Skip to content
Theos Quantum TQ globe markTHEOS QUANTUM

Cryptographic exposure signals

Four panels on the state of post-quantum exposure, drawn from public catalogues and published documents. Each one names the body it came from, states the window it covers and shows when it was last updated. Where a figure is not available, the panel says so instead of showing a zero.

The Signal Replay

Seven years of cryptographic failure, with receipts.

The vetted advisory record this site already publishes, replayed in the order the world learned of each failure. Every pulse is a named advisory with a date and a source link in the ledger; each is plotted at a stated seat — the vendor's campus, the maintainer's institution, or the cataloguer's — because advisories have no geography and we will not invent one. No countdown, no “threats near you”: a record, not a show.

Signal replay · record

2024

2017–2024 · vetted

Disclosures pulsed

0/12

record settled

cyan · the advisory record, at stated seats · white · the eleven named institutions · the thread traces disclosure order — every active advisory links to its source

Quantum exposure · 2017 — 2026

Watch the quantum exposure grow.

The same decade the replay above just played, told as a trajectory: one sphere per year, each anchored to a public milestone, growing and reddening as the record accumulates. Every year names the event that moved it.

2017LOW

ROCA: a flaw in Infineon's RSA key generation exposes millions of smartcards and TPMs at once. The era's warning shot — one primitive, one library, global blast radius.

ROCA disclosure, Oct 2017 — in this site's vetted advisory record

2018LOW

NIST's post-quantum standardisation is underway: 69 first-round candidate algorithms under public cryptanalysis. The replacement era begins on paper.

NIST PQC Standardization, Round 1

2019GROWING

Google's Sycamore processor publishes the first quantum-advantage claim. Contested in degree ever since — but not in direction.

Arute et al., Nature, Oct 2019

2020GROWING

CurveBall: Windows certificate validation fooled by crafted elliptic-curve parameters. Classical public-key trust failing with no quantum computer required.

CVE-2020-0601 — in this site's vetted advisory record

2021ELEVATED

Log4Shell shows how little estates know about their own dependencies — precisely the blindness a cryptographic inventory exists to remove.

CVE-2021-44228 — in this site's vetted advisory record

2022ELEVATED

The turn: NIST names its winning algorithms, the White House orders migration planning in NSM-10, and NSA publishes CNSA 2.0 with dates attached.

NIST selection Jul 2022 · NSM-10 May 2022 · CNSA 2.0 Sep 2022

2023HIGH

Harvest-now-decrypt-later moves from theory to planning assumption in public guidance, while IBM's Condor crosses one thousand physical qubits.

CISA/NSA/NIST quantum-readiness factsheet Aug 2023 · IBM Condor Dec 2023

2024HIGH

FIPS 203, 204 and 205 are final — migration stops being research. MAS advises financial institutions to inventory their cryptography and plan the transition.

NIST, 13 Aug 2024 · MAS/TCRS/2024/01, Feb 2024

2025SEVERE

NIST adds HQC as a backup KEM and drafts the retirement schedule: RSA and ECC deprecated after 2030, disallowed after 2035.

NIST HQC selection Mar 2025 · NIST IR 8547 (draft)

2026CRITICAL

Regulators move from advice to instruments: Singapore's CSA, GovTech and IMDA publish a Quantum-Safe Migration Handbook and readiness index — and the published migration window this site counts is already more than a third elapsed.

CSA / GovTech / IMDA, 16 Jul 2026 · this site's Quantum Window arithmetic

Every year above is anchored to the public event its source line names; three are rows in this site's own vetted advisory record. The LOW → CRITICAL grades are our editorial reading of those milestones' direction — a judgement, labelled as one, not a measured figure.

Where the work is

The organisations behind the standards and the machines

Eleven named institutions across North America, Europe and Asia: the bodies whose documents set the dates on this page, and the programmes building the hardware those dates exist because of. Every one is listed beside the globe with the page its location is confirmed from.

Window
Current principal sites, as published by each organisation. Not time-windowed.
Last updated
Static. Reviewed 2026-07-27. Each entry links the page its location is taken from.

What this globe is not

It is not a threat map. No marker is an attack, an interception, an incident, a customer or an exposure, and nothing on it is derived from anything we observed. Each marker is one organisation's published location, plotted at city precision — a dot is a city and not a building, and the size of every dot is identical because there is no quantity here to encode. Presence on the globe says the organisation publishes standards or builds hardware. It says nothing about how capable, how advanced or how close to anything that organisation is.

Standards and guidance

Quantum-computing programmes

The list is not exhaustive and does not try to be. Organisations we cite elsewhere on this page are absent where we could not confirm a principal site from a page they publish, because a marker we cannot point at a source for is a marker this page has already said it will not draw.

The rule this page follows

A number renders only if it has a source, a window and a freshness state

All three, on every panel, without exception. A figure with a source but no window cannot be checked, and a figure with both but no freshness state cannot be trusted the day after it was written. Two of the four panels are fetched and carry a degraded state; two are static and carry a review date. Nothing on this page moves while you read it.

Dates

Every date here is ISO 8601. Day-precision dates are written YYYY-MM-DD, and that is the format used for the review stamps, the deadline dates and the advisory publication dates alike. A time appears in exactly one place, the advisory fetch stamp, in UTC, because those catalogues are refetched hourly and the hour is the part that matters. No month names, no locale formats, no seconds anywhere else.

Degraded states

A fetched panel that could not reach its catalogue falls back to a committed set of previously disclosed entries and is badged Snapshot. If there is nothing to fall back to, the figure reads Unavailable inside a dashed panel. Unavailable and zero are drawn differently on purpose: a zero is a measurement and the absence of one is not.

What this page does not carry

  • A date for a cryptographically relevant quantum computer, or any countdown towards one. No such date is defensible, so the migration-window panel shows the arithmetic and leaves the unknowable term unfilled.
  • Any counter that only ever rises — captured traffic, harvested signatures, records at risk. We cannot verify a single increment of one.
  • A cost of delay, an encryption-debt figure or anything accruing per second. Published constants would make the arithmetic reproducible and the claim would still be rhetoric.
  • A bytes-per-second or records-per-second rate, and any share-of-global-traffic percentage. We do not observe global traffic.
  • A ranking of countries or vendors derived by us from a feed we did not audit.
  • Platform activity figures — estates scanned, engagements completed, subscribers. We are pre-revenue, and a zero beside a sales link is worse than saying nothing.
  • A threat map. No marker anywhere on this page is an attack, an interception, an incident or an exposure — we do not observe those, and a globe that implied we did would be the most persuasive untrue thing on the site. The globe above plots published office locations of named organisations, each one linked, and nothing else.

The full list, with the reasoning behind each refusal, is published as a standard we can be held to.

Panel 1 · Advisory volume

What is being exploited in the field

Cryptography fails through implementation long before any quantum computer is involved. These are the two public catalogues we watch. Neither count is ours: both are counts of the rows published by the body named beside them, computed from the rows rendered on this page.

Window
Up to eight entries per catalogue, newest first. Each list prints the ISO date range of the entries it actually renders, and both the tiles and the lists use that same rule.
Last updated
Fetched 2026-09-26T08:22:08Z, and refetched hourly. Both catalogues were reached on this build.

CISA KEV entries

8

Entries rendered from the CISA catalogue inside the window above.

GitHub advisory entries

8

Entries rendered from the GitHub Advisory Database inside the window above.

Distinct CVE identifiers

8

Counted across the two lists below. An entry identified only by a GHSA number is not counted, so this figure can be lower than the other two tiles added together.

We publish no severity of our own here and we do not re-score these entries. Where a severity appears it is the value the issuing catalogue published; where a catalogue publishes none, the field is absent rather than filled in. The third body these lists depend on is the NIST National Vulnerability Database, which is where each CISA entry resolves to.

Panel 2 · Standards status

Which post-quantum standards are final

The publications a migration is measured against, and the state each one is in. We implement FIPS 203, FIPS 204 and FIPS 205. The remaining two rows are tracked because they are not final, and we make no claim of support for either.

Window
Not time-windowed. This board records the state of each publication, not activity over a period.
Last updated
Static. Reviewed 2026-07-27. Each row links the NIST page its state is taken from.

Ordered by FIPS number, lowest first. The backup key-encapsulation mechanism has no FIPS number assigned and is therefore last.

  1. ML-KEM (Kyber)

    FINAL

    FIPS 203 · Key encapsulation

    NIST CSRC — FIPS 203

  2. ML-DSA (Dilithium)

    FINAL

    FIPS 204 · Digital signatures

    NIST CSRC — FIPS 204

  3. SLH-DSA (SPHINCS+)

    FINAL

    FIPS 205 · Hash-based signatures

    NIST CSRC — FIPS 205

  4. FN-DSA (FALCON)

    DRAFT

    FIPS 206 · Compact lattice signatures

    NIST CSRC — PQC standardization (FIPS 206 in development)

  5. HQC

    SELECTED

    Backup KEM · code-based

    NIST CSRC — NIST IR 8545

Panel 3 · Regulatory deadlines

The dates that are already published

Regulators and standards bodies have set dates, and those dates bind estates regardless of when any hardware arrives. Each row names the body that issued it and links the document that sets it, so the date can be checked at source.

Window
Whole days between each ISO deadline date and the reference date below. Day granularity throughout; nothing here is counted in hours or seconds.
Last updated
Recomputed on each build. As at 2026-09-26.

Ordered by date, earliest first. Where two rows share a date, the framework name breaks the tie alphabetically.

  1. EU DORA

    Applies now · 617 days in force

    2025-01-17 · EU · EUR-Lex

    Digital Operational Resilience Act applies — EU financial entities must manage ICT & third-party risk, including cryptographic posture.

    EUR-Lex — Regulation (EU) 2022/2554 (DORA)

  2. NSA CNSA 2.0 · new acquisitions

    In 97 days

    2027-01-01 · US · NSS · NSA

    CNSSP 15, as cited by NSA: from 1 January 2027 all new National Security System acquisitions must be CNSA 2.0 compliant (ML-KEM, ML-DSA, SHA-384/512) unless otherwise noted.

    NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)

  3. NIST IR 8547 · RSA/ECC deprecated

    In 1,557 days

    2030-12-31 · US · Federal · NIST CSRC

    NIST draft transition guidance: 112-bit-strength classical public-key crypto (RSA-2048, ECDSA P-256) deprecated after 2030.

    NIST CSRC — NIST IR 8547 (initial public draft)

  4. NSA CNSA 2.0 · algorithms mandated

    In 1,922 days

    2031-12-31 · US · NSS · NSA

    NSA: by 31 December 2031 CNSA 2.0 algorithms are mandated for use across National Security Systems unless otherwise noted. Equipment that cannot support them must be phased out a year earlier.

    NSA — CNSA 2.0 and Quantum Computing FAQ (Ver. 2.1, Dec 2024)

  5. NIST IR 8547 · RSA/ECC disallowed

    In 3,383 days

    2035-12-31 · US · Federal · NIST CSRC

    NIST draft transition guidance: classical public-key algorithms disallowed for federal use after 2035.

    NIST CSRC — NIST IR 8547 (initial public draft)

The rows above are the whole board, rendered by the same component that renders it on its own page, so the two cannot drift apart. The Deadline Board adds what the board deliberately does not do, and an embeddable version for your own risk pages.

Panel 4 · Migration window

The arithmetic, with the inputs visible

Most post-quantum urgency arguments are adjectives. This one is a comparison of three durations, and it produces an uncomfortable answer without anybody predicting a date. The inputs are shown because a conclusion you cannot inspect is not worth having.

Window
Not time-windowed. The inequality compares three durations; it does not measure activity over a period.
Last updated
Static. Reviewed 2026-07-27. Nothing in this panel is computed from a clock.

The Mosca inequality

if x + y > z, exposure has already begun

Michele Mosca's formulation. If the data must outlive the migration, and the migration outlasts the protection, then the decision was overdue before the reader arrived at this page.

  1. x

    Confidentiality horizon

    Input · You declare it

    How long the data must stay secret, counted from the moment it could be captured. Your retention schedule and your regulatory obligations set this, so we do not estimate it for you.

  2. y

    Migration duration

    Input · [PLACEHOLDER: migration duration, estimated per estate]

    How long the change takes across the systems that hold that data, including the counterparties who have to move with you. We estimate it with you against a discovered inventory rather than publishing an average, because an average of other estates says nothing about yours.

  3. z

    Time until the cryptography is breakable

    Input · We publish no value

    How long before an adversary can break the public-key cryptography you are running now. No one can source this figure, so we do not assert one, and nothing on this page derives a date from anything else on it.

Because the third term has no published value, this panel prints no result. That is the honest surface: the arithmetic, and the two terms that are yours. The Quantum Window sets out the published dates the window is measured between. The readiness check runs the comparison on your own two figures in your browser, and the migration window defines each term with worked substitutions.

The same arithmetic is drawn against the published schedule on The Quantum Window, which also offers an embeddable version for your own risk pages. That page measures how much of the window between the standards being finalised and the deadlines they carry has elapsed. It is a policy schedule and not a prediction of when hardware arrives, which is why the elapsed figure lives there and not on this page.

Hardware disclosures

Announced physical qubit counts

Counts as disclosed by the organisation that built the machine, each one linked to the announcement it came from. We publish the table because readers ask for it, and we publish the caveat beneath it with equal prominence because the number is widely misread.

Window
Not time-windowed. Each row is a single disclosure, held until the organisation publishes a later one.
Last updated
Static. Reviewed 2026-07-27. Each row links the announcement its count is taken from.

What this table is not

A physical qubit count is not a threat metric. Error rates and the number of usable logical qubits decide when public-key cryptography is at risk, and no count below implies a machine that can recover an RSA-2048 or ECDSA P-256 private key. Published resource estimates for that task sit far above anything announced here, and they carry large assumption-dependent uncertainty of their own. The counts track a trend line. They do not date an event, and we derive no date from them.

Ordered by announced physical qubit count, highest first. Where two systems share a count, the organisation name breaks the tie alphabetically, so the order does not change between renders. The order is a way of arranging the rows and not a ranking of capability.

  1. Organisation and system

    Atom Computing · 1,180-qubit neutral-atom array

    Physical qubits

    1,180

    Vendor noteannounced Oct 2023

    Atom Computing — first to exceed 1,000 qubits

  2. Organisation and system

    IBM · Condor

    Physical qubits

    1,121

    Vendor noteunveiled Dec 2023

    IBM Quantum — IBM Quantum System Two announcement

  3. Organisation and system

    IBM · Heron r2

    Physical qubits

    156

    Vendor noteerror-focused tuning

    IBM Quantum — 100x100 performance challenge

  4. Organisation and system

    Google · Willow

    Physical qubits

    105

    Vendor notebelow-threshold error correction, Dec 2024

    Google — Meet Willow, our state-of-the-art quantum chip

  5. Organisation and system

    USTC · Zuchongzhi 3.0

    Physical qubits

    105

    Vendor notesuperconducting

    USTC — Zuchongzhi-3 announcement

  6. Organisation and system

    Quantinuum · H2

    Physical qubits

    56

    Vendor notetrapped-ion, high fidelity

    Quantinuum — 56-qubit H2 launch

  7. Organisation and system

    IonQ · Forte

    Physical qubits

    36

    Vendor note#AQ 36 algorithmic qubits

    IonQ — IonQ Forte system specifications

Row notes are carried as the organisation worded them in the linked announcement, which is why some describe a month rather than a day. Every other date on this page is an ISO date we set ourselves.

How we got here

Three decades from theory to deadline

The public record, one row per event, each linked to the paper, standard or draft it comes from. It runs from the algorithm that created the problem to the years policy has now fixed for retiring the cryptography that problem affects.

Window
1994 to 2035. Recorded events through the present, and beyond it the dates set by published draft guidance.
Last updated
Static. Reviewed 2026-07-27. Each row links its own source.

What this list is not

It is not a countdown, and it does not narrow towards a date when cryptography breaks. No row below states when a cryptographically relevant quantum computer arrives, because no public source states it. Rows dated after 2026 are deadlines written into draft guidance for United States federal systems — a policy schedule that can be revised by the body that published it, and not a forecast of when hardware becomes capable.

  1. 1994

    Recorded

    Peter Shor publishes the algorithm that breaks RSA and ECC on a large quantum computer.

    Shor — Proc. 35th FOCS (1994)

  2. 2016

    Recorded

    NIST opens the global post-quantum cryptography standardization competition.

    NIST CSRC — PQC standardization project

  3. 2019

    Recorded

    Google reports quantum supremacy on the 53-qubit Sycamore processor.

    Nature 574, 505–510 (2019)

  4. 2022

    Recorded

    NIST selects CRYSTALS-Kyber, CRYSTALS-Dilithium, SPHINCS+ and FALCON for standardization.

    NIST CSRC — NIST IR 8413 (third-round report)

  5. 2023

    Recorded

    Atom Computing announces a 1,180-qubit neutral-atom array; IBM unveils the 1,121-qubit Condor processor.

    Atom Computing — first to exceed 1,000 qubitsIBM Quantum — roadmap to 2033

  6. 2024

    Recorded

    NIST finalizes FIPS 203, 204 and 205 on 13 August. Google reports below-threshold error correction on Willow.

    NIST CSRC — FIPS 203Google — Willow quantum chip

  7. 2025

    Recorded

    NIST selects HQC as a backup key-encapsulation mechanism; FN-DSA (FIPS 206) remains in drafting.

    NIST CSRC — NIST IR 8545

  8. 2030

    Scheduled

    NIST draft transition guidance deprecates RSA-2048 and ECDSA P-256 for federal use.

    NIST CSRC — NIST IR 8547 (initial public draft)

  9. 2035

    Scheduled

    The same draft disallows classical public-key algorithms for federal use after 2035.

    NIST CSRC — NIST IR 8547 (initial public draft)

The 2019 row says Google reported quantum supremacy rather than achieved it. The result was contested when it was published, and the citation is to the claim as published. The two rows dated 2030 and 2035 cite the same draft because the same document sets both.

Your estate, not the landscape

These signals are public. Your exposure is specific.

Nothing on this page tells you which of your systems negotiates a vulnerable key exchange, or which certificate chain expires into a deadline above. AutoPQC discovers the cryptography you actually run, maps it to FIPS 203, 204 and 205, and sequences the work. A demonstration walks through that on a real estate.

Page reviewed 2026-07-27. Corrections are recorded in the Signal Log.