The PQC market is the fastest-growing sub-sector in cybersecurity.
A regulatorily-mandated, BFSI-anchored, multi-source-confirmed 38–46% CAGR category — with the largest U.S. and EU financial institutions already deploying production systems.
Five reputable analyst houses converge on the same picture.
Triangulating across MarketsandMarkets, Grand View, Mordor, SNS Insider, and Fortune Business Insights, the PQC software + services TAM is $0.42–1.58B in 2025 growing to $2.8–7.8B by 2030, with a base-case CAGR of 38–46%.
| Source | 2024 / 2025 | 2030 / 2033 | CAGR |
|---|---|---|---|
| MarketsandMarkets (Oct 2025) | $0.42B (2025) | $2.84B (2030) | 46.2% |
| Grand View Research | $1.58B (2025) | $7.82B (2030) | 37.6% |
| Mordor Intelligence | $0.88B (2025) | $4.60B (2030) | 39.2% |
| SNS Insider | $1.35B (2025E) | $22.68B (2033) | 42.3% |
| Fortune Business Insights | $0.27B (2025) | $2.26B (2034) | 26.5% |
The single largest buying vertical is exactly the one whose buyers write the cheque.
MarketsandMarkets explicitly states that BFSI will account for the largest share of PQC spend through 2030. This is critical: it is the same vertical — banks, custodians, payment networks — whose boards are simultaneously sanctioning billion-dollar acquisitions in tokenized money and stablecoins.
Standards are no longer a recommendation. They are a deadline.
NIST finalizes FIPS 203 / 204 / 205
ML-KEM (Kyber), ML-DSA (Dilithium), SLH-DSA (SPHINCS+) ratified. The "PQ" stack is now an official, deployable, standards-track family.
CNSA 2.0 begins · ETSI hybrid standard · Apple PQ3 in production
NSA CNSA 2.0 mandates PQC in NSS software/firmware. ETSI publishes TS 104 015 (hybrid KEX). Apple ships PQ3 in iMessage. Microsoft, Google, AWS, Cloudflare deploy hybrid PQC TLS at scale.
CNSA 2.0 NSS-acquisition deadline
All new U.S. national-security system acquisitions must be CNSA 2.0-compliant by default. Defense contractors, critical infrastructure, and federally regulated banks move first.
Classical PKC deprecation target
NIST, NSA, and ASD recommend deprecation of classical public-key cryptography. Hybrid mode becomes table-stakes; PQC-only deployments reach double-digit share across Fortune 1000.
CNSA 2.0 classical algorithms disallowed in NSS
The final hard cutover. RSA, ECDSA, DH, ECDH no longer permitted in any U.S. national-security system. International alignment follows.
The threat is already active.
Adversaries are intercepting and storing today's encrypted data with the explicit intent of decrypting it once a cryptographically-relevant quantum computer (CRQC) is available. For data with multi-decade confidentiality — defense, medical, IP, financial records, KYC — the migration is overdue today, not in 2030.
This is why even late-moving CISOs are running 7- to 8-figure PQC migration programs, and why 5% deployment in 2025 expands to ~80% by 2030 — the buyers do not have the luxury of waiting.
What this means for the domain
- Category is mandated, not optional. Procurement teams are now writing PQ- prefixes into RFPs.
- The "pq" prefix is the de facto shorthand in NIST, ETSI, NSA, BSI, ANSSI, BIS documentation.
- The .com is the only procurement-grade TLD for BFSI, defense, and regulated enterprise buyers.
- First-mover brand wins the category. A Fortune 500 brand-defining acquisition in 2026 is 3–5 years ahead of any challenger.
See who's already deploying.
Fortune 1000 PQC adoption is not theoretical — it's running in production at JPMorgan, HSBC, Google, Apple, and Microsoft.