← Back to Blog

The Quantum Cold War: USA vs China in the Race to Break (and Defend) Encryption

The Quantum Cold War: USA vs China in the Race to Break (and Defend) Encryption - QNSQY post-quantum encryption guide

A Race with Two Prizes

The "quantum arms race" framing suggests one side will win by building a Cryptographically Relevant Quantum Computer first. The reality is more interesting: both sides are simultaneously racing to build the attacker (CRQC) and the defender (Post Quantum Cryptography). Whichever side builds CRQC first wins the ability to read the other's legacy-encrypted archives. Whichever side migrates to PQC first protects its own future communications. The United States and China are the only two nations credibly pursuing both prizes simultaneously.

Funding Comparison

ProgramReported fundingSource
US NQI Reauth$2.7B FY25-29 (pending)Congress.gov
US DOE QIS Centers$625M Phase 2 (Dec 2024)Energy.gov
China (aggregated)$10-15B (disputed)OECD-flagged as unverified
EU Quantum Flagship€1B (2018-28)European Commission
UK NQTP+Strategy£2.5B (2024-33)DSIT
Japan Moonshot+Q-LEAP$7B estimatedCabinet Office
India NQM$730M (2023-31)DST
Australia (PsiQuantum)$940M AUD (2024)DISR

China's aggregated $10-15B is reported but not independently audited. OECD has flagged these figures as unverified. Concrete individual budgets are diffused across agencies and classified channels.

Hardware Parity (as of April 2026)

MetricUSA leaderChina leader
Qubits (superconducting)IBM Condor 1,121Zuchongzhi 3.0 105
Logical qubits (peer-reviewed)Google Willow (surface code below threshold, 105 physical)Limited public data
Photonic quantum advantageXanadu, PsiQuantumJiuzhang 3.0 255 photons
Trapped ionQuantinuum H2, IonQ Forte EnterpriseLimited public program
Neutral atomAtom Computing 1,180MSU 72 (neutral atom)
AnnealerD-Wave 5,000+ qubits (Canadian)N/A

The HNDL Dimension

Both US and Chinese signals intelligence agencies have Internet backbone access capable of stockpiling encrypted traffic. The NSA's Utah Data Center (Bluffdale, UT, operational 2014) has classified capacity estimated at 3-12 exabytes in public analyses. China's equivalent capabilities are less publicized but broadly comparable.

The Harvest Now Decrypt Later attack does not require either side to win the CRQC race first. It requires only:

  1. Sufficient intelligence collection infrastructure (both sides have it).
  2. Storage capacity for decades of encrypted traffic (cheap for both).
  3. Eventual CRQC access (expected within the 10-30 year horizon).

Every day of delay in PQC migration adds to both sides' stockpiles of decryptable future intelligence.

Cryptographic Standards: A Surprising Alignment

Despite the competitive framing, NIST PQC standards are adopted by implementers worldwide including in China. Chinese academic papers contribute to lattice analysis, code-based cryptography, and isogeny cryptanalysis. The 2022 Castryck-Decru attack on SIDH was cited globally, including in Chinese PQC research.

China's Office of State Cryptography Administration has its own SM series (SM2, SM3, SM4, SM9). SM2 is an ECC variant, broken by Shor like any other ECC. Chinese PQC adoption parallels NIST's timeline though in separate standards infrastructure.

The Five Eyes Axis

The US, UK, Canada, Australia, and New Zealand coordinate PQC migration via Five Eyes. NSA CNSA 2.0 (2022), NCSC UK migration timelines (2024), and equivalent Australian/Canadian/New Zealand guidance all point to 2035 as the full migration horizon. This is effectively the Western bloc's coordinated PQC deadline.

Outcomes

The most likely outcome of the quantum cold war is neither side breaks the other's PQC cryptography. Lattice and hash-based PQC will hold. Instead, both sides will spend the 2030s slowly decrypting the legacy RSA/ECC traffic they stockpiled during the 2010s and 2020s. The winner of the HNDL battle is whoever migrated to PQC earlier.

What You Should Do

  1. Apply Mosca's theorem to your own data.
  2. Deploy hybrid ML-KEM in any new system.
  3. Inventory classical cryptography in legacy systems.
  4. Plan a full migration to PQC by 2035 following NIST FIPS 203/204/205.

Frequently Asked Questions

Is the US or China ahead in quantum?

Depends on metric. US has larger aggregate public funding. China has the largest photonic quantum advantage demonstration (Jiuzhang 3.0 at 255 photons). Neither has a CRQC. Both are years to decades away.

Does China have a published PQC migration deadline?

China has its own SM series of cryptographic standards through the Office of State Cryptography Administration. A formal national PQC migration deadline comparable to NSA CNSA 2.0 has not been publicly published as of April 2026.

Are Western PQC standards usable in China?

NIST FIPS 203, 204, and 205 algorithms are freely available and can be implemented anywhere. Chinese regulated industries may prefer the SM series for domestic compliance; global products can use NIST.

Which intelligence service harvests more data?

Both NSA and Chinese MSS have extensive Internet collection programs. Neither publishes exact figures. The prudent assumption for anyone with long-lived sensitive data is that it is collected by at least one.

Sources

  1. NSA CNSA 2.0
  2. GRI 2025
  3. Castryck-Decru SIDH attack

Related Articles

Protect Your Data Before Q-Day Arrives

QNSQY's NIST-standardized post-quantum encryption protects files against both current and quantum-era threats.

Try QNSQY

Originally published at quantumsequrity.com/blog/quantum-cold-war-usa-vs-china.