Research edition · Q4 2026
State of Quantum Cybersecurity
Two original studies. Complete evidence inside. A Q4 planning report for the people who must approve the transition.
From exposure to a defensible transition. Evidence through 8 September 2026.

- Original research
- Two studies, evidence archives attached
- Operation timings
- 18,000
- TLS handshakes
- 80
- Evidence cutoff
- 8 September 2026
Original research · QQ-TLS-LOCAL-2026-09
A hybrid handshake has more than one proof
Eighty complete, certificate-verified TLS 1.3 handshakes across four configurations, twenty each. The client verified the server certificate and the test hostname, and both sides exchanged synthetic application data. Transport was in-memory SSL, with no network sockets.
| Server identity | Key exchange | Record bytes | Completed |
|---|---|---|---|
| ECDSA P-256 | X25519 | 1,029–1,031 | 20 / 20 |
| ECDSA P-256 | Hybrid ML-KEM | 3,351–3,353 | 20 / 20 |
| RSA-2048 | X25519 | 1,613 | 20 / 20 |
| RSA-2048 | Hybrid ML-KEM | 3,935 | 20 / 20 |
Hybrid is X25519MLKEM768. Record bytes are the complete local TLS handshake records, before application data. Both identity types use classical authentication. No TCP or internet path was measured.
The fifty bytes a field-only budget misses
RFC 10024 specifies 1,216 client and 1,120 server key-exchange bytes for X25519MLKEM768. Against two 32-byte X25519 shares, the specified increase is 2,272 bytes. The observed hello messages grew by 2,322.
| Role | Hybrid | X25519 | Increase |
|---|---|---|---|
| Client | 1,216 | 32 | +1,184 |
| Server | 1,120 | 32 | +1,088 |
| Net field increase | 2,272 | ||
02 · local configuration
- +36
- Extra client share and entry header
- +14
- Additional supported-group identifiers
2,272
field increase
+ 50
configuration extras
= 2,322
observed hello growth
Field sizes from RFC 10024. The extra bytes reflect this OpenSSL 3.5.7 setup. These are hello-message bytes, before network framing.
Original research · QQ-PQC-LOCAL-2026-09
Latency has a distribution
18,000 recorded operation timings. Medians show the typical call. The 95th percentile shows why a single average is insufficient — signing p95 ran roughly 2.8 to 3.2 times the median, because FIPS 204 defines a Fiat-Shamir-with-aborts rejection-sampling loop.
| Operation | Median | p95 |
|---|---|---|
| ML-KEM-512 encapsulate | 43.8 | 59.1 |
| ML-KEM-512 decapsulate | 56.4 | 71.8 |
| ML-KEM-768 encapsulate | 66.3 | 89.3 |
| ML-KEM-768 decapsulate | 81.3 | 114.0 |
| ML-KEM-1024 encapsulate | 100.0 | 137.5 |
| ML-KEM-1024 decapsulate | 118.4 | 158.6 |
| ML-DSA-44 sign | 304.1 | 966.5 |
| ML-DSA-44 verify | 99.8 | 135.9 |
| ML-DSA-65 sign | 506.7 | 1643.8 |
| ML-DSA-65 verify | 160.0 | 229.0 |
| ML-DSA-87 sign | 648.1 | 1802.6 |
| ML-DSA-87 verify | 260.4 | 341.4 |
1,000 observations per operation in five blocks, one CPU-pinned Linux container, pqcrypto 0.3.4, after 20 excluded warm-ups. Includes Python and CFFI overhead. Neither the distribution nor this explanation establishes side-channel security.
The bytes are part of the architecture
Observed key, ciphertext and signature lengths across six standardised parameter sets. Every observed length matched FIPS 203 Table 3 or FIPS 204 Table 2. This verifies the observed encoding lengths, not the security of the implementation.
| Parameter set | Components | Bytes | Total |
|---|---|---|---|
| ML-KEM-512 | public key + ciphertext | 800 + 768 | 1,568 |
| ML-KEM-768 | public key + ciphertext | 1,184 + 1,088 | 2,272 |
| ML-KEM-1024 | public key + ciphertext | 1,568 + 1,568 | 3,136 |
| ML-DSA-44 | public key + signature | 1,312 + 2,420 | 3,732 |
| ML-DSA-65 | public key + signature | 1,952 + 3,309 | 5,261 |
| ML-DSA-87 | public key + signature | 2,592 + 4,627 | 7,219 |
ML-KEM totals exclude authentication, framing and any traditional hybrid component. They are exchanged at different steps and are not one measured network packet.
Evidence you can carry
Two studies. Three attached artifacts.
Both research archives and the CBOM acceptance sheet are attached inside the report, with their checksums published below. Save the originals, verify the hashes and inspect the method. Each archive carries a README and a recompute script, so the numbers above can be reproduced rather than taken on trust.
- 01 · Primitive studyQtonic_Quantum_Original_Research_Q4_2026.zip
SHA-256 ebb8cb716dc568dfb70cca04f5f89ebcb2cf74b9b3a75451b7ffeeec62eef6f4
- 02 · TLS studyQtonic_Quantum_TLS_Proof_Study_Q4_2026.zip
SHA-256 d5728e297dab86ad884baf1815876545dad976f41f3274d14c9282a989df8a20
- 03 · CBOM acceptance sheetQtonic_Quantum_CBOM_Acceptance_Requirements.pdf
SHA-256 e62f5978dd72a4b3d48882fbe4f4440761ac913146e8d3f3ac9862ffbe41f13c
Keep the conclusion in scope. These are publication experiments, not product tests, field studies or FIPS validation. Neither archive includes production credentials or test private keys.
Addendum · measured 10 September 2026
A 24-hour transit clock, recorded after this edition closed
This edition's evidence cutoff is 8 September 2026, and within it QShield v1.0 status is recorded as a Qtonic Quantum statement rather than a measurement. On 10 September 2026 a 24-hour clock completed across an encrypted overlay between two United States regions, US West (Oregon) and US East (Virginia). It is published here, outside the report, because it post-dates the cutoff and because it was measured rather than reported.
- Window
- 9 Sep 22:09 UTC to 10 Sep 22:09 UTC
- Elapsed
- 86,438 s (24 h 00 m 38 s)
- Samples
- 1,363
- Aborts
- 0
- Final sample loss
- 0 %
- Final sample round trip
- 55.727 ms
After the clock stopped and the client process exited, the overlay was re-checked with the daemon still running: four of four probes returned, zero loss, 55.665 ms average round trip, and a 65,536-byte transfer matched end to end.
| Record | SHA-256 |
|---|---|
| Sample log, 1,364 lines | 9bdc08fb61519bcfaa5e01de9166cdb4eea6a05f8c88d7d10872df60eb4f9f06 |
| Daemon binary, unchanged across the run | 43ece1b40fb8752bd8b0ea751725428f7538b7c8b2c7e7eccea675f5bc6344b5 |
What this does not establish. It is a transit clock, not a cryptographic validation. It is not an ATLAS result, it is not FIPS validation, and no release authorisation was granted on the strength of it. Implementation status, independent assessment and authorisation remain distinct claims, exactly as the report states. The sample log is reproducible from the checksum above; two independent archives of it were confirmed byte-identical.
The executive briefing
Five decisions deserve priority
A credible quarter plan begins with the organisation's most consequential decisions, then assigns the information needed to resolve them. These are Qtonic Quantum recommendations, not survey findings.
- 01
Set the protection objective
Identify information and trust relationships whose compromise would cause lasting harm. Separate confidentiality from authenticity, and current exposure from uncertainty about future capability.
- 02
Establish the boundary
Approve services, suppliers and environments for assessment. Record exclusions and outsourced dependencies. A business-service owner may lack authority over connected systems.
- 03
Find the limiting dependency
Identify the supplier, compatibility, equipment, budget or maintenance-window constraint that prevents change. Fund the dependency that unlocks the next defensible step.
- 04
Require a deployment decision
Give each pilot a written acceptance threshold and decision date. Preserve adverse results, recovery requirements and exceptions so the result supports an explicit choice.
- 05
Make evidence renewable
Agree when records expire and what triggers reassessment. Changes to software, suppliers, routes or trust anchors can invalidate an earlier conclusion.
Contents
Find the decision you came for
| 01 | The executive briefingPriorities, changes and evidence. | 4–7 |
| 02 | Threat, standards and policyThe CBOM milestone and migration obligations. | 8–24 |
| 03 | Architecture and original researchFollow dependencies. Inspect both studies. | 25–45 |
| 04 | Industry and buyer decisionsApply the transition to the service that matters. | 46–63 |
| 05 | The Q4 execution planMake the next ninety days measurable. | 64–78 |
| 06 | The Qtonic Quantum approachPortable evidence and the people behind it. | 79–85 |
| 07 | Sources and referenceTerminology, primary documents and methodology. | 86–91 |
Evidence boundary
What this report is, and is not
Selective, not exhaustive
A selective primary-source review, not exhaustive news coverage. Sources and conditions may change after the stated cutoff. October to December activities are proposed work, never reported results.
Commercial interest disclosed
Qtonic Quantum Corp commissioned this edition and has a commercial interest in its products and services. Third-party references do not imply endorsement. Examples are not customer outcomes or product certifications.
Planning analysis, not advice
General information and planning analysis. It is not legal, regulatory, investment or individualised security advice. The original instrument governs. Forecasts and resource estimates depend on assumptions and do not guarantee an arrival date.
Method is published
Method and limitations on page 91. Source register on pages 88 to 90. Index sponsorship and evidence differences are disclosed on page 80.
Turn the quarter plan into an owned decision
Choose one consequential service, accept a usable cryptographic bill of materials, and settle the evidence for a pilot. We will confirm the assessment boundary before anything runs.