---
title: The biggest shapers of PQC compliance
description: Explore the standards, collaboration and practical planning shaping PQC compliance and secure post-quantum migration.
image: https://arqitgroup.com/hubfs/Website/Website%20Imagery%202025/1200%20x%20450/shutterstock_2445193579.webp
---

[Skip to content](https://arqitgroup.com/resources/blog/pqc-compliance#main-content)

[ Close ](https://arqitgroup.com/resources/blog/pqc-compliance#)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)[![Arqit_Logo_Midnight_Citrus_Horizontal](https://arqitgroup.com/hubfs/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_Midnight_Citrus_Horizontal.svg)](https://arqitgroup.com/)

- Solutions 
    - [PQC Migration](https://arqitgroup.com/products/encryption-intelligence)
    - [Key Sovereignty ](https://arqitgroup.com/products/ska-platform) 
          - [SKA Edge Controller](https://arqitgroup.com/products/ska-ec)
          - [SKA Central Controller](https://arqitgroup.com/products/ska-cc)
    - [Network Security](https://arqitgroup.com/products/networksecure)
- Sectors 
    - [Telecoms](https://arqitgroup.com/sectors/telecoms)
    - [Defense](https://arqitgroup.com/sectors/defense)
    - [Govt & CNI](https://arqitgroup.com/sectors/govt-cni)
    - [U.S Markets](https://arqitgroup.com/mission-readiness)
- [Resources](https://arqitgroup.com/resource) 
    - [Case Studies](https://arqitgroup.com/resources/tag/case-studies)
    - [Product sheets](https://arqitgroup.com/resources/tag/product-sheets)
    - [White Papers](https://arqitgroup.com/resources/tag/white-papers)
    - [Arqit Terms](https://arqitgroup.com/resources/tag/legal)
    - [Blog](https://arqitgroup.com/resources/blog)
- About 
    - [Our Approach](https://arqitgroup.com/company/our-approach) 
          - [Strong](https://arqitgroup.com/company/our-approach#strong)
          - [Simple](https://arqitgroup.com/company/our-approach#simple)
          - [Scalable](https://arqitgroup.com/company/our-approach#scalable)
          - [Standards-based](https://arqitgroup.com/company/our-approach#standards-based)
    - Our Technology 
          - [Simplicity](https://arqitgroup.com/company/simplicity)
          - [Agility](https://arqitgroup.com/company/agility)
          - [Trust](https://arqitgroup.com/company/trust)
          - [Compliance](https://arqitgroup.com/company/compliance)
    - [Company](https://arqitgroup.com/who-we-are) 
          - [Leadership](https://arqitgroup.com/who-we-are#leadership)
          - [Awards](https://arqitgroup.com/who-we-are#awards)
    - [Partners](https://arqitgroup.com/partners/partners)
    - [Press](https://arqitgroup.com/resources/tag/press-releases)
    - [Careers](https://arqitgroup.com/careers)
    - [Investors](https://ir.arqit.uk/)
- [Book a demo](https://arqitgroup.com/demo/demo-hub)

<https://arqitgroup.com/resources/blog/pqc-compliance#>

![](https://arqitgroup.com/hs-fs/hubfs/Website/Website%20Imagery%202025/1200%20x%20450/shutterstock_2445193579.webp?width=300&name=shutterstock_2445193579.webp)

[Arqit](https://arqitgroup.com/resources/blog/author/arqit)Feb 18, 2026 2:13:01 PM4 min read

# The biggest shapers of PQC compliance

There’s only so much preparation you can do without knowing exactly what you’re preparing for.

So far, this has been a big hurdle to PQC readiness.

Most organizations are happy to do a bit of scoping and preparation. But they can’t reasonably invest resources into something before they have clear guidance from regulators and public bodies.

Finally, the ambiguity and uncertainty around PQC are coming to an end.

So, now that the International Year of Quantum Science and Technology (2025) has come to an end… What should organizations expect the PQC compliance landscape to look like?

 

#### It’s time for public bodies to step up

Michael Murphy, Deputy CTO at Arqit, has a shortlist of PQC expectations for 2026.

First and foremost, he argues that public bodies need to:

1. Be explicit about timelines, expectations, and priorities for PQC migration
2. Manage export controls to protect national security without crippling legitimate vendors

“Regulation is what drives improvements in cyber hygiene,” he explains. “Many organizations need that push and guidance to move from awareness to action. And that’s very reasonable when you consider the potential commercial consequences of moving before you have clear guidance. You could end up investing in technologies that don’t get backing, and lose a lot of time and money.”

Murphy believes that public bodies around the world will step up this year and deliver firm timelines and guidance that organizations need to start taking real action on PQC migration.

 

#### Moving beyond standards: FIPS-validated PQC modules

For over a year, we’ve had FIPS-validated PQC standards: FIPS 203, 204, and 205.

Now, another major milestone is approaching: the arrival of the first fully FIPS-validated cryptographic modules for post-quantum algorithms.

That may sound like a mouthful, but it’s an important step forward. A cryptographic module is a component of an IT system that securely implements cryptographic algorithms.

The [Cryptographic Module Validation Program](https://csrc.nist.gov/projects/cryptographic-module-validation-program), operated by NIST and the Canadian Centre for Cyber Security, aims to “promote the use of validated cryptographic modules and provide Federal agencies with a security metric to use in procuring equipment containing validated cryptographic modules”.

Put simply, the program aims to make it easier for federal agencies (and ultimately, everyone) to purchase IT systems that contain secure cryptographic modules. There are already over 1,000 validated modules, but none currently use validated PQC encryption standards.

Murphy expects these validations to start appearing toward the end of the year.

Why does this matter? FIPS validation is often the gatekeeper for adoption in government, defence, finance, and other regulated environments. Once validated modules exist, PQC can move beyond pilots and proofs of concept into:

- Standard cryptographic libraries
- Commercial products
- Procurement frameworks

At that point, PQC stops being a “tomorrow problem” and starts becoming an operational reality.

 

#### Digital sovereignty needs are driving PQC

Digital and data sovereignty are rising sharply on the agenda, especially in the EU and UK. This is driven by regulations such as DORA and NIS2, as well as a sense that old assumptions about global alliances and shared infrastructure no longer hold in quite the same way.

Murphy outlines three broad options for global organizations dealing with varied regional rules:

1. Full repatriation of workloads back on-premises
2. Use of sovereign cloud offerings
3. Cryptographic approaches that allow continued use of public cloud infrastructure with much stronger technical safeguards

The good news is that full data sovereignty in the public cloud is now possible.

For example, Arqit and Intel have developed a solution using Trust Domains and quantum-safe  -key encryption that ensures data is securequantum-safe at rest, in transit, and in use. This allows organizations to retain the scale and economic benefits of public cloud while helping them manage current and likely future compliance needs.

 

#### Practical collaborations and real integrations

Standards and regulations are essential and will drive PQC adoption. But Roberta Faux, US Head of Cryptography and Field CTO at Arqit, argues that meaningful progress depends on deeper collaboration between government and industry:

“We can tell organizations to meet certain standards, but that’s extremely difficult if the commercial reality doesn’t match the regulatory landscape,” she explains. “Procurement is a powerful lever for adoption, so we need practical collaborations and real integrations between the public and private sectors as soon as possible.”

“Organizations need to make purchasing decisions with confidence without running into compliance problems a year or two down the line,” she continues. “That means we need shared testbeds and procurement profiles, so that ‘quantum safe’ in a brochure actually aligns with what works at scale in real environments.”

 

#### How Arqit is contributing to the PQC compliance landscape

Naturally, we’re doing everything we can to push PQC readiness forward. In the last year, Arqit has joined several relevant bodies and programs, including:

- The NCSC’s [Post-Quantum Cryptography Pilot](https://www.ncsc.gov.uk/schemes/assured-cyber-security-consultancy/pqc-pilot), aiding national efforts to understand what large-scale migration realistically looks like.
- Vodafone’s [Tomorrow Street Scaleup X](https://www.tomorrowstreet.co/scaleupx) programme and the Oracle Defense Ecosystem, making quantum-safe capabilities available in environments already trusted by defense and public-sector organizations.
- MEF, a global consortium focused on enterprise digital transformation, to work on how quantum-resistant security will be embedded into future network and service standards.

Through these and our own continued research, development, and real-world implementation of PQC solutions, we continue to help organizations prepare for the post-quantum world.

To find out how Arqit can help your organization prepare for PQC migration and remain compliant in the post-quantum world, [get in touch](https://arqitgroup.com/contact-us).

 

---

 

18 February 2026

 

#### **Arqit** 

 

## RELATED ARTICLES

[![Arqit_Logo_White_Citrus_Horizontal](https://7543877.fs1.hubspotusercontent-na1.net/hubfs/7543877/Website%20Brief%20December%2024/Arqit%20Logos/Arqit_Logo_White_Citrus_Horizontal.svg) ](https://arqitgroup.com/)

<https://www.linkedin.com/company/arqit>

- [Get in Touch](https://arqitgroup.com/contact-us)

![NQA_ISO27001_CMYK_UKAS (1)](https://arqitgroup.com/hubfs/NQA_ISO27001_CMYK_UKAS%20(1).webp)

![FIPS 140-3 validated product logo image in color (1)](https://arqitgroup.com/hubfs/FIPS%20140-3%20validated%20product%20logo%20image%20in%20color%20(1).webp)

[![Consultancy_Post-Quantum Cryptography (Discovery and Migration Planning) (1)](https://arqitgroup.com/hubfs/Consultancy_Post-Quantum%20Cryptography%20(Discovery%20and%20Migration%20Planning)%20(1).webp) ](https://www.ncsc.gov.uk/schemes/assured-cyber-security-consultancy/pqc-pilot)

[![Cyber Essentials Badge (1)](https://arqitgroup.com/hubfs/Cyber%20Essentials%20Badge%20(1).webp) ](https://www.ncsc.gov.uk/cyberessentials/overview)

[![IDC-Innovator-2024-badge-blue-withlabel (1)](https://arqitgroup.com/hubfs/IDC-Innovator-2024-badge-blue-withlabel%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![GLOMO (1)](https://arqitgroup.com/hubfs/GLOMO%20(1).webp) ](https://www.mwcbarcelona.com/articles/2024-glomo-award-winners-unveiled-at-mwc-barcelona)

[![e_sig_the_cyber_defence_product_of_the_year_33 (1)](https://arqitgroup.com/hubfs/e_sig_the_cyber_defence_product_of_the_year_33%20(1).webp) ](https://thenationalcyberawards.org/2024-winners/)

[![CTGSEA25-Winner+Cat_Endpoint Security Solution Award (1)](https://arqitgroup.com/hubfs/CTGSEA25-Winner+Cat_Endpoint%20Security%20Solution%20Award%20(1).webp) ](https://arqitgroup.com/who-we-are?hsLang=en#awards)

[![NaaS Innovation 1080x1080 (1) (1)](https://arqitgroup.com/hubfs/NaaS%20Innovation%201080x1080%20(1)%20(1).webp) ](https://www.mplify.net/news/mplify-names-winners-of-the-2025-naas-excellence-awards/)

All rights reserved

- [Terms of Use](https://arqitgroup.com/resources/arqit-terms)
- [Privacy Policy](https://arqitgroup.com/privacy-policy)
- [Visit the Arqit website](https://arqitgroup.com)

<https://arqitgroup.com/resources/blog/pqc-compliance#>

```json
{
  "@context" : "https://schema.org",
  "@type" : "Organization",
  "address" : {
    "@type" : "PostalAddress",
    "addressCountry" : "",
    "addressLocality" : "London",
    "addressRegion" : "United Kingdom",
    "postalCode" : "SW1H 0BF",
    "streetAddress" : "1st Floor, 3 Orchard Place"
  },
  "knowsLanguage" : "en",
  "name" : "Arqit Quantum Inc",
  "url" : "https://arqitgroup.com/resources/blog/pqc-compliance"
}
```

```json
{
  "@context" : "https://schema.org",
  "@type" : "BlogPosting",
  "author" : {
    "@type" : "Person",
    "name" : "Arqit",
    "url" : "https://arqitgroup.com/resources/blog/author/arqit"
  },
  "dateModified" : "2026-07-24T09:36:17.587Z",
  "datePublished" : "2026-02-18T14:13:01.000Z",
  "headline" : "The biggest shapers of PQC compliance",
  "image" : [ "https://arqitgroup.com/hubfs/Website/Website%20Imagery%202025/1200%20x%20450/shutterstock_2445193579.webp" ],
  "mainEntityOfPage" : {
    "@id" : "https://arqitgroup.com/resources/blog/pqc-compliance",
    "@type" : "WebPage"
  },
  "publisher" : {
    "@type" : "Organization",
    "logo" : {
      "@type" : "ImageObject",
      "url" : "https://arqitgroup.com/hubfs/Arqit_Logo_Horizontal_Night.png"
    },
    "name" : "Arqit"
  }
}
```

```json
{
      "@context": "https://schema.org",
      "@type": "BlogPosting",
      "headline": "The New Face of Cyber Warfare:  A Warning for Critical Infrastructure Security",
      "image": 
        "https://7543877.fs1.hubspotusercontent-na1.net/hub/7543877/hubfs/Website/Website%20Imagery%202025/1200%20x%20450/1200x800_0039_arqit_new_brand_general-%2827%29.webp?width=2000&name=1200x800_0039_arqit_new_brand_general-%2827%29.webp",
      "datePublished": "2025-05-01T11:08:34.000Z",
      "text": "In 2024, sophisticated cyberattacks targeted major U.S. telecommunications providers, marking a pivotal moment in the evolution of nation-state cyber aggression. Unlike conventional distributed denial-of-service (DDoS) attacks or financially motivated ransomware campaigns, the Chinese cyber hackers, Salt Typhoon launched a highly coordinated, multi-vector intrusion designed to exploit vulnerabilities at the intersection of network infrastructure, cloud services, and software supply chains. This advanced persistent threat compromised data integrity, disrupted services, and raised concerns about national cybersecurity resilience.  
The scale and precision of this attack have raised critical concerns about the resilience of national communications networks, as well as the broader implications for 5G, IoT, and critical infrastructure. As the digital backbone of modern society, telecommunications infrastructure represents both a strategic asset and a prime target for adversarial entities seeking to disrupt economic, military, and civilian communications. 
The Unprecedented Attack 
Salt Typhoon exploited multiple layers of telecommunications infrastructure, employing zero-day vulnerabilities, advanced persistent threats (APTs), and supply-chain infiltration to bypass traditional security measures. 
Telecom networks are built on legacy protocols that, while robust, were not originally designed to withstand modern cyber threats. Salt Typhoon leveraged critical vulnerabilities in network management interfaces, DNS hijacking, and Border Gateway Protocol (BGP) route manipulation to intercept and reroute traffic between telecom providers, enabling large-scale data exfiltration.  The attacker injected malware into core network components, to allow for long-term persistence. Finally, the attacks were able to compromise SS7 signaling which allowed them to intercept SMS-based authentication messages and disrupt services. 
This was exacerbated by the increased reliance on cloud-native architectures and API-driven services. This enabled Salt Typhoon to target weaknesses in multi-tenant cloud environments, exploiting misconfigured Kubernetes clusters, unsecured API gateways, and credential stuffing attacks.  This allowed unauthorized lateral movement, the compromise of telecom employee accounts, and ultimately unauthorized access to critical backend functions. 
A particularly insidious aspect of Salt Typhoon was its use of supply chain infiltration. By compromising third-party software vendors, attackers injected malicious updates into telecom systems, granting backdoor access to network monitoring tools, customer data repositories, and real-time call routing systems. 
These tactics illustrate a fundamental shift in cyberattack strategies: rather than breaching individual devices, adversaries weaponize the dependencies that underpin entire industries. 
The Implications 
The implications of Salt Typhoon extend beyond the immediate data breaches, network downtime, and operational disruptions experienced by telcos. The attack underscores a larger geopolitical struggle over digital sovereignty, cryptographic resilience, and  
Telecommunications networks are not just commercial assets—they are essential to mlitary communications and logistics, government intelligence operations, and critical infrastructure coordination (energy, finance, emergency services). A breach at this scale exposes vulnerabilities in both civilian and military command-and-control systems, making Salt Typhoon not just a cybercrime but an act of asymmetric cyber warfare. 
The financial damage of the Salt Typhoon is estimated in the billions.  This consists of firect costs (network restoration, security audits, regulatory fines), indirect costs (customer churn, reputational damage, loss of investor confidence), and legal liabilities (class-action lawsuits from affected consumers and businesses). A breach of this magnitude erodes consumer trust in telecom providers, raising questions about data privacy, accountability, and the long-term viability of centralized network models. 
The sophistication of Salt Typhoon also highlights the impending vulnerability of traditional cryptographic defenses. Current encryption standards, including RSA-2048 and ECC, are vulnerable to quantum computing advancements. If quantum-capable adversaries obtain exfiltrated data today, they can store it for future decryption - a tactic known as 'store now, decrypt later.' This makes quantum-safe security an urgent priority for telecommunications and critical infrastructure providers. 
Mitigating the Threat 
In response to Salt Typhoon and similar threats, organizations must proactively enhance their encryption frameworks, particularly for secure communications and remote access. One of the most effective countermeasures is the adoption of Quantum-Safe VPNs, which integrate quantum-safe cryptographic algorithms to ensure long-term security. 
 
By replacing classical cryptographic primitives with quantum-resistant alternatives, organizations can prevent data exfiltration from being decrypted in the future, ensure secure long-term key exchanges, and protect high-value assets such as telecom routing tables, call logs, and metadata. 
For organizations seeking to implement next-generation security, essential features include the option for hybrid cryptography. Zero Trust Architecture further ensures that no device or user is inherently trusted, rather every endpoint is continuously authenticated. 
While full-scale quantum computing threats may still years away, Salt Typhoon is a warning shot—traditional VPNs relying on RSA-based key exchanges will soon become defunct against quantum adversaries. 
The Salt Typhoon attack is a stark reminder that telecommunications security is no longer just a corporate responsibility - it is a national imperative. The breach exposed fundamental weaknesses in network design, encryption protocols, and supply chain security, signaling an urgent need for next-generation cybersecurity frameworks. 
As cyber adversaries evolve, so must our defenses. Quantum-safe cryptography is no longer a theoretical safeguard - it is an operational necessity for securing global telecommunications infrastructure. The race to protect critical infrastructure is not against hackers alone—it is against time.",
      "author": {
         "@type": "Person",
         "name": "Arqit",
         "sameAs": "http://arqitgroup.com/"
     }
    }
```