Quantum Computing

Prepare for quantum on two fronts.

Understand where quantum computing could matter to your organization and prepare for its effect on cryptography. We prototype quantum and hybrid algorithms against strong classical baselines and plan post-quantum migrations that can begin today.

From architecture to integration to operation
A quantum circuit against a classical baselineq0Hq1Hq2Hq3HCandidate screenOptimizationSimulationSamplingBaselineClassical baselineMost problems stay classical: screen honestly

The opportunity

Start with a decision
worth improving.

A financial institution wants to know whether quantum methods could help with portfolio optimization, and how long its encrypted records will stay safe. The two questions run on different timelines and involve different teams.

From possibility to a working system

Follow the flow.

Three connected decisions. One considered architecture.

A quantum circuit against a classical baselineq0Hq1Hq2Hq3HCandidate screenOptimizationSimulationSamplingBaselineClassical baselineMost problems stay classical: screen honestly

Conceptual flow, not a live system or measured result.

01

Find a suitable problem

Screen candidate workloads in optimization, simulation and sampling. Most business problems remain better served by classical computing, so the first output is an honest shortlist with a classical baseline for each.

A quantum circuit against a classical baselineq0Hq1Hq2Hq3HCandidate screenOptimizationSimulationSamplingBaselineClassical baselineMost problems stay classical: screen honestly
OptimizationSimulationSamplingBaseline
02

Prototype a hybrid

Implement promising candidates on simulators and cloud-accessible quantum hardware using SDKs such as Qiskit, Cirq or Amazon Braket. Compare results, cost and noise sensitivity with the classical approach.

A quantum circuit against a classical baselineq0Hq1Hq2Hq3HHybrid benchmarkSimulatorQPUHybrid loopBenchmarkClassical baselineSimulator and cloud QPU, compared to classical
SimulatorQPUHybrid loopBenchmark
03

Migrate the cryptography

Inventory where public-key cryptography is used, prioritize long-lived sensitive data and plan a crypto-agile transition to the NIST post-quantum standards ML-KEM, ML-DSA and SLH-DSA.

A quantum circuit against a classical baselineq0Hq1Hq2Hq3HPQC migrationInventoryPriorityML-KEMML-DSAClassical baselineInventory keys · prioritize · move to NIST PQC
InventoryPriorityML-KEMML-DSA

The work, made concrete

What we can build
with your team.

We agree scope, dependencies and acceptance criteria before delivery. Your project can start with an assessment, a pilot or an integration into an existing system.

01

Quantum use-case screen with classical baselines

Clarify the system boundary, the responsible owners and the decisions the architecture needs to support.

02

Hybrid algorithm prototypes and benchmarks

Turn the agreed design into reviewable work, evaluated against representative inputs and explicit success criteria.

03

Post-quantum cryptography migration roadmap

Make the next step operable: document responsibilities, known limitations and the path from pilot to ongoing use.

In depth

Go deeper into quantum readiness

One page for each front: how to run the cryptographic inventory that starts a post-quantum migration, and how to benchmark quantum optimization fairly against classical solvers.

  1. 01ProcessCryptographic inventory for post-quantum migrationHow to find and record every use of public-key cryptography, structure it as a CBOM and decide what to migrate first to ML-KEM, ML-DSA and SLH-DSA.
  2. 02ComparisonQuantum optimization vs classical solvers: how to benchmarkCompare quantum annealing, QAOA and quantum-inspired methods with MIP solvers and heuristics, and learn a fair benchmarking protocol before funding a pilot.

Two fronts, two clocks and two sets of owners

Quantum readiness bundles two questions that behave very differently. The first is opportunistic: could quantum or hybrid methods eventually solve an optimization, simulation or sampling problem better than the classical tools you already run? Its timing depends on hardware progress nobody controls, and its owners are usually analytics, operations research or R&D leads. Doing nothing costs little while classical methods keep winning.

The second is defensive: when will the public-key cryptography protecting your data and transactions stop being safe? Its timing is set by how long your data must stay confidential and by public deadlines. The UK NCSC asks organizations to complete migration of all systems by 20355, and NIST's draft transition plan proposes disallowing quantum-vulnerable signature and key-establishment algorithms after 20354. Its owners are the CISO, security architects and procurement, and doing nothing has a cost that grows every year because migrations take years.

Running both as one program is a common mistake. The computing question gets judged by a security team's urgency, or the cryptography question gets parked with the innovation budget. ColdAI treats them as separate tracks that share vocabulary and governance but have different sponsors, evidence and decision dates1.

Where quantum methods are proposed, and the classical yardstick for each

A screening view of the problem classes that come up in quantum conversations. It shows what any quantum result would have to beat, not where quantum already wins.

Problem classQuantum approach usually proposedClassical yardstick to beatWhat would have to change
Combinatorial optimizationQuantum annealing or variational circuits such as QAOAMixed-integer solvers, decomposition and tuned heuristicsHardware that handles realistic instance sizes after formulation and noise
Molecular and materials simulationVariational eigensolvers today; error-corrected phase estimation laterDensity functional theory and other established computational chemistry methodsError-corrected machines able to run deep circuits on chemically relevant molecules
Sampling and Monte Carlo estimationQuantum amplitude estimation for risk and pricingClassical Monte Carlo with variance reduction on GPUsFault-tolerant hardware; the expected gains assume long, error-free circuits
Machine learningQuantum kernels and parameterized circuit modelsGradient-boosted trees, neural networks and classical kernelsEvidence of an advantage that survives comparison with quantum-inspired classical methods
Breaking public-key cryptographyShor's algorithm on a cryptographically relevant quantum computerNot a yardstick question: the response is migration, not benchmarkingNothing; the risk is planned for regardless of the arrival date

General characteristics only, not measured results. AWS groups current quantum applications into number theory, optimization, oracular computing and simulation6. For the benchmarking method itself, see the optimization comparison page linked below.

Vocabulary for reading quantum claims critically

Most confusion in quantum proposals comes from a few terms used loosely. These are the meanings we work with.

NISQ
Noisy intermediate-scale quantum: today's devices, whose errors are too frequent to run long algorithms such as Shor's without error correction6.
Physical vs logical qubit
A physical qubit is a hardware element; a logical qubit is an error-corrected unit built from many physical ones. Headline qubit counts usually mean physical qubits.
Hybrid quantum-classical loop
A classical optimizer repeatedly adjusts the parameters of a quantum circuit and reads back results, as in variational algorithms6.
Cryptographically relevant quantum computer
A machine able to break widely used public-key algorithms such as RSA and elliptic-curve schemes; the CISA, NSA and NIST factsheet uses the abbreviation CRQC8.
Harvest now, decrypt later
Recording encrypted data today in order to decrypt it once a capable quantum computer exists, which makes long-lived secrets urgent before any such machine is built8.
Crypto-agility
Designing systems so algorithms, keys and parameters can be replaced through configuration or upgrade rather than a rebuild.
Hybrid key exchange
Combining a classical algorithm with a post-quantum one such as ML-KEM, so a session stays secure while either remains unbroken.

Which quantum front to start on, by situation

  • If

    You hold data that must stay confidential for many years, such as health, financial, legal or state records

    Then

    Start the cryptographic track now with a discovery and inventory cycle, even if no computing question exists.

    Harvest-now, decrypt-later exposure begins the day data is captured, not the day a quantum computer appears.

  • If

    You ship devices, firmware or signed software that stays in the field for a decade or longer

    Then

    Prioritize signing chains and supplier commitments, and require post-quantum upgrade paths in new procurement.

    Roots of trust in fielded hardware are the slowest cryptography to change.

  • If

    An optimization or simulation problem is missing a business target despite a tuned classical solver

    Then

    Screen it for quantum and quantum-inspired methods with a fixed benchmarking protocol on simulators and cloud hardware.

    Only a real, measured gap justifies the formulation and access cost.

  • If

    Neither applies, but the board is asking about quantum

    Then

    Put quantum on a frontier watch list with explicit re-test triggers, and brief the board on both fronts separately.

    A clear 'not yet' with triggers is a stronger answer than a speculative pilot.

Failure modes in quantum readiness programs

Accepting advantage claims at face value

Early signalA proposal compares a quantum result with an untuned or naive classical method.

MitigationRequire benchmarks against the strongest classical approach you can field, on your instances, with end-to-end timing.

Buying hardware access before naming a problem

Early signalReserved quantum capacity or a research agreement exists, but no business owner or success criterion does.

MitigationTie any spend to a specific problem, a baseline and a stop rule agreed in advance.

Treating post-quantum migration as a library swap

Early signalThe plan lists algorithms but not protocols, certificates, devices or suppliers.

MitigationStart from an inventory that records ownership, data shelf-life and how each use can be changed.

Waiting for a confirmed quantum computer date

Early signalMigration is deferred until experts agree when a capable machine will exist.

MitigationPlan against public migration deadlines and your own data lifetimes instead of a forecast.

Freezing on today's algorithm list

Early signalSystems hard-code ML-KEM or ML-DSA in the same way they once hard-coded RSA.

MitigationBuild crypto-agility in; NIST has already selected further algorithms, such as HQC and Falcon, for ongoing standardization7.

How the quantum practice connects to research and ledger engineering

Some quantum questions are open research rather than delivery. ColdAI's Frontier R&D practice lists post-quantum cryptography and quantum computing among its research areas and starts each engagement from a written question with evaluation fixed before experiments run2. When a question such as the cost of post-quantum signatures inside a ledger needs measurement, the work moves there; see the page on post-quantum signature performance.

The standards themselves are settled enough to plan against. NIST finalized ML-KEM, ML-DSA and SLH-DSA in FIPS 203, 204 and 2053, and distributed ledgers are among the systems most affected because every transaction carries a signature. That is why this page links to our distributed ledger and decentralised identity work, where signature schemes and key rotation are design decisions rather than background settings.

Frequently asked questions

When will a cryptographically relevant quantum computer exist?

Nobody can say with confidence, and planning should not depend on a forecast. Public bodies have instead set migration deadlines: the UK NCSC targets completed migration by 20355, and NIST's draft transition plan proposes disallowing quantum-vulnerable algorithms after 20354. Because large migrations take years and recorded data can be decrypted later, organizations with long-lived secrets start now regardless of the eventual date.

Is post-quantum migration only a concern for governments and banks?

No. Any organization that relies on TLS, VPNs, code signing, certificates or digital signatures uses the algorithms a capable quantum computer would break. Urgency differs: sectors holding long-lived confidential data or shipping long-lived devices should move first, while others can follow vendor upgrades more closely. The inventory step tells you which group you are in.

Can our existing hardware security modules and key stores run post-quantum algorithms?

It depends on the vendor, the model and the firmware version, so it has to be checked rather than assumed. Record the supported algorithms of each HSM and key-management service in your cryptographic inventory, ask suppliers for firmware roadmaps covering ML-KEM and ML-DSA, and treat hardware that cannot be upgraded as a replacement item in the migration plan.

Do we need quantum specialists on staff before starting either track?

Not for the first steps. A cryptographic inventory is security engineering, PKI and procurement work. Screening an optimization problem needs operations research skills and an honest classical baseline. Quantum-specific expertise becomes necessary when formulating and running prototypes on simulators or hardware, which is the part most organizations source externally at first.

How does this page differ from ColdAI's frontier technologies practice?

The frontier technologies practice decides which emerging technologies deserve investment across extended reality, brain-computer interfaces, smart-city IoT and quantum. This page covers quantum specifically: how to screen and prototype quantum methods, and how to plan the post-quantum cryptography migration that applies whether or not quantum computing becomes useful to you.

Sources

  1. Quantum Computing: prepare for quantum on two fronts — ColdAI
  2. Frontier R&D: research areas and engagement approach — ColdAI
  3. NIST Releases First 3 Finalized Post-Quantum Encryption Standards — National Institute of Standards and Technology
  4. NIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography Standards — National Institute of Standards and Technology
  5. Timelines for migration to post-quantum cryptography — National Cyber Security Centre (UK)
  6. What is Amazon Braket? — Amazon Web Services
  7. Post-Quantum Cryptography project — NIST Computer Security Resource Center
  8. Quantum-Readiness: Migration to Post-Quantum Cryptography (factsheet) — CISA, NSA and NIST

Connect the architecture

The next connection.

Explore the complementary capabilities that can turn an individual technology into a complete workflow.

Your next move

Bring us the
real problem.

A workflow that takes too long. A system that cannot connect. An idea that needs a technical path. Start there, and we can define what to investigate, build and measure.

  • A computational problem worth testing
  • A view of the systems that use encryption
  • Security and architecture owners
See how we approach delivery
Where are you starting?

Opens your email app with an editable brief. Nothing is sent until you send it.

shayan@coldai.org