Megatrend · Quantum Computing

The one quantum business actually making money today — even though the machine isn't here yet

Almost the entire quantum field is still a "promise" — even world-class hardware companies like IonQ and Quantinuum lose hundreds of millions of dollars a year, because a genuinely useful quantum computer is still far off. But there's one corner of this trend that already has "real orders, real money" coming in — and the funny part is, it makes money because of the threat from a machine that isn't even built yet. This is the story of the "shovel sellers" in the quantum gold rush.

Category Quantum Computing Level Sub-theme Maturity early revenue starting to come in (early revenue) Read time ~12 min
A miner stands selling shovels and picks to a crowd running toward a distant gold mine that hasn't been struck yet — and the shovel seller is the only one with pockets full of coins.
ภาพประกอบ (hero.png)
The shovel sellers of the gold rush. While everyone runs toward the quantum "gold mine" that hasn't been struck yet, the one actually pocketing money is the one selling the tools to guard against that mine.

01What it is — from the quantum field's point of view

When we talk about the "quantum megatrend," most people picture a strange computer in a super-cold room that will one day solve problems no supercomputer can. That's right — but that machine isn't here yet, and no one knows when it will arrive (see the parent lesson Quantum Computing, bluntly titled "the race no one has won").

But the quantum field has one node that flips the whole story — instead of waiting for the machine to succeed before making money, it makes money because that machine is coming. That node is Quantum-Safe / Post-Quantum Cryptography (PQC), or "encryption that resists quantum."

Here's why: a quantum computer big enough could "crack" the encryption that locks the entire internet today (RSA/ECC) in an instant. That threat forces the whole world to swap its keys for a new kind of code that even quantum can't break — starting today. And a worldwide swap means someone has to pay right now.

Which angle this lesson tells it from We dig deep into "how the new codes work / NIST / the countdown clock" from the cybersecurity angle, over at Post-Quantum & Cryptographic Trust · this chapter tells it from the quantum angle — why PQC is the "flip side" that actually makes money in the quantum megatrend, while the rest of it is still burning cash.
Key terms
Quantum-safe / Post-quantum (quantum-resistant)

It means a new generation of encryption algorithms built on a different kind of math from the old ones (like lattice-based), which neither ordinary computers nor quantum ones can solve — in August 2024, the U.S. NIST officially announced the world's first standards (FIPS 203/204/205) after an 8-year selection. This is the "real thing" that manufacturers can already put into products and sell.

02Why it's the only quantum making money today

The best way to understand PQC from the quantum angle is to set it next to its "siblings" in the same trend and look at the bottom line.

In 2025, the most famous quantum-hardware companies on the stock market are still burning enormous amounts of cash — IonQ became the first in the group to top $100 million in revenue, but lost over half a billion dollars for the year. Quantinuum (a Honeywell subsidiary that just IPO'd) had only $30.9 million in annual revenue but a net loss of $192.6 million — nearly 6× more loss than revenue — and poured $165 million into R&D, 5× its full-year sales. This group is still "pre-profit," and the stock prices move on hope-filled news, not on results.

Quantum industry's problem: little revenue, enormous losses (2025)
Revenue vs. net loss of quantum-hardware companies (millions of dollars)
Source: company earnings reports / ad-hoc-news, TechTimes (FY2025) — the quantum-hardware group is still "pre-profit"

Now look at PQC. SEALSQ (part of WISeKey), which makes quantum-resistant chips, reported 2025 revenue of $18.3 million, up 66% from the prior year. And more importantly — after launching its QS7001 chip in late 2025, it has a "revenue pipeline" of $49.8 million already booked for 2026–2028, up from ~$11.4 million the year before. These are real orders, not R&D money burned away.

This difference isn't a coincidence — it's structural: quantum hardware makes money only once the machine succeeds (which may be 5–10 years out, or longer). But PQC makes money because the threat already exists today — and the law forces organizations to act before the machine arrives. That makes it one of the few parts of the quantum field where demand is a "must buy," not a "want to buy."

$49.8M the value of orders/pipeline that SEALSQ has already booked for its quantum-resistant QS7001 chip in 2026–2028 — while the whole quantum-hardware group still loses billions combined. This is what "revenue you can actually count" looks like in a trend that's mostly still hope.

03How it works: a future threat that forces you to migrate now

The mechanism that lets PQC "make money from the future starting today" comes down to a single storyline: because the threat can't wait, the migration can't wait either.

Today, almost everything on the net — passwords, bank transactions, medical records, state secrets — is locked with the same math (RSA/ECC) that's "hard" for ordinary computers but will be "easy" for a big enough quantum computer in the future. The problem is that the adversary doesn't wait — they intercept and stockpile your encrypted data today, waiting to decrypt the whole pile at once the day the machine is ready (called "Harvest Now, Decrypt Later" — we unpack this mechanism in detail in the Post-Quantum & Cryptographic Trust chapter).

The business consequence is exactly what makes this node special: if your data has to stay secret for 10–30 years and the machine arrives in ~10, that means you're already too late if you haven't started swapping keys. So organizations have to migrate from old codes to quantum-resistant ones right now — not wait for Q-Day. And that's the money flowing to PQC vendors and service providers starting now.

A future quantum threat forces the encryption system to migrate starting today The shadow of a future quantum computer makes the old RSA/ECC keys in use today unsafe, so organizations have to migrate to quantum-resistant PQC now, before the threat arrives Quantum computer (future ~2030–2035) 1 Old keys: RSA / ECC lock the entire internet today future quantum can crack them Migrate "now" — can't wait for Q-Day 2 New keys: PQC (quantum-resistant) NIST standards 2024 — ready to put into products and sell
A future threat = today's orders. The shadow of a quantum computer that isn't even finished makes the old keys expire ahead of schedule. So organizations have to buy and install "quantum-resistant keys" right now — and that's the revenue PQC actually collects.

So the heart of it, from the economic angle, is about "time": most trends sell when the technology is ready. But PQC sells because the risk exists before the technology is ready — it converts fear of the future into today's budget.

04Where it sits in the quantum field

Under the megatrend Quantum Computing, nearly every node is on the "machine-building side" — hardware, software, components, all betting on the day the machine succeeds. PQC is the one node on the "flip side" — it doesn't build the machine, it protects the world from the machine. And that makes its relationships with its siblings in the trend especially interesting:

  • Directly opposite the hardware side: the faster the machine-building side (Quantum Hardware — Pure-plays and the hyperscalers) advances, the more urgent PQC becomes — a sibling's success = its demand. It's one of the few cases where one technology "sells" to another the moment that other one makes progress
  • The partner often confused with Quantum Networking & QKD: both are on the "quantum security" side, but they're polar opposites — PQC is software/algorithm that runs on ordinary machines and rolls out worldwide via updates, while QKD is hardware that needs special fiber or satellites laid down. That's why the U.S. government chose PQC as the main path — it's far cheaper and easier to scale — and why PQC makes money before QKD
  • Handing off to Cybersecurity & Digital Trust: PQC's real business "home" is in the cybersecurity world — it's the deepest layer of trust. We dig into that angle (the code mechanism, NIST, government deadlines, the market) over at Post-Quantum & Cryptographic Trust
  • Converging with Semiconductors: the durable solution is to embed PQC "into the chip" from manufacture — because long-lived devices (cars, satellites, medical equipment) are hard to update later, which makes chipmakers key players

The angle that sums it all up best is this: in the "quantum gold rush," most people are digging for gold (building the machine). PQC is the shovel seller — it doesn't have to strike gold to get rich. As long as people believe the gold is real, that alone is enough to make the whole world buy shovels.

05Where things stand now + the players

2025–2026 is when PQC crossed from "an academic topic" to "real orders." And the one holding the stopwatch is the government. The U.S. security agency (NSA), under the CNSA 2.0 framework, ruled that starting January 1, 2027 all new procurement by security agencies must support quantum-resistant codes, gear that can't be upgraded must be retired by the end of 2030, and the whole system must be quantum-resistant by 2035. These deadlines are what turn "fear" into a "purchase order."

The market size reflects this clearly. The global PQC market is still small — about $0.4–1.4 billion in 2025 (research firms give different numbers because the market is brand new). But they agree it's growing fast: MarketsandMarkets puts it at ~$2.84 billion in 2030 at a CAGR of ~46%, while firms looking out to 2033–2035 give figures of $15–30 billion once you fold in the "migration market" (the services to survey and switch over systems) — adding that in multiplies the number several times over.

PQC market — small today, but fast-growing in the quantum field
market size (billions of dollars) — a midpoint across multiple firms; the market is brand new
Source: MarketsandMarkets (2030: $2.84B, CAGR ~46%), SNS Insider (2033: ~$22.7B, CAGR ~42%) — including the migration market

The standout feature of this arena, from the quantum angle, is this — the ones who actually pocket the money tend to be the incumbent giants in chips and security, not the small quantum pure-plays. Because PQC isn't a standalone new product, it's a "feature" that has to be embedded into key hardware, chips, and certificate systems that already have a customer base.

Key players in this field
Note
We arrange the players by their role in the PQC value chain (standards · chips · key hardware · certificates) rather than raw market cap — many of the key players in the certificate layer are still private companies off the stock market · not investment advice
Switzerland/U.S. · a pure-play with real revenue
Launched QS7001 in late 2025 — the first chip to embed NIST-standard PQC algorithms directly into hardware (for IoT and crypto wallets). 2025 revenue of $18.3 million (+66%), a pipeline of $49.8 million already booked for 2026–28, and around $220 million in cash — one of the few quantum pure-plays that can actually sell product.
core · pure-play (with revenue)
IBMIBM · US
U.S. · the standard's inventor + on both sides
Its Zurich research team developed 2 of the 3 NIST standards (ML-KEM & ML-DSA) — and the striking part is that IBM is on both the machine-building side (the threat side) and the side selling Quantum Safe services that migrate enterprise customers (the fix side) — collecting money both ways.
core · standard-setter
Netherlands · embedding PQC in chips
A leader in security chips (secure elements) in cards, passports, and cars — embedding PQC into silicon, because embedded devices last 10–20 years and have to be quantum-resistant from manufacture. This is where quantum converges with Semiconductors.
secondary · chip security
ThalesHO · FR
France · key-storage hardware
The market leader in HSMs (enterprise-grade safes for storing keys) — the new Luna HSM firmware already embeds ML-KEM/ML-DSA, so customers can upgrade to quantum-resistant right away. The "upgrade the installed base" model = revenue you can count.
secondary · HSM/crypto
Arqit/ Quantum eMotionARQQ · QNC · US/CA
UK / Canada · small challengers
Arqit sells quantum-resistant symmetric-key systems to government/defense (partnered with Intel and Equus), while Quantum eMotion makes true quantum random-number chips (QRNG) feeding blockchain and crypto-wallet systems — still early-stage, with small and highly volatile revenue.
core · pure-play (early-stage)
DigiCert/ Entrustprivate · US
U.S. · certificates/PKI
The two big players in the digital-certificate (PKI) layer that issue "ID cards" to websites and devices worldwide — the front line that has to issue quantum-resistant certificates. Both are private companies, so they're not on the stock market.
core · PKI (private)

From the investing angle told from the quantum side, the key point is this — small pure-play PQC stocks tend to "move on quantum news" as much as quantum-hardware stocks, but they're fundamentally different: a player like SEALSQ is starting to land real orders, while most hardware still has only hope. Telling these two apart is an essential skill for anyone playing the quantum trend.

06The road ahead

The first direction is a migration wave lasting a decade — and one that pays off no matter when the quantum machine arrives. This is what separates PQC from other quantum bets financially. Even if Q-Day slips another 5–10 years, the government deadlines (CNSA 2.0's 2027/2030/2035) still force organizations to spend. Every organization's first job is to "inventory its keys" — figure out which systems use which codes. It sounds dull, but it's an entire service business being born from scratch.

A long procession of servers and devices crossing a bridge from the old-key shore to the new quantum-resistant-key shore, with the shadow of a quantum computer waiting in the distance.
ภาพประกอบ (migration.png)
The bridge-crossing that pays today. The whole digital world has to move from old keys to quantum-resistant ones — a big, slow job that has to begin before the distant quantum shadow creeps in.

The second direction is embedding PQC into hardware upstream. SEALSQ's QS7001 chip is a signal that PQC's future isn't only in software but in silicon — because long-lived devices need to be quantum-resistant from the day they're made, and can't be updated later. This is where PQC will absorb value from the enormous volume of chips over the long run, and it's the true convergence point between quantum and Semiconductors.

The third direction is becoming a "matter of national sovereignty". China is building its own commercial cryptography supply chain in parallel with the international standards, which reflects encryption becoming a national-security matter — and that all but guarantees "state money" will keep flowing into PQC across many countries, not just the U.S.

07Challenges & risks

PQC really is the "quantum business making money today." But it has its own particular traps that anyone playing the quantum trend needs to watch.

The first risk is timeline uncertainty. No one in the industry knows for sure whether Q-Day arrives in 2030, 2035, or much later. But there's an important paradox here — even if Q-Day slips, the government deadlines still force the spending anyway. So PQC demand is cushioned by law more than quantum hardware, which only sells once the machine succeeds. That said, if news of quantum progress goes quiet for a long stretch, the urgency (and the budgets organizations are willing to pay early) could soften.

The second risk is the "early-stage bubble". Small pure-play PQC stocks tend to swing hard on any quantum news, even though their real revenue is still thin and highly volatile. The long-term value is more likely to land with the incumbent giants who embed PQC as a feature into a large customer base (chips, key hardware, certificates) than with newcomers selling just a "story" — the trap is confusing "a stock rising on the theme" with "a company with real orders."

The third risk is the cost and slowness of migration. The last algorithm switch (SHA-1 → SHA-256) took over 5 years even though it was far simpler. This time it's many times bigger. NIST itself warns the migration is running "slower than planned" — budgets may balloon and many organizations may miss the deadline. This slowness is both a risk (the threat is real) and an opportunity (service demand lasts longer).

The fourth risk is overlap with QKD and other alternatives. PQC isn't the only way to resist quantum — QKD (quantum key distribution) is a rival/complement in some cases. Even though PQC wins on cost and scale today, if the technology or the rules change, each path's share could shift. And the PQC standard itself is still "young" — there have been algorithms that made the NIST shortlist and were then dropped because someone found a way to break them, which is why the world is using a "double-layer (hybrid)" approach during the transition.

The bottom line for investors In the map of the quantum megatrend, PQC is the node that can make money today "from a future that hasn't arrived" — three keys: (1) it's the "shovel seller" whose demand is forced by government deadlines + the HNDL threat, so it's a "must buy," not a "want to buy," and it pays off even if Q-Day slips · (2) the real value is more likely to land with the incumbent giants (chips/HSM/certificates) than with small pure-plays selling a story — look at "real orders," not a stock price moving on news · (3) don't confuse PQC (already making money) with quantum hardware (still burning cash) just because they're in the same trend.

In short: in a quantum megatrend that's almost all still "expensive promises," Quantum-Safe / PQC is the quieter flip side that actually makes money — it doesn't have to wait for a quantum computer to succeed before booking revenue. Just the "possibility" that the machine is coming is enough to make the whole world start swapping keys — and pay the people selling the new keys, starting today.

Explore this theme — live data, stocks & news →