Summary
Summary
- Recent research estimates that breaking 256-bit elliptic curve cryptography (ECDLP-256) may need about 20 times fewer physical qubits than previously thought. IonQ has published a blueprint that would do it in about 26 days with 19,397 physical qubits.
- Google has set 2029 as the deadline to migrate its authentication services to post-quantum cryptography, and NIST plans to deprecate today’s public-key algorithms by 2030.
- The standards are in place: NIST’s lattice-based ML-KEM and ML-DSA, hash-based SLH-DSA, and code-based HQC as a backup.
- M&A is consolidating the supply chain. IonQ bought ID Quantique and Qubitekk; Quantum Computing Inc. bought NuCrypt and NHanced Semiconductors. Buyers want practical, deployable security, not lab demos.
01 · Research
Why 2029 has become the date
The threat arrived early.
Most of the internet’s security relies on public-key cryptography such as RSA and elliptic curves. A large, error-corrected quantum computer could break both. For years that seemed a distant problem. The estimates have now moved sharply.
Recent research suggests breaking 256-bit elliptic curve cryptography (ECDLP-256) may need about 20 times fewer physical qubits than earlier estimates. IonQ has published a blueprint for a fault-tolerant trapped-ion machine that could solve ECDLP-256 in about 26 days using 19,397 physical qubits. Google has set 2029 as the deadline to migrate its own authentication services.
There is a second reason for urgency: harvest now, decrypt later. Data intercepted today can be stored and decrypted once capable machines exist, so anything that must stay secret for years needs protecting now.
02 · Research
The standards: what enterprises are migrating to
Lattice first, with a code-based backup.
| Algorithm | Family | Use |
|---|---|---|
| ML-KEM (FIPS 203) | Lattice-based | Key establishment |
| ML-DSA (FIPS 204) | Lattice-based | Digital signatures |
| SLH-DSA (FIPS 205) | Hash-based | Digital signatures |
| HQC (selected 2025) | Code-based | Backup key establishment |
NIST’s post-quantum programme (opens in a new tab) published the first three standards in August 2024 and selected HQC in 2025 as a mathematically different backup. NIST has also proposed deprecating today’s quantum-vulnerable public-key algorithms by 2030 and disallowing them by 2035.
The hard part is not the algorithms. It is finding every place cryptography lives inside a large organisation and replacing it without breaking anything. That is a software, services and hardware opportunity measured across every bank, government and cloud.
03 · Research
The quiet consolidation of the quantum security supply chain
Practical capability over hype.
- IonQ: building a full-stack quantum security platformIonQ acquired ID Quantique, a pioneer in quantum key distribution and quantum random number generation, and Qubitekk, a quantum networking specialist. Together they give a hardware company a commercial security and networking business.
- Quantum Computing Inc.: room-temperature and manufacturing capabilityQCI completed its acquisition of NuCrypt, a quantum communications and photonics company, for $5m on 5 March 2026, then NHanced Semiconductors for an initial $73.1m plus up to $72m in earnouts on 22 June 2026. Both now operate as wholly owned subsidiaries.
| Acquirer | Target | Capability | Terms |
|---|---|---|---|
| IonQ | ID Quantique | Quantum key distribution, QRNG | Strategic |
| IonQ | Qubitekk | Quantum networking | Strategic |
| Quantum Computing Inc. | NuCrypt | Quantum communications, photonics | $5m (Mar 2026) |
| Quantum Computing Inc. | NHanced Semiconductors | Advanced semiconductor packaging | $73.1m + up to $72m earnout (Jun 2026) |
The NHanced structure is instructive. An earnout nearly equal to the upfront price lets the buyer pay for proven commercial delivery rather than promise. Our earnout modelling tool shows how those structures shift risk.
04 · Research
What it means for buyers and sellers
Three places value is forming.
- Cryptographic discovery and migration softwareTools that inventory where cryptography is used and automate the move to post-quantum algorithms. Every regulated enterprise needs them before the 2030 deprecation window.
- PQC-ready hardware and secure elementsHardware security modules, chips and devices with post-quantum algorithms built in, sold into payments, telecoms, defence and automotive.
- Quantum networking and key distributionSpecialist capability that hardware leaders are buying rather than building, as IonQ’s acquisitions show.
For cybersecurity founders, a credible post-quantum roadmap is fast becoming a diligence question in its own right. For acquirers, the window to buy specialist teams before the 2029 rush is open now.
Reference
Frequently asked questions
What is the 2029 post-quantum deadline?
Google has set 2029 as its deadline to migrate its authentication services to post-quantum cryptography, citing progress in quantum hardware and error correction. It has become a reference date for enterprises planning their own migration.
What is post-quantum cryptography?
Encryption and digital-signature methods designed to stay secure against attacks from large quantum computers. NIST standardised the first algorithms in August 2024: ML-KEM and ML-DSA (lattice-based) and SLH-DSA (hash-based), with the code-based HQC selected as a backup in 2025.
What is the difference between lattice-based and code-based cryptography?
Both rely on maths problems believed to be hard for quantum computers. Lattice-based schemes, such as ML-KEM, are compact and fast and are the main standards. Code-based schemes, such as HQC, rest on error-correcting codes and provide a mathematically different backup in case lattice schemes are ever weakened.
Which quantum security acquisitions have happened recently?
IonQ acquired quantum networking and security companies ID Quantique and Qubitekk. Quantum Computing Inc. completed its acquisition of NuCrypt for $5m on 5 March 2026 and NHanced Semiconductors for an initial $73.1m, with up to $72m in earnouts, on 22 June 2026.




