PQRegistry
Independent registry of the post-quantum transition

Who has already measured the quantum shift?

We don't ask vendors — we measure. An independent, dated scan of the post-quantum readiness of {n} software and infrastructure companies, from public evidence. What's real, who's moving, and where the promise doesn't match the handshake.

0
measuring PQC live
0
flipped this week
0
contradictions
Scroll to read the story
01 Today

Harvest now,
decrypt later.

harvest now, decrypt later

What's encrypted today can be stored to open once a quantum computer arrives. The defense already exists — NIST standardized the algorithms in 2024 — and the hardware isn't waiting.

94protected logical qubits demonstrated · Quantinuum, Mar 2026
200logical qubits targeted for fault tolerance · IBM Starling, 2029
3PQC standards already finalized: ML-KEM · ML-DSA · SLH-DSA · NIST, 2024
02 The rules

It's not a guess. It's a calendar with force of law.

Governments have already turned the threat into dated deadlines. This is the factual part of the clock — we read the official dates, we don't estimate when the machine arrives.

2024
NIST
First PQC standards finalized (ML-KEM, ML-DSA, SLH-DSA).
2026
US · Executive Order
"Securing the Nation" (Jun) reaches federal contractors via the FAR.
2027
CNSA 2.0
New national-security acquisitions must support PQC (Jan).
2030
NIST · NSA
RSA-2048 and ECC P-256 deprecated; PQC key required.
2035
US · EU · UK
Vulnerable algorithms banned; full transition required.
The CNSA 2.0 window

The migration corridor the registry knows how to photograph

The CNSA 2.0 is the suite the NSA requires in national-security systems, in a 2025→2035 corridor: support from 2025, mandatory in new acquisitions in Jan 2027, exclusive use by category in 2030–2033, legacy banned in 2035. It names exactly which algorithms count — and that's what we measure, vendor by vendor: who already moves within the window, and who's been left behind.

ML-KEMML-DSALMS / XMSSAES-256SHA-384/512RSA-2048 · deprecatedECC P-256 · deprecated
03 The gap

Everyone knows what to do.
Almost no one has started.

Between the legal deadline and execution lives the expensive, recurring, mandatory question: "are my vendors ready?"

0%
of organizations are already planning, testing or implementing PQC — the intent is nearly universal.
0%
have actually moved more than half of their certificates to quantum-safe cryptography.

Source · DigiCert Quantum Readiness Outlook 2026 (“The Quantum Execution Gap”).

04 The measure

What they actually do — not what they promise.

Each vendor is read across five signals — the CDPAM model — from public evidence. Where there's no evidence, the field stays empty, never zero. And when the promise contradicts the handshake, the P6 contradiction is born.

C · certified

Certified

NIST validation (CAVP/CMVP): the algorithm passed official certification.

D · demonstrated

Demonstrated

The scan measures ML-KEM live in the TLS handshake. Done, not said.

P · promised

Promised

Self-declared (PQCCM). The weakest signal — and the one that can become a contradiction.

A · admitted

Admitted

Risk acknowledged in regulated filings (SEC) and official documents.

M · mobilized

Mobilized

Public procurement and PQC jobs: money moves before the product.

the index — illustrative excerpt
measuring live
Vendor
Measured signal
Declared × measured
Measured
Cloud provider · A
ML-KEM live in TLS
Demonstrated
aligned
18/08
Messaging · B
partial hybrid handshake
Demonstrated
partial
15/08
VPN · C
classical in handshake
Contradiction P6
declares PQC × measures classical
12/08
Database · D
no public evidence
Empty, never zero
no promise
09/08
Illustrative data — names anonymized. The real registry covers ~{n} vendors, with append-only, dated, reproducible evidence from the log.
◆ 01

Attested verification

Every claim with evidence and a timestamp. Auditable provenance, not a PR in a repo.

◆ 02

Machine-consumable

Queryable API and CBOM: "given my client's inventory, which vendors are the bottleneck?"

◆ 03

LATAM depth

BR/LATAM vendors and regulation in PT/ES — the angle global trackers don't prioritize.

05 When

How much time is left — and what's still only an estimate.

Regulatory deadlines are dated facts: we count them in real time. "Q-Day" is an expert forecast — and we mark it as such. Measuring and guessing are not the same.

CNSA 2.0 · NSS acquisitions
days left
New acquisitions must support PQC.
target · Jan 1 2027
NIST · deprecation
days left
RSA-2048 and ECC P-256 deprecated.
target · 2030
US · EU · UK · ban
days left
Legacy banned; full transition.
target · 2035
◇ Forecast — not a measurement

Estimated "Q-Day" window

Experts estimate 5 to 15 years until a machine at the scale to break today's cryptography. It's a band of uncertainty, not a number ticking down — which is why it lives here, labeled, and not on the official clock.

2026
2030
2033
2035+
Range from expert surveys (e.g., Global Risk Institute, Quantum Threat Timeline). We update it as the consensus shifts.

The transition will be measured.
The question is by whom.

While regulators score the system's readiness — like Hong Kong's Monetary Authority quantum index — PQRegistry scores the other side: who delivers. Independent, dated, verifiable.