On March 27, 2026, a Toronto company that builds computers out of light started trading on both the Nasdaq and the Toronto Stock Exchange. Xanadu Quantum Technologies went public through a merger with a special-purpose acquisition company, raising roughly US$302 million, according to DatacenterDynamics. When the deal was first announced in November 2025, BetaKit reported a pro forma valuation of about US$3.6 billion.
That’s a lot of money for machines that still can’t do much useful work. Yet the past two years have produced real technical progress, especially on the field’s hardest problem: errors. Meanwhile, governments have quietly started replacing the encryption that a future quantum computer could break.
Here’s where things stand in the fall of 2026: what a qubit is, what the big error-correction results actually showed, who the Canadian players are, and why your IT department should care about post-quantum cryptography even if you never touch a quantum computer.
Qubits, without the hand-waving
An ordinary computer stores information in bits, each of which is either 0 or 1. A quantum computer uses qubits. A qubit can be put into a superposition, a state that carries some amount of 0 and some amount of 1 at once, until you measure it and it settles into one or the other.
The popular line that a quantum computer “tries every answer at the same time” is misleading. What makes qubits powerful is how they combine. Qubits can be entangled, so their states are linked in ways classical bits can’t be, and a well-designed quantum algorithm uses interference to make wrong answers cancel out and right answers reinforce, a bit like noise-cancelling headphones. That only works for certain kinds of problems: simulating molecules and materials, some optimization tasks, and, famously, factoring large numbers.
The catch is fragility. Qubits are disturbed by heat, vibration and stray electromagnetic noise. Each operation has a small chance of going wrong, and those errors pile up quickly. Companies build qubits in very different ways, and each approach has its own trade-offs:
- Superconducting circuits, chilled to near absolute zero (Google, IBM, and in a different form Nord Quantique and D-Wave).
- Trapped ions, individual charged atoms held by electromagnetic fields (Quantinuum).
- Photons, particles of light travelling through chips and optical fibre (Xanadu).
- Spins in silicon, tiny magnetic properties of defects in a silicon chip, linked by light (Photonic).
Error correction: the milestone that mattered
The fix for fragile qubits is quantum error correction. Instead of trusting one physical qubit, you spread a single “logical” qubit across many physical ones and constantly check for mistakes without destroying the information. The theory has been around since the 1990s. The problem was that adding more qubits also added more opportunities for error. Unless each physical qubit is good enough, crossing a quality bar known as the threshold, bigger codes make things worse rather than better.
Google’s Willow
In December 2024 Google announced Willow, a 105-qubit superconducting chip. The headline result, published in Nature, was that as Google grew its logical qubit from a 3-by-3 grid of physical qubits to 5-by-5 and then 7-by-7, the error rate was cut in half at each step. That’s what “below threshold” means in practice: scaling up finally made things better. Google described it as a goal the field had pursued for nearly 30 years.
Willow also ran a benchmark called random circuit sampling in under five minutes, a task Google estimated would take a leading classical supercomputer about 10 septillion years. That number got the headlines, but the benchmark has no practical use. In October 2025 Google followed up with something closer to useful: an algorithm called Quantum Echoes, which ran about 13,000 times faster on Willow than on classical supercomputers and was applied, with UC Berkeley researchers, to studying the structure of two molecules.
Others closing in
- IBM laid out a roadmap in June 2025 to deliver a fault-tolerant machine called Starling by 2029, with 200 logical qubits able to run 100 million operations. It’s betting on a family of codes called qLDPC, which IBM says cut the overhead of error correction by roughly 90 per cent.
- Quantinuum launched its Helios trapped-ion system in November 2025 with 98 physical qubits and a two-qubit gate fidelity of 99.921 per cent, and reported running 48 error-corrected logical qubits.
Our read: the error-correction problem has moved from “might be impossible” to “very hard engineering.” That’s a big shift, but useful fault-tolerant machines are still years away by the companies’ own timelines.

Canada’s quantum players
Canada punches above its weight in this field, and four companies show how differently people are attacking the problem.
D-Wave
Founded in 1999, D-Wave describes itself as the world’s first commercial supplier of quantum computers. Its machines are annealers, a specialized design aimed at optimization and simulation rather than general-purpose computing. It grew up as a Canadian company, but its corporate headquarters is now in Palo Alto, California, though it still lists a Canadian office. In May 2025 it made its Advantage2 system generally available, with more than 4,400 qubits. Earlier that year D-Wave published a paper in Science claiming its hardware simulated magnetic materials far beyond what classical supercomputers could manage. As insideHPC noted, not every researcher accepted that claim.
Xanadu
Toronto-based Xanadu builds photonic quantum computers, which encode information in light and can operate largely at room temperature. In January 2025 it unveiled Aurora, a 12-qubit modular system spread across four server racks, 35 photonic chips and 13 kilometres of optical fibre. Twelve qubits is small; the point was to show that the design can be networked and scaled. Chief executive Christian Weedbrook told BetaKit that about 85 per cent of the company’s 260-person team works in Toronto, and that the company intends to stay.
Photonic
Vancouver’s Photonic Inc. uses defects in silicon called T centres, which act as qubits that can also send and receive light. That lets separate chips be linked over optical networks, an approach the company calls “Entanglement First.” It works with Microsoft, offering access through Azure, and in September 2026 the two companies announced joint work on resource estimation using Photonic’s SHYPS error-correcting codes. The same month, Photonic, led by chief executive Don Mattrick, proposed Project VANGUARD, a semiconductor manufacturing facility in Canada worth up to $500 million to serve quantum, AI, aerospace and defence customers.
Nord Quantique
Sherbrooke, Que.-based Nord Quantique, founded in 2020, takes a different route to error correction. It uses superconducting bosonic codes, an approach designed so that each physical qubit can carry its own error protection, giving what the company describes as a one-to-one ratio of logical to physical qubits. In 2025 it was one of eleven companies selected for Stage B of the U.S. Defense Advanced Research Projects Agency’s Quantum Benchmarking Initiative. In May 2026 it announced a US$1.4-billion valuation after a $30-million round, and said it is targeting a useful fault-tolerant machine by 2030. It also received $16 million through the federal Quantum Champions Program.
| Company | Home base | Qubit approach |
|---|---|---|
| D-Wave | Canadian roots; HQ now Palo Alto | Superconducting annealing |
| Xanadu | Toronto | Photonic (light) |
| Photonic Inc. | Vancouver | Silicon spin qubits linked by light |
| Nord Quantique | Sherbrooke, Que. | Superconducting bosonic codes |
Investors interested in any of these companies should remember that valuations in this sector rest heavily on future promises; it’s worth getting independent financial advice before buying in.
The encryption problem, and its fix
The most concrete reason quantum computing matters to ordinary organizations today has nothing to do with buying one. Much of the internet’s security, including RSA and elliptic-curve cryptography, relies on maths problems that a large, error-corrected quantum computer could solve.
How large? In May 2025, Google researchers Craig Gidney and Sophie Schmieg estimated that breaking 2048-bit RSA could take about a million noisy qubits running for roughly a week, a twentyfold drop from a 2019 estimate of 20 million qubits. No machine is anywhere close to that today, but the target keeps getting nearer from both directions.
There’s also a reason not to wait. Security agencies warn about “harvest now, decrypt later”: attackers can record encrypted traffic today and store it until they can break it. Medical records, legal files and state secrets that must stay private for decades are already exposed to that risk.
The NIST standards
On August 13, 2024, the U.S. National Institute of Standards and Technology published its first three post-quantum cryptography standards:
- FIPS 203 (ML-KEM), based on CRYSTALS-Kyber, for general encryption and key exchange.
- FIPS 204 (ML-DSA), based on CRYSTALS-Dilithium, the primary standard for digital signatures.
- FIPS 205 (SLH-DSA), based on SPHINCS+, a hash-based backup signature scheme.
A fourth standard based on the FALCON algorithm was planned to follow. In March 2025 NIST also selected HQC, which relies on error-correcting codes rather than lattices, as a backup to ML-KEM, with a final standard expected in 2027. NIST’s message to organizations was blunt: start integrating the new standards now, because the full transition will take time.
Canada’s timeline
Ottawa has set its own deadlines. The Canadian Centre for Cyber Security’s post-quantum migration roadmap, issued in June 2025, required federal departments to have initial migration plans by April 2026, to move high-priority systems by the end of 2031, and to finish all remaining systems by the end of 2035. Businesses that supply government, or that simply hold long-lived sensitive data, would be wise to plan on a similar schedule.
What to take from all this
Quantum computing in 2026 sits in an odd place. The science has passed genuine milestones, error correction above all, and Canadian companies are among the serious contenders. But no quantum computer yet does commercially valuable work that a classical machine can’t, and most credible timelines for that point to around the end of the decade.
For most organizations, the practical step isn’t buying quantum time. It’s taking an inventory of where you use encryption, asking your software and cloud vendors when they’ll support ML-KEM and ML-DSA, and putting post-quantum migration on the same multi-year plan as any other major upgrade. The quantum machines are still coming. The deadline for being ready for them has already been set.
Sources and further reading
- DatacenterDynamics: Xanadu has gone public (2026)
- BetaKit: Xanadu to go public on Nasdaq and TSX (2025)
- The Quantum Insider: Xanadu announces Aurora
- Google: Meet Willow, our state-of-the-art quantum chip
- Quantum Computing Report: Google’s Quantum Echoes
- IBM: Roadmap to Quantum Starling
- Quantinuum: Helios launch
- D-Wave: About the company
- D-Wave: Advantage2 general availability
- insideHPC: D-Wave Advantage2 and the supremacy debate
- Photonic Inc.: Resource estimation with Microsoft
- Photonic Inc.: Project VANGUARD
- Nord Quantique: US$1.4-billion valuation
- Google: Tracking the cost of quantum factoring
- NIST: First three post-quantum encryption standards
- NIST: HQC selected as fifth algorithm
- Canadian Centre for Cyber Security: PQC migration roadmap
Leave a comment