One Quantum Threat, Many Migrations: How and Why PQC Programmes Are Diverging Around the World
Table of Contents
I flew back from Dubai on Friday. GISEC Global is the largest cyber security event in the Middle East and Africa – around 25,000 people over three days – and this year it ran from 16 to 18 September. The UAE Cyber Security Council and the Technology Innovation Institute ran a quantum summit that filled the whole final day on its own stage.
I was there to talk about PQC migration in large enterprises, and I expected the usual mix of quantum curiosity and vendor theatre. What I got instead was a room working through vendor lock-in, board reporting, and what to do about an HSM estate that can’t take a firmware update. On 17 and 18 September, alongside the summit, the International Telecommunication Union and the UAE Cyber Security Council ran a Global Quantum Drill. The first scenario, The Long Tail, was written for the people who receive incident reports, write the rules and answer for the outcome. It asked what happens to established supervisory practice when an adversary can harvest now and decrypt later. The second, run by the Technology Innovation Institute, was a set of capture-the-flag challenges on implementation weaknesses in systems built on post-quantum primitives, FALCON and HAWK among them. Nobody was asking whether quantum computers were real. They were rehearsing a migration failure.
On Tuesday I give the closing keynote at the PQC Summit in College Park, Maryland, the day before Quantum World Congress. The room will include the NIST team that wrote the standards, the Department of War, and the people who will enforce CNSA 2.0, the NSA’s algorithm suite for national security systems. Applied Quantum, my firm, runs migration programmes for clients in the Middle East, the United States, Mexico, Canada, the EU, Singapore, Malaysia, Japan and elsewhere, so I see the same threat being managed in many regulatory cultures at once. Almost everyone started from NIST’s algorithms and then built a different programme around them, and the two countries that didn’t, China and South Korea, are standardising their own algorithms as well.
The reasons for the differences are rarely written down. Each migration has also produced at least one instrument the others lack. This piece sets out how the migrations differ and why, what the differences cost anyone who operates in more than one jurisdiction, and what I think each could borrow from the others.
The four migration patterns
I have given the four patterns regional names, but a country can follow more than one at once. The United States itself runs separate national-security and civilian tracks.
The United States
I will start with what the United States did that no other government has matched. NIST ran the largest and longest open evaluation of cryptographic primitives anyone has run, over eight years and four rounds, and produced FIPS 203, 204 and 205 in August 2024. The United Kingdom, Canada, Japan, Singapore, Australia and the EU adopted those algorithms into their national guidance, in most cases verbatim.
And NIST isn’t finished. It selected HQC in March 2025 as a code-based backup to ML-KEM, and its additional-signature process is still an open competition. Nine candidates advanced to a third round in May 2026. HAWK, the only lattice-based scheme among them, was withdrawn on 29 July after Anthropic researchers showed that recovering a HAWK key reduces to a shortest-vector problem in roughly half the dimension, which leaves eight.
The United States also wrote the deadlines that change vendor roadmaps. CNSA 2.0 requires every new national security system acquisition from 1 January 2027 to support ML-KEM-1024 and ML-DSA-87. The requirement is passed down through contract clauses under the Federal Acquisition Regulation (FAR) and its defence supplement (DFARS), NIAP protection profiles and the Approved Products List into the supply chain of every company that sells to the US government.
Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, signed 22 June 2026, gives civilian agencies until 31 December 2030 to move high-value assets and high-impact systems to post-quantum key establishment and until 31 December 2031 for signatures. It also directs covered contractors to comply with the PQC FIPS by the end of 2030 and requires guidance on a cryptographic bill of materials (CBOM). OMB memorandum M-26-15, issued two days later, turned that into agency instructions. I covered the order when it was signed.
And the measurable deployment is American. Cloudflare’s 2025 year in review recorded post-quantum encrypted traffic rising from 29 per cent of human-generated web traffic in January to 52 per cent by early December. Twenty-eight countries more than doubled their share over the year. Several jumped within weeks of Apple enabling hybrid key exchange by default in iOS 26.
Cloudflare has set its own deadline for full post-quantum readiness, authentication included, at 2029. On 30 June, eight days after the executive order, Microsoft moved its completion date from 2033 to 2029. Google, Apple, Cloudflare and Amazon drew the adoption curve in Cloudflare’s data, which no other country’s companies could have done for the public internet.
So the US migration is standards-led, procurement-driven, federally scoped and, at the internet layer, already largely done. What the US programme lacks is any binding instrument that names post-quantum cryptography and applies to a bank, a utility or a hospital that does not sell to the federal government.
Europe
Europe adopted NIST’s algorithms and then hedged them. Germany’s federal cybersecurity office, BSI, has recommended FrodoKEM and Classic McEliece alongside the NIST selections since version 2020-01 of Technical Guideline TR-02102-1, dated 24 March 2020, more than two years before NIST announced its first selections. The current 2026-01 revision, published 23 January 2026, keeps both alternatives and sunsets classical-only key agreement at 31 December 2031. It also retains the 120-bit floor that BSI first set in 2017 as the target for the period after 2022 and has treated as the current minimum since 2023.
France’s cybersecurity agency, ANSSI, requires hybrid for any product with a long-term security claim and reserves the right to certify non-NIST algorithms. On 16 June 2026 it announced that from 2027 it will stop certifying security products that lack quantum-resistant cryptography. In November 2024 cybersecurity agencies from eighteen EU member states issued a joint statement calling the deployment of hybrid post-quantum solutions urgent.
The United Kingdom, outside the EU, is closer to Washington on this point: NCSC prefers a single migration to pure PQC and runs its own 2028, 2031 and 2035 milestones.
Europe took its conservative alternatives to ISO. ISO/IEC 18033-2:2006/Amd 2:2026, published in June 2026, added ML-KEM, FrodoKEM and Classic McEliece to the international standard for asymmetric ciphers. In NIST IR 8545, NIST gave key size and deployment interest, not security, as its reasons for choosing HQC over Classic McEliece. The transatlantic disagreement on backup primitives is therefore about engineering trade-offs and risk appetite, and both sides say so.
Europe also chose a different lever. Where the US exports its requirements through what the government buys, the EU exports them through what anyone is allowed to sell. The Cyber Resilience Act (CRA), in force since 10 December 2024 with obligations applying from 11 December 2027, creates the legal hook for crypto-agility as a condition of placing any product with digital elements on the European market. The harmonised standards being written under Mandate M/606, accepted by CEN, CENELEC and ETSI on 3 April 2025, are meant to define what a conformant product has to demonstrate. The coordinated roadmap from the NIS Cooperation Group asks member states for national plans by the end of 2026, high-risk systems by the end of 2030 and everything else by 2035.
The Gulf and Asia
The third migration is regulator-driven and unusually practical, and Dubai was a fair sample of it. The quantum summit at GISEC was the third year of a series. For two years the UAE Cyber Security Council and the Technology Innovation Institute ran CyberQ as a standalone conference, and I spoke at both. Two years ago it was the first event I know of anywhere to spend two days on nothing but quantum security, and more than 2,000 people came.
Folding it into GISEC this year was the smarter play. The people who travel to a quantum-only conference already care. The people who wander into a quantum summit at a 25,000-person cyber event mostly haven’t started, and they are still the majority. The regulators in this group work on the same logic: instead of waiting for the converted, they write to the people who haven’t started.
What these regulators have done so far:
- The UAE Cyber Security Council’s National Encryption Policy requires board-level transition plans, automated cryptographic inventory and crypto-agility as a design constraint.
- The Bank of Israel wrote to every banking corporation and licensed payment provider on 7 January 2025, in a letter addressed to the chairman of the board and the CEO, requiring a quantum preparedness plan discussed by the board and submitted within one year.
- The Hong Kong Monetary Authority (HKMA) published the sector’s first Quantum Preparedness Index on 27 July 2026: 2.3 out of 10, with 68 per cent of surveyed banks at the awareness, planning or pilot stage, 32 per cent not yet started, about half without a formal plan, and a target of 10 by 2030. I covered the whitepaper in August.
- The Monetary Authority of Singapore (MAS) ran a QKD sandbox with DBS, HSBC, OCBC and UOB and published the technical report on 29 September 2025.
- The Australian Signals Directorate (ASD) set the earliest hard retirement date anywhere for classical public-key cryptography, requiring RSA, DH, ECDH and ECDSA out of use by the end of 2030.
Switzerland’s financial market supervisor, FINMA, belongs in this group too. For its Guidance 05/2026, published 9 July 2026, FINMA surveyed 60 institutions between November 2025 and January 2026 and found that 43 of them (72 per cent) had neither planned nor implemented a single quantum-safe measure, while 8 per cent had a concrete roadmap. FINMA’s answer was to demand a PQC roadmap by mid-2027, derived from a strategy adopted by the board. It did not need a new rule to do that, because it read the existing technology-neutral governance requirements as already covering the risk.
There is nothing cryptographically sophisticated in any of these instruments, but each one is addressed to somebody who has to answer it. A bank in Tel Aviv was told twenty months ago to take a quantum plan to its board. A Swiss insurer will have a board-backed roadmap by next summer or explain to its supervisor why not.
China and Korea
China and South Korea decided that the algorithm layer itself should be domestic. South Korea’s KpqC competition selected HAETAE, AIMer, SMAUG-T and NTRU+ in January 2025. Seoul routes them through a validation programme built around Korean algorithms and targets full transition by 2035 under its national master plan. China’s Institute of Commercial Cryptography Standards issued a global call on 5 February 2025 for its own quantum-resistant algorithms. In March 2026 Chinese officials were reported to expect national standards within about three years.
China is also the only country running two tracks. Underneath its post-quantum programme it has built a physical key-distribution layer that nobody else has matched at scale. A 2025 paper in npj Quantum Information describes the China Quantum Communication Network as an operational trusted-relay QKD network exceeding 10,000 kilometres, with 145 backbone nodes and 20 metropolitan networks across 17 provinces and 80 cities, plus six ground stations linked to the Jinan-1 microsatellite. My own coverage puts the total including the Beijing–Shanghai backbone above 12,000 kilometres, serving hundreds of government departments, banks and state-owned enterprises. In May 2025 China Telecom Quantum Group launched a commercial system combining QKD with post-quantum cryptography across sixteen cities, opening with a quantum-encrypted call over 1,000 kilometres between Beijing and Hefei.
The NSA does not recommend QKD for national security systems, and the UK’s NCSC will not support it for government or military use. The technical objections are sound – I have made them myself. Authentication has to come from outside the protocol, trusted nodes are needed at every hop, and distance and key-rate limits apply. Implementation attacks also defeat assumptions the mathematics does not cover.
But the Western fallback for confidentiality on the highest-value links, if lattice cryptography were ever broken, is pre-placed symmetric key material distributed by logistics – a contingency for selected links that nobody has built national infrastructure for. China built the physical version. The United States chose not to, so I wouldn’t call it a race America is losing. China has deployed a hedge that the West has only on paper.
Levers, hybrid stances, deadlines and enforcement by jurisdiction
| Lever | Hybrid stance | Earliest cited milestone | Who is bound | Enforcement so far | |
|---|---|---|---|---|---|
| US national security systems | Procurement (CNSA 2.0) | Interim only, pure PQC end state | 1 Jan 2027 new acquisitions | Agencies, contractors, their suppliers | None identified |
| US civilian | Executive order and FAR rule | Permitted | 31 Dec 2030 key establishment, 31 Dec 2031 signatures | Agencies; contractors once the FAR rule is final | None identified |
| EU | Market access (CRA) plus national guidance and certification | Required or strongly recommended (BSI, ANSSI) | 2027 ANSSI certification gate; 11 Dec 2027 CRA obligations | Any vendor selling into the EU; products seeking French certification | None identified |
| UK | National guidance | Prefers pure PQC | 2028 discovery, 2031 priority, 2035 full | Advisory | None identified |
| Australia | National guidance (ISM) | Allowed in transition, discouraged as end state | End 2030 retirement of RSA, DH, ECDH, ECDSA | Government; ISM as procurement constraint | None identified |
| Canada | Contract clauses | Permitted | 1 Apr 2026 clauses in every new digital contract | Whole of federal government and its suppliers | Plans filed; none identified |
| Israel | Supervisor letter to boards | Not specified | 7 Jan 2026 plans submitted | Banks and licensed payment providers | None identified |
| Hong Kong | Supervisor index and target | Not specified | Score of 10 by 2030 | Authorised institutions | Diagnostic index; none identified |
| Switzerland | Existing governance rules applied | Not specified | Mid-2027 roadmaps | Supervised financial institutions | Survey and guidance; none identified |
| Korea | Sovereign algorithms plus validation | Not the axis | 2035 | Government and validated products | None identified |
| China | Sovereign algorithms plus QKD backbone | Not the axis | National standards reported for about 2028 | State sector first | None identified |
Why the migrations diverge
Different risk appetites on hybrid
The hybrid split is the divergence people cite most, and it is usually misread as distrust of NIST. BSI and ANSSI require or strongly recommend classical-plus-post-quantum key establishment, and NIST SP 800-227 permits it. NSA’s CNSA 2.0 accepts it as an interim step only and specifies a pure-PQC end state, while the UK’s NCSC prefers a single migration to pure PQC and Australia’s ASD allows hybrid as a transition but discourages it as a destination.
The stated rationales are about maturity. NIST’s own transition text says field-deployment confidence in a primitive accrues over decades, and ANSSI’s position papers warn against overestimating the maturity of post-quantum algorithms. Europe defaults to the belt-and-braces option for anything with a long confidentiality life. The US national security community treats hybrid as complexity it would rather remove from controlled environments. Nobody in Bonn or Paris thinks NIST got the mathematics wrong. BSI’s recommendations date from 2020, so the conservatism predates any argument about Washington.
Who writes the rules
In the United States, binding post-quantum requirements apply to federal agencies, national security systems and their contractors. They do not apply to private companies directly, and the sectoral regulators have not written their own.
In the power sector, for example, the North American Electric Reliability Corporation (NERC) gave US utilities three Critical Infrastructure Protection (CIP) standards to comply with in 2026:
- CIP-003-9, effective 1 April 2026, covers low-impact governance, vendor remote access and supply chain.
- CIP-012-2, effective 1 July 2026, covers the protection of real-time operational data between control centres.
- CIP-015-1, approved by the Federal Energy Regulatory Commission (FERC) on 26 June 2025 and effective 2 September 2025 with phased compliance into 2030, covers internal network monitoring.
None of the three mentions post-quantum cryptography. CIP-012 is the standard about protecting data in transit between control centres. It was revised this year, and it is silent on cryptography that a quantum computer breaks.
Outside the United States the first regulators to act were financial supervisors, and they did it by writing to boards. The Gulf and Asian programmes I see are further into governance than the American ones, despite starting later, because a supervisor wrote to their boards and not because they are more technically sophisticated.
Procurement versus market access
Canada is the only country other than the United States to have made post-quantum cryptography a condition of sale with comparable precision, and it did so for the whole of government. Under the Treasury Board’s standard on post-quantum cryptography, every new federal contract with a digital component since 1 April 2026 must include clauses requiring PQC per Cyber Centre guidance, modules validated under the Cryptographic Module Validation Program (CMVP) and crypto-agility, with ITSM.00.501 supplying the clause language. Departments filed migration plans in April and report annually.
The US civilian equivalent is the FAR Council’s proposed rule under EO 14412. Canada’s clauses are already in contracts, while the American ones are still in a rulemaking.
Europe’s Cyber Resilience Act is the third model. A vendor with customers on both sides of the Atlantic now answers to a US procurement gate and an EU market-access gate, with different expectations on hybrid, on validation and on what agility means. I haven’t seen a clean published account of how anyone reconciles them.
Sovereignty and the United States as a dependency
Nobody I have spoken to doubts NIST’s cryptography. What a growing number of governments and companies question is the United States as a long-term dependency, and their post-quantum programmes are where they have started to build around it. The reason is a political one that nobody in the international community says to NIST’s face.
In April 2024, before anything that happened this year, the European Union adopted the revised eIDAS regulation. Its Article 45 requires browsers to trust certificate authorities that member states place on the EU Trusted List and limits the browsers’ ability to remove them for cause.
The Electronic Frontier Foundation warned that browsers would lose the ability to act on security incidents at government-approved CAs. The Internet Governance Project wrote in November 2023 that the provision would replace a globalised trust anchor run by non-state actors with territorial anchors under government control. Mozilla, Cloudflare and the Linux Foundation signed an open letter against it, along with several hundred security researchers.
The European Parliament voted yes anyway. For the first time since 1995, European governments and not four American companies would decide which certificate authorities European users trust. To get there, Europe accepted what its own technical community described as a security regression.
Europe will first use that power in the post-quantum transition, because moving to new algorithms means reissuing every certificate in every trust chain. Google has said Chrome will not add traditional X.509 certificates carrying post-quantum algorithms to its root store at all. It is building a separate Chrome Quantum-resistant Root Store that accepts only Merkle Tree Certificates, with onboarding requirements to be finalised in the third quarter of 2027. The IETF is standardising those certificates in its PLANTS working group. If Europe runs its own trusted list under Article 45 while Chrome, Apple, Microsoft and Mozilla run theirs, the post-quantum PKI can fork along a line that already exists in law.
In its Recommendation of 11 April 2024 on the PQC roadmap, the Commission recalls that the EU’s Security Union and Cybersecurity strategies both treat encryption as a key technology for resilience and technological sovereignty. The European Parliament’s research service published an eight-page briefing in November 2024, by Stefano De Luca and Tristan Marcelin, titled Cryptographic security: critical to Europe’s digital sovereignty.
In the Quantum Europe Strategy of July 2025 and the Quantum Act scheduled in its 2026 work programme, the Commission treats quantum – and cryptography with it – as industrial capability to be built on purpose. The US runs its quantum industrial policy and its PQC migration from different agencies, each with its own budget; Europe is fusing the two.
These governments also have a recent example of how Washington can cut off access to a technology without notice. On 12 June 2026 the Commerce Department issued an is-informed letter to Anthropic under the Export Administration Regulations (EAR). The letter required a licence before any export, re-export or in-country transfer of two AI models to any foreign person worldwide, including the company’s own employees in the United States. Unable to filter users by nationality in real time, the company suspended global access.
The Commerce Department lifted the restrictions on 30 June after the company agreed to new safeguards. Mayer Brown’s analysis called the action unprecedented. An is-informed letter can be issued without rulemaking, notice and comment or advance publication, and it contains no allied exemption. The action was aimed at a nationality-verification problem, but its effect was to switch off a technology worldwide for eighteen days. The model Commerce restricted in June is the one Anthropic’s researchers used to find the HAWK weakness six weeks later.
Commerce already controls cryptography under the same regulations. Encryption software is listed in EAR Category 5 Part 2. The reason global distribution is routine is License Exception ENC, which is policy and can be narrowed by the same process.
European officials also remember a precedent. The 1990s export controls that limited exportable cryptography to 40-bit and then 56-bit keys pushed development offshore. RSA Data Security and others argued, in the amicus brief they filed in Bernstein v. US Department of Justice in November 1997, that the controls undermined national security by encouraging good cryptographic software to be built outside the United States. Several of the officials now drafting sovereignty policy in Europe were working in the field when that happened.
Since roughly the start of this year, several dozen large organisations on four continents have asked my firm for advice on cryptographic discovery, inventory and CBOM tooling with a condition I had never heard in over thirty years of doing cyber work: the tool must not be American. A completed cryptographic inventory is a complete list of where an organisation is weakest. Those companies have decided they won’t hand that list to a vendor subject to US jurisdiction and the CLOUD Act, for the same reason they wouldn’t hand it to a vendor subject to Chinese jurisdiction.
None of them has said so in public, and what is on the record shows American vendors doing well. SandboxAQ, one of the vendors I am regularly asked about, closed a Series E of more than $450 million in April 2025. Its named customers are the US Air Force, the Department of Health and Human Services and, since December 2025, the Department of War CIO under a five-year agreement. That is federal business won at scale inside the United States. What I am describing is demand outside it, from buyers who do not announce their purchases. The only evidence I have is that they keep telling me.
My impression of enterprise posture in the US and elsewhere
I can’t document this last difference the way I can the other four, so take it as an impression. The United States leads the world in cryptography through NIST, which I think is why, in my conversations with American enterprises, I hear a quiet confidence that the quantum threat is a solved problem in waiting. The assumption is that Silicon Valley will sell a product and that buying it will close the matter. The people I work with elsewhere treat the threat as an open risk on two fronts, a cyber risk and a sovereignty risk. Their conversations are about what an enterprise or a government should do next.
I tested that impression against this year’s conference calendar. GISEC’s quantum summit was convened by a regulator, an intergovernmental body and a national research institute, and its two exercises put supervisors and implementers under pressure. At RSA Conference in March, post-quantum cryptography and crypto-agility were, by the account of vendors who attended, the conversation of the week. The practical sessions I can find were the ones vendors hosted: Thales’s PQC Palooza with Michele Mosca, Keyfactor’s panel on NIST’s crypto-agility paper, DigiCert’s session on trust models for the quantum era. That is useful content, and its convenors also sell the remedy.
DEF CON’s Quantum Village is a different thing and a good one. It is a non-profit in its fourth year, its 2025 capture-the-flag drew more than 750 people, and it has shipped a fully open-source quantum sensor built from off-the-shelf parts and a nitrogen-vacancy diamond. It exists to get hackers into quantum technology, and it does that well, but a bank trying to get through a migration isn’t its audience.
I couldn’t find a US event this year at which a regulator asked supervisors to rehearse a quantum incident.
I have one more number of my own, as anecdotal as the others. Quantum Academy, the training business I am launching publicly this week, has already received several dozen inquiries from companies for private PQC training. One came from the EU and all the others from the Middle East and Asia.
Against that impression, the largest commercial PQC vendors are in the United States. Google, Cloudflare and Microsoft have set 2029 completion dates, earlier than any government has set for the civilian economy. The impression I am describing is of the enterprises that buy from those companies, and of the regulators that have not yet told those enterprises to buy.
What the divergence will cost
Contradictory guidance for anyone operating across borders
A multinational bank configuring TLS is told by Germany to use hybrid, by Australia to avoid it as an end state, and by US national security guidance to treat it as temporary. The pragmatic resolution I see in practice is to inherit whatever hybrid the protocol already ships, which for TLS 1.3 means X25519MLKEM768. Teams defer the harder question of hybrid signatures, where the IETF’s composite signature work is still unsettled.
That works for web traffic, but it isn’t an answer for a VPN estate, an HSM fleet or a code-signing pipeline that has to satisfy three regulators at once.
Validating the same algorithm six times
A cryptographic module cannot be sold into most regulated markets without a FIPS 140-3 certificate from the CMVP, a programme the US government runs. FIPS 140-3 validations now take an average of 542 days, up from 367 under FIPS 140-2, according to SafeLogic’s analysis of CMVP data, a figure NIST does not publish itself. FIPS 140-2 certificates move to historical status on 21 September 2026. The CNSA 2.0 acquisition gate opens 102 days later.
The EU Common Criteria scheme became applicable in February 2025, received its second amendment on 8 December 2025, and its cryptography guidelines now include post-quantum recommendations. Korea’s KCMVP, Japan’s JCMVP, China’s certification under the State Cryptography Administration and India’s STQC run in parallel. A global vendor that wants to sell one ML-KEM implementation in Washington, Brussels, Seoul, Tokyo, Beijing and Delhi will validate it six times under six regimes. I haven’t yet met a programme budget with that line in it.
A forked PKI
Chrome will accept only Merkle Tree Certificates in its quantum-resistant root store, while the trust lists under Article 45 of eIDAS are built from X.509 qualified certificates, so the two already diverge on certificate format. If the European trusted list and the American root programmes diverge further on post-quantum certificate policy or simply on timing, a European bank with an American cloud provider will run two certificate hierarchies for the same services. Article 45 made that legally possible in 2024, and the post-quantum reissuance makes it operationally likely, because every trust chain is being rebuilt anyway.
No enforcement anywhere yet
As of this month, I can find no fine, examination finding, procurement rejection or public censure that any regulator or buyer has issued over a post-quantum requirement, anywhere. That applies to the regulators I have praised here as much as to the ones I have criticised. The Bank of Israel’s one-year deadline passed in January, and I haven’t been able to establish what the banks submitted or what the supervisor did with it. HKMA’s index and FINMA’s survey are diagnostic; Canada’s departments have so far reported only plans. Supervisors under the EU’s Digital Operational Resilience Act (DORA) have not published a quantum finding, and CMVP has excluded nobody.
When a regulator does act, I expect a supervisory finding under DORA or from MAS that names a missing inventory, not a fine over a broken algorithm.
So the Gulf, Europe and Asia lead on rule-writing and on board attention, and no jurisdiction has enforced anything. That is the strongest evidence I know for the argument I have been making for two years, that PQC migration is a governance programme with a cryptographic component. The programmes I have run go to about 120,000 discrete tasks, of which fewer than 30,000 touch cryptography directly.
No regulator anywhere yet asks for evidence of execution. Until one does, every jurisdiction’s lead exists only on paper. That includes the American lead at the internet layer, because Cloudflare’s 52 per cent is a measure of browser support. It does not cover the internal PKI, the mainframe or the HSM estate, which is where most of those 120,000 tasks are.
The adversary does not care which migration you are in
Whoever is running a harvest-now-decrypt-later operation is indifferent to jurisdiction. Data captured from a European subsidiary in 2026 is as exposed as data captured from an American parent. A programme that meets the strictest of three regulators on paper while its HSM fleet runs RSA-2048 until 2031 is no more resilient because its paperwork is multilingual.
For the organisation that has to comply with all of them, the divergence between regimes adds cost and no protection.
What each migration could borrow from the others
I don’t think the United States should copy eIDAS, or that Europe should copy CNSA 2.0 wholesale, or that anyone should copy China’s quantum backbone. But each migration has produced one instrument the others lack.
From the Gulf and Asia, a two-page letter to boards. The Bank of Israel’s letter changed what Israeli bank directors discussed in 2025, and FINMA achieved the same result by reading existing rules. FERC, the US banking agencies, HHS and TSA could each write one this quarter without new legislation.
From Canada, contract clauses that already exist. The April 2026 language is liftable, and the FAR rule under EO 14412 could be finished before 2030.
From Europe, market access as a lever, and a testable definition of crypto-agility. The CRA’s harmonised standards will be the first attempt anywhere to define it as a conformance requirement. NIST’s CSWP 39, published in December 2025 and updated in June 2026, defines the term well and mandates nothing.
From the United States, a procurement gate with a date on it, and a validation queue that everyone else still routes through. If the 542-day figure is right, vendors will meet the January 2027 gate with exception paperwork instead of validated modules. Allied vendors will draw their own conclusions about depending on that queue. EO 14412 already directs NIST to revisit CMVP, and I think that is the most consequential thing Washington could fix, for everyone else’s migration as well as its own.
From Dubai, a rehearsal. The Global Quantum Drill that the ITU and the UAE Cyber Security Council ran during GISEC is the first post-quantum migration-failure exercise I have seen a regulator actually run. The Bank of England did the equivalent for cyber crisis response with Waking Shark more than a decade ago, and the same format would work here. A US regulator could run one with three banks and two utilities before the January gate and would learn more about readiness in two days than from a year of inventory reports.
I left Dubai with the impression that the people taking the migration most seriously are those who treat it as an operational problem with a board, a supervisor and a rehearsal attached, and the people taking it least seriously are those who treat it as an algorithm swap with a deadline. Almost all of these programmes start from the same NIST algorithms, and no two of them are alike. By 2027 the difference will be visible in who has moved.