Skip to content

Research edition · Q4 2026

State of Quantum Cybersecurity

Two original studies. Complete evidence inside. A Q4 planning report for the people who must approve the transition.

From exposure to a defensible transition. Evidence through 8 September 2026.

Cover of the State of Quantum Cybersecurity Q4 2026 research edition
Original research
Two studies, evidence archives attached
Operation timings
18,000
TLS handshakes
80
Evidence cutoff
8 September 2026

Original research · QQ-TLS-LOCAL-2026-09

A hybrid handshake has more than one proof

Eighty complete, certificate-verified TLS 1.3 handshakes across four configurations, twenty each. The client verified the server certificate and the test hostname, and both sides exchanged synthetic application data. Transport was in-memory SSL, with no network sockets.

80 certificate-verified TLS 1.3 handshakes · four configurations
Server identityKey exchangeRecord bytesCompleted
ECDSA P-256X255191,029–1,03120 / 20
ECDSA P-256Hybrid ML-KEM3,351–3,35320 / 20
RSA-2048X255191,61320 / 20
RSA-2048Hybrid ML-KEM3,93520 / 20

Hybrid is X25519MLKEM768. Record bytes are the complete local TLS handshake records, before application data. Both identity types use classical authentication. No TCP or internet path was measured.

The fifty bytes a field-only budget misses

RFC 10024 specifies 1,216 client and 1,120 server key-exchange bytes for X25519MLKEM768. Against two 32-byte X25519 shares, the specified increase is 2,272 bytes. The observed hello messages grew by 2,322.

01 · selected key-exchange fields
RoleHybridX25519Increase
Client1,21632+1,184
Server1,12032+1,088
Net field increase2,272

02 · local configuration

+36
Extra client share and entry header
+14
Additional supported-group identifiers

2,272

field increase

+ 50

configuration extras

= 2,322

observed hello growth

Field sizes from RFC 10024. The extra bytes reflect this OpenSSL 3.5.7 setup. These are hello-message bytes, before network framing.

Original research · QQ-PQC-LOCAL-2026-09

Latency has a distribution

18,000 recorded operation timings. Medians show the typical call. The 95th percentile shows why a single average is insufficient — signing p95 ran roughly 2.8 to 3.2 times the median, because FIPS 204 defines a Fiat-Shamir-with-aborts rejection-sampling loop.

Local call latency · microseconds · median to p95
OperationMedianp95
ML-KEM-512 encapsulate43.859.1
ML-KEM-512 decapsulate56.471.8
ML-KEM-768 encapsulate66.389.3
ML-KEM-768 decapsulate81.3114.0
ML-KEM-1024 encapsulate100.0137.5
ML-KEM-1024 decapsulate118.4158.6
ML-DSA-44 sign304.1966.5
ML-DSA-44 verify99.8135.9
ML-DSA-65 sign506.71643.8
ML-DSA-65 verify160.0229.0
ML-DSA-87 sign648.11802.6
ML-DSA-87 verify260.4341.4

1,000 observations per operation in five blocks, one CPU-pinned Linux container, pqcrypto 0.3.4, after 20 excluded warm-ups. Includes Python and CFFI overhead. Neither the distribution nor this explanation establishes side-channel security.

The bytes are part of the architecture

Observed key, ciphertext and signature lengths across six standardised parameter sets. Every observed length matched FIPS 203 Table 3 or FIPS 204 Table 2. This verifies the observed encoding lengths, not the security of the implementation.

Observed bytes · 1,000 valid cycles per parameter set
Parameter setComponentsBytesTotal
ML-KEM-512public key + ciphertext800 + 7681,568
ML-KEM-768public key + ciphertext1,184 + 1,0882,272
ML-KEM-1024public key + ciphertext1,568 + 1,5683,136
ML-DSA-44public key + signature1,312 + 2,4203,732
ML-DSA-65public key + signature1,952 + 3,3095,261
ML-DSA-87public key + signature2,592 + 4,6277,219

ML-KEM totals exclude authentication, framing and any traditional hybrid component. They are exchanged at different steps and are not one measured network packet.

Evidence you can carry

Two studies. Three attached artifacts.

Both research archives and the CBOM acceptance sheet are attached inside the report, with their checksums published below. Save the originals, verify the hashes and inspect the method. Each archive carries a README and a recompute script, so the numbers above can be reproduced rather than taken on trust.

  1. 01 · Primitive studyQtonic_Quantum_Original_Research_Q4_2026.zip

    SHA-256 ebb8cb716dc568dfb70cca04f5f89ebcb2cf74b9b3a75451b7ffeeec62eef6f4

  2. 02 · TLS studyQtonic_Quantum_TLS_Proof_Study_Q4_2026.zip

    SHA-256 d5728e297dab86ad884baf1815876545dad976f41f3274d14c9282a989df8a20

  3. 03 · CBOM acceptance sheetQtonic_Quantum_CBOM_Acceptance_Requirements.pdf

    SHA-256 e62f5978dd72a4b3d48882fbe4f4440761ac913146e8d3f3ac9862ffbe41f13c

Keep the conclusion in scope. These are publication experiments, not product tests, field studies or FIPS validation. Neither archive includes production credentials or test private keys.

Addendum · measured 10 September 2026

A 24-hour transit clock, recorded after this edition closed

This edition's evidence cutoff is 8 September 2026, and within it QShield v1.0 status is recorded as a Qtonic Quantum statement rather than a measurement. On 10 September 2026 a 24-hour clock completed across an encrypted overlay between two United States regions, US West (Oregon) and US East (Virginia). It is published here, outside the report, because it post-dates the cutoff and because it was measured rather than reported.

Window
9 Sep 22:09 UTC to 10 Sep 22:09 UTC
Elapsed
86,438 s (24 h 00 m 38 s)
Samples
1,363
Aborts
0
Final sample loss
0 %
Final sample round trip
55.727 ms

After the clock stopped and the client process exited, the overlay was re-checked with the daemon still running: four of four probes returned, zero loss, 55.665 ms average round trip, and a 65,536-byte transfer matched end to end.

Checksums for the 24-hour transit clock
RecordSHA-256
Sample log, 1,364 lines9bdc08fb61519bcfaa5e01de9166cdb4eea6a05f8c88d7d10872df60eb4f9f06
Daemon binary, unchanged across the run43ece1b40fb8752bd8b0ea751725428f7538b7c8b2c7e7eccea675f5bc6344b5

What this does not establish. It is a transit clock, not a cryptographic validation. It is not an ATLAS result, it is not FIPS validation, and no release authorisation was granted on the strength of it. Implementation status, independent assessment and authorisation remain distinct claims, exactly as the report states. The sample log is reproducible from the checksum above; two independent archives of it were confirmed byte-identical.

The executive briefing

Five decisions deserve priority

A credible quarter plan begins with the organisation's most consequential decisions, then assigns the information needed to resolve them. These are Qtonic Quantum recommendations, not survey findings.

  1. 01

    Set the protection objective

    Identify information and trust relationships whose compromise would cause lasting harm. Separate confidentiality from authenticity, and current exposure from uncertainty about future capability.

  2. 02

    Establish the boundary

    Approve services, suppliers and environments for assessment. Record exclusions and outsourced dependencies. A business-service owner may lack authority over connected systems.

  3. 03

    Find the limiting dependency

    Identify the supplier, compatibility, equipment, budget or maintenance-window constraint that prevents change. Fund the dependency that unlocks the next defensible step.

  4. 04

    Require a deployment decision

    Give each pilot a written acceptance threshold and decision date. Preserve adverse results, recovery requirements and exceptions so the result supports an explicit choice.

  5. 05

    Make evidence renewable

    Agree when records expire and what triggers reassessment. Changes to software, suppliers, routes or trust anchors can invalidate an earlier conclusion.

Contents

Find the decision you came for

Report contents by section and page range
01The executive briefingPriorities, changes and evidence.4–7
02Threat, standards and policyThe CBOM milestone and migration obligations.8–24
03Architecture and original researchFollow dependencies. Inspect both studies.25–45
04Industry and buyer decisionsApply the transition to the service that matters.46–63
05The Q4 execution planMake the next ninety days measurable.64–78
06The Qtonic Quantum approachPortable evidence and the people behind it.79–85
07Sources and referenceTerminology, primary documents and methodology.86–91

Evidence boundary

What this report is, and is not

Selective, not exhaustive

A selective primary-source review, not exhaustive news coverage. Sources and conditions may change after the stated cutoff. October to December activities are proposed work, never reported results.

Commercial interest disclosed

Qtonic Quantum Corp commissioned this edition and has a commercial interest in its products and services. Third-party references do not imply endorsement. Examples are not customer outcomes or product certifications.

Planning analysis, not advice

General information and planning analysis. It is not legal, regulatory, investment or individualised security advice. The original instrument governs. Forecasts and resource estimates depend on assumptions and do not guarantee an arrival date.

Method is published

Method and limitations on page 91. Source register on pages 88 to 90. Index sponsorship and evidence differences are disclosed on page 80.

Turn the quarter plan into an owned decision

Choose one consequential service, accept a usable cryptographic bill of materials, and settle the evidence for a pilot. We will confirm the assessment boundary before anything runs.