PQCClear Research
Why Your PQC Timeline Shouldn't Depend on Proof of a Quantum Breakthrough
September 8, 2026 · PQCClear · 7 minute read
Most conversations about post-quantum urgency eventually circle back to the same question: how would we actually know when to worry? A recent, carefully argued piece from independent quantum security researcher Marin Ivezic makes a case worth taking seriously. We may not get a clear answer to that question, and planning as though we will is a mistake.
The Case for a Coming Blackout
Ivezic’s piece, published on his site PostQuantum.com, traces a pattern through 2026’s most significant quantum cryptanalysis results. For the first time, teams publishing landmark resource estimates felt the need to explain and justify the act of publishing at all, one company pairing its results with a formal responsible disclosure statement, another briefing the U.S. government before release and withholding key technical details behind a cryptographic proof. Both experiments in partial or careful disclosure ran into trouble quickly. Independent researchers reconstructed the withheld technical details within about two months.
The lesson Ivezic draws from that episode is not the comfortable one. Full openness and full silence, he argues, are the two stable positions in this field. Partial disclosure fails because it leaves a trail for others to reconstruct. That points toward an uncomfortable middle ground disappearing entirely, with the institutions closest to the frontier increasingly choosing silence, encouraged by an expanding export control regime that already governs the sharing of certain quantum information.
~24 years classified
Public-key cryptography concepts, 1970s intelligence-agency origin
Kept classified for roughly two decades before public disclosure, during which the wider cryptographic community independently reinvented the same ideas without knowing they already existed.
~16 years classified
A major cipher-design cryptanalysis technique, 1970s corporate-lab origin
Discovered by researchers at a technology company during cipher design, then kept confidential at a government agency's request until the open research community independently rediscovered it more than a decade later.
What This Doesn't Change, and What It Does
To be clear about what this argument is and isn’t: it is not a claim that a cryptographically relevant quantum computer already exists, or that one is imminent. Ivezic is explicit that some of what motivated his piece is unverifiable rumor, and that his argument doesn’t depend on any of it being true. The point is narrower and, we think, more useful: even in a fully honest, fully open research environment, the public literature has always lagged real internal progress by some margin. If that lag is now widening, possibly by design, then the published record was never a reliable clock to plan against, and it’s about to become an even less reliable one.
A fragile anchor
The published research record
- Depends on labs choosing to publish
- Was always lagging real progress by months to years
- Increasingly subject to export-control and national-security pressure to stay silent
- Cannot distinguish “nothing happened” from “something happened and wasn’t disclosed”
A durable anchor
The regulatory calendar
- Set by regulators, examiners, and institutional risk policy
- Already in motion regardless of what any lab publishes next
- Observable, dated, and independently verifiable today
- Was never derived from quantum computing headlines in the first place
That second column is the more useful place to anchor a migration or vendor-assessment program. The deadlines already shaping post-quantum policy, executive orders, federal migration frameworks, examination expectations building toward 2027 and beyond, sector task forces coordinating vendor readiness, were built by regulators and institutions reasoning about risk exposure and migration lead time, not by reading the latest quantum cryptanalysis paper. They don’t require a public breakthrough to justify acting on them, and they won’t disappear if the breakthroughs stop being publicly visible.
You cannot time your migration to a signal that may never arrive publicly. You can still time it to the deadline that’s already on the calendar.
Why This Matters for How Vendor Risk Gets Assessed
This has a direct, practical implication for how PQCClear approaches assessment, and it’s worth stating plainly. A methodology that quietly assumed “we’ll know how urgent this really is once the quantum computing news gets scary enough” would be building on exactly the ground Ivezic’s argument is warning is eroding. Ours doesn’t. Vendor readiness is assessed against cryptographic exposure, data sensitivity, data longevity, migration readiness, and counterparty exposure, factors that matter regardless of whether next year brings a dramatic public quantum computing headline or a quiet one. The regulatory clock this entire space is built around was never contingent on that headline arriving on schedule, and neither is a sound assessment methodology.
Build against the deadline, not the headline
PQCClear helps banks, credit unions, and payment processors assess vendor quantum readiness against the risk factors and regulatory timeline that already apply today, not against a research trail that may or may not stay visible.
Get in touchThis piece reflects PQCClear’s own analysis as of September 8, 2026. It should not be construed as legal, regulatory, or investment advice.
Referenced: Marin Ivezic, “The Coming CRQC Blackout: Why the Papers Will Stop Before the Progress Does,” PostQuantum.com (July 9, 2026). The arguments, historical examples, and framing in that piece are the author’s own original analysis and are paraphrased here with attribution, not reproduced.