Quantum Academy begins operations on September 15, 2026. Enrollment opens soon.
Skip to content

Market Reality

A Field Guide to Misleading Quantum Marketing

Marin Ivezic7 min read

A datasheet arrives with the words “quantum-safe certified” across the front page. There is no such certification. FIPS 140-3 validation exists, and the NIST Cryptographic Module Validation Program (CMVP) grants it to a named module, running named algorithms, in a named operating configuration. It is not available for a proprietary cipher that no outside cryptographer has read. The phrase on the datasheet borrows a credential from a program that would never have issued it.

We see some version of that page most months, and so do the security teams we train. Quantum vocabulary moves procurement budgets now, and marketing departments have worked that out. Most vendors using the words are honest, and the technology underneath is real. NIST finalized ML-KEM, ML-DSA and SLH-DSA in August 2024, and migrations are already underway. Genuine progress is exactly what makes exaggeration plausible, and when the science is unfamiliar to the buyer, a claim that sounds precise is very hard to price.

This guide is not a dictionary. PostQuantum.com maintains one, term by term, and the link is at the end. This is the shorter thing a buyer needs in the room. Two shapes a bad claim takes, and four questions that tell them apart from a real one.

Two ways a quantum claim goes wrong

Invented vocabulary. Some phrases have no meaning in physics, computing or cryptography. “Quantum-grade encryption” is the tidiest example, built on the same pattern as “military-grade” and equally empty. No standards body defines the grade and none issues it. A few minutes with a search engine settles most of these, and the only pages using the phrase are usually the pages selling something.

Hijacked vocabulary. The harder case uses real terms. “Unconditionally secure,” “perfect secrecy” and “information-theoretic security” are precise results from information theory, and each one holds under stated conditions. Marketing keeps the term and drops the conditions. The sentence stays true of the mathematics and stops being true of the product in the rack.

A search catches the first kind. Only a question catches the second.

Four questions that sort a datasheet

Which of the three are we talking about?

Three unrelated things travel under quantum branding. Quantum key distribution (QKD) is optical hardware that establishes keys using the physical states of photons. Post-quantum cryptography is classical mathematics running on ordinary processors, designed so that Shor’s algorithm gives an attacker no shortcut. The third category is a classical product with quantum branding and no quantum content, or at most a quantum random number generator somewhere in the key path.

What we tell candidates is to ask which one is being sold, in those words. A QKD vendor says QKD immediately, because the hardware is the product. A post-quantum vendor names FIPS 203, 204 or 205. If the answer stays vague across two attempts, treat the product as the third category until something proves otherwise. The IETF published RFC 9794 to pin this vocabulary down. The ambiguity had become expensive enough for a standards body to act.

Name the algorithm

Auguste Kerckhoffs set the rule in 1883. A cryptographic system should stay secure with everything about it public except the key. Nothing since has overturned it, and the modern version is blunt. A vendor names the algorithm, or the product can’t be evaluated at all.

Acceptable answers are ML-KEM, ML-DSA, SLH-DSA, or a named candidate that has been through public cryptanalysis. Unacceptable answers are proprietary, patent-pending, and available under NDA. We treat the NDA answer as the most reliable single signal of trouble in this market, and asking for it costs nothing.

State the assumptions

Claude Shannon proved in 1949 that perfect secrecy requires a key at least as long as the message, generated at random and used only once. A product offering perfect secrecy with a short reusable key is contradicting the proof rather than improving on it. The same discipline applies to quantum key distribution. Information-theoretic security is a property of the protocol under its stated assumptions, and the equipment in your rack is one implementation of that protocol, with detectors and firmware and a supply chain behind it.

Lydersen and colleagues showed in 2010, in Nature Photonics, that commercial QKD detectors could be blinded with bright light, and the key read without alerting either legitimate party. The NSA and the UK’s National Cyber Security Centre (NCSC) both advise against QKD for national security systems, and both point at implementation and authentication problems rather than any flaw in the physics. We ask QKD vendors which attack models the product defends against and which it doesn’t. Real engineers enjoy that conversation.

What was validated, and by whom?

Validation claims are checkable, and awards are not. A FIPS 140-3 certificate names the module, its version, the approved algorithms and the operational environment, and the certificate number can be looked up in the public CMVP registry. We tell buyers to ask for that number and then read the security policy, checking what the cryptographic boundary actually covers. A validated module inside a product does not validate the product.

Everything else in the credibility section of a pitch deck deserves less weight than the deck gives it. Magazine covers can be bought. Trade show awards are frequently given to every exhibitor who applies. A partnership is sometimes a customer relationship written the other way round. Journal publication means something in journals the field actually reads.

Hype and denial produce the same purchase order

Two sales stories work on the same buyer, and we see both inside a single procurement cycle. The first pulls Q-Day forward, treats every qubit-count headline as a countdown to the day a quantum computer breaks current public-key encryption, and sells the urgency. The second pushes Q-Day out to never, argues that error correction will never scale, and sells the relief of doing nothing. They look like opposites and they finish in the same place. The organization has no cryptographic inventory, no migration plan, and no clear picture of which systems still depend on RSA.

Neither story sets your deadline. Regulators, insurers and customers set it. The NSA’s Commercial National Security Algorithm Suite (CNSA 2.0) requires national security systems to be fully transitioned by 2035, with earlier dates for software and firmware signing. Large financial and telecom buyers now ask about post-quantum plans in their supplier questionnaires. Those dates hold whether a cryptographically relevant quantum computer arrives in 2030 or in 2040.

What a straight answer sounds like

The contrast is easy to hear once you have heard it twice. A vendor with real work behind the product names algorithms without being pushed, holds or is pursuing FIPS 140-3 validation and says which, and tells you where the product’s guarantees stop. Bring an independent cryptographer into the evaluation and the good vendors are relieved rather than defensive. A technical buyer is cheaper to sell to and much cheaper to support afterwards.

The test that resolves most cases is smaller than any of the four questions. Ask something technical and see whether you get a technical answer. Deflection, a recital of credentials, or visible offence at the question tells you what kind of pitch you are in.

Where to look up a specific term

When a phrase turns up in a pitch and this guide doesn’t cover it, the Quantum Snake Oil Dictionary on PostQuantum.com works through the vocabulary term by term and gives the physics behind each verdict. For the work on your own side of the contract, the PQC Migration Framework sets out the inventory and planning that no vendor can do for you.

Building the reflex

None of these four questions needs a physics degree behind it. They need someone on the team who knows what ML-KEM is, what FIPS 140-3 covers, what quantum key distribution does and doesn’t promise, and why Kerckhoffs’s rule still decides the argument. That is ordinary professional literacy for anyone signing cryptography contracts, and most security teams don’t have it yet.

Building it across a team is what our programs are for. Quantum Academy covers the standards, the threat model and vendor evaluation together, so the person reading the datasheet knows which question comes next. You can see the current programs and credentials at quantumacademy.com/.