Post-Quantum Cryptography
The migration to quantum-safe encryption has started — driven by regulators, not quantum computers.
Traction · 2026-W34+1 this week
Why it's moving
- Standards are final and implementations are shipping: major TLS stacks, browsers and CDNs now support ML-KEM hybrid key exchange in production.
- Government deadlines create real budgets: US federal guidance and EU regulators set migration timelines that large enterprises must plan against now.
- A significant share of human-initiated HTTPS traffic at major CDNs is already quantum-safe — measurable adoption, not press coverage.
- Open-source implementations (Open Quantum Safe, language-level libraries) show steady contributor growth.
- Certificate authorities, HSM vendors and cloud KMS products are adding PQC support, unblocking the enterprise supply chain.
What changed this week
- liboqs-python weekly downloads rose 2.9% to 22,886 — steady, but small enough that adoption scores 24 on the published download and star scales.
- 10 arXiv submissions in 30 days keep research volume high relative to a very small deployment footprint.
- No Hacker News stories matched this theme's terms in the last 30 days.
Why you should care
Encrypted data captured today can be decrypted once quantum computers mature, so anything that must stay confidential for a decade is already at risk. Standards are final, browsers and CDNs ship quantum-safe TLS by default, and government deadlines are turning this into budgeted migration work. Still early inside enterprises, but the direction is clear.
What is it?
Post-quantum cryptography (PQC) replaces today's public-key algorithms (RSA, elliptic curves) with ones believed secure against quantum computers. NIST finalised the first standards — ML-KEM for key exchange and ML-DSA for signatures — and the migration has begun: browsers, TLS libraries, cloud providers and operating systems are shipping hybrid quantum-safe connections by default. The threat driving urgency is 'harvest now, decrypt later': encrypted data captured today could be decrypted once quantum computers mature.
What should you do?
For managers
What this could change
This is a compliance-driven, multi-year infrastructure migration — closer to Y2K than to a product trend. Any data that must stay confidential for 10+ years (health, financial, legal, IP) is already exposed to harvest-now-decrypt-later collection. The immediate action is inexpensive: inventory where your organisation uses public-key cryptography (a 'cryptographic bill of materials'), ask vendors for their PQC roadmaps, and put migration into 2027 budget planning. Organisations that wait for a quantum computer to exist will be years too late.
Bring to your next engineering conversation
Commission a cryptographic inventory now and ask vendors for their PQC roadmaps — the first step is cheap; being late is not.
For developers
What to learn and build
You mostly won't implement PQC algorithms yourself — you'll consume them through libraries and TLS. Learn the vocabulary (ML-KEM, ML-DSA, hybrid key exchange), understand where public-key crypto lives in your systems, and check whether your TLS termination already negotiates hybrid PQC (modern browsers and CDNs do). Practise crypto-agility: abstract algorithm choices behind configuration so future swaps are cheap. Experiment with liboqs or your language's PQC bindings to demystify the primitives.
This week's move
Learn the vocabulary (ML-KEM, hybrid key exchange) and check whether your TLS endpoints already negotiate it.
Learning path
No prior knowledge assumed — understand what it is and try it once.
Every resource is editorially reviewed and link-checked before publication. Dated items are at most six months old; “maintained” marks continuously-updated docs and repositories.
- 1Understand the conceptNIST Post-Quantum Cryptography project — why migration is happeningNIST CSRC · maintained · 15 min
- 2Watch a practical videoPost Quantum Cryptography - ComputerphileYouTube · April 2026 · 13 min
- 3Build something realCheck your connection — is your TLS already post-quantum?Cloudflare Research · maintained · 10 min
- 4Follow the ecosystemNIST →Cloudflare →
Why this scores 58
How is this calculated? →Repository usage, package downloads, stars, forks, contributors and enterprise implementations.
How quickly adoption indicators are changing (4- and 8-week growth).
Whether the trend appears across several independent sources — developers, open source, research, cloud providers, enterprises and media.
Potential relevance for organisations: productivity, infrastructure, security, cost and strategy.
Whether understanding the technology is likely to remain useful beyond the immediate news cycle.
Measured this week · 2026-W34
- GitHub stars (tracked repos)
- 3,537+10
- Package downloads / week
- 22,886+653
- Source types reporting
- 4
Collected automatically from GitHub and package registries; deltas compare against the previous week's collection.
Signals detected
The evidence behind this theme's score. Every entry links to its source.
4 sources across 3 categories
NIST →Cloudflare →IETF →GitHub →- NISTFIPS 203/204/205 final; migration guidance active
Finalised standards plus ongoing NIST guidance anchor enterprise migration planning.
foundationStandards
- CloudflareLarge share of HTTPS already quantum-safe
CDN-level measurement shows hybrid post-quantum TLS is now mainstream on supported clients.
vendorTraffic share
- IETFHybrid ML-KEM in TLS advancing
IETF work standardising hybrid post-quantum key exchange for TLS 1.3.
foundationProtocol standardisation
- GitHubSteady contributor growth
Open Quantum Safe reference implementations see sustained cross-industry contribution.
open-sourceRepository activity
Traction over time
Measured history has not started yet
The first measured week has been recorded. A trend line appears once there are two weekly collections to compare.
Editorial baseline (illustrative, not measured)
An editor's estimate of how this theme developed before Tech Signal began measuring it, kept for context. It is deliberately not joined to the measured series above, and it never feeds a score.
| Month | Traction Score |
|---|---|
| Mar | 36 |
| Apr | 39 |
| May | 42 |
| Jun | 47 |
| Jul | 56 |
| Aug | 57 |
Related themes
Post-Quantum Cryptography connects to:
How this theme developed
August 2026
- Crypto-agility assessments become a standard item in enterprise security roadmaps.
July 2026
- Quantum-safe TLS reaches mainstream traffic share on major CDNs.
- Certificate and HSM ecosystem support continues to unblock enterprise adoption.
June 2026
- Theme entered the weekly top list: regulatory timelines plus shipping implementations moved PQC from research topic to active migration.