QianHeng乾珩 PQC Docs Hub量子文档 ✦ Ask AI✦ 问问文档 ⚐ Scan⚐ 扫一扫

PQC ecosystem pulse 2025-2026

In 2025-2026 the post-quantum cryptography (PQC) transition crossed a threshold: it moved from "standards published" to "shipping broadly." Mainstream platforms are moving from pilots toward default enablement: some operating systems, browsers / edge networks, messaging apps and network gear now negotiate post-quantum / hybrid key exchange by default or as a configurable option, while governments converted aspirational guidance into dated migration deadlines.

Where the transition is headed — key milestones 2024–2035:

2024 2025 2026 2027 2030 2035 FIPS 203/204/205finalized SP 800-227 · HQCbig-tech rollout FIPS 206/207 draftson-ramp Round 3 CNSA 2.0 (NSS)ANSSI cert cutoff deprecate RSA/ECCEU high-risk done disallow legacymigration complete
Snapshot as of June 2026 — verify before citing. Milestones below are based on official releases, standards, regulatory filings, or vendor documentation; vendor roadmaps and rumors are marked separately. Cross-check against Resources — full standards register.

Timeline

DateEvent
2024-08-13NIST finalizes FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), FIPS 205 (SLH-DSA) (confirmed)
2024-12Apple ships PQ3 for iMessage (iOS 17.4 era); Google announces Willow 105-qubit chip (confirmed)
2025-03-11NIST selects HQC as an additional KEM standardization target, serving as a backup to ML-KEM; not yet a final FIPS standard as of this snapshot (selection confirmed; standard pending)
2025-05PQC Coalition (MITRE, IBM, Microsoft, PQShield, SandboxAQ) publishes 4-stage Migration Roadmap (confirmed)
2025-05-30NSA re-issues CNSA 2.0 algorithm advisory (confirmed)
2025-06-06US Executive Order 14306 amends EO 14144 — drops near-term mandatory procurement triggers, keeps CISA PQC product list and TLS 1.3 by 2030 (confirmed)
2025-06-23EU NIS Cooperation Group PQC roadmap: national strategies by end-2026, high-risk critical infrastructure by 2030, medium-risk by 2035 (confirmed)
2025-08NIST submits FIPS 206 (FN-DSA / Falcon) for clearance; the Initial Public Draft has not yet been published — the draft is still in NIST / Commerce clearance, with publication and the final standard expected around 2026–2027
2025-08Palo Alto Networks PAN-OS 12.1 "Orion" — full NIST PQC, quantum-safe IKEv2 VPN, Quantum Readiness Dashboard (per vendor docs)
2025-09NIST SP 800-227 (KEM guidance) final; Apple enabled quantum-secure TLS by default for URLSession and the Network framework on iOS 26 / macOS 26 etc. (coverage per Apple docs) (confirmed)
2025-10Signal ships SPQR ("Triple Ratchet") extending ML-KEM beyond PQXDH (confirmed)
2025-11Microsoft GA: ML-KEM / ML-DSA on Windows 11 and Server 2025; AWS Payments Cryptography adds PQC in transit (confirmed)
2025-12Cloudflare: ~52% of human web traffic is post-quantum (up from ~29% early 2025) (confirmed)
2026-03Google shortens quantum-safe target to 2029 (Android ML-DSA); OpenTitan advancing post-quantum secure boot and a production-grade root of trust (per official announcements)
2026-04Meta publishes PQC migration framework (5 maturity levels) (confirmed)
2026-05-14NIST advances 9 signature on-ramp candidates to Round 3 (confirmed)
2026-06Quantinuum Nasdaq IPO — rumored / expected, pending an official listing filing or exchange announcement (rumored)
2026-06-22US issues EO 14412 "Securing the Nation Against Advanced Cryptographic Attacks" — directs federal information systems to migrate to NIST-approved FIPS PQC, with post-quantum encryption and authentication targets for high-sensitivity systems set to 2030 / 2031 respectively (confirmed)
2025-02China: ICCS / SCA next-gen (quantum-resistant) commercial-crypto algorithm call — submission deadline 2026-06-30, no shortlist yet (confirmed call, outcome pending)
2025-10China Mobile publishes 抗量子密码迁移白皮书 (anti-quantum cryptography migration white paper) (confirmed)

Standards

The core ML-KEM / ML-DSA / SLH-DSA trio is final; HQC (expected FIPS 207, final expected ~2027) and Falcon (FIPS 206) are in the pipeline, and a fresh signature on-ramp keeps the catalog growing. For the algorithm lineage and competition rounds see Round 4 & the signature on-ramp; for normative documents and profiles see Standards and Timeline.

Shipping at scale

Adoption is now measurable, not theoretical. Cloudflare reports ~52% of human web traffic protected by post-quantum key exchange as of December 2025. Apple enabled quantum-secure TLS by default for URLSession and the Network framework on iOS 26 / macOS 26 etc. (coverage per Apple docs); Signal extended its ratchet with SPQR; Microsoft brought ML-KEM and ML-DSA to Windows 11 and Server 2025; and AWS Payments Cryptography added PQC for data in transit. On the device side, OpenTitan is advancing SLH-DSA secure boot and a production-grade root of trust (per official announcements). See TLS & transport and Hybrid deployment.

Alliances

The PQC Coalition (MITRE, IBM, Microsoft, PQShield, SandboxAQ) anchors cross-vendor migration guidance with its 4-stage roadmap. The Linux Foundation Post-Quantum Cryptography Alliance (PQCA) continues to consolidate open-source implementations, joined in January 2025 by NVIDIA cuPQC for GPU-accelerated PQC primitives. See Global vendors, PQC hardware and PQC HSMs.

China

China is running a parallel track. In February 2025 the ICCS / SCA issued a call for next-generation quantum-resistant commercial-crypto algorithms with a submission deadline of 2026-06-30; no shortlist has been published yet. In October 2025 China Mobile released its 抗量子密码迁移白皮书, signalling carrier-level migration planning. Expect domestic algorithms (SM-family successors) rather than direct NIST adoption. See China vendors.

Standards & references

产业动态 2025-2026

2025 至 2026 年,PQC 迁移跨过了一道门槛,从"标准已发布"走向"规模化落地"。主流平台开始从试点走向默认启用:部分操作系统、浏览器/边缘网络、即时通讯和网络设备已默认或可配置协商抗量子/混合密钥交换;各国政府也把方向性指引落实为带明确期限的迁移要求。

迁移走向——2024 至 2035 关键里程碑

2024 2025 2026 2027 2030 2035 FIPS 203/204/205finalized SP 800-227 · HQCbig-tech rollout FIPS 206/207 draftson-ramp Round 3 CNSA 2.0 (NSS)ANSSI cert cutoff deprecate RSA/ECCEU high-risk done disallow legacymigration complete
本文为 2026 年 6 月的快照,引用前请自行核实。以下里程碑以官方发布、标准文件、监管文件或厂商文档为依据;厂商路线图与传闻另行标注。请同时对照 资源链接 — 完整标准登记册

时间线

日期事件
2024-08-13NIST 正式发布 FIPS 203 (ML-KEM) FIPS 204 (ML-DSA) FIPS 205 (SLH-DSA) (confirmed)
2024-12Apple 为 iMessage 推出 PQ3(iOS 17.4 时期) Google 公布 Willow 105 量子比特芯片 (confirmed)
2025-03-11NIST 选定 HQC 作为额外的 KEM 标准化对象,用作 ML-KEM 的备份算法;截至快照时点尚未成为最终 FIPS 标准 (入选 confirmed 终稿待定)
2025-05PQC Coalition(MITRE IBM Microsoft PQShield SandboxAQ)发布四阶段迁移路线图 (confirmed)
2025-05-30NSA 重新发布 CNSA 2.0 算法指引 (confirmed)
2025-06-06美国 第 14306 号行政命令 修订 EO 14144 取消近期强制采购触发条件 保留 CISA PQC 产品清单与 2030 年前 TLS 1.3 要求 (confirmed)
2025-06-23欧盟 NIS 合作组 PQC 路线图 各国战略于 2026 年底前出台 高风险关键基础设施 2030 年前完成 中风险 2035 年前完成 (confirmed)
2025-08NIST 提交 FIPS 206 (FN-DSA / Falcon) 进入审批;其首个公开草案 IPD 尚未公开发布,仍处于审批阶段,尚未成为最终标准(预计 2026—2027)
2025-08Palo Alto Networks PAN-OS 12.1 "Orion" 全面支持 NIST PQC 抗量子 IKEv2 VPN 量子就绪仪表盘 (以厂商文档为准)
2025-09NIST SP 800-227(KEM 指南)定稿 Apple 在 iOS 26、macOS 26 等系统的 URLSession 与 Network.framework 中默认启用量子安全 TLS(覆盖范围以 Apple 文档为准)(confirmed)
2025-10Signal 推出 SPQR("Triple Ratchet")将 ML-KEM 拓展至 PQXDH 之外 (confirmed)
2025-11Microsoft 正式发布 Windows 11 与 Server 2025 的 ML-KEM / ML-DSA AWS Payments Cryptography 为传输环节加入 PQC (confirmed)
2025-12Cloudflare 数据 人类网页流量约 52% 已用抗量子密钥交换(2025 年初约 29%)(confirmed)
2026-03Google 将抗量子目标提前至 2029(Android ML-DSA) OpenTitan 后量子安全启动与量产级信任根进展 (以官方公告为准)
2026-04Meta 发布 PQC 迁移框架(五级成熟度)(confirmed)
2026-05-14NIST 将 9 个签名 on-ramp 候选 推进至 Round 3 (confirmed)
2026-06Quantinuum 纳斯达克 IPO 传闻 / 预期,尚待官方上市文件或交易所公告确认 (rumored)
2026-06-22美国发布 EO 14412《Securing the Nation Against Advanced Cryptographic Attacks》,要求联邦信息系统向 NIST-approved FIPS PQC 迁移,并将高敏感系统的后量子加密与认证目标分别推进至 2030 / 2031 时间窗 (confirmed)
2025-02中国 ICCS / SCA 启动下一代(抗量子)商用密码算法征集 提交截止 2026-06-30 尚无入围名单 (征集 confirmed 结果待定)
2025-10中国移动发布《抗量子密码迁移白皮书》(confirmed)

标准进展

核心的 ML-KEM / ML-DSA / SLH-DSA 三件套已定稿,HQC(预期 FIPS 207 终版预计 2027 年前后)与 Falcon(FIPS 206)尚在路上,新一轮签名 on-ramp 则让算法目录持续扩充。算法谱系与竞赛轮次见 Round 4 与签名 on-ramp,规范文档与 profile 见 标准时间线

规模化落地

采用率已可量化,不再停留在理论。Cloudflare 数据显示,截至 2025 年 12 月,约 52% 的人类网页流量受抗量子密钥交换保护。Apple 在 iOS 26、macOS 26 等系统的 URLSession 与 Network.framework 中默认启用量子安全 TLS(覆盖范围以 Apple 文档为准),Signal 以 SPQR 扩展棘轮,Microsoft 把 ML-KEM 与 ML-DSA 带入 Windows 11 与 Server 2025,AWS Payments Cryptography 也为传输数据加入了 PQC。设备侧,OpenTitan 正推进 SLH-DSA 安全启动与量产级信任根(以官方公告为准)。参见 TLS 与传输混合部署

联盟生态

PQC Coalition(MITRE、IBM、Microsoft、PQShield、SandboxAQ)以四阶段路线图统领跨厂商的迁移指引。Linux Foundation 后量子密码联盟 PQCA 持续整合开源实现,2025 年 1 月 NVIDIA cuPQC 加入,提供 GPU 加速的 PQC 原语。参见 全球厂商PQC 硬件PQC HSM

中国动态

中国走的是并行路线。2025 年 2 月,ICCS / SCA 发布下一代抗量子商用密码算法征集,提交截止 2026-06-30,目前尚无入围名单。2025 年 10 月,中国移动发布《抗量子密码迁移白皮书》,释放出运营商级迁移规划的信号。预计中国将采用国产算法(SM 系列的后继者),而非直接采纳 NIST 标准。参见 中国厂商

标准与参考

⚑ Report an error⚑ 纠错与校正