← Back to the full report
Strategic Technology · Strategic Risk · 2026 Free Edition

Q-Day India

India has roughly four years before exogenous deadlines - CNSA 2.0 (2030-2033), SWIFT’s migration programme, Quad interoperability - force a national post-quantum migration. A country that cannot guarantee the confidentiality of its own strategic communications has ceded a core function of statehood.

Published 02 Aug 2026Domain Strategic TechnologyReading time ~7 minEdition Free - 152 pagesAuthor Techadyant Labs · Research
Q-Day India report cover
Free edition cover · 152 pages · Strategic Risk 2026
01

The Thesis

India is a cryptographic superpower on borrowed infrastructure. Aadhaar authenticates 1.4 billion residents, UPI processed 134 billion transactions in 2025, and GSTN, RTGS, the e-Rupee and defence C2 networks all rest on RSA and elliptic-curve cryptography that a sufficiently large quantum computer breaks. Beneath them, the trust infrastructure itself is imported: 92% of HSMs, the crypto libraries, the entropy sources. The migration to post-quantum cryptography is therefore not an IT project - it is a sovereignty event, and India is the only Quad member without a published national roadmap for it.

02

Key Numbers

~4 years
to the CNSA 2.0 preferential deadline (2030); final deadline 2033 - then Quad interop makes it de facto binding on India
Ch 2 / Ch 4 - Verified
92% / <8%
foreign-sourced HSM installed base / domestic share; Thales alone ~34%
Ch 3 - Verified
87%
of national HND-vulnerable traffic sits in four sectors: defence C2, BFSI, telecom backbone, government digital
Exposure model - Ch 1
1.4B / 134B
Aadhaar identities / UPI transactions (2025) - both protected by quantum-vulnerable RSA and ECC
Ch 3 - Verified
₹15,500 cr
projected domestic PQC market by 2033; unlocked by ₹8,500-11,000 cr of cumulative investment
Market model - Ch 13
10-18%
probability of a cryptographically relevant quantum computer by 2029; modal Q-Day estimate 2031-2035
Expert survey - Ch 1
03

Key Findings

The harvest is already happening

Harvest-now-decrypt-later is present tense, not a future risk: adversaries are capturing encrypted Indian government, defence and banking traffic today. A CRQC arriving in 2033 retroactively compromises data harvested in 2026. Biometric templates, defence C2 transcripts and sovereign records carry decade-scale confidentiality horizons.

[Ch 1 / Ch 3 - Verified]

The trust infrastructure is 92% imported

India’s HSM installed base is 92% foreign-sourced - Thales ~34%, Entrust and Utimaco the rest. Crypto libraries and entropy sources are imported too. A single-vendor displacement event during the migration window would halt BFSI and government HSM refresh for 12-18 months.

[Ch 3 / Ch 10 - Verified]

Four sectors carry 87% of the exposure

Defence C2 networks, banking and capital markets, the telecom backbone and government digital infrastructure account for an estimated 87% of national HND-vulnerable traffic. Healthcare and power face high-band exposure (70-78%) through long-life records and SCADA systems.

[Exposure model - Ch 1]

No mandate, no roadmap, no industry

As of January 2026 India is the only Quad member without a published national PQC roadmap. Domestic industry employs under 1,500 crypto engineers; startups hold under ₹150 crore of cumulative funding; the IT Act, DPDP Act, CERT-In directions and RBI guidelines nowhere reference PQC.

[Ch 3 / Ch 8 / Ch 9 - Verified]

Defence interop is a 2030 binding requirement

CNSA 2.0 interoperability with US INDOPACOM systems is a 2030 binding requirement for joint-operational infrastructure. The Tactical Communication System, Air Defence Grid and Naval ACOTS networks carry multi-decade-confidentiality traffic and must adopt PQC-agile architectures by 2028.

[Ch 4 - Verified]

The base case is Drift - until policy fires

Without aggressive 2026 policy action, the Drift pathway dominates through 2028: compliance without sovereignty, foreign-controlled stack, HND exposure through the 2030s. With the recommended mandate set, Sovereign-Leap rises from 10% to 65% probability and becomes modal by 2031.

[Scenario model - Ch 14]
04

The Framework

The report’s analytical core is a layered national cryptographic stack map - applications, protocols, libraries, HSMs and entropy sources - scored for HND exposure and sovereignty. A sectoral exposure model quantifies vulnerable traffic (87% in four sectors); a market-sizing cascade (TAM → SAM → SOM) sizes the domestic opportunity; a scenario model projects Sovereign-Leap, Catch-Up and Drift probabilities to 2033; and a five-pillar implementation roadmap sequences the 2026-2033 migration against CNSA 2.0, SWIFT and Quad deadlines. Every claim carries a confidence rating and every model a documented assumption set in the methodology section.

PQC deadline stack timeline 2026 to 2033 with Q-Day modal window 2031 to 2035
Figure 1 - The deadline stack: exogenous deadlines (2027-2033) converge before the modal Q-Day window (2031-2035) opens.
HND exposure: four sectors carry 87 percent of national vulnerable traffic, healthcare and power 70 to 78 percent
Figure 2 - HND exposure: 87% of national vulnerable traffic in four sectors; healthcare and power at 70-78% via long-life records and SCADA.
India PQC market 2033: BFSI 3200-4100, Aadhaar UPI 2800-3500, middleware 2500-3500, services 3000, HSM 1200-1800 crore
Figure 3 - The 2033 market: ~₹15,500 cr total, with the BFSI migration and the Aadhaar/UPI retrofit as the two largest programmes.
Scenario probability trajectories 2026 to 2033: Drift 50 to 10, Catch-Up 40 to 25, Sovereign-Leap 10 to 65 percent
Figure 4 - Trajectories: with the recommended policy set notified in 2026, Sovereign-Leap rises from 10% to 65% and becomes modal by 2031.
India HSM installed base: 92 percent foreign today, 35 percent domestic target by 2030
Figure 5 - The HSM build-out: from 92% foreign (Thales ~34%) to a 35% domestic share by 2030 under PLI and strategic-preferential procurement.
05

What It Means

For the Government of India: the absence of a national PQC mandate is the single largest strategic gap in the country’s cybersecurity posture. A mandate notified in 2026 unlocks an estimated ₹8,500-11,000 crore of compliance-driven private-sector investment through 2033.

For the Reserve Bank of India: BFSI faces the highest absolute migration cost (₹3,200-4,100 crore over 2027-2033) but has the clearest regulatory template. The CBDC track is the leapfrog: a PQC-native e-Rupee by 2028 makes India the first major economy with a quantum-safe sovereign digital currency.

For the Ministry of Defence: CNSA 2.0 interoperability with US, UK, Australian and Japanese systems is a 2030 binding requirement. TCS, the Air Defence Grid and Naval ACOTS networks must adopt PQC-agile architectures by 2028, with sovereign-preferential procurement for crypto hardware.

For boards and CISOs: PQC migration is a capital-expenditure programme with a hard external deadline, not an R&D line item. Treat 2030 as the operational compliance year and 2033 as absolute; the cost-of-delay premium is an estimated ₹3,500-4,000 crore for the BFSI sector alone.

For investors: the Indian PQC market sits at the inflection point Indian cybersecurity occupied in 2015. Capital deployed in 2026-2028 - in HSMs, crypto-agility middleware and integration services - compounds at venture-grade returns through 2033.

06

The Numbers, Tabulated

2033 scenarios with 2026 and 2033 probabilities and outcomes
Scenario2026 probability2033 (with policy)Outcome
Sovereign-Leap10%65%Domestic PQC stack, 35% domestic HSM, third pole of global capability by 2033
Catch-Up40%25%PQC adopted broadly, but on foreign technology - compliance without sovereignty
Drift50%10%CNSA 2.0 window missed; HND exposure through the 2030s; forced migration crisis mid-decade
Five pillars of the Sovereign-Leap pathway
PillarActionDeadline
National PQC MandateMeitY notification with RBI, MoD, TRAI and MoP directions2026; phased 2027 / 2030 / 2033
Sovereign PQC StackCDAC + DRDO with startups and IT incumbents - production KEM, signature, HSM, key orchestrationProduction by 2028
Domestic HSM build-outPLI + strategic-preferential procurement; domestic share 8% to 35%By 2030
Crypto-agility retrofitAadhaar, UPI, CBDC, GSTN, defence C2, telecom backbone, SCADA2027-2031
Talent and standardsDouble PQC-trained crypto engineers every two years (15,000 by 2033); NIST, IETF, ISO JTC1 SC27, TSDSI representationContinuous to 2033

Migration cost centres: BFSI ₹3,200-4,100 cr; Aadhaar + UPI retrofit ₹2,800-3,500 cr; crypto-agility middleware ₹2,500-3,500 cr cumulative; integration services ~₹3,000 cr by 2033. Domestic PQC industry employs fewer than 1,500 crypto engineers today; Sovereign-Leap needs ~7,500 by 2030 and 15,000 by 2033.

07

What to Watch

  • 2026
    National PQC Mandate expected - unlocks an estimated ₹8,500-11,000 cr of compliance-driven private-sector investment through 2033.
  • 2027
    New systems PQC-only; BFSI HSM replacement cycle begins (₹3,200-4,100 cr through 2033); Aadhaar and UPI crypto-agility retrofit funded (₹2,800-3,500 cr).
  • 2028
    Sovereign stack production (CDAC/DRDO); a PQC-native e-Rupee makes India the first major economy with a quantum-safe sovereign digital currency; defence systems PQC-agile.
  • 2029
    Quad PQC interoperability formalises into a treaty-grade arrangement with India as designated third pole; CRQC by this year is 10-18% probable.
  • 2030
    CNSA 2.0 preferential deadline; defence interop binding; domestic HSM share at the 35% target.
  • 2033
    The verdict: Sovereign-Leap (₹15,500 cr market, 15,000 engineers, third pole) or Drift (foreign-controlled stack, secrets in foreign HSMs).
08

Frequently Asked Questions

What is Q-Day and when is it?

Q-Day is the date a cryptographically relevant quantum computer becomes operational - one large enough to run Shor’s algorithm and break RSA-2048 and ECC-P256 in operationally relevant time. The modal expert estimate is 2031-2035, squarely inside the CNSA 2.0 compliance window; a CRQC by 2029 is non-trivially probable (10-18%).

What is harvest-now-decrypt-later?

An adversary intercepts and stores encrypted traffic today, then decrypts it once a CRQC becomes available. Because long-life data - biometric templates, defence command-and-control transcripts, sovereign bond documentation - has a confidentiality horizon measured in decades, HND makes PQC migration urgent before Q-Day, not after it. A CRQC in 2033 retroactively compromises traffic harvested in 2026.

What does India actually need to migrate?

Everything on RSA, ECDSA and ECDH: Aadhaar (1.4 billion identities), UPI (134 billion transactions in 2025), GSTN, RTGS, the e-Rupee CBDC, defence C2 networks and the telecom backbone. Beneath the applications, the trust infrastructure itself - HSMs (92% foreign), crypto libraries and entropy sources - is imported and must be replaced with PQC-capable, preferably sovereign, components.

What are the hard deadlines?

CNSA 2.0: 2025 software/firmware signing, 2030 preferential, 2033 final. SWIFT has run a PQC migration programme since 2024. Quad interoperability makes 2033 a de facto deadline for any Indian defence, intelligence or financial-messaging system touching US, UK, Australian or Japanese infrastructure. The report recommends Indian phases aligned to these: 2027 new systems, 2030 critical infrastructure, 2033 all regulated systems.

What would Sovereign-Leap cost and return?

Roughly ₹8,500-11,000 crore of cumulative investment through 2033 across government, regulated industry and private capital - against a domestic PQC market estimated at ₹15,500 crore by 2033 (about US$1.8B, with a 53% sovereign-fit capture yielding a ~US$950 million domestic opportunity). The strategic return is measured in sovereignty, not P&L: ownership of the cryptographic stack that protects Indian defence, financial and identity infrastructure through the post-quantum century.

What should an organisation do now?

Four actions in 2026: build a cryptographic inventory (algorithms, keys, HSMs, vendors); classify long-life data by confidentiality horizon; mandate crypto-agility for all new systems so primitives can be swapped without re-architecting; and plan HSM refresh with PQC-capable paths. Boards should treat 2030 as the operational compliance year and 2033 as absolute.

09

Sources & Methodology

Derived from the Q-Day India free edition, Strategic Risk 2026. Forward claims carry confidence ratings; model assumptions are documented in the Methodology section. Primary sources:

  1. NIST FIPS 203 (Kyber), 204 (Dilithium), 205 (SPHINCS+) - August 2024 [Verified]
  2. NSA CNSA 2.0 deadlines (2025 / 2030 / 2033); NCSC, ASD and NISC parallel roadmaps [Verified]
  3. SWIFT PQC migration programme (since 2024); RBI cyber-security framework; CERT-In directions (April 2022); DPDP Act 2023; MeitY NQM documents [Verified]
  4. Expert consensus surveys - ETSI, Global Risk Institute, NIST PQC forum; peer-reviewed quantum-roadmap literature 2024-2025 [Estimate]
  5. Industry disclosures - Thales, Entrust, Utimaco, PQShield, ISARA, Crypto4A; QNu Labs, BosonQ Psi, DataGrid; TCS, Infosys, Wipro, HCL [Verified]
  6. Techadyant Labs exposure, market-sizing, scenario and roadmap models [Model]

Read the full methodology and scoring rubrics →

Q-Day India - Free Edition

Free · 152 pages

The complete strategic-risk report - 17 chapters, 40 figures, sector deep-dives on defence, BFSI, telecom and government, plus the startup, policy, funding and supplier directories.

Download the full report (PDF)Open the report page

What’s inside

The Q-Day threat from theoretical to operational · global migration mandates and 2026-2033 deadlines · India’s cryptographic posture · four sectoral deep-dives · the PQC ecosystem · policy and regulatory framework · supply-chain vulnerabilities · the sovereign-security opportunity · the 2026-2033 implementation roadmap.