Who has already measured the quantum shift?
We don't ask vendors — we measure. An independent, dated scan of the post-quantum readiness of {n} software and infrastructure companies, from public evidence. What's real, who's moving, and where the promise doesn't match the handshake.
Harvest now,
decrypt later.
harvest now, decrypt later
What's encrypted today can be stored to open once a quantum computer arrives. The defense already exists — NIST standardized the algorithms in 2024 — and the hardware isn't waiting.
It's not a guess. It's a calendar with force of law.
Governments have already turned the threat into dated deadlines. This is the factual part of the clock — we read the official dates, we don't estimate when the machine arrives.
The migration corridor the registry knows how to photograph
The CNSA 2.0 is the suite the NSA requires in national-security systems, in a 2025→2035 corridor: support from 2025, mandatory in new acquisitions in Jan 2027, exclusive use by category in 2030–2033, legacy banned in 2035. It names exactly which algorithms count — and that's what we measure, vendor by vendor: who already moves within the window, and who's been left behind.
Everyone knows what to do.
Almost no one has started.
Between the legal deadline and execution lives the expensive, recurring, mandatory question: "are my vendors ready?"
Source · DigiCert Quantum Readiness Outlook 2026 (“The Quantum Execution Gap”).
What they actually do — not what they promise.
Each vendor is read across five signals — the CDPAM model — from public evidence. Where there's no evidence, the field stays empty, never zero. And when the promise contradicts the handshake, the P6 contradiction is born.
Certified
NIST validation (CAVP/CMVP): the algorithm passed official certification.
Demonstrated
The scan measures ML-KEM live in the TLS handshake. Done, not said.
Promised
Self-declared (PQCCM). The weakest signal — and the one that can become a contradiction.
Admitted
Risk acknowledged in regulated filings (SEC) and official documents.
Mobilized
Public procurement and PQC jobs: money moves before the product.
Attested verification
Every claim with evidence and a timestamp. Auditable provenance, not a PR in a repo.
Machine-consumable
Queryable API and CBOM: "given my client's inventory, which vendors are the bottleneck?"
LATAM depth
BR/LATAM vendors and regulation in PT/ES — the angle global trackers don't prioritize.
How much time is left — and what's still only an estimate.
Regulatory deadlines are dated facts: we count them in real time. "Q-Day" is an expert forecast — and we mark it as such. Measuring and guessing are not the same.
Estimated "Q-Day" window
Experts estimate 5 to 15 years until a machine at the scale to break today's cryptography. It's a band of uncertainty, not a number ticking down — which is why it lives here, labeled, and not on the official clock.
The transition will be measured.
The question is by whom.
While regulators score the system's readiness — like Hong Kong's Monetary Authority quantum index — PQRegistry scores the other side: who delivers. Independent, dated, verifiable.