NEWS
CIOs Face a $3 Billion Quantum Market They Should Not Buy
Quantum computing heads for $3 billion by 2028, Gartner still says do not buy a machine, and CISA now wants a crypto inventory before Q-Day.
Quantum computing has a $1.4 billion market, a $3 billion 2028 forecast, and a standing order from Gartner: do not buy a machine. Mark Horvath, VP analyst for quantum computing at Gartner, still gets that purchase question several times a day.
The machines are real enough to rent. The CIO work that already has a calendar is encryption, and that clock is tighter than the 2035 date most plans still cite.
Gartner Still Tells CIOs Not to Buy a Quantum Computer
Horvath’s line is blunt because the hardware is not a faster rack you can drop next to the GPU cluster. A quantum computer needs a quiet, isolated hall, cut off from heat and noise, and it has to sit near absolute zero to run. The staff who can keep it alive and write for it are scarce. Physics, electrical engineering, photonics, and computer science are all short, and the industry also wants people who can hold two of those trades at once.
You should not buy a quantum computer under any circumstances.
Mark Horvath, VP analyst for quantum computing, Gartner
Michael Brett, worldwide go-to-market strategy leader for quantum technologies at AWS, has watched the punchline of the field change. “Quantum has had a reputation of previously always being 10 years away,” he said. “Now, it’s like 18 months away.” That shorter horizon still does not make a purchase order rational. Brett said each unit is a hand-built, highly complex device, and ramping to large numbers will be hard in the first couple of years. Vendors, in his view, still have to learn which machines are worth backing as they scale.
billion quantum market CIOs should not buy
The $1.4 Billion Market Runs on Rented Hours
Most firms that need a quantum run never take delivery. They buy time on someone else’s fridge. AWS sells that as Amazon Braket, which gives on-demand access to quantum computers from several makers, including superconducting chips from IQM and Rigetti, trapped-ion systems from IonQ, and QuEra’s analog atom array. Users pay per task and shot, or they reserve a block of time, and they can prototype on simulators first. AWS also sells Quantum Embark, a 12-week, fixed-price program that walks a company through one problem, then benchmarks it against classical code.
Horvath said that rental path will likely become the default. It does not skip the homework. It shortens it, because the buyer does not have to stand up the hall, the cryogenics, or the night shift. Brett said most Braket users today are still researchers at labs and universities doing science, not production IT. Enterprise interest is rising anyway, which is why AWS built the 12-week on-ramp.
The Quantum Economic Development Consortium’s 2026 industry report, released April 14, 2026, puts the global pure-play quantum workforce at nearly 16,500 people, up about 2,000 in a year, with job and internship openings up 11%. That is growth from a small base. Celia Merzbacher, the consortium’s executive director, said public and private funding jumped in 2025 and companies hired more workers. The same report still describes an early commercial market, not a product you stock like servers.
QED-C Sees Computing Revenue Hit $3 Billion by 2028
The consortium’s State of the Global Quantum Industry 2026 report is the source for the market split CIOs keep seeing. Computing was $1.4 billion in 2025. Sensing added $470 million. Together they made a $1.9 billion quantum technology market. Computing is projected to reach $3 billion by 2028 at a 30% annual rate, with a faster path once someone shows advantage on a business-relevant problem. Sensing is seen at $1.1 billion by 2028, growing at 32%. The whole quantum technology pile is expected to double, exceeding $4 billion by 2028.
QED-C 2025 TO 2028 MARKET SPLIT
| Segment | 2025 revenue | 2028 forecast | Annual rate |
|---|---|---|---|
| Quantum computing | $1.4 billion | $3 billion | 30% |
| Quantum sensing | $470 million | $1.1 billion | 32% |
| All quantum technology | $1.9 billion | More than $4 billion | Market doubles |
On the company side, 37% of quantum computing firms surveyed project more than 25% revenue growth from 2025 to 2026, and more than half expect at least 11%. No respondents in that survey expected a decline. The consortium counted 7,418 quantum-engaged organizations at the end of 2025, including 556 pure-play companies. New public funding commitments rose by more than $12.7 billion, to an estimated $56.7 billion total. Private venture capital hit $4.9 billion in 2025, and U.S.-headquartered firms raised more than $2.7 billion of that. China accounted for 54% of quantum-related patent filings last year, with total filings up 31%.
Those are supplier numbers. They measure who is getting paid to build and run machines, not how many CIOs will ever own one.
Logistics and Chemistry Already Use the Machines
Horvath said the workloads that already make sense are narrow: logistics, national security resource management, financial services, and hard sciences such as chemistry. The point is not that quantum is faster at the jobs your data center already does. It is that a small set of algorithms can attack problems that stall on classical hardware, if you can state the problem in the right form.
Brett said CIOs at global firms are the ones putting money in so far, and that everyone else should know the field even if they are not writing checks. Horvath’s practical step is smaller than a lab tour. Assign one person to hunt for a fit, then bring the CIO in only if that person finds something. Talk to vendors about live cases in your industry. Renting time still requires that work. It just means you do not also have to invent the freezer.
So the compute story for a typical enterprise in 2026 is a watch list plus, at most, a short paid trial. The security story is not a watch list.
The Encryption Clock Lands in 2029
A large quantum computer that can run Shor’s algorithm would break the public-key math that now wraps TLS, VPNs, software updates, and a lot of stored data. That machine does not have to sit in your dock. It has to exist somewhere, in the hands of a state or anyone who can buy time on it. Traffic captured today can be stored and read later. That is why the migration started before the attack is cheap.
NIST released three post-quantum encryption standards in August 2024: FIPS 203 (ML-KEM) for key wrapping, FIPS 204 (ML-DSA) for signatures, and FIPS 205 (SLH-DSA) as a hash-based signature backup. NIST says those three can and should be put into use now. Under the transition timeline in NIST IR 8547, quantum-vulnerable algorithms come out of its standards by 2035, with high-risk systems moving much earlier.
Gartner’s public note is sharper than that 2035 line. It says advances in quantum computing will make asymmetric cryptography unsafe by 2029 and fully breakable by 2034. Separately, Gartner puts a 25% chance that a state actor has a cryptographically relevant quantum computer by 2029, rising to 75% by 2031. Google in March 2026 set its own post-quantum migration target at 2029, after new work cut the estimated hardware needed to break elliptic-curve crypto. The UK’s National Cyber Security Centre wants the highest-priority moves done by 2031 and the rest finished by 2035. U.S. high-value federal systems are on a faster track, with key establishment due by December 31, 2030 and signatures by December 31, 2031.
DATES THAT NOW GOVERN THE MIGRATION
| Who set it | Date | What it covers |
|---|---|---|
| 2029 | Internal post-quantum encryption migration | |
| Gartner | 2029 / 2034 | Asymmetric crypto unsafe, then fully breakable |
| Gartner (state-actor odds) | 2029 / 2031 | 25% then 75% chance of a cryptographically relevant machine |
| U.S. high-value federal systems | Dec. 31, 2030 / Dec. 31, 2031 | Key establishment, then digital signatures |
| UK National Cyber Security Centre | 2031 / 2035 | Highest-priority work, then full migration |
| NIST | 2035 | Quantum-vulnerable algorithms removed from standards |
Hardware people have already pulled the live date toward 2029. A program that still treats 2035 as the working horizon is planning to finish after the threat model Google is using. Harvest-now, decrypt-later collection does not wait for your refresh cycle. Long-lived records in banks, health systems, and government files are in scope the moment they go on the wire under today’s public-key wrapping.
CISA and G7 Partners Put Crypto Inventories First
On September 3, 2026, CISA and the G7 Cyber Security Working Group issued a call to begin transitioning now. The note asks organizations and governments to start moving to post-quantum encryption to protect data, login systems, and critical assets. France’s ANSSI chaired the working group under France’s 2026 G7 presidency. The national cyber agencies of Canada, France, Germany, Italy, Japan, the UK, and the U.S. signed it, with support from the European Commission and ENISA.
Quantum computing advancements pose a real threat to public-key encryption. Our call to action with G7 partners urges orgs to inventory cryptographic assets, map dependencies, develop phased transition plans, & integrate PQC into procurement. Read more 🔑 https://t.co/VRhLvwLPg6 pic.twitter.com/SkJOGkoXnF
— CISA Cyber (@CISACyber) September 3, 2026
CISA’s own post put the operator sequence in four steps: inventory cryptographic assets, map dependencies, write a phased plan, and fold post-quantum rules into buying. That matches what Suja Viswesan, VP of security and runtime products at IBM, told CIOs. This is not only a CISO file. The person who owns software spend, vendor contracts, and the estate map has to run it.
G7 PRIORITIES IN THE SEPTEMBER 3 CALL
- Awareness: Raise the quantum risk and the need for post-quantum encryption inside government and industry.
- National plans: Write strategies that support adoption and aim for an adequate supply of hardware and software that already includes the new algorithms.
- Research: Keep funding work on quantum-safe tools that can actually ship.
- Partnerships: Share expertise and capacity across government, vendors, and universities.
- Procurement: Put post-quantum rules into cybersecurity requirements and purchase contracts, and swap gear on the normal refresh cycle where you can.
IBM’s 2026 Cost of a Data Breach Report, run by Ponemon Institute across 602 organizations, shows how far that inventory still has to go. Only 37% of breached organizations said they encrypt sensitive data both at rest and in transit. Just 34% have visibility into cryptographic assets. Quantum-safe spending is rising, IBM said, while the basic encryption and key-management gaps stay open. The global average breach in that study cost $4.99 million, up 12%.
What CIOs Should Ask Every Software Vendor
Viswesan said firms should use the NIST timeline as a guide even if they never touch a federal contract, because the same algorithms will become the default. The first job is a list: software, subscriptions, and what is encrypted, including tools that arrive through a supplier. Then the questions move into the contract.
VENDOR QUESTIONS THAT BELONG IN THE NEXT RENEWAL
- Hardware: Is this box quantum-safe, or does it still wrap keys with RSA or elliptic-curve math that a future machine can break?
- Software: Will this product speak ML-KEM and ML-DSA on a dated roadmap, and can you swap algorithms later without a forklift upgrade?
- Data in motion: Where is TLS, VPN, SSH, and certificate issuance still using public-key suites that NIST plans to retire?
- Third parties: Which suppliers hold your long-lived records, and who owns the migration if they do not move?
- Proof: Can the vendor show a cryptographic bill of materials, not a slide that says quantum-ready?
You cannot be reactive on this because it’s a long term journey. This is not a sprint. People who start early have a competitive advantage.
Suja Viswesan, VP of security and runtime products, IBM
Horvath’s compute advice and Viswesan’s security advice only look like they conflict. One says skip the capital project. The other says start a years-long cleanup of math that is already in production. Both are about not waiting for a demo that makes the decision obvious. The rental market will keep growing toward that $3 billion computing line. The fridge still does not belong on the CIO’s floor. The work that starts now is a list of where RSA and elliptic-curve tools still sit, including in software bought from someone else.
-
ENTERTAINMENT2 weeks agoDolly Parton Laid to Rest as the Public Funeral Began
-
NEWS4 days agoJohn Ternus Debuts a $2,099 Foldable and Holds iPhone 18
-
NEWS4 days agoTesla Burns AI Cash While SpaceX Sends the Invoices
-
NEWS3 days agoThe Book on China’s Car Brain Still Stars Infineon
-
NEWS3 days agoSAP Puts Token Spend on the Same Line as Hiring
