Malaysia Is the Only ASEAN State Rated Tier 1 for Post-Quantum Cryptography Migration Readiness in SITG-Consulting's September 2026 Assessment of the ASEAN-10
Quentir Defense Monitor
Evidence-based insights for quantum defense and security. Published by Quentir Systems LLC · September 15, 2026.

Malaysia's National Security Council announced on September 15, 2026 that Malaysia stands alone in ASEAN at Tier 1, the highest of five grades, for readiness to migrate national systems to post-quantum cryptography. The grade comes from an independent assessment of all ten ASEAN member states that counted only what each government has verifiably done, and it excluded statements of intent by design. That combination makes this a more interesting announcement than the usual national ranking story, because the instrument behind it is a working example of something the quantum security field has lacked: an external assessment regime that grades post-quantum cryptography migration on evidence a third party can check.
The assessment, "ASEAN Post-Quantum Cryptography Readiness 2026: An Empirical Assessment of the ASEAN-10," was written by Brian Couzens of the UK consultancy SITG-Consulting and published on September 1, 2026 on Zenodo under a CC BY 4.0 license with a citable DOI. The National Security Council's statement, carried by Bernama, gives the full standings: Malaysia alone at Tier 1; Brunei, Cambodia, Indonesia, Singapore, Thailand and Vietnam at Tier 2; the Philippines at Tier 3; Laos at Tier 4; and Myanmar at Tier 5. The council was direct about why it values this particular grade, saying the assessment "is based on verifiable national-level actions and implementation, rather than merely relying on statements of intent."
What the five-tier framework counts and what it refuses to count: public evidence as of August 17, 2026
The report's method does most of the work, and the exclusions are where its character shows. SITG-Consulting's own summary describes a locked five-tier framework applied identically to all ten states, using publicly verifiable national evidence gathered through August 17, 2026. Vendor claims did not count. Declarations of intent did not count. Participation in regional cooperation forums did not count. Most striking for readers of this Monitor, quantum computing research and quantum key distribution initiatives did not count either. The author treats those as answers to different questions, separate from whether a government is actually moving its cryptographic estate onto quantum-resistant algorithms. A five-tier scale then runs from an operating national migration effort with real implementation machinery at Tier 1 down to Tier 5, where no publicly verifiable activity specific to post-quantum cryptography could be found at all.
That discipline produces the assessment's most instructive placement, and it involves the region's acknowledged cyber heavyweight. Singapore sits at Tier 2. The report credits Singapore with mature guidance and milestones that carry specific dates, then observes that all of it is voluntary for the entities it addresses. Tier 1 required obligations with legal force behind them and money moving into real trials. The report's general warning travels well beyond Southeast Asia: sophistication of discourse differs from sophistication of governance. A state can host excellent conferences on the quantum threat, publish thoughtful advisories, and still leave every critical infrastructure operator free to postpone a cryptographic inventory indefinitely.
Quantum pillar: post-quantum cryptography (standards and certification). Use posture: defensive. Technology readiness: not applicable. Today's development is an assessment regime plus a set of national policy instruments, so there is no device or implementation to place on the ladder; the algorithms Malaysia is adopting are the ones NIST finished standardizing in 2024.
The machinery behind Tier 1: a Cabinet-approved policy, Directive No. 9 under the Cyber Security Act 2024, and a sandbox that pays for proofs of concept
What did Malaysia show that six neighbors could not? The report identifies four pieces of evidence that together constitute what it calls operating national migration machinery. There is a national cryptography policy with Cabinet approval behind it, addressing the quantum era at the level of government policy rather than agency guidance. There is a statutory instrument under the Cyber Security Act 2024 requiring operators of National Critical Information Infrastructure, the NCII sectors, to submit cryptographic migration data to the state; the council's own list of measures includes Chief Executive Directive No. 9 of the National Cyber Security Agency, which is the instrument that turns a voluntary best practice into a legal reporting obligation. There is a National PQC Migration Plan whose launch was led by the Chief Secretary to the Government, the most senior civil servant in the country. And there is a national proof-of-concept sandbox that was already awarding grants for post-quantum implementation trials before the public plan launch, which is the detail a skeptical reader should weigh most heavily, because budgets spent before the press conference are the opposite of theater.
The surrounding policy stack has been building for a while. Malaysia's National Cyber Security Agency and the Ministry of Digital presented a national readiness roadmap for post-quantum cryptography on October 29, 2025 at a PKI Consortium conference in Kuala Lumpur, and Marin Ivezic's analysis of that roadmap describes a 2025 to 2030 framework built on three strands: technical readiness through proof-of-concept deployments and the government sandbox, strategic alignment with international standards including hybrid cryptography, and workforce development. The council's September 15 statement adds the MyCryptography Action Plan 2026-2030 and an awareness effort aimed at NCII operators. None of this invents new mathematics. The algorithms in question are the ones NIST standardized in August 2024 as FIPS 203, 204 and 205, with quantum-vulnerable algorithms scheduled for deprecation by 2035. Malaysia's contribution is administrative: a state apparatus that knows which of its systems use which cryptography, holds the legal power to demand that information from critical operators, and pays for early implementations to surface the engineering problems before the deadline years arrive.
What a Tier 1 grade lets a defense planner rely on, and what it leaves unmeasured
Read as defense capability, migration machinery of this kind is squarely defensive, and the beneficiary is the state that runs it. The threat model is the one this Monitor returns to weekly: an adversary that collects encrypted government, financial and military-adjacent traffic today and stores it against the arrival of a cryptanalytically relevant quantum computer. Against harvest now, decrypt later collection, the only defense that works is replacing the vulnerable key exchange before the data worth stealing crosses the wire, which makes the speed and completeness of a national migration a security parameter in its own right. A state whose critical infrastructure operators are legally required to report their cryptographic exposure can sequence that replacement; a state relying on voluntary guidance is guessing. The same logic is appearing in procurement far from Southeast Asia, where United States federal contractors now face an evidence test for post-quantum readiness that asks for inventories and tested rotation paths instead of statements of support.
The second thing the announcement demonstrates is what an external assessment regime does to the politics of migration. A five-tier grade with a public evidence base converts a diffuse future risk into a standing that governments compare and defend, and the effect is visible in the very existence of the September 15 statement: a national security council chose to publicize a consultancy's report because the grade was worth claiming. Quentir has watched the same mechanism operate at sector scale, where Hong Kong's quantum readiness score made the migration work visible to bank boards that had previously filed the threat under someday. Assessment regimes of this kind are how the standards half of the post-quantum story acquires teeth between formal certification schemes: they do for national programs what FIPS validation does for individual products, imperfectly but publicly.
A planner should also hold on to what the tier does not say. The framework grades governance machinery, so a Tier 1 state has directives, plans and funded trials; the report does not claim to measure what fraction of Malaysia's cryptographic estate has actually been converted, and no tier here certifies a single migrated system. The evidence base is public documents, so classified networks, defense communications among them, sit outside the assessment entirely. The framework is one consultancy's instrument, locked and applied consistently, yet still awaiting the scrutiny that an ISO-track or regional standard would attract. And the evidence window closed on August 17, 2026, so any state whose mandate is sitting in a draft became invisible to this edition. The honest reading for a defense buyer is that Malaysia has demonstrated the administrative preconditions for a fast migration, and that the region now has a published yardstick that rewards obligations over announcements. Whether the preconditions convert into migrated systems by 2030 is the claim the next edition can test, and the useful signal to watch is whether Malaysia begins publishing conversion metrics under its own directive, because a state that measures its operators eventually has numbers of its own to show.
Sources
Primary source: Brian Couzens (SITG-Consulting), "ASEAN Post-Quantum Cryptography Readiness 2026: An Empirical Assessment of the ASEAN-10," September 1, 2026, published on Zenodo, read together with the Malaysian National Security Council's September 15 statement carried by Bernama. Other material: SITG-Consulting's report summary, Marin Ivezic's PostQuantum.com analysis of Malaysia's readiness roadmap, and NIST's Post-Quantum Cryptography project pages.