Tracking the migration off RSA and ECC

The post-quantum transition, tracked in one place

QCrypt Watch follows the standards, national mandates, funding and deployments that decide when and how the world replaces classical public-key cryptography, and how much time your data actually has.

Until RSA and ECC are disallowed for US federal use
9.3 yrs

Until RSA and ECC are disallowed for US federal use

National programs with published migration timelines
12

National programs with published migration timelines

NIST algorithms on the tracker
7

NIST algorithms on the tracker

Vendors mapped across the PQC supply chain
20+

Vendors mapped across the PQC supply chain

Latest intelligence

Standards decisions, regulation, funding and real-world deployment, filtered for signal.

View all
AdoptionGlobal·

Signal deploys the SPQR triple ratchet

Signal extends its earlier PQXDH work with a post-quantum ratchet, closing the gap for long-lived conversation state.

Signal
Read at Signal
IndustryGlobal·

Crypto-agility becomes the dominant enterprise buying criterion

Buyers increasingly prioritize the ability to swap algorithms over any single algorithm choice, reshaping vendor roadmaps across PKI and HSM portfolios.

Entrust
Thales
Keyfactor
Read at NIST CSWP 39
IndustryGlobal·

Harvest-now-decrypt-later moves from theory to procurement language

Government and defense contracts increasingly specify long-term confidentiality horizons, forcing suppliers to answer for data captured today and decrypted later.

NATO
US DoD
Read at CISA
IndustryGlobal·

Banks pilot post-quantum protection for payment rails

Several tier-one institutions begin hybrid key exchange trials on interbank links, citing harvest-now-decrypt-later exposure on decades-long confidentiality requirements.

JPMorgan
HSBC
Mastercard
Read at BIS Project Leap
AdoptionGlobal·

Cloudflare reports the majority of its human-originated TLS traffic is post-quantum protected

Hybrid X25519MLKEM768 key agreement crosses a visible adoption threshold on the public internet, driven by default-on browser support.

Cloudflare
Google
Mozilla
Read at Cloudflare Radar
ResearchGlobal·

Researchers narrow the resource estimate for breaking RSA-2048

A revised analysis lowers the estimated qubit count needed for Shor's algorithm against RSA-2048, tightening credible Q-Day windows without changing near-term feasibility.

Google
Read at arXiv 2505.15917

Standards tracker

ML-KEM, ML-DSA, SLH-DSA, FN-DSA and HQC with status, security levels and real adoption notes, plus every dated milestone from NIST, NSA, ETSI and national bodies.

Open the tracker

Vendor landscape

Who builds the migration tooling, the silicon, the HSMs and the certificate infrastructure, with funding rounds mapped against segment and geography.

See the landscape

Q-Day exposure model

Mosca's inequality made concrete: set your confidentiality horizon, migration time and Q-Day estimate to see how much slack you have, if any.

Run the model

Free with sign-up

The PQC Migration Plan, a six-page, actionable brief

Target-state algorithms, the full deadline map from CNSA 2.0 to the 2035 disallowance, a five-phase program with owners and deliverables, a first-90-days checklist, and the failure modes that sink migrations. Downloads automatically the moment you create an account.

The weekly brief on the cryptographic transition

One email a week: what changed in standards, what regulators did, who raised money, and what it means for migration planning.