Cryptographic exposure signals
Four panels on the state of post-quantum exposure, drawn from public catalogues and published documents. Each one names the body it came from, states the window it covers and shows when it was last updated. Where a figure is not available, the panel says so instead of showing a zero.
The Signal Replay
Seven years of cryptographic failure, with receipts.
The vetted advisory record this site already publishes, replayed in the order the world learned of each failure. Every pulse is a named advisory with a date and a source link in the ledger; each is plotted at a stated seat — the vendor's campus, the maintainer's institution, or the cataloguer's — because advisories have no geography and we will not invent one. No countdown, no “threats near you”: a record, not a show.
Signal replay · record
2024
2017–2024 · vetted
Disclosures pulsed
0/12
record settled
cyan · the advisory record, at stated seats · white · the eleven named institutions · the thread traces disclosure order — every active advisory links to its source
Quantum exposure · 2017 — 2026
Watch the quantum exposure grow.
The same decade the replay above just played, told as a trajectory: one sphere per year, each anchored to a public milestone, growing and reddening as the record accumulates. Every year names the event that moved it.
ROCA: a flaw in Infineon's RSA key generation exposes millions of smartcards and TPMs at once. The era's warning shot — one primitive, one library, global blast radius.
ROCA disclosure, Oct 2017 — in this site's vetted advisory record
NIST's post-quantum standardisation is underway: 69 first-round candidate algorithms under public cryptanalysis. The replacement era begins on paper.
NIST PQC Standardization, Round 1
Google's Sycamore processor publishes the first quantum-advantage claim. Contested in degree ever since — but not in direction.
Arute et al., Nature, Oct 2019
CurveBall: Windows certificate validation fooled by crafted elliptic-curve parameters. Classical public-key trust failing with no quantum computer required.
CVE-2020-0601 — in this site's vetted advisory record
Log4Shell shows how little estates know about their own dependencies — precisely the blindness a cryptographic inventory exists to remove.
CVE-2021-44228 — in this site's vetted advisory record
The turn: NIST names its winning algorithms, the White House orders migration planning in NSM-10, and NSA publishes CNSA 2.0 with dates attached.
NIST selection Jul 2022 · NSM-10 May 2022 · CNSA 2.0 Sep 2022
Harvest-now-decrypt-later moves from theory to planning assumption in public guidance, while IBM's Condor crosses one thousand physical qubits.
CISA/NSA/NIST quantum-readiness factsheet Aug 2023 · IBM Condor Dec 2023
FIPS 203, 204 and 205 are final — migration stops being research. MAS advises financial institutions to inventory their cryptography and plan the transition.
NIST, 13 Aug 2024 · MAS/TCRS/2024/01, Feb 2024
NIST adds HQC as a backup KEM and drafts the retirement schedule: RSA and ECC deprecated after 2030, disallowed after 2035.
NIST HQC selection Mar 2025 · NIST IR 8547 (draft)
Regulators move from advice to instruments: Singapore's CSA, GovTech and IMDA publish a Quantum-Safe Migration Handbook and readiness index — and the published migration window this site counts is already more than a third elapsed.
CSA / GovTech / IMDA, 16 Jul 2026 · this site's Quantum Window arithmetic
Every year above is anchored to the public event its source line names; three are rows in this site's own vetted advisory record. The LOW → CRITICAL grades are our editorial reading of those milestones' direction — a judgement, labelled as one, not a measured figure.
Where the work is
The organisations behind the standards and the machines
Eleven named institutions across North America, Europe and Asia: the bodies whose documents set the dates on this page, and the programmes building the hardware those dates exist because of. Every one is listed beside the globe with the page its location is confirmed from.
- Window
- Current principal sites, as published by each organisation. Not time-windowed.
- Last updated
- Static. Reviewed 2026-07-27. Each entry links the page its location is taken from.
What this globe is not
It is not a threat map. No marker is an attack, an interception, an incident, a customer or an exposure, and nothing on it is derived from anything we observed. Each marker is one organisation's published location, plotted at city precision — a dot is a city and not a building, and the size of every dot is identical because there is no quantity here to encode. Presence on the globe says the organisation publishes standards or builds hardware. It says nothing about how capable, how advanced or how close to anything that organisation is.
Standards and guidance
NIST
Gaithersburg, Maryland, US
ETSI
Sophia Antipolis, France
BSI
Bonn, Germany
Quantum-computing programmes
IBM Research
Yorktown Heights, New York, US
Google Quantum AI
Santa Barbara, California, US
Atom Computing
Berkeley, California, US
Quantinuum
Broomfield, Colorado, US
IonQ
College Park, Maryland, US
IQM
Espoo, Finland
USTC
Hefei, Anhui, CN
DST-NQM Hub for Quantum Computing, IISc
Bengaluru, India
The list is not exhaustive and does not try to be. Organisations we cite elsewhere on this page are absent where we could not confirm a principal site from a page they publish, because a marker we cannot point at a source for is a marker this page has already said it will not draw.
The rule this page follows
A number renders only if it has a source, a window and a freshness state
All three, on every panel, without exception. A figure with a source but no window cannot be checked, and a figure with both but no freshness state cannot be trusted the day after it was written. Two of the four panels are fetched and carry a degraded state; two are static and carry a review date. Nothing on this page moves while you read it.
Dates
Every date here is ISO 8601. Day-precision dates are written YYYY-MM-DD, and that is the format used for the review stamps, the deadline dates and the advisory publication dates alike. A time appears in exactly one place, the advisory fetch stamp, in UTC, because those catalogues are refetched hourly and the hour is the part that matters. No month names, no locale formats, no seconds anywhere else.
Degraded states
A fetched panel that could not reach its catalogue falls back to a committed set of previously disclosed entries and is badged Snapshot. If there is nothing to fall back to, the figure reads Unavailable inside a dashed panel. Unavailable and zero are drawn differently on purpose: a zero is a measurement and the absence of one is not.
What this page does not carry
- A date for a cryptographically relevant quantum computer, or any countdown towards one. No such date is defensible, so the migration-window panel shows the arithmetic and leaves the unknowable term unfilled.
- Any counter that only ever rises — captured traffic, harvested signatures, records at risk. We cannot verify a single increment of one.
- A cost of delay, an encryption-debt figure or anything accruing per second. Published constants would make the arithmetic reproducible and the claim would still be rhetoric.
- A bytes-per-second or records-per-second rate, and any share-of-global-traffic percentage. We do not observe global traffic.
- A ranking of countries or vendors derived by us from a feed we did not audit.
- Platform activity figures — estates scanned, engagements completed, subscribers. We are pre-revenue, and a zero beside a sales link is worse than saying nothing.
- A threat map. No marker anywhere on this page is an attack, an interception, an incident or an exposure — we do not observe those, and a globe that implied we did would be the most persuasive untrue thing on the site. The globe above plots published office locations of named organisations, each one linked, and nothing else.
The full list, with the reasoning behind each refusal, is published as a standard we can be held to.
Panel 1 · Advisory volume
What is being exploited in the field
Cryptography fails through implementation long before any quantum computer is involved. These are the two public catalogues we watch. Neither count is ours: both are counts of the rows published by the body named beside them, computed from the rows rendered on this page.
- Window
- Up to eight entries per catalogue, newest first. Each list prints the ISO date range of the entries it actually renders, and both the tiles and the lists use that same rule.
- Last updated
- Fetched 2026-09-26T08:22:08Z, and refetched hourly. Both catalogues were reached on this build.
CISA KEV entries
8
Entries rendered from the CISA catalogue inside the window above.
GitHub advisory entries
8
Entries rendered from the GitHub Advisory Database inside the window above.
Distinct CVE identifiers
8
Counted across the two lists below. An entry identified only by a GHSA number is not counted, so this figure can be lower than the other two tiles added together.
CISA Known Exploited Vulnerabilities catalogue
Fetched · hourly8 entries · 2026-09-22 to 2026-09-25
- CVE-2026-879022026-09-25
- CVE-2026-656602026-09-25
- CVE-2026-672792026-09-25
Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability
- CVE-2026-713622026-09-24
Adobe Commerce and Magento Incorrect Authorization Vulnerability
- CVE-2026-54302026-09-24
- CVE-2026-851022026-09-22
Check Point Multiple Products Improper Certificate Validation Vulnerability
- CVE-2026-936162026-09-22
- CVE-2026-941272026-09-22
Each entry above links to its record in the NIST National Vulnerability Database.
8 entries · 2026-09-25
- GHSA-q986-4x7x-gx39high · 2026-09-25
SCBE-AETHERMOORE Unauthenticated AetherBrowser Ops API Exposes Operator Email Digests
- GHSA-vj8p-hp9x-gh47high · 2026-09-25
- GHSA-qpxh-ff8m-c62vmedium · 2026-09-25
- GHSA-vv77-66rf-pm86high · 2026-09-25
- GHSA-wrvw-254r-wpmvhigh · 2026-09-25
CliInvoke.Specializations has command injection in PowerShell and Cmd shell wrappers
- GHSA-j73w-8hfr-4gc9high · 2026-09-25
CliInvoke: Argument Injection in Extensibility Runner Factory
- GHSA-62mm-xwmv-crhghigh · 2026-09-25
- GHSA-9gfj-28hw-jchphigh · 2026-09-25
Each entry above links to its advisory page in the GitHub Advisory Database.
We publish no severity of our own here and we do not re-score these entries. Where a severity appears it is the value the issuing catalogue published; where a catalogue publishes none, the field is absent rather than filled in. The third body these lists depend on is the NIST National Vulnerability Database, which is where each CISA entry resolves to.
Panel 2 · Standards status
Which post-quantum standards are final
The publications a migration is measured against, and the state each one is in. We implement FIPS 203, FIPS 204 and FIPS 205. The remaining two rows are tracked because they are not final, and we make no claim of support for either.
- Window
- Not time-windowed. This board records the state of each publication, not activity over a period.
- Last updated
- Static. Reviewed 2026-07-27. Each row links the NIST page its state is taken from.
Ordered by FIPS number, lowest first. The backup key-encapsulation mechanism has no FIPS number assigned and is therefore last.
ML-KEM (Kyber)
FINALFIPS 203 · Key encapsulation
ML-DSA (Dilithium)
FINALFIPS 204 · Digital signatures
SLH-DSA (SPHINCS+)
FINALFIPS 205 · Hash-based signatures
FN-DSA (FALCON)
DRAFTFIPS 206 · Compact lattice signatures
HQC
SELECTEDBackup KEM · code-based
Panel 3 · Regulatory deadlines
The dates that are already published
Regulators and standards bodies have set dates, and those dates bind estates regardless of when any hardware arrives. Each row names the body that issued it and links the document that sets it, so the date can be checked at source.
- Window
- Whole days between each ISO deadline date and the reference date below. Day granularity throughout; nothing here is counted in hours or seconds.
- Last updated
- Recomputed on each build. As at 2026-09-26.
Ordered by date, earliest first. Where two rows share a date, the framework name breaks the tie alphabetically.
EU DORA
Applies now · 617 days in force2025-01-17 · EU · EUR-Lex
Digital Operational Resilience Act applies — EU financial entities must manage ICT & third-party risk, including cryptographic posture.
NSA CNSA 2.0 · new acquisitions
In 97 days2027-01-01 · US · NSS · NSA
CNSSP 15, as cited by NSA: from 1 January 2027 all new National Security System acquisitions must be CNSA 2.0 compliant (ML-KEM, ML-DSA, SHA-384/512) unless otherwise noted.
NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)
NIST IR 8547 · RSA/ECC deprecated
In 1,557 days2030-12-31 · US · Federal · NIST CSRC
NIST draft transition guidance: 112-bit-strength classical public-key crypto (RSA-2048, ECDSA P-256) deprecated after 2030.
NSA CNSA 2.0 · algorithms mandated
In 1,922 days2031-12-31 · US · NSS · NSA
NSA: by 31 December 2031 CNSA 2.0 algorithms are mandated for use across National Security Systems unless otherwise noted. Equipment that cannot support them must be phased out a year earlier.
NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)
NIST IR 8547 · RSA/ECC disallowed
In 3,383 days2035-12-31 · US · Federal · NIST CSRC
NIST draft transition guidance: classical public-key algorithms disallowed for federal use after 2035.
The rows above are the whole board, rendered by the same component that renders it on its own page, so the two cannot drift apart. The Deadline Board adds what the board deliberately does not do, and an embeddable version for your own risk pages.
Panel 4 · Migration window
The arithmetic, with the inputs visible
Most post-quantum urgency arguments are adjectives. This one is a comparison of three durations, and it produces an uncomfortable answer without anybody predicting a date. The inputs are shown because a conclusion you cannot inspect is not worth having.
- Window
- Not time-windowed. The inequality compares three durations; it does not measure activity over a period.
- Last updated
- Static. Reviewed 2026-07-27. Nothing in this panel is computed from a clock.
The Mosca inequality
if x + y > z, exposure has already begun
Michele Mosca's formulation. If the data must outlive the migration, and the migration outlasts the protection, then the decision was overdue before the reader arrived at this page.
- x
Confidentiality horizon
Input · You declare it
How long the data must stay secret, counted from the moment it could be captured. Your retention schedule and your regulatory obligations set this, so we do not estimate it for you.
- y
Migration duration
Input · [PLACEHOLDER: migration duration, estimated per estate]
How long the change takes across the systems that hold that data, including the counterparties who have to move with you. We estimate it with you against a discovered inventory rather than publishing an average, because an average of other estates says nothing about yours.
- z
Time until the cryptography is breakable
Input · We publish no value
How long before an adversary can break the public-key cryptography you are running now. No one can source this figure, so we do not assert one, and nothing on this page derives a date from anything else on it.
Because the third term has no published value, this panel prints no result. That is the honest surface: the arithmetic, and the two terms that are yours. The Quantum Window sets out the published dates the window is measured between. The readiness check runs the comparison on your own two figures in your browser, and the migration window defines each term with worked substitutions.
The same arithmetic is drawn against the published schedule on The Quantum Window, which also offers an embeddable version for your own risk pages. That page measures how much of the window between the standards being finalised and the deadlines they carry has elapsed. It is a policy schedule and not a prediction of when hardware arrives, which is why the elapsed figure lives there and not on this page.
Hardware disclosures
Announced physical qubit counts
Counts as disclosed by the organisation that built the machine, each one linked to the announcement it came from. We publish the table because readers ask for it, and we publish the caveat beneath it with equal prominence because the number is widely misread.
- Window
- Not time-windowed. Each row is a single disclosure, held until the organisation publishes a later one.
- Last updated
- Static. Reviewed 2026-07-27. Each row links the announcement its count is taken from.
What this table is not
A physical qubit count is not a threat metric. Error rates and the number of usable logical qubits decide when public-key cryptography is at risk, and no count below implies a machine that can recover an RSA-2048 or ECDSA P-256 private key. Published resource estimates for that task sit far above anything announced here, and they carry large assumption-dependent uncertainty of their own. The counts track a trend line. They do not date an event, and we derive no date from them.
Ordered by announced physical qubit count, highest first. Where two systems share a count, the organisation name breaks the tie alphabetically, so the order does not change between renders. The order is a way of arranging the rows and not a ranking of capability.
Organisation and system
Atom Computing · 1,180-qubit neutral-atom array
Physical qubits
1,180
Vendor noteannounced Oct 2023
Organisation and system
IBM · Condor
Physical qubits
1,121
Vendor noteunveiled Dec 2023
Organisation and system
IBM · Heron r2
Physical qubits
156
Vendor noteerror-focused tuning
Organisation and system
Google · Willow
Physical qubits
105
Vendor notebelow-threshold error correction, Dec 2024
Organisation and system
USTC · Zuchongzhi 3.0
Physical qubits
105
Vendor notesuperconducting
Organisation and system
Quantinuum · H2
Physical qubits
56
Vendor notetrapped-ion, high fidelity
Organisation and system
IonQ · Forte
Physical qubits
36
Vendor note#AQ 36 algorithmic qubits
Row notes are carried as the organisation worded them in the linked announcement, which is why some describe a month rather than a day. Every other date on this page is an ISO date we set ourselves.
How we got here
Three decades from theory to deadline
The public record, one row per event, each linked to the paper, standard or draft it comes from. It runs from the algorithm that created the problem to the years policy has now fixed for retiring the cryptography that problem affects.
- Window
- 1994 to 2035. Recorded events through the present, and beyond it the dates set by published draft guidance.
- Last updated
- Static. Reviewed 2026-07-27. Each row links its own source.
What this list is not
It is not a countdown, and it does not narrow towards a date when cryptography breaks. No row below states when a cryptographically relevant quantum computer arrives, because no public source states it. Rows dated after 2026 are deadlines written into draft guidance for United States federal systems — a policy schedule that can be revised by the body that published it, and not a forecast of when hardware becomes capable.
1994
Recorded
Peter Shor publishes the algorithm that breaks RSA and ECC on a large quantum computer.
2016
Recorded
NIST opens the global post-quantum cryptography standardization competition.
2019
Recorded
Google reports quantum supremacy on the 53-qubit Sycamore processor.
2022
Recorded
NIST selects CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON for standardization.
2023
Recorded
Atom Computing announces a 1,180-qubit neutral-atom array; IBM unveils the 1,121-qubit Condor processor.
Atom Computing — first to exceed 1,000 qubitsIBM Quantum — roadmap to 2033
2024
Recorded
NIST finalizes FIPS 203, 204 and 205 on 13 August. Google reports below-threshold error correction on Willow.
2025
Recorded
NIST selects HQC as a backup key-encapsulation mechanism; FN-DSA (FIPS 206) remains in drafting.
2030
Scheduled
NIST draft transition guidance deprecates RSA-2048 and ECDSA P-256 for federal use.
2035
Scheduled
The same draft disallows classical public-key algorithms for federal use after 2035.
The 2019 row says Google reported quantum supremacy rather than achieved it. The result was contested when it was published, and the citation is to the claim as published. The two rows dated 2030 and 2035 cite the same draft because the same document sets both.
Your estate, not the landscape
These signals are public. Your exposure is specific.
Nothing on this page tells you which of your systems negotiates a vulnerable key exchange, or which certificate chain expires into a deadline above. AutoPQC discovers the cryptography you actually run, maps it to FIPS 203, 204 and 205, and sequences the work. A demonstration walks through that on a real estate.
Page reviewed 2026-07-27. Corrections are recorded in the Signal Log.