Table of Contents

The post-quantum cryptography patent landscape has shifted more in the last two years than in the whole decade before it. When NIST finalized its first three quantum-resistant standards in August 2024, it converted a research field into a procurement mandate — and a wave of filing, licensing and freedom-to-operate questions followed. For any company building or buying quantum-safe encryption, the patent record is now the difference between shipping a product and drafting around someone else’s claim. This page maps what the landscape shows, who owns what, the deadlines forcing the market, and how to read the filing record before you commit an engineering budget.
What the Post-Quantum Cryptography Patent Landscape Shows in 2026
The post-quantum cryptography patent landscape in 2026 is defined by a single inflection point: the migration off RSA and elliptic-curve cryptography onto quantum-resistant algorithms is no longer optional or theoretical. Once NIST published usable standards, every vendor of security hardware, TLS libraries, HSMs, VPNs, payment rails and identity systems acquired a reason to file — both to protect implementation advantages and to stake ground in a field that is being rebuilt from the cryptographic primitive up.
Three characteristics separate this landscape from a normal software-security field. First, the underlying mathematics is public and standardized, so the patentable novelty sits in implementation, acceleration, side-channel protection and integration — not in the algorithm itself. Second, a meaningful share of the foundational academic work is already patented, which is why NIST had to negotiate licenses before it could publish. Third, the filing curve is being pulled forward by hard government deadlines rather than market demand alone, which compresses the timeline in which white space stays open.
Reading this landscape well means separating the three layers — standardized primitive, patented implementation, and integration into a product — because the freedom-to-operate risk lives almost entirely in the second and third.
Why the Filing Surge Started: NIST’s 2024 Standards
The surge has a precise trigger. On 13 August 2024 NIST released three finalized post-quantum standards: FIPS 203 (ML-KEM), a module-lattice key-encapsulation mechanism derived from CRYSTALS-Kyber; FIPS 204 (ML-DSA), a lattice-based digital-signature algorithm derived from CRYSTALS-Dilithium; and FIPS 205 (SLH-DSA), a stateless hash-based signature scheme derived from SPHINCS+. NIST urged administrators to begin integrating them immediately, warning that “full integration will take time.”
The standard set kept growing. NIST has said a fourth signature standard, FIPS 206 (FN-DSA, based on Falcon), is forthcoming, and in March 2025 it selected HQC — a code-based rather than lattice-based scheme — as a backup key-encapsulation mechanism, deliberately diversifying the mathematical basis of the portfolio. For a patent analyst, each new standard is a fresh magnet for implementation filings: hardware accelerators, constant-time software, fault-injection defenses and hybrid classical-plus-PQC constructions.
The macro backdrop amplifies the effect. WIPO reported roughly 3.7 million patent applications filed worldwide in 2024, a fifth consecutive year of growth, and PCT filings reached 275,900 in 2025. Post-quantum cryptography is a fast-growing sliver of that flow, and because patents publish 18 months after filing, the 2024–2025 surge is only now becoming visible in the public record.
The Patent Ownership Problem NIST Had to Solve
The most important fact in the whole post-quantum cryptography patent landscape is that the flagship standard was not patent-free when it was chosen. Foundational lattice work — notably patents associated with Gaborit and Aguilar-Melchor, controlled by French research institutions including CNRS, alongside a separately held US portfolio — raised a real question about whether implementers of ML-KEM could be sued.
NIST resolved it with intellectual-property engineering, not just cryptographic engineering. It secured two royalty-free patent license agreements covering ML-KEM: one for the US-held portfolio and one for the French portfolio. Under both, the licensors agreed, on a royalty-free basis, to place any right of enforcement into abeyance against implementers and end-users of the CRYSTALS-Kyber / ML-KEM algorithm.
The catch matters as much as the concession. As commentators have stressed, the NIST agreements neutralize the specific licensed portfolios but are not a blanket freedom-to-operate for every ML-KEM product. A hardware accelerator, a side-channel countermeasure or a novel integration can still read on a third party’s implementation patent that has nothing to do with the two licensed families. That is exactly why a landscape read and an FTO search remain necessary even for a standardized algorithm — the standard is licensed; your implementation of it is not.
Where the Filing Is Concentrating: Algorithms, Assignees, Sectors
Where is the filing actually concentrating? Three lenses matter.
- By algorithm. Lattice-based schemes dominate because they underpin the two primary standards (ML-KEM and ML-DSA); the patentable surface is implementation — number-theoretic transform hardware, polynomial multiplication, key/ciphertext compression and constant-time execution. Hash-based (SLH-DSA) and code-based (HQC) work forms smaller but distinct clusters that a diversifying filer should watch.
- By assignee. Independent landscape reporting describes activity led by large electronics and semiconductor firms — with Japan’s Toshiba prominent and several Chinese institutions among the most active applicants — alongside a rising cohort of financial and cloud filers. Wells Fargo, for example, has been granted US post-quantum cryptography patents, a signal that regulated end-users are filing defensively, not just security vendors.
- By sector. Finance is moving first because of the ‘harvest now, decrypt later’ threat — DHS, the UK NCSC, ENISA and Australia’s ACSC have all issued guidance premised on adversaries collecting encrypted traffic today for future decryption. HSBC, BT and Toshiba ran the first bank trial of quantum key distribution on the London quantum-secure metro network, and more than a dozen global banks now run quantum-readiness programs.
The practical read: a challenger should benchmark inside the specific sub-cluster it files in — lattice accelerator IP is a different competitive field from hash-based signatures or protocol-integration patents — not against a headline ‘post-quantum’ count that blends unrelated inventions.
The Deadlines Forcing the Market: 2030, 2033 and 2035
What turns this from an interesting field into an urgent one is a stack of government deadlines that give filers and buyers a countdown.
- NIST IR 8547 (initial public draft, Nov 2024). It signals that RSA-2048 and ECC-256 should be deprecated by 2030 and disallowed after 2035 for federal systems and the organizations that handle federal data. Deprecated means discouraged and flagged as risk; disallowed means no longer permitted.
- NSA CNSA 2.0. New National Security Systems acquisitions are expected to support quantum-resistant algorithms from 1 January 2027, with required transition dates across categories landing in the 2030–2033 window.
- The commercial knock-on. Federal deprecation dates propagate through supply chains: any vendor selling into government, defense, finance or critical infrastructure inherits the timeline whether or not it is a federal contractor.
For patent strategy the implication is blunt: the white space in the post-quantum cryptography patent landscape has a shelf life. An implementation cluster that is thin today will be crowded well before the 2030 deprecation date, because every serious vendor is filing against the same clock. A landscape read that arrives after the R&D commitment documents a missed window; one that arrives before it directs the spend.
How to Read the Landscape Before You File or Build
Before you file a priority application or ship a quantum-safe product, the landscape has to be read at the layer where risk actually lives. A disciplined read answers four questions:
- What is standardized versus patented? The algorithm (ML-KEM, ML-DSA) is standardized and, for the two licensed families, royalty-free; your acceleration, side-channel and integration techniques are not automatically clear.
- Where is filing momentum, not just volume? Priority-year trend by sub-cluster shows which doors are closing. Cumulative counts hide the fact that a specific lattice-accelerator or hybrid-protocol niche may still be open.
- Who owns the adjacent implementation claims? Benchmarking the specific assignees in your sub-field — then setting a monitoring watch — converts a static map into an early-warning system as the field accelerates toward the deadlines.
- What is the freedom-to-operate exposure? A focused FTO search against live, in-force implementation patents is the step the NIST license agreements do not substitute for.
Done in that order, the landscape stops being a headline number and becomes a filing plan: where to build, how fast, and what to clear first.
What You Receive
- A filing-trend analysis of post-quantum cryptography — application momentum by year and by algorithm family (lattice, hash-based, code-based), corrected for the 18-month publication lag
- Top-assignee benchmarking — electronics and semiconductor leaders versus financial and cloud filers, benchmarked inside the sub-cluster you actually file in
- A technology-cluster map — NTT/polynomial-multiply hardware, side-channel countermeasures, key/ciphertext compression, hybrid classical-plus-PQC and protocol integration
- A freedom-to-operate readout on ML-KEM and ML-DSA implementations — what the NIST royalty-free licenses cover, and the third-party implementation patents they do not
- A deadline-aware white-space shortlist — the thin, defensible veins that are still open before the 2030 deprecation date closes them
Data Sources & References
This analysis draws on primary patent and market data:
- NIST — First 3 Finalized Post-Quantum Encryption Standards (13 Aug 2024) — FIPS 203 (ML-KEM, from CRYSTALS-Kyber), FIPS 204 (ML-DSA, from CRYSTALS-Dilithium) and FIPS 205 (SLH-DSA, from SPHINCS+) finalized; FIPS 206 (FN-DSA/Falcon) forthcoming; administrators urged to integrate immediately.
- NIST — Post-Quantum Cryptography: IPR / License Summary — NIST secured two royalty-free patent license agreements for CRYSTALS-Kyber / ML-KEM (a US portfolio and a French portfolio), with enforcement placed into abeyance against implementers and end-users.
- NIST IR 8547 (ipd) — Transition to Post-Quantum Cryptography Standards — Initial public draft (Nov 2024) signaling RSA-2048 and ECC-256 deprecated by 2030 and disallowed after 2035 for federal systems and organizations handling federal data.
- NSA — Commercial National Security Algorithm Suite 2.0 (CNSA 2.0) — New National Security System acquisitions expected to support quantum-resistant algorithms from 1 Jan 2027, with required transition dates in the 2030-2033 window.
- WIPO — World Intellectual Property Indicators 2025 (Patents Highlights) — About 3.7 million patent applications filed worldwide in 2024 (+4.9%), a fifth consecutive year of growth, with Asia driving the increase.
Request a Post-Quantum Cryptography Patent Landscape Read
Map the filing record, benchmark the assignees in your sub-cluster, and get an FTO-aware white-space shortlist before you commit an engineering budget.
Request a Post-Quantum Cryptography Patent Landscape Read
Related PerspireIP work: Cybersecurity Patent Landscape · Quantum Computing Patent Landscape · Freedom-to-Operate Analysis · Post-Quantum Cryptography Patent Analysis Case Study.
Frequently Asked Questions
What is a post-quantum cryptography patent landscape analysis?
It is a structured read of the patent record for quantum-resistant cryptography — filing trends by algorithm family, top-assignee benchmarking, a technology-cluster map and a freedom-to-operate readout — used to decide where to file, how fast, and what to clear before building a quantum-safe product.
Is ML-KEM (CRYSTALS-Kyber) free to use?
The algorithm is standardized as FIPS 203, and NIST secured two royalty-free patent license agreements — a US portfolio and a French portfolio — that place enforcement into abeyance for implementers. Those licenses are not a blanket freedom-to-operate: a specific hardware or side-channel implementation can still read on a third party’s patent, which is why an FTO search still matters.
Why did post-quantum patent filing surge after 2024?
NIST finalized FIPS 203, 204 and 205 on 13 August 2024, turning a research topic into a procurement requirement. Every vendor of security hardware, libraries and protocols gained a reason to file on implementation techniques, and government deadlines added a countdown.
What deadlines are driving the market?
NIST IR 8547’s draft signals RSA-2048 and ECC-256 deprecated by 2030 and disallowed after 2035, while NSA’s CNSA 2.0 expects new national-security acquisitions to support quantum-resistant algorithms from 2027, with required dates in 2030-2033.
Which algorithm families dominate the filings?
Lattice-based schemes lead because ML-KEM and ML-DSA are the primary standards; the patentable surface is implementation (accelerators, compression, side-channel defenses). Hash-based SLH-DSA and code-based HQC form smaller, distinct clusters worth watching for a diversifying filer.
How is this different from a general cybersecurity patent landscape?
A cybersecurity landscape spans network defense, endpoint, identity and detection. The post-quantum cryptography patent landscape is a narrower, faster-moving sub-field built on standardized primitives, where the risk sits in implementation and integration patents rather than the algorithm itself. It interlinks with our broader cybersecurity and quantum-computing landscape work.