning horizon: Google's March 2026 declaration of a 2029 internal migration deadline, driven by faster-than-expected advances in hardware and error correction, has compressed the industry's working timeline by six years relative to NIST's 2035 outer bound. The practical window for migrating cryptographic infrastructure is narrowing faster than most organizations are moving, and adversaries are already collecting encrypted data today for later decryption. NIST finalized its first three post-quantum standards in August 2024, providing the technical foundation, but as of mid-2026, a McKinsey-cited estimate suggests over 90% of businesses still lack a documented migration roadmap.

  • CISOs and security architects: Begin cryptographic asset inventory immediately; the gap between when Google completes migration (2029) and when most enterprises begin (2027-2028) creates a window of maximum exposure.
  • Risk officers and investors: The post-quantum cryptography market is growing at roughly 46% annually according to Markets and Markets projections, and the largest near-term revenue is in migration services, not algorithm development; position accordingly.
  • Government and compliance teams: US federal agencies face a 2030 deadline for high-value systems under current White House policy; agencies without completed inventories are already behind schedule.

Organizations that wait for the 2035 regulatory deadline to begin migration will find themselves executing a multi-year engineering project with no remaining runway.

Key Findings

  • Google's 2029 migration deadline signals that the team building quantum hardware believes a cryptographically relevant quantum computer is plausible this decade, not the next.* Google announced in March 2026, authored by Heather Adkins and Sophie Schmieg, that it would migrate its full stack including Chrome, Android, Google Cloud, and Gmail by 2029. According to SecureWorld's reporting on the announcement, this reflects updated estimates across hardware development, error correction, and factoring resource requirements. The Quantum Insider noted in August 2026 that no other organization operates both a major quantum hardware program and a leading internet security infrastructure simultaneously, making Google's internal probability distribution the most credible public signal available.
  • The "harvest now, decrypt later" threat is already active, meaning organizations with long-lived sensitive data are exposed today regardless of when Q-Day arrives.* Fortinet's 2026 threat landscape guidance confirms that nation-state actors are actively collecting encrypted data with plans to decrypt it once sufficiently powerful quantum computers become available. CyberScoop's analysis notes that financial records, health data, government communications, and intellectual property are all in scope. NIST's own 2024 guidance states the threat "underscores the necessity of acting immediately, especially for data with long-term sensitivity." The evidence for active harvesting is corroborated across government, trade press, and vendor sources; the evidence of confirmed decryption is, by definition, not yet visible.
  • NIST's August 2024 finalization of three post-quantum standards (ML-KEM, ML-DSA, SLH-DSA) has shifted the bottleneck from algorithm selection to enterprise deployment, and most organizations have not started.* NIST released FIPS 203, 204, and 205 on August 13, 2024, providing the regulatory foundation for migration. A McKinsey-cited estimate in AppViewX's July 2026 analysis found over 90% of businesses lack a documented PQC migration roadmap. Dark Reading's October 2025 industry report confirmed that while critical-sector organizations in finance and government have begun asset inventories, most businesses are not yet engaging the threat.
  • Financial services and government are the first-mover sectors, but telecoms and critical infrastructure operators face structurally harder migrations that will likely extend past voluntary deadlines.* The Hong Kong Monetary Authority launched a Quantum Preparedness Index in February 2026 to score banking readiness. Singapore's MAS issued advisory guidance in 2024. The Australian Government has recommended organizations stop using traditional asymmetric algorithms by 2030. The Quantum Insider's August 2026 analysis notes that telecoms and utilities operate hardware with decade-long replacement cycles, meaning their migration timelines are constrained by physical infrastructure, not just software.
  • The quantum computing market is growing at a pace that makes hardware breakthroughs before 2035 plausible, but expert consensus still places a cryptographically relevant machine beyond 2030 for most scenarios.* Market Research Future sized the quantum computing market at $1.3 billion in 2025 and projects a 27% compound annual growth rate through 2035. The Alan Turing Institute's CETaS analysis from April 2026 notes that estimates for a fault-tolerant quantum computer range from 2029 to 2035 and beyond, with industry forecasts consistently more optimistic than academic ones. The range runs wide enough that planning for a 2030 horizon is prudent, but certainty in either direction is not warranted.

The Gap Between Hardware Progress And Organizational Readiness

Quantum hardware is advancing faster than most security roadmaps anticipated. In March 2026, Google disclosed it would expand its quantum research into neutral-atom approaches in addition to its existing superconducting-qubit program, and expects commercially relevant superconducting computers by the end of this decade. A paper cited by the CETaS April 2026 report found that breaking RSA-2048 may require roughly a million noisy qubits, still well beyond today's hundreds. But the key variable is the rate of improvement, not the current level. APS Physics reported in August 2026 that new resource estimates suggest some cryptographic systems may become vulnerable sooner than previously modeled, citing updated factoring algorithms.

The New Scientist reported in 2026 on a separate but structurally important problem: a large-scale analysis of quantum computing research papers found most results cannot be replicated, which creates genuine uncertainty about whether headline qubit counts and error-correction claims represent reproducible capability or laboratory artifacts. Fred Chong at the University of Chicago, quoted in the analysis, noted that reproducibility is lower priority in fast-moving early-stage fields. The implication is that the field's public capability claims could be understated or overstated, and organizations calibrating their migration timelines to published qubit counts alone are likely miscalibrated.

This matters directly for financial planning: a migration that costs one amount when started in 2026 will cost substantially more if deferred to 2029, because the workforce of cryptographic engineers capable of executing these projects is finite and will be bidding on more contracts as deadlines approach. The broader systemic implications include supply chain pressure on hardware security modules (HSMs), where the Quantum Insider noted in August 2026 that no HSM vendor has yet completed FIPS 140-3 Level 3 validation including PQC algorithms within the validated module boundary, meaning the certification infrastructure has not caught up with the algorithms.

Who Is Moving And Who Is Stalling

Government programs are the most structured and most publicly documented. The US federal mandate, codified in White House guidance, requires high-value assets to complete migration for cryptographic key establishment by end of 2030 and digital signatures by end of 2031, with all remaining systems completed by 2035. The State Department's Cyber and Technology Security Directorate, represented by Deputy Assistant Secretary Gharun Lacy in CyberScoop's 2026 reporting, has framed the migration as a collective ecosystem problem, not an individual agency one, specifically citing China's ability to target "entire ecosystems" for digital compromise. That framing reflects a geopolitical dimension that drives procurement urgency beyond normal compliance timelines.

The geopolitical and cybersecurity dimensions compound each other by a specific mechanism: China maintains its own national cryptographic standards (the SM series) and is unlikely to adopt Western NIST standards, which means the two largest quantum computing programs globally are not converging on interoperable post-quantum infrastructure. This creates asymmetric exposure: Western organizations transitioning to NIST standards gain protection against future quantum decryption, but only if adversaries with quantum capabilities lack equivalent post-quantum defenses, which cannot be assumed.

In financial services, the picture is uneven. Singapore's MAS and Hong Kong's HKMA are ahead of most other regulators in issuing prescriptive guidance. According to the Quantum Insider's August 2026 analysis, the HKMA's Quantum Preparedness Index is the most granular regulatory scoring mechanism currently operational. US financial regulators have been slower to issue sector-specific mandates, relying instead on the federal civilian mandate framework. Forescout's analysis, cited by Dark Reading in October 2025, noted that some financial systems still run software from previous decades, creating legacy exposure that will not be resolved by algorithm selection alone.

Forbes contributor Chuck Brooks, writing in August 2026, characterized the 2025-2026 period as the shift from physics to engineering in quantum computing, citing IBM's 70 logical qubit computation as a marker of practical progress. The engineering transition is what makes the timeline feel more concrete to practitioners than to policymakers: logical qubit counts are the metric that matters for cryptographic attacks, and they are improving faster than raw physical qubit counts would suggest.

Key Assumptions

The following table maps the load-bearing assumptions in this assessment and identifies the single observable data point that would most quickly confirm or falsify each one.

AssumptionSupporting EvidenceFalsifying EvidenceImpact if WrongMonitoring Metric
A cryptographically relevant quantum computer is plausible before 2035Google's March 2026 2029 internal deadline; APS Physics August 2026 noting faster resource estimates; IBM 70 logical qubit milestone per Forbes August 2026No demonstrated improvement in logical qubit error rates beyond current benchmarks; academic consensus holding firm at post-2035 estimatesIf the threat is further away, premature migration investment still provides security value but at higher immediate cost; urgency framing changesCETaS/Turing Institute quarterly quantum hardware review; IBM and Google annual quantum roadmap updates
Most organizations have not yet begun PQC migrationMcKinsey estimate (cited AppViewX July 2026) that over 90% of businesses lack a PQC roadmap; Dark Reading October 2025 reporting on enterprise inactionSurge in FIPS 140-3 Level 3 HSM certifications including PQC; enterprise procurement data showing widespread cryptographic library upgradesIf organizations are actually further along than public reporting suggests, the gap is smaller and timeline pressure is lowerFIPS 140-3 certificate registry (NIST CMVP); quarterly procurement data from HSM vendors
Harvest-now-decrypt-later attacks are occurring at scale by nation-state actorsFortinet 2026 Threat Landscape guidance; CyberScoop PQC analysis citing long-term intelligence and IP value of stored encrypted data; State Department framing of China as targeting "entire ecosystems"A credible government declassification confirming no active collection programs existIf no active harvesting is occurring, urgency for migrating existing data protection is lower; digital signature migration remains equally urgentNSA/CISA joint advisories; five-eyes intelligence community public threat assessments
The largest near-term economic opportunity in PQC is migration services, not new algorithmsCIR market report 2026 citing cryptographic discovery, migration planning, compliance consulting, and managed services as primary revenue categoriesMajor algorithm developer acquisitions commanding valuations that exceed service-provider multiplesInvestor positioning in algorithm-focused firms would need to shift toward services-oriented playsPublic company earnings calls from IonQ, Arqit, and D-Wave; private round disclosures in PQC services

Why it matters: Google's 2029 deadline rests on three beliefs: a cryptographically relevant quantum computer arrives before 2035, most enterprises have not started migrating, and nation-states are collecting encrypted data now to decrypt later. If any one of these is wrong, the urgency drops, though the third remains urgent regardless.

Counterarguments

  1. The 2029 deadline may reflect Google's competitive positioning more than its actual threat assessment. A company that builds quantum hardware and sells cloud security services has a structural incentive to accelerate the market's sense of urgency. Publishing a 2029 internal deadline is simultaneously a genuine security commitment and a marketing signal to enterprise cloud customers. The evidence that Google's threat model is accurate rather than commercially motivated rests heavily on a single organization's stated reasoning. The CETaS April 2026 analysis, which draws on a broader academic base, places the expert consensus for a cryptographically relevant machine beyond 2035 in most scenarios. Organizations that calibrate entirely to Google's 2029 signal may be over-investing in migration speed at the expense of other security priorities.

  2. The reproducibility problem in quantum computing research makes the hardware timeline genuinely unknowable. New Scientist's 2026 analysis of thousands of quantum computing papers found most results cannot be independently replicated. If the field's published capability benchmarks are systematically overstated due to poor reproducibility norms, the hardware timeline could be substantially longer than even academic consensus estimates. This does not eliminate the migration imperative (harvest-now-decrypt-later attacks are real regardless of when Q-Day arrives), but it changes the urgency calculus for organizations choosing between a 2028 and a 2032 migration start.

  3. The certification infrastructure bottleneck may be more binding than the organizational willingness bottleneck. The Quantum Insider's August 2026 analysis noted that no HSM vendor has completed FIPS 140-3 Level 3 validation including PQC algorithms within the validated module boundary. Financial institutions and government agencies with compliance obligations cannot deploy uncertified cryptographic hardware regardless of how urgently they want to migrate. If the certification pipeline does not accelerate, sector-level migration timelines are constrained not by organizational readiness but by standards body throughput, a factor largely absent from most urgency narratives.

Indicators To Watch

IndicatorCurrent State (as of Sep 2026)Warning ThresholdTime Horizon
FIPS 140-3 Level 3 HSM certifications including PQC algorithmsZero certified modules as of August 2026 (Quantum Insider)First certification issued; signals deployment pipeline opening6-18 months
Google Willow successor qubit count and logical qubit error rateWillow at 105 physical qubits; logical qubit error rates improvingDemonstrated logical qubit error rate below 0.1% at scale; signals CRQC timeline compression12-36 months
US federal agency PQC inventory completion rateMandate active; completion rate unverifiedGAO or OMB report showing fewer than 50% of high-value systems inventoried by Q4 20263-6 months
Enterprise HSM upgrade procurement volumeLow; most organizations pre-planningQuarter-on-quarter procurement growth exceeding 40%; signals market activation6-12 months
NIST legacy algorithm deprecation enforcement actionsDeprecation scheduled for 2030; no enforcement yetFirst federal agency contract penalty or audit finding tied to non-compliant cryptography12-24 months
China's domestic PQC standardization progressSeparate SM-series standards; OSCCA activity opaqueAnnouncement of Chinese national PQC; signals asymmetric migration dynamics12-36 months

Near-term watch list: (1) NIST CMVP FIPS 140-3 certificate registry update (Q4 2026), specifically for any HSM vendor submission including ML-KEM or ML-DSA in the validated boundary, which would signal the hardware deployment phase has begun in earnest; (2) IBM quantum roadmap annual update (expected late 2026), where any revision to fault-tolerant timeline estimates will recalibrate enterprise planning assumptions across the sector; (3) OMB federal cybersecurity posture report (Q1 2027), which will include the first auditable data on agency-level PQC inventory completion against the 2030 deadline.

Why it matters: The first HSM certification, the next IBM quantum milestone, and federal inventory completion rates by Q1 2027 will show whether the migration window is genuinely compressed or whether enterprise lag and hardware progress are moving at different speeds than Google's internal estimates assume.

Decision Relevance

Scenario A (~55%): Orderly migration window, Q-Day arrives 2031-2035. Organizations that begin migration in 2026-2027 complete it before the threat materializes. If your organization holds encrypted data with more than five years of sensitivity value, begin cryptographic asset discovery now, prioritizing key exchange and authentication systems, because these are the categories NIST identifies as first-deadline items. If you lack a current inventory of cryptographic dependencies, commission one before year-end 2026; the cost of discovery is a fraction of the cost of emergency migration under deadline pressure. Investors should weight PQC migration service providers over algorithm developers, as CIR's 2026 market report identifies services as the largest near-term revenue category.

Scenario B (~35%): Accelerated timeline, Q-Day arrives 2028-2030, Google's signal proves accurate. If your organization manages long-lived sensitive data in finance, healthcare, defense, or government, this scenario means harvest-now-decrypt-later exposure is already material and data collected today may be decrypted within this decade. Begin migration for key exchange and authentication systems on an 18-month sprint timeline, accepting higher near-term cost. If you are a technology vendor with cryptographic dependencies, publish a customer-facing PQC transition roadmap; major enterprise buyers in finance and government are already requesting this in RFP processes. Policy teams advising on financial regulation should push sector-specific guidance rather than relying on the federal civilian mandate, which does not extend to private financial infrastructure.

Scenario C (~10%): Hardware delay, Q-Day pushed past 2040. Even in this scenario, the regulatory deadlines are binding and the harvest-now attacks remain real for any data with long-term value. Migration costs are sunk regardless of when the threat materializes. If your organization has already allocated migration budget, do not redirect it; the option value of early completion is positive even if the threat horizon extends. Monitor the NIST CMVP registry and IBM roadmap for the evidence that would confirm this scenario before making any resource reallocation.

Analytical Limitations

  • The most consequential unknown, the internal state of adversary quantum programs, is not visible in any open source. China's quantum computing investment and timeline are assessed through proxy indicators only; if Beijing has achieved hardware milestones not yet disclosed, the harvest-now-decrypt-later exposure is higher than any public estimate suggests.
  • No publicly available data confirms the scale of active harvest-now-decrypt-later collection operations. Government advisories assert the threat exists; they do not quantify volume or identify what data has been collected.
  • The reproducibility problem in quantum research, documented by New Scientist in 2026, means the hardware timeline range is wider than expert consensus intervals suggest. Published qubit counts and error-correction claims should not be treated as independently verified benchmarks.
  • Migration cost estimates in the evidence base come primarily from vendors with commercial interests in urgency. Independent, sector-specific cost studies are scarce, meaning the cost-of-delay calculations widely cited in industry materials should be treated as advocacy-weighted rather than neutral.
  • The HSM certification gap identified by the Quantum Insider in August 2026 introduces a potential constraint that is structurally absent from most migration timelines. If FIPS 140-3 certification throughput does not accelerate, compliance-bound organizations cannot complete migration on voluntary timelines regardless of intent.

Expert Integration

Expert Consensus Assessment

Experts broadly agree that migration should begin now due to harvest-now-decrypt-later risk, and that NIST's standardized algorithms provide the foundation for doing so. Consensus fractures on timing: industry practitioners cluster around 2029-2033, academic researchers around 2035 and beyond.

Expert Disagreement Areas

  • Q-Day timing: CETaS/Turing Institute April 2026 places expert consensus beyond 2035 for most scenarios; Google's March 2026 announcement implies 2029 as a credible planning horizon. These positions are separated by up to six years, which is material for migration investment decisions.
  • Hardware trajectory: Forbes (Chuck Brooks, August 2026) characterizes 2025-2026 as the transition from physics to engineering, implying accelerating practical capability; New Scientist's 2026 reproducibility analysis implies published milestones may be unreliable, implying potentially slower real progress.
  • Organizational readiness: McKinsey-cited data (via AppViewX, July 2026) suggests over 90% of businesses lack roadmaps; this figure is widely repeated in vendor materials and has not been independently verified by a non-commercial source.

Systematic-Expert Alignment

Alignment: MIXED

This assessment aligns with expert consensus on the migration imperative and the harvest-now-decrypt-later framing. It diverges slightly from academic consensus on urgency, leaning toward the industry-practitioner view that Google's 2029 signal deserves to be weighted heavily given its unique position as both a quantum hardware developer and a cryptographic infrastructure operator. The reproducibility caveat is included specifically to avoid overstating hardware confidence, which is where the evidence base is thinnest.

Sources & Evidence Base

Methodology version: 2026-09-03

Get the next analysis when it's published

Free email alerts for new briefings. No spam, unsubscribe in one click.

Source-graded evidence. Competing hypotheses. Calibrated confidence. Delivered daily.

Want to bookmark and save analyses? Create a free account →

Apply this analytical approach to your priority topics.

Source-graded evidence, competing hypotheses, and calibrated confidence, with limitations stated, not hidden.

Request a Demo

Accountability

Every Mapshock forecast is published with its confidence assessment and resolution horizon, and resolved in public against subsequent evidence.

View the public forecast record
Share

Continue Reading

supply-chain15 min read

USMCA Renewal Uncertainty and North American Supply-Chain Continuity: Annual Review Framework Implications

The Trump administration's refusal to commit to a 16-year USMCA renewal on July 1, 2026 has moved North American trade from a predictable, long-horizon framework into an annual review cycle.

technologyJul 2, 202615 sourcesHigh Confidence13 min read