Introduction: mapping the regulatory landscape
For years, Post-Quantum Cryptography (PQC) was treated as an academic exercise. It was a landscape reserved for mathematicians and cryptographers working to solve a future problem for the middle of the 21st century.
Recently, however, it’s become clear that the problem is no longer theoretical, and the landscape has shifted dramatically into focus, with national authorities now targeting 2030 as a deadline for quantum-resilience in critical products, and 2035 for standard products. Tech breakthroughs powered by AI have only accelerated the urgency, sculpting the landscape into a real-world problem, not for the future, but for the fast-moving world of the late 2020s – especially when considering the long-life cycle data and assets currently under threat from Harvest-Now-Decrypt-Later attacks.
On the surface, the PQC landscape is seemingly straightforward – NIST’s 2024 standardization of PQC algorithms set the bar.
However, the real friction lies in how these algorithms are implemented. And that’s where the landscape changes again – with different approaches around the world shaping the future of post-quantum algorithm adoption.
For example, the US National Security Agency (NSA) forbids hybrid PQ/T systems for national security applications. PQ/T systems combine post-quantum cryptographic algorithms (PQ) with traditional cryptography (T) to form a hybrid protection against both quantum and classical threats. In this way, the United States mandates a direct leap to pure PQC, while in Europe, major bodies such as ANSSI in France, and BSI in Germany state the opposite, mandating or strongly recommending hybrid PQ/T implementations to guarantee backward compatibility.
For product owners trying to build a single, globally compliant solution, regulatory split-screens such as this create a dilemma. In addition, there are constraints from national or regional authorities, categorizing algorithms as either globally or regionally specific to protocol system standards. The terrain that must be crossed in order to migrate to quantum-resilience, could be daunting.
In this article, we break down the picture into national-level guidance, mapping the landscape into regional variants and explaining the approach of some of the key players.
The following table shows a high-level of view of the regulatory landscape by region, as of August 2026.