Twenty countries qualify as post-quantum makers, arXiv study says

An arXiv preprint posted on September 17 introduces a model to score national readiness and sovereignty for post-quantum cryptography (PQC), finding 20…

Hannah Vogel ·

Twenty countries qualify as post-quantum makers, arXiv study says

In a preprint posted September 17 on arXiv, a research team introduces a Readiness‑Sovereignty Capability Model (RSCM) for post‑quantum cryptography and applies it to 57 documented cryptographic actors, concluding that 20 countries clear a “maker” gate for indigenous post‑quantum creation while 25 are dependent. The paper reports that 15 of the 20 are full‑stack makers and five are research makers; 11 hold strong general cryptographic capacity without post‑quantum control; and one is a ready adopter. The model’s gate requires demonstrated, institutionally sustained creation at least in one core layer—design, implementation or validation—rather than mere adoption. The authors report substantial agreement in their gate coding (quadratic‑weighted kappa of 0.71), and they note readiness tracks independent cyber indices (rank correlations up to 0.70) while post‑quantum creation shows no significant correlation with a commitment index (a rank correlation of 0.22). This is, so far, single‑source—an arXiv preprint—with no outside parties consulted or quoted in the packet.

Sovereignty is being operationalized into a procurement criterion, not just a policy slogan

The immediate business significance is not the scoreboard of who made the “maker” cut; it’s that the study operationalizes sovereignty into measurable constructs procurement can use: indigenous cryptographic capacity, indigenous post‑quantum control, and external dependency. Most corporate security plans have treated PQC as a checkbox readiness problem—swap algorithms, patch libraries, update hardware modules. The RSCM reframes it as a sourcing problem that changes who you buy from and what you are on the hook to disclose. A vendor able to demonstrate indigenous post‑quantum control—in design, code or validation—may soon qualify differently in public tenders and regulated‑sector RFPs than one that only integrates external libraries. That moves PQC from an engineering sprint to a supplier classification that legal and procurement will enforce.

The denominator the market has ignored: who actually makes post‑quantum, not just who declares it

The paper’s most uncomfortable finding for buyers is the separation between readiness and control. Readiness correlates with existing cyber indices; creation does not. The reported 0.22 rank correlation between post‑quantum creation and a commitment index means public promises and roadmaps are weak predictors of who can actually build or validate post‑quantum assets. If you are a bank or critical‑infrastructure operator, that is the denominator you have not been measuring. Many suppliers will pass readiness audits while remaining externally dependent for the cryptographic core. For procurement, that creates a mispriced risk: the control plane of your future encryption stack may sit outside your sovereign or contractual perimeter even when the release notes say “PQC‑ready.”

Why this changes how software is bought: PQC becomes a vendor‑lock and venue decision

RSCM’s gate is a policy lever with direct commercial consequences. If governments adopt it or a similar rubric, buyers in regulated sectors will confront a new triage: do we source from a “maker” to maintain indigenous control, partner with a “ready adopter,” or accept dependence and document it? The model’s insistence on “institutionally sustained creation” in at least one layer raises the bar beyond a single integration sprint or lab demo. For software vendors, that pulls cryptography out of the commodity bucket and back into a differentiator buyers will pay for—or will mandate in contracts. Cloud providers, HSM vendors, SDK maintainers and embedded device makers should expect RFPs to start distinguishing “makers” from assemblers, with corresponding price and liability implications.

The gate’s design implies a longer lock‑in than typical software refresh cycles

The authors argue PQC choices can lock in dependence or sovereignty for decades because algorithms, implementations, hardware and standards adopted now are sticky. That stickiness matters to contract structure. Consumption‑priced services have trained buyers to treat crypto upgrades as a variable, rolling cost. But PQC adoption entails hardware modules, key‑management protocols and certificate hierarchies that are expensive to swap. Once you anchor on a specific library or HSM vendor for post‑quantum, the change‑out is not a quarterly refactor—it’s a migration measured in years. That means procurement will favor suppliers who can evidence indigenous control and stable maintenance capacity, and may press for escrow or multi‑vendor validation to limit unilateral dependency. Vendors relying on upstream open‑source without institutionalized validation will face more intrusive due diligence, even if their product passes functional tests.

The sovereignty split will ripple through partner programs and reseller economics

Resellers and systems integrators live off standardized stacks and predictable certifications. A sovereignty‑weighted rubric fragments those standard stacks. If a given country or sector insists on makers for one layer—say, algorithm implementation—global resellers will need multiple PQC lines to satisfy different jurisdictional demands. That breaks volume discounts and complicates support economics. The paper’s classification of five “research makers” suggests a middle path: partners can combine indigenous algorithm design with external implementations or validation. That offers integrators an option to meet a sovereignty gate without a full vertical stack—but it also forces program managers to track where indigenous control actually sits, not just brand badges on slides. Expect to see partner tiers relabeled to map to “design,” “implementation,” and “validation” roles in PQC, mirroring the model’s layers.

The skeptic’s case: a preprint is not a mandate, and threshold uncertainty matters

There is a reasonable counter: this is a research preprint, not a standard, and the authors acknowledge uncertainty at the threshold. A quadratic‑weighted kappa of 0.71 indicates substantial agreement, not unanimity. In practice, that means some actors near the gate could tip from “dependent” to “maker” (or vice versa) as evidence accumulates. Buyers should be cautious about treating the categories as settled or assuming a specific vendor’s upstream dependencies track one‑to‑one with a country’s classification. The study also doesn’t claim causal links between control and outcomes; it measures capabilities and dependencies with cited public evidence. Policymakers and auditors may adapt rather than adopt its exact thresholds, and industry may resist sovereign gates that constrain global supply chains.

What changes for the next renewal cycle: disclosures and due diligence, not just crypto‑agility

In the near term, this is a disclosure shift. Security and legal teams will start asking suppliers to document where indigenous control resides in their PQC stack: who designed the algorithm and who maintains it, who implements the library, and who validates the build—backed by evidence of institutionally sustained creation. The model’s three constructs provide a checklist. Buyers in finance, healthcare and public sector will be pressed to evidence their own posture as commitments become less persuasive than creation. Given the paper’s finding that readiness correlates with cyber indices while creation does not, audit committees will ask for both: a readiness roadmap and a sovereignty map. Vendors who can satisfy both will find room to price and to negotiate liability caps; those who cannot may face harder SLAs, escrow demands, or exclusion in sovereign‑sensitive tenders.

Signals to watch: procurement language, vendor documentation, and trade policy linkages

Whether this model becomes market‑moving depends on adoption. Three observable signals will tell us. First, procurement: watch national frameworks and sector RFPs for explicit references to “indigenous post‑quantum control,” “maker” criteria, or the RSCM itself. Second, vendor documentation: look for supplier security annexes that identify PQC algorithm provenance, implementation maintainers, and validation practices—moving beyond “PQC‑ready” marketing. Third, trade: monitor whether export controls, certification schemes, or funding programs tie eligibility to indigenous PQC capabilities in design, implementation, or validation. If any of these materialize, the sovereignty criterion will become a de facto buying gate as real as an ISO certificate. If they do not, PQC may remain an engineering project with uneven sourcing discipline.

The arXiv preprint does not name companies, and it does not prescribe which algorithms or vendors to choose. It does something more operationally useful: it supplies a measurement frame that separates readiness from control and forces buyers and sellers to prove where their cryptographic competence actually resides. As PQC migration begins in earnest, that frame can either harden into a procurement standard or be ignored. Either way, vendors and buyers who treat sovereignty as a measurable input—not a slogan—will make fewer expensive, path‑dependent mistakes.

More stories

Latest news