Submitted:
23 August 2025
Posted:
25 August 2025
You are already at the latest version
Abstract
Under the threat window of ‘interception first, decryption later’ in quantum computing, national security and industrial sovereignty face new systemic challenges. This paper proposes a dual-track approach of ‘PQC baseline + QKD enhancement’ to comprehensively compare the standard systems, governance models, and engineering progress of China and the United States in post-quantum cryptography (PQC) and quantum key distribution (QKD). The study employs a three-tier evidence integration framework of ‘policy-standards-engineering,’ combining authoritative documents from NIST, OMB, CISA, and other sources with China’s national standard platform and industry announcements. It constructs an analysis model of ‘standard hierarchy-migration ecosystem-international interoperability’ and evaluates the feasibility of the scheme through gap-risk mapping, roadmap design, and KPI matrix assessment. The results show that the United States has established a closed-loop system of ‘primary standards + redundancy’ based on FIPS 203/204/205 and HQC backup algorithms, and has entered an auditable implementation phase driven by mandatory migration and toolchain initiatives from OMB and CISA; China maintains an advantage in QKD engineering and standardisation, but national standards for PQC have not yet been solidified, and the migration governance system lags behind, resulting in a structural shortfall of ‘engineering leading the way while algorithm standards lag behind.’ Based on this, this paper proposes a ‘three-year-five-year-ten-year’ national roadmap: establish a standardised baseline within three years, achieve large-scale migration and verification within five years, and complete consolidation and internationalisation within ten years. This will be supplemented by protocols, PKI/certificates, key lifecycle management, testing and certification, and algorithm switching mechanisms, in conjunction with a five-tier governance structure led by the State Cryptography Administration, with TC260/TC485 as the technical focal points, and the Ministry of Industry and Information Technology/ the Cyberspace Administration of China/People’s Bank of China, operator and critical infrastructure implementation, and research institutes. The conclusion states that PQC must be established as the ‘basic defence line’ in the quantum era, while QKD should serve as the ‘enhanced defence line’ for critical links; China must complete the construction of PQC national standards and migration governance capabilities within a three-year standardisation, five-year consolidation, and ten-year internationalisation timeline, and achieve dual-track integration and international interoperability with the QKD standard suite, thereby safeguarding national security, consolidating industrial resilience, and enhancing international influence.
Keywords:
I. Introduction
II. Posture Assessment and National Security Implications
III. Timeline of the Evolution of Standards in China and the United States
| vintages | United States (PQC) | China (Quantum Communications/QKD Mainline) |
| 2016 | Released NISTIR 8105, proposed PQC roadmap |
— |
| 2017 | First round of 69 candidate algorithms announced on 20 December (NIST, 2019) | — |
| 2019 | Announcement of 26 candidate algorithms for the second round |
— |
| 2020 | Release of Second Round Status Report NISTIR 8309 (NIST, 2020) | — |
| 2022 | Proposed standardised algorithms announced on 5 July: Kyber, Dilithium, SPHINCS+ (Falcon as a backup) (NIST, 2022) | The Ministry of Industry and Information Technology’s QKD series of standards for the communications industry and commercial confidentiality industry continue to improve. |
| 2023 | OMB M-23-02 Requirement for Federal Agencies to Initiate PQC Migration Readiness | GB/T 42829-2023 “Basic Requirements for Quantum Secure Communication Applications” published (implemented on 2024-03-01) (SAMR, 2023) |
| 2024 | Official release of FIPS 203/204/205 on 13 August (NIST, 2024a; Federal Register, 2024) | GB/T 43692-2024 “Quantum Communication Terms and Definitions” published (implemented on 2024-10-01) |
| 2025 | 11 March Selection of HQC as Alternate KEM and Release of NIST IR 8545 (NIST, 2025) | QKD Safety Requirements, Test and Evaluation Methods (Part 1: Requirements) published for comment on 25 April (TC260, 2025) |
IV. Gaps and Risk Assessment
V. China’s PQC National Standards and QKD Dual-Track Strategy “3 Years-5 Years-10 Years” Roadmap
| Lane | Task | Owner | Start | End | KPI | Milestone | DependsOn |
| Standards | PQC GB/T (KEM v1) | TC260 | 2025-10-01 | 2026-09-30 | 1 standard | ✔ | - |
| Standards | PQC GB/T (Signature v1) | TC260 | 2025-12-01 | 2026-12-31 | 1 standard | ✔ | - |
| Standards | Conformance test methods v1 | SCA | 2026-01-15 | 2026-10-31 | 1 method | ✔ | PQC GB/T (KEM v1) |
| Standards | Backup algorithm policy (selection rules) | SCA | 2026-03-01 | 2026-11-30 | policy ready | ✕ | - |
| Protocols & PKI | Hybrid suite baseline (TLS/QUIC/IPsec/5G) | MIIT | 2025-11-01 | 2026-09-30 | baseline | ✔ | - |
| Protocols & PKI | Certificates/keys & Guomi PKI transition spec | PBOC | 2026-02-01 | 2026-10-15 | spec | ✔ | - |
| Migration Governance | National PQC migration roadmap | SCA | 2026-01-01 | 2026-06-30 | roadmap | ✔ | - |
| Scaled Migration | Dual-stack rollout (Gov/Finance/Power/Telcos) | Multi | 2027-01-01 | 2028-12-31 | 40% links | ✕ | National PQC migration roadmap |
| Testing & Certification | Conformity catalog & red-teaming (BAU) | SCA | 2027-03-01 | 2028-12-31 | 25 rounds/yr | ✕ | Conformance test methods v1 |
| Procurement & Localization | Gov procurement & localization lists | MOF | 2027-04-01 | 2028-06-30 | lists | ✔ | Conformity catalog & red-teaming (BAU) |
| Internationalization | ≥80% migration / ISO submissions / BRI go-global | TC260 | 2029-01-01 | 2035-12-31 | ≥80% coverage | ✕ | Phase B complete |
| dimension (math.) | 2026 | 2027 | 2030 |
| Issuance of PQC GB/T Quantity (KEM / Signature / Test) | ≥2 / ≥1 / ≥1 | 1 round of revisions completed | Formation of a series of families |
| Asset Inventory Coverage (SS/Kwanji) | 60 % | 85 % | 100 % |
| Focused Link Dual Stacking (PQC+QKD) | 15 % | 40 % | 70 % |
| Domestic equipment through the consistency of the proportion of certification | 30 % | 60 % | 80 %+ |
| Number of interoperability tests (cross-vendor / cross-domain) | 10 | 25 | 50 |
| Alternate Algorithm Annual Exercise | 1 | 2 | 2+ |
VI. Governance Structure and Division of Responsibilities
VII. Technical Baseline
VIII. Key Risks and Responses
IX. Discussion
X. Conclusion
References
- Bureau of Industry and Security. (2021, March 29). Encryption and Export Administration Regulations (EAR). https://www.bis.doc.gov/index.php/policy-guidance/encryption.
- CCSA/SAMR. (2021, March 5). YD/T 3834.1-2021 量子密钥分发(QKD)系统技术要求 第1部分:基于诱骗态BB84协议的QKD系统 [Technical requirements for QKD systems—Part 1: Decoy-state BB84-based QKD]. 全国标准信息公共服务平台. https://std.samr.gov.cn/hb/search/stdHBDetailed?id=C362B3DB621BA067E05397BE0A0A1ED8.
- Cyberspace Administration of China. (2014, August 1). 国家互联网信息办公室职责 [Functions of the Cyberspace Administration of China]. https://www.cac.gov.cn/2014-08/01/c_1111903999.htm.
- Cyberspace Administration of China. (2025, July 1). 关键信息基础设施商用密码使用管理规定 [Administrative provisions on the use of commercial cryptography in critical information infrastructure]. https://www.cac.gov.cn/2025-07/01/c_1753083518894995.htm.
- Cybersecurity and Infrastructure Security Agency. (2023, August 21). Quantum-readiness: Migration to post-quantum cryptography. https://www.cisa.gov/resources-tools/resources/quantum-readiness-migration-post-quantum-cryptography.
- Cybersecurity and Infrastructure Security Agency. (2024, September 26). Strategy for migrating to automated PQC discovery and inventory tools (PDF). https://www.cisa.gov/sites/default/files/2024-09/Strategy-for-Migrating-to-Automated-PQC-Discovery-and-Inventory-Tools.pdf.
- Federal Register. (2024, August 14). Announcing issuance of Federal Information Processing Standards (FIPS): FIPS 203/204/205. https://www.federalregister.gov/documents/2024/08/14/2024-17956/announcing-issuance-of-federal-information-processing-standards-fips-fips-203-module-lattice-based.
- ISO/IEC JTC 1/SC 27. (n.d.). Information security, cybersecurity and privacy protection. https://www.iso.org/committee/45306.html.
- National Cybersecurity Center of Excellence. (2023a, August). Migration to post-quantum cryptography (PQC) – Fact sheet. National Institute of Standards and Technology. https://www.nccoe.nist.gov/sites/default/files/2023-08/mpqc-fact-sheet.pdf.
- National Cybersecurity Center of Excellence. (2023b, December 19). SP 1800-38B (preliminary draft): Crypto agility considerations—Migrating to post-quantum cryptographic algorithms (PDF). National Institute of Standards and Technology. https://www.nccoe.nist.gov/sites/default/files/2023-12/pqc-migration-nist-sp-1800-38b-preliminary-draft.pdf.
- National Cybersecurity Center of Excellence. (2023). Crypto agility considerations: Migrating to post-quantum cryptographic algorithms (Project page; includes SP 1800-38 resources). National Institute of Standards and Technology. https://www.nccoe.nist.gov/crypto-agility-considerations-migrating-post-quantum-cryptographic-algorithms.
- National Information Security Standardization Technical Committee (TC260). (n.d.). 首页与标准化工作信息 [Homepage and standardization work information]. https://www.tc260.org.cn/.
- National Public Service Platform for Standards Information. (n.d.-a). TC485 全国通信标准化技术委员会 [TC485 National Technical Committee on Communications Standardization]. https://std.samr.gov.cn/search/orgDetailView?tcCode=TC485.
- National Institute of Standards and Technology. (2024, August 13). NIST releases first 3 finalized post-quantum encryption standards (FIPS 203/204/205). https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards.
- National Institute of Standards and Technology. (2025, March 11). NIST selects HQC as fifth algorithm for post-quantum encryption. https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption.
- National Institute of Standards and Technology. (2025, March). NIST IR 8545: Status report on the fourth round of the NIST post-quantum cryptography standardization process (PDF). https://nvlpubs.nist.gov/nistpubs/ir/2025/NIST.IR.8545.pdf.
- NIST CSRC. (2024, August 13). Post-quantum cryptography FIPS approved. Computer Security Resource Center. https://csrc.nist.gov/news/2024/postquantum-cryptography-fips-approved.
- NIST CSRC. (2025). Post-Quantum Cryptography Standardization (including NIST IR 8545 and HQC selection information). https://csrc.nist.gov/projects/post-quantum-cryptography/post-quantum-cryptography-standardization.
- Office of Management and Budget. (2022, November 18). M-23-02: Migrating to post-quantum cryptography (PDF). Executive Office of the President. https://www.whitehouse.gov/wp-content/uploads/2022/11/M-23-02-M-Memo-on-Migrating-to-Post-Quantum-Cryptography.pdf.
- People’s Bank of China. (2025). Order No. 2 [2025] of the People’s Bank of China … https://www.pbc.gov.cn/en/3688253/3689009/4180845/5741155/index.html.
- SAMR. (2023). GB/T 42829-2023 量子保密通信应用基本要求 [Basic requirements of quantum secure communication applications]. 国家标准信息公共服务平台. https://openstd.samr.gov.cn/bzgk/gb/newGbInfo?hcno=867AE36ABF49F8013D496C24437222A8.
- SAMR. (2024). GB/T 43692-2024 量子通信术语和定义 [Quantum communication terminology and definition]. 国家标准信息公共服务平台. https://std.samr.gov.cn/gb/search/gbDetailed?id=14156507D16E0337E06397BE0A0AE656.
- State Council of the People’s Republic of China. (2008, July 17). 工业和信息化部职责、内设机构和编制规定(全文) [Functions, internal organs, and staffing of the Ministry of Industry and Information Technology]. https://www.gov.cn/zfjs/2008-07/17/content_1048292.htm.
- State Cryptography Administration. (2020, January 21). 密码政策问答(十五) [Cryptography policy Q&A (No. 15)]. https://www.oscca.gov.cn/sca/xxgk/2020-01/21/content_1060613.shtml.
- State Cryptography Administration. (2020, May 11). 商用密码产品认证目录(第一批) [Catalogue of commercial cryptography product certification (first batch)] [PDF]. https://www.oscca.gov.cn/sca/xwdt/2020-05/11/1060749/files/2dafffd5b75d4e25aab610f357bb5ec9.pdf.
- State Cryptography Administration. (2021, October 19). GM/T 0108-2021 诱骗态BB84量子密钥分配产品技术规范 [Decoy-state BB84 quantum key distribution product specification]. https://www.oscca.gov.cn/sca/xxgk/2021-10/19/content_1060886.shtml.
- State Cryptography Administration. (2023, October 7). 商用密码检测机构管理办法(国家密码管理局令第2号) [Administrative measures for commercial cryptography testing institutions (SCA Order No. 2)]. https://www.oscca.gov.cn/sca/xxgk/2023-10/07/content_1061108.shtml.
- State Cryptography Administration. (2024, November 11). 国家密码管理局公告(第49号) [Announcement No. 49 of the State Cryptography Administration]. https://www.oscca.gov.cn/sca/xwdt/2024-11/11/content_1061214.shtml.
- The Central People’s Government of the People’s Republic of China. (2019, October 27). 中华人民共和国密码法 [Cryptography Law of the People’s Republic of China]. https://www.gov.cn/xinwen/2019-10/27/content_5445395.htm.
- The Central People’s Government of the People’s Republic of China. (2023). 国家密码管理局令(第3号)商用密码应用安全性评估管理办法 [SCA Order No. 3: Administrative measures for the security assessment of commercial cryptography applications]. https://www.gov.cn/gongbao/2023/issue_10846/202311/content_6917320.html.
- World Intellectual Property Organization. (n.d.). Standard-essential patents (SEPs). https://www.wipo.int/en/web/patents/topics/sep.






Disclaimer/Publisher’s Note: The statements, opinions and data contained in all publications are solely those of the individual author(s) and contributor(s) and not of MDPI and/or the editor(s). MDPI and/or the editor(s) disclaim responsibility for any injury to people or property resulting from any ideas, methods, instructions or products referred to in the content. |
© 2025 by the authors. Licensee MDPI, Basel, Switzerland. This article is an open access article distributed under the terms and conditions of the Creative Commons Attribution (CC BY) license (http://creativecommons.org/licenses/by/4.0/).