惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
Schneier on Security
博客园_首页
量子位
博客园 - 司徒正美
S
SegmentFault 最新的问题
J
Java Code Geeks
小众软件
小众软件
博客园 - 【当耐特】
The Register - Security
The Register - Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Microsoft Azure Blog
Microsoft Azure Blog
G
Google Developers Blog
Blog — PlanetScale
Blog — PlanetScale
T
Tailwind CSS Blog
博客园 - Franky
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
G
GRAHAM CLULEY
Cyberwarzone
Cyberwarzone
腾讯CDC
Apple Machine Learning Research
Apple Machine Learning Research
V
Visual Studio Blog
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
The Hacker News
The Hacker News
aimingoo的专栏
aimingoo的专栏
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
Scott Helme
Scott Helme
L
LINUX DO - 热门话题
F
Full Disclosure
D
DataBreaches.Net
Martin Fowler
Martin Fowler
Cisco Talos Blog
Cisco Talos Blog
L
LINUX DO - 最新话题
云风的 BLOG
云风的 BLOG
C
Check Point Blog
T
Threatpost
Google DeepMind News
Google DeepMind News
WordPress大学
WordPress大学
W
WeLiveSecurity
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
有赞技术团队
有赞技术团队
Hugging Face - Blog
Hugging Face - Blog
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
L
Lohrmann on Cybersecurity
Last Week in AI
Last Week in AI
T
Tor Project blog
T
Troy Hunt's Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
S
Security Affairs
SecWiki News
SecWiki News

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary What Is PQC Migration? The Largest Cryptographic Overhaul Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is Quantum Cyber Security?
Marin Ivezic · 2026-05-04 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

Quantum cyber security is the practice of protecting organizations against threats from quantum computing while preparing to adopt quantum technologies for defense. For most CISOs and security leaders, this means one thing above all else: migrating cryptographic infrastructure from classical algorithms to post-quantum cryptography (PQC) before regulatory deadlines and quantum computing advances converge.

Why Quantum Computing Changes the Security Calculus

A sufficiently powerful quantum computer will break the public-key cryptography that underpins TLS, VPNs, digital signatures, PKI, code signing, and virtually every authenticated or encrypted transaction in enterprise IT. Shor’s algorithm handles RSA and Diffie-Hellman. It also handles Elliptic Curve Cryptography (ECC), which recent research suggests may be easier to break than RSA. Grover’s algorithm weakens symmetric cryptography like AES, though the mitigation there (larger key sizes) is straightforward.

The machine capable of executing these attacks is called a Cryptographically Relevant Quantum Computer (CRQC). No one has built one yet. The resource estimates for building one keep shrinking, and my CRQC Quantum Capability Framework tracks the ten engineering capabilities that must converge before a CRQC becomes operational. The timeline is genuinely uncertain, which is precisely why the focus for security leaders should be on the deadlines that are certain rather than on Q-Day predictions that vary by a decade or more depending on who you ask.

The Threat Is Already Active

Quantum cyber security is not a problem you can defer until a CRQC exists. Two categories of attack are already underway or exploitable today.

Harvest Now, Decrypt Later (HNDL) is the interception and storage of encrypted data by adversaries who plan to decrypt it once quantum capabilities mature. Nation-state intelligence services have the collection infrastructure and the strategic patience to execute this at scale. Any data that must remain confidential for more than a decade is exposed to HNDL right now, regardless of when a CRQC arrives.

The less discussed counterpart is Trust Now, Forge Later (TNFL), a concept I introduced in 2018. TNFL targets trust rather than confidentiality: digital signatures made today with RSA or ECC could be forged retroactively by a future quantum computer. The consequences cascade through software supply chains, legal instruments, identity systems, and any domain where digital signatures establish authenticity. I have argued that signature migration should precede encryption migration because the trust infrastructure is harder to replace and the failure modes are more systemic.

What a Quantum Cyber Security Program Looks Like

For a CISO building a quantum readiness program, the work breaks down into phases that mirror other large-scale cryptographic transitions, except that the scope is broader and the interdependencies run deeper. I have described PQC migration as the largest, most complex cryptographic overhaul in IT history, with a large enterprise program spanning upwards of 120,000 discrete tasks.

The first phase is discovery. You cannot migrate what you cannot find. A cryptographic inventory catalogues where vulnerable algorithms are deployed across your enterprise, ideally formalized as a Cryptographic Bill of Materials (CBOM). If a full inventory feels overwhelming, risk-driven strategies allow you to prioritize the systems with the highest HNDL and TNFL exposure first.

Then comes assessment and planning. Mosca’s inequality provides one framework for prioritization: if the time your data needs to remain secure, plus the time it will take to migrate, exceeds the time until a CRQC exists, you are already too late. The Quantum Readiness Assessment formalizes this evaluation, and the PQC Readiness Self-Assessment Scorecard provides a quick benchmark of organizational posture.

Migration itself is where the work becomes tangible. It involves deploying NIST-standardized PQC algorithms (ML-KEM, ML-DSA, SLH-DSA) across network protocols, certificate hierarchies, key management systems, application code, and vendor integrations. Hybrid cryptography provides defense-in-depth during the transition. Crypto-agility ensures you can adapt as standards evolve.

Vendor engagement runs parallel to all of this. Most organizations depend on third-party products for their cryptographic infrastructure. Start asking vendors for their PQC roadmaps now, and include PQC requirements in new procurement decisions. The vendors who cannot answer that question are telling you something important about their own readiness.

The Deadlines Driving Action

I have argued repeatedly that the deadlines are already set, and they come from regulators, standards bodies, and technology vendors rather than from Q-Day predictions.

NSA’s CNSA 2.0 requires quantum-resistant algorithms for all new National Security System acquisitions by January 2027. Software and firmware signing must migrate by 2030. Full compliance is expected by 2035. NIST’s draft IR 8547 deprecates RSA, ECDSA, and Diffie-Hellman for federal systems by 2030 and disallows them by 2035. Google has committed to a 2029 PQC migration deadline. Cloudflare has published a phased roadmap to full post-quantum security by 2029. In Europe, NIS2 and DORA create parallel compliance pressure, and the US PQC regulatory framework is already comprehensive.

These deadlines cascade. Defense contractors must meet CNSA 2.0 timelines to retain contracts. Cloud-dependent enterprises inherit their providers’ migration timelines. Regulated industries face audit and compliance pressure whether or not a CRQC is imminent.

NIST estimates that a large agency migration takes three to five years once fully resourced. Organizations starting in 2026 are on schedule. Organizations starting in 2028 will be compressed. Waiting until 2030 means missing the first wave of hard deadlines entirely.

Getting Started

The Applied Quantum PQC Migration Framework provides the structured, open-source methodology for planning and executing a migration program. My practical steps guide maps the first concrete actions, and my first-year planning guide covers how to scope, resource, and govern the program. If you need a comprehensive resource for organizational readiness strategy, my forthcoming book Quantum Ready covers the full picture.

For CISOs facing budget conversations, I have also written about how to use quantum readiness to secure bigger budgets and why the negligence and liability implications of ignoring quantum risk are becoming increasingly concrete.

Go Deeper

Q-Day Deadlines Are Set — why the ecosystem clock matters more than Q-Day predictions

Getting Started With Quantum Security and PQC Migration — the structured starting point

Practical Steps to Quantum Readiness — first concrete actions for cybersecurity teams

120,000 Tasks: Why PQC Migration Is Enormous — full program plan breakdown

Planning the First Year of a Quantum Readiness Program — scoping and governance

The Quantum Threat: A Guide for Executives and Boards — board-level briefing

CISO Negligence and Personal Liability — legal exposure from inaction

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum