Back to Intelligence Pulse

Post-Quantum Cryptography

Industry: ICT
Pulse Type: Industry Snapshot
Published:

Quantum-resistant encryption has gone from a theoretical concern to a procurement mandate - driven by NIST finalizing standards, government deadlines, and the very real threat of harvest-now-decrypt-later attacks targeting sensitive data today. This report covers market sizing, who's buying, and which vendors are best positioned to lead the migration.

Strategic Analysis

  • Industry Snapshot & Market Sizing - Market size, growth rate, and who's really buying, scored for durability.
  • Tailwinds & Headwinds - The forces driving growth, and the one risk that could cap it.
  • Competitive Landscape & Clustering - Who's winning, who's falling behind, and why, ranked by strength.
  • Key Trends with Time Horizon - What's changing next, rated by impact, and whether to act now or wait.
  • Analyst View & Strategic Implications - The bottom-line call on where this market is headed.

Overview

The post-quantum cryptography (PQC) market is projected to grow from US$1.6 billion in 2025 to US$20.5 billion by 2033, at a CAGR of 37.8%, driven by NIST's finalization of FIPS 203-205 standards in August 2024 and a 2035 roadmap to phase out RSA and ECC. The US federal government estimates approximately US$7.1 billion in PQC migration costs through 2035, while the EU's 2024 PQC roadmap requires member states to define transition strategies for public systems and critical infrastructure. The 'Harvest Now, Decrypt Later' threat - where adversaries collect encrypted data today for future quantum decryption - is accelerating early investment in quantum-safe encryption across defense, healthcare, finance, and government sectors. Government and defense agencies are the primary buyers, with the US and Europe co-leading adoption, while PQC talent scarcity and legacy infrastructure complexity remain the biggest constraints on migration velocity.

Source(s): Link1, Link2, Link3, Link4

Key points

  • NIST finalized FIPS 203-205 in August 2024, establishing the first standardized post-quantum cryptography algorithms and creating a 2035 transition roadmap to phase out RSA and ECC public-key cryptography across enterprises and governments.
  • The US estimates approximately US$7.1 billion in federal PQC migration costs through 2035, and the EU's 2024 PQC roadmap requires member states to define transition strategies for public systems and critical infrastructure.
  • Cloud-hosted PQC deployment is growing at approximately 44.85% CAGR, with AWS, Google, and Microsoft embedding PQC into cloud security and key management services, while the Linux Foundation's PQCA (2024) is accelerating industry-wide adoption.
  • Hybrid cryptography - combining RSA/ECC with quantum-safe algorithms - is emerging as the default PQC transition architecture, endorsed by NIST and BSI as best practice, with Google and Vodafone already deploying hybrid PQC implementations.
  • India's BFSI sector averaged a PQC preparedness score of just 2.4 out of 5, illustrating broader capability gaps across emerging markets and increasing enterprise reliance on specialist PQC migration services.
  • IoT and automotive sectors are emerging as the next PQC growth wave, with connected devices projected to approach approximately 40 billion by 2030; long device lifecycles of 10-20 years for automotive and 5-10 years for industrial IoT mean hardware shipped today must withstand future quantum attacks.

Source(s): Link1, Link2, Link3, Link4, Link5, Link6

FAQ's

NIST finalized FIPS 203-205 in August 2024, establishing the first standardized post-quantum cryptography algorithms. NIST's roadmap targets phasing out RSA and ECC by 2035, creating a defined migration window for enterprises and governments to transition to quantum-safe encryption.

Source(s): Link1, Link2