A sufficiently powerful quantum computer could break the protections that today secure government communications, banking transactions, and infrastructure networks. The United Arab Emirates and Saudi Arabia have launched their own sovereign cryptographic programs, running parallel to the international standardization process led by the American NIST. This dual approach poses a concrete interoperability problem between countries.

The essentials

  • The NIST published three first post-quantum standards in August 2024, but the process remains open with fourteen additional candidates in the second round.
  • The Technology Innovation Institute of the United Arab Emirates, the TII, the scientific arm of the Abu Dhabi government, announced its first post-quantum cryptography software library in April 2021.
  • In November 2025, Aramco and French company Pasqal put into service the Middle East’s first industrial quantum computer, oriented toward energy and materials.
  • Quantum training programs were launched at KFUPM and KAUST in Saudi Arabia, signaling a willingness to build a local sector and not simply purchase equipment.
  • The tension between cryptographic sovereignty and international interoperability has no simple resolution: both imperatives are real.

The quantum threat imposes a timeline that no one controls

The schedules of quantum computing and international standardization present a significant lag.

RSA relies on the difficulty of integer factorization, while elliptic-curve protocols rely on the difficulty of the discrete logarithm problem on elliptic curves. In both cases, a quantum computer of sufficient power could solve these problems in a few hours, whereas for sufficiently large keys, a classical attack could take billions of years according to estimates, the cost depending on the system, key size, and available resources. A quantum computer of sufficient power would do it in a few hours. This vulnerability has been known since the 1990s. It is not yet exploitable, because current quantum machines remain limited in the number of stable qubits.

Progress exists, but its pace and the date of arrival of a machine capable of threatening cryptography remain uncertain.

The strategy known as “harvest now, decrypt later” heightens the urgency. State actors can intercept and store encrypted communications today, waiting to have quantum capabilities to decrypt them in five or ten years. For sensitive long-lived data—infrastructure plans, identities, treaties, industrial secrets—the threat is already active, even if quantum computers capable of exploiting it do not yet exist.

This is why the NIST, the American agency for technological standards, published in August 2024 its three first finalized post-quantum algorithms. Three algorithms on which an international consensus built over several years of work had been constructed, with teams from around the world. And fourteen additional candidates under evaluation for a second round. The process is rigorous. It is also slow by design: international standardization requires consensus, time, and cross-review.

States that manage critical infrastructures cannot suspend their security while consensus forms.

The Emirates go it alone, and it’s a deliberate choice

The Technology Innovation Institute published its PQC library in April 2021. NIST’s initial standards were published in August 2024, more than three years after that announcement. The Emirates did not wait for American approval to deploy their own solution.

The TII is not a marginal player: it is the institution that developed Falcon, a family of AI language models, also contributing to cryptographic research recognized internationally. The Emirates have genuine cryptographic expertise, founded on contributions recognized on the international stage. Their approach reflects a logic of digital sovereignty that one finds in other technological domains, as shown by Asian industrial strategies in robotics and semiconductors.

In 2026, the Emirates also launched a national cryptography discovery platform, intended to accelerate the migration of government systems toward protocols resistant to quantum attacks. The stated objective is to enable public and private entities to assess their exposure and plan their transition, an internal coordination tool that Washington would not have provided in time.

This movement raises an architectural question: a sovereign cryptographic library, if it is solid, protects national systems. But if it diverges from international standards, it creates a problematic interface with partners. Incompatible protocols may require an upgrade, a gateway, or a translation, and each layer of adaptation is a potential attack surface.

Saudi Arabia bets on industrial quantum

Saudi Arabia took a different, complementary direction. In November 2025, Saudi Aramco and French company Pasqal announced the activation of the Middle East’s first industrial quantum computer. The machine is operational in the energy and materials sectors, network optimization, and molecular simulation for petrochemical chemistry.

This deployment has a double significance. First, it anchors quantum capacity on Saudi soil, which reduces dependence on foreign infrastructure for sensitive calculations. Second, and more strategically, it creates a local ecosystem around this technology: trained engineers, documented use cases, an industrial base that can evolve.

The collaboration with Pasqal, a company specializing in neutral-atom quantum computers, illustrates a broader trend: Gulf countries are not seeking to develop basic quantum technology alone, but to accelerate its industrial adoption by relying on European or American partners for hardware, while maintaining control of applications and data. It is a form of pragmatic partial sovereignty.

Saudi universities are preparing for this. KFUPM already offered a master’s program in quantum computing before 2024; institutional sources consulted do not confirm the launch of an equivalent dedicated master’s by KAUST between 2024 and 2025. The complete transition to new algorithms could take 10 to 20 years according to NIST; starting now means building a capacity for local expertise to adapt and evaluate post-quantum solutions by 2035. This bet on training is consistent with regional strategies for developing skills in the face of AI.

NIST standardizes but cannot impose

The structural limit of the process lies in its very nature: a standard produced by consensus cannot anticipate each state’s sovereignty needs. Consensus requires that each participant accept deferring certain national requirements in favor of collective agreement. For states that judge their critical infrastructure too sensitive to tolerate this deferral, participation in the process and autonomous deployment are complementary.

The NIST process deserves close examination, because it embodies both the strength and the limit of the international standardization model.

Launched in 2016, it brought together cryptographers from around the world, including, notably, teams from the Emirati TII, to evaluate and select algorithms resistant to quantum attacks. The August 2024 result includes ML-KEM derived from CRYSTALS-Kyber, ML-DSA derived from CRYSTALS-Dilithium, and SLH-DSA derived from Sphincs+. Fourteen other candidates are under evaluation for the second round, targeting specific use cases or particular hardware constraints.

This process has real value. Algorithms subjected to years of public cross-review by hundreds of independent researchers offer assurance that no single state can produce alone. Flaws are detected before deployment. Trust is built collectively.

But NIST is an American agency. Its standards, even when they result from an open process, remain American standards. Some countries perceive a dependence in adopting protocols whose governance Washington controls. China has been developing its own post-quantum cryptographic standards independently of NIST for several years. Russia as well.

The Middle East is taking a different position: neither complete break with the international process nor blind adoption. The Emirates contributed to NIST work and also have their own cryptographic resources. The two movements hold together.

This is a strategy of redundancy: participate in international standards while developing national cryptographic capabilities.

Interoperability remains the unresolved problem

The coexistence of multiple protocols creates technical challenges: each adaptation layer added to make distinct cryptographic environments communicate introduces additional complexity that security teams must maintain over time.

The difficulty is at once technical, operational, and systemic. A credible post-quantum algorithm requires expert design, then public, independent, and prolonged analysis before standardization. The real difficulty is systemic: systems will need to communicate securely while multiple families of protocols coexist.

One can sketch two plausible scenarios for the end of the decade. In the first, NIST standards impose themselves as a global reference through progressive adoption, including in the Middle East, and sovereign libraries serve as a compatibility layer. In the second, multiple cryptographic blocs stabilize—American, Chinese, and regional variants—with translation interfaces at digital borders, more complex to secure and maintain.

The parallel with other technological domains is relevant. Dependence on centralized data infrastructure creates structural vulnerabilities that states seek to correct. Post-quantum cryptography is a case of this broader tension between global efficiency and local resilience.

What is established today: the Emirates and Saudi Arabia are no longer mere importers of security technology. They are investing in the capacity to produce it, adapt it, and deploy it on their own schedule. It is a shift in position within the global technology value chain, not simply one more national project.

Training engineers in sovereign cryptography

A master’s program does not make headlines. Yet the decisions made at KAUST and KFUPM are probably the most structuring of those discussed here.

Post-quantum algorithms exist. Industrial quantum machines exist. What is almost everywhere lacking, including in developed countries, are engineers capable of deploying them correctly, auditing them, adapting them to the specific constraints of each system. Correctly implemented cryptography is rare. Correctly implemented post-quantum cryptography is even rarer.

Training Saudi and Emirati cryptographers means building the capacity to independently evaluate solutions proposed by foreign vendors, adapt protocols to national constraints, and participate in future rounds of international standardization with real weight. It is also a form of soft power in future negotiations over standards: those who produce credible researchers carry weight in technical committees.

By 2030, Middle Eastern countries will seek to weigh sufficiently in international standardization processes for their sovereign constraints to be taken into account, rather than having to choose between adopting foreign standards and isolation. Current investments aim precisely at reaching this point of influence.


Sources

  1. Computer Weekly, UAE launches national cryptography discovery platform: https://www.computerweekly.com/news/366643900/UAE-launches-national-cryptography-discovery-platform-to-accelerate-post-quantum-security-transition
  2. NIST, Post-Quantum Cryptography Standards, August 2024: https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
  3. Telecom Review Middle East, coverage of regional quantum initiatives 2026
  4. PwC Middle East, analysis of post-quantum strategies in the Middle East
  5. Technology Innovation Institute (TII), Abu Dhabi, post-quantum cryptographic library, September 2024: https://www.tii.ae
  6. Aramco / Pasqal, deployment of the Middle East’s first industrial quantum computer, November 2025: https://www.pasqal.com