Data encrypted today using public-key mechanisms vulnerable to quantum computing can become decryptable later by an adversary who has recorded exchanges and possesses a cryptographically relevant quantum computer. This threat, called “harvest now, decrypt later,” makes an anticipated cryptographic transition necessary for states that must protect sensitive data over the long term. Saudi Arabia and the United Arab Emirates have undertaken distinct initiatives in quantum computing and post-quantum cybersecurity.
The Essentials
- The quantum threat to encrypted data is active today: adversarial actors are collecting data to decrypt it later, making inaction immediately costly.
- Aramco and French company Pasqal deployed a 200-qubit operational system in 2026, making Saudi Arabia one of the first states to operate domestic quantum infrastructure at this scale.
- KAUST in Saudi Arabia and MBZUAI in the United Arab Emirates are training the next generation of post-quantum cryptography researchers, reducing dependence on Western expertise.
- The American NIST published its first post-quantum standards in 2024, but their operational deployment at state and enterprise scale will remain partial before 2030-2032.
- Quantum-resistant encryption could become an open global standard or a proprietary advantage that first movers will transform into a lever of dependence.
The Threat Accumulating Before Quantum Computers Even Exist
To understand why Gulf states are investing heavily in post-quantum cryptography in 2024-2026, one must grasp a counterintuitive logic: the threat is present before the threat becomes operational.
Many communication systems use RSA, ECDH, or ECDSA for key establishment, signatures, or authentication, while encryption of data in transit often relies on symmetric algorithms. RSA rests on the difficulty of integer factorization; ECDSA rests on the difficulty of the discrete logarithm problem on elliptic curves. A cryptographically relevant quantum computer using Shor’s algorithm could break RSA and cryptosystems based on discrete logarithm, but computation time would depend heavily on technical parameters. No such computer exists yet. An adversary can collect and retain certain flows protected by mechanisms vulnerable to public-key cryptography in order to attempt to decrypt them when relevant quantum capacity becomes available.
This is the strategy called “harvest now, decrypt later,” documented by the British National Cybersecurity Center and several Western agencies.
The delay between collection and decryption depends on the cryptographic mechanisms employed, data retention duration, and available computing capabilities. Classified data, infrastructure contracts, and diplomatic communications could become readable later if protected by quantum-vulnerable mechanisms. For a petrostate whose long-term contract negotiations represent hundreds of billions of dollars in exposure, the stakes are concrete and immediate. Saudi Arabia and the United Arab Emirates are investing in their quantum and cybersecurity capabilities.
The Aramco-Pasqal Partnership Reveals Saudi Strategy
Saudi Aramco and Pasqal installed a 200-qubit quantum processor in Dhahran in November 2025, then officially inaugurated its operation and a commercial QCaaS platform in May 2026. The figure deserves context: Google had announced 127 qubits with its Eagle processor in 2021, and IBM reached 433 qubits in 2022. A 200-qubit system is not the absolute frontier of the field. But the geographic location of the infrastructure, not just its qubit volume, is what matters here.
Possessing a domestic quantum computer means several things simultaneously. First, the capacity to experiment with post-quantum algorithms on sovereign infrastructure, without depending on cloud access to calculators from IBM, Google, or IonQ, and without exposing its own data to foreign environments. Second, the possibility of training national engineers and researchers on real hardware, not just simulators. Finally, a strong political signal: Saudi Arabia positions itself as an actor in the quantum transition, not as a passive consumer of technologies defined elsewhere.
This logic fits within a broader technological sovereignty strategy that the Gulf has been deploying for several years. The question of regulating without building arises acutely for states seeking to control fundamental technologies: Saudi Arabia has clearly opted for the second option. Aramco is not a startup: it is the world’s most profitable oil company, with the means to engage in long-term technological partnerships on subjects deemed strategic by the state.
The choice of Pasqal, a French company specializing in neutral atoms, a qubit technology different from the superconducting qubits of Google and IBM, also reveals a desire to diversify dependencies. Working with an intermediate-sized European actor, rather than with American giants, reduces exposure to a single ecosystem and preserves negotiating margins.
KAUST and MBZUAI: Training Experts Before the Market Demands Them
Hardware infrastructure is not enough. The post-quantum cryptographic transition requires engineers capable of migrating existing systems, auditing protocols, and deploying new standards. This competency is today rare and concentrated in a few Western universities and laboratories.
The King Abdullah University of Science and Technology (KAUST), founded in 2009 in Saudi Arabia with an initial endowment of 10 billion dollars, has integrated post-quantum cryptography into its computer science research programs. The institution entered the global top 100 universities in less than fifteen years, a trajectory that illustrates what sustained investment and international recruitment policy can accomplish in a short window. KAUST trains not only Saudi researchers: it attracts doctoral students from around the world, creates publications cited in reference journals, and builds a critical mass of local expertise.
In the United Arab Emirates, the Mohamed bin Zayed University of Artificial Intelligence (MBZUAI), founded in 2019 in Abu Dhabi, has specialized in artificial intelligence and its mathematical foundations, a domain directly adjacent to cryptography. Endowed with faculty recruited from the world’s best universities and scholarships that fully cover training costs, MBZUAI produces within a few years a cohort of researchers who, ten years ago, would have had no option but to train at Stanford or ETH Zurich.
This strategy of preemptive training has a precedent: this is exactly what South Korea and Taiwan did in semiconductors in the 1980s-1990s, by massively training engineers in domains deemed strategic before the global market demanded them. The current geopolitical fragmentation accelerates this logic: states that do not master the key competencies of a fundamental technology will find themselves structurally dependent on those who do.
The NIST Timeline Illustrates Western Slowness
In August 2024, the American National Institute of Standards and Technology published its first three post-quantum cryptography standards: FIPS 203 (ML-KEM, derived from CRYSTALS-Kyber) for key establishment, FIPS 204 (ML-DSA, derived from CRYSTALS-Dilithium), and FIPS 205 (SLH-DSA, derived from SPHINCS+) for signatures. This is a real advance, the fruit of several years of collaborative work with cryptographers from around the world, including several European and Asian teams. These standards constitute the basis on which future systems must migrate.
But publishing standards and their operational deployment are two things separated by a considerable gulf. Banking systems, critical infrastructure, government networks use cryptographic libraries embedded in dozens of software layers. Migrating these systems requires inventory, audit, testing, training, and time. ENISA indicates that the transition will take years; a detailed timeline over approximately ten years is notably proposed by the British NCSC, not by NIST and ENISA in the form of an explicit five to ten-year range. Large organizations still need to establish a systematic inventory of their cryptographic assets.
The European Union is advancing on the subject: ENISA has published guidelines, and several member states, Germany, the Netherlands, and France, have launched national transition programs. But there is no binding unified timeline for vital operators, nor a common verification mechanism. The European cybersecurity regulation (NIS2, in force since October 2024) imposes general resilience requirements, but does not specifically address post-quantum migration with precise deadlines.
The gap between standards availability and their actual deployment can allow states investing in this transition to develop their capabilities. While Western administrations negotiate their migration budgets and map their dependencies, states starting from more recent and less complex infrastructure can build systems that are natively post-quantum, without having to migrate technical legacy accumulated over forty years.
What Is at Stake in the Next Five Years
Saudi and Qatari strategies for transformation and cybersecurity support diversification, innovation, and national digital capabilities; the assertion of an explicit and symmetric reference to “digital sovereignty” requires a more precise textual source. The Qatar National Cyber Security Agency published a national cybersecurity strategy for 2024-2030; no specifically post-quantum national strategy has been confirmed. The Technology Innovation Institute in Abu Dhabi has an active quantum center. These institutions do not work in isolation: they rely on partnerships with American, European, and Asian universities, and publish in open forums like the NIST Post-Quantum Cryptography Standardization Project.
This openness is important to note. Gulf institutions are developing their competencies in a domain where research and standardization remain largely collaborative. The concentration of power in the hands of a small number of technological actors is a systemic risk that regional powers are seeking precisely to avoid by building their own capabilities. Post-quantum cryptography is a terrain where this remains possible: the field is sufficiently open, publications sufficiently accessible, standards sufficiently recent that a determined actor can catch up and even get ahead on specific segments.
Post-quantum algorithms can be integrated into services, libraries, and migration tools offered by different actors. NIST standards are open, but implementations, optimized libraries, migration services, and operational expertise are not necessarily. Mastery of competencies, deployment tools, and training can contribute to national capabilities for securing critical systems.
Organizations that have not yet begun must establish an inventory of their cryptographic assets. This inventory addresses two points: systems using RSA or ECDSA, and data whose value extends over a horizon of ten years or more. These two criteria make it possible to prioritize a migration that, without them, remains an abstract budgetary item easy to postpone. Gulf states have undertaken this approach.
The West still has time to do so, provided it measures time correctly.
Sources
- Middle East Institute, AI, the Gulf, and the US: A Primer: https://mei.edu/report/ai-the-gulf-and-the-us-a-primer/
- NIST Post-Quantum Cryptography Standards (FIPS 203, 204, 205), August 2024: https://www.nist.gov/pqcrypto
- KAUST, King Abdullah University of Science and Technology: https://www.kaust.edu.sa
- Mohamed bin Zayed University of Artificial Intelligence (MBZUAI): https://mbzuai.ac.ae
- ENISA, Post-Quantum Cryptography: Current State and Quantum Mitigation, 2024: https://www.enisa.europa.eu/publications/post-quantum-cryptography-current-state-and-quantum-mitigation
- Qatar National Cybersecurity Agency, National Cybersecurity Strategy: https://www.ncsa.gov.qa
- Technology Innovation Institute, Quantum Research Center (Abu Dhabi): https://www.tii.ae/quantum