Qtonic Quantum Lab scores are generated through automated evaluation using publicly available evidence. Scores reflect conditions at the time of evaluation and may change as solutions evolve. Vendors may request a retest at any time. See our fidelity commitment for full details.
Some infrastructure assurance belongs to the underlying provider. It supports buyer diligence, but it is not a Qtonic Quantum-held certification or attestation.
Evidence · 13 sourced anchors
Published PQC solution evidence is mapped against 13 technical, policy, sector, and data-protection anchors for technical review. Evidence status is disclosed instead of presenting legal compliance determinations.
NIST
Specifies ML-KEM (formerly CRYSTALS-Kyber), a key-encapsulation mechanism based on the Module Learning With Errors problem. Defines three parameter sets: ML-KEM-512 (NIST Level 1), ML-KEM-768 (Level 3), and ML-KEM-1024 (Level 5).
What Qtonic Quantum Lab evaluates:
NIST
Specifies ML-DSA (formerly CRYSTALS-Dilithium), a digital signature algorithm based on the Module Learning With Errors problem. Defines three parameter sets: ML-DSA-44 (NIST Level 2), ML-DSA-65 (Level 3), and ML-DSA-87 (Level 5).
Primary-source timeline
August 13, 2024 · NIST
FIPS 203, 204, and 205 became the first finalized NIST PQC standards.
Final standards
NIST release (opens in new tab)Fall 2024 · OCC
Banks are encouraged to inventory where encryption is used and assess third-party PQC transition plans.
Supervisory guidance
OCC risk perspective (opens in new tab)October 22, 2026 · OMB M-26-15
Federal agency PQC Migration Plans are due within 120 days of the June 24, 2026 memo; this date is derived from that window.
Agency requirement
OMB M-26-15Lab Journey
Overview
Evidence-linked registry and queue entry point
Leaderboard
Public leaderboard
Our Approach
Scoring and evidence model
Coverage
Evidence-linked registry vs research queue
Standards
Compliance tracking and deadlines
Fidelity
Proof, signing, and retest policy
Changelog
Public revisions and retests
Compare
Side-by-side PQC evaluation
Next Steps
Qtonic Quantum Lab scores are independent research opinions based on a published rubric and publicly available evidence. Provenance labels disclose the review state. No vendor pays for inclusion, ranking, or evaluation. Scores are not endorsements, certifications, warranties, or legal advice. Read the published methodology or the full research disclaimer.
What Qtonic Quantum Lab evaluates:
NIST
Specifies SLH-DSA (formerly SPHINCS+), a stateless hash-based digital signature algorithm. Provides conservative security assumptions based solely on hash function properties. Defines 12 parameter sets across SHA-256 and SHAKE variants.
What Qtonic Quantum Lab evaluates:
NSA
NSA guidance for National Security Systems transitioning to quantum-resistant algorithms. Identifies ML-KEM-1024, ML-DSA-87, and SLH-DSA for relevant NSS profiles and sets staged transition milestones through 2031; applicability depends on system category, mission owner, and governing contract language.
What Qtonic Quantum Lab evaluates:
White House
Presidential direction for scoped federal actions on quantum-vulnerable cryptography, including inventory reporting and migration prioritization. It is a federal policy anchor, not a universal private-sector PQC mandate.
What Qtonic Quantum Lab evaluates:
White House
Federal cybersecurity order covering government modernization, software-supply-chain security, and related controls. It is adjacent assurance context for cryptographic implementations, not a PQC migration mandate.
What Qtonic Quantum Lab evaluates:
PCI SSC
Payment-card security standard with scoped requirements for strong cryptography and key management. PCI DSS v4.0.1 does not itself create a PQC migration mandate; the Lab mapping is forward-looking technical review.
What Qtonic Quantum Lab evaluates:
HHS
The HIPAA Security Rule requires safeguards for ePHI. Its current encryption implementation specifications are addressable and risk-based; the rule does not prescribe PQC algorithms.
What Qtonic Quantum Lab evaluates:
European Union
GDPR Article 32 requires risk-appropriate technical and organizational measures and lists encryption as one possible measure. It does not prescribe PQC or a specific algorithm.
What Qtonic Quantum Lab evaluates:
South Africa
POPIA Section 19 requires appropriate, reasonable technical and organizational safeguards. It does not prescribe encryption or PQC; applicability depends on the processing context.
What Qtonic Quantum Lab evaluates:
Singapore
Singapore PDPA section 24 requires reasonable security arrangements for personal data. It does not prescribe PQC; the Lab mapping tests whether cryptographic controls can remain adequate as threats evolve.
What Qtonic Quantum Lab evaluates:
Brazil
LGPD Article 46 requires technical and administrative security measures for personal data. It does not prescribe encryption or PQC; the Lab mapping is a technical risk lens, not a legal determination.
What Qtonic Quantum Lab evaluates:
SWIFT
SWIFT CSP defines mandatory and advisory security controls according to each user architecture. The Lab PQC mapping is readiness analysis and does not assert that every v2026 CSP control mandates PQC.
What Qtonic Quantum Lab evaluates:
December 31, 2027 · EO 14412
NIST is directed to complete a PQC migration pilot on an appropriate subset of its systems.
Executive order
White House EO 14412 (opens in new tab)December 31, 2030 · EO 14412
Non-NSS federal high-value assets and high-impact systems are directed to transition key establishment to PQC.
Executive order
White House EO 14412 (opens in new tab)December 31, 2031 · EO 14412
Non-NSS federal high-value assets and high-impact systems are directed to transition digital signatures to PQC.
Executive order
White House EO 14412 (opens in new tab)2030–2031 · NSA CNSA 2.0
For applicable NSS, unsupported equipment and services phase out by the end of 2030 and CNSA 2.0 use is required by the end of 2031 unless otherwise noted.
NSS requirement
NSA CNSA 2.0 FAQ (opens in new tab)After 2030 / 2035 · NIST IR 8547
The initial public draft proposes deprecation of specified quantum-vulnerable schemes after 2030 and broader disallowance after 2035.
Initial public draft
NIST IR 8547 IPD (opens in new tab)Monthly insights on PQC migration and quantum risk. No spam.
© 2024–2026 Qtonic Quantum Corp. Miami, Florida.