POST-QUANTUM CRYPTOGRAPHY / BEGINNER

What Is Post-Quantum Cryptography And Why It Matters Now

Post-quantum cryptography is a set of new algorithms that run on ordinary computers but are designed to resist quantum attack. Here is what it replaces, what it leaves alone and why the work starts now.

Checked against primary sources and independently reviewed on . Sources are listed at the end.

Almost every secure connection you make relies on public-key cryptography. It is what lets your browser agree a secret key with a bank it has never met, and what lets your laptop check that a software update really came from the vendor. The algorithms doing that work today, mainly RSA and elliptic curve cryptography, have a known weakness: a large enough quantum computer could break them.

Post-quantum cryptography, often shortened to PQC, is the response. It is a family of new public-key algorithms that run on the computers and phones we already have, but are built on mathematical problems that quantum computers are not known to solve efficiently. The US National Security Agency describes such algorithms as ones that can run on today’s computers and are believed to resist attack from both classical and quantum machines.1

This article explains what PQC replaces, what it does not need to touch, and why standards bodies are telling organisations to begin now rather than wait for a quantum computer to appear.

What Quantum Computers Would Break

Public-key cryptography does two main jobs. Key establishment lets two parties agree a shared secret over an open network. Digital signatures prove who sent something and that it has not been changed. Both jobs currently rest on problems such as factoring large numbers or computing discrete logarithms, which a quantum computer running Shor’s algorithm could solve. Our Quantum Threat section explains how that attack works.

NIST’s draft transition guidance, NIST IR 8547, lists the algorithms it treats as quantum-vulnerable. They include RSA, ECDSA and EdDSA for signatures, and finite field and elliptic curve Diffie-Hellman for key establishment.2 Between them, these cover most of the public-key cryptography in use on the internet today.

Symmetric cryptography is in a different position. NIST’s draft states that its approved symmetric algorithms and hash functions with at least 128 bits of classical security are believed to meet its lowest post-quantum security category.2 So AES and SHA-2 stay, although many organisations choose larger sizes for long-term protection. The NSA’s own suite for national security systems, CNSA 2.0, keeps AES with 256-bit keys and SHA-384 or SHA-512.1

Cryptographic JobTypical Algorithm TodayQuantum ImpactPost-Quantum Answer
Key establishmentRSA, ECDH (for example X25519)Broken by a large quantum computerML-KEM (FIPS 203)
Digital signaturesRSA, ECDSA, EdDSABroken by a large quantum computerML-DSA (FIPS 204) or SLH-DSA (FIPS 205)
Bulk encryptionAESWeakened, not brokenKeep AES; AES-256 for long-term data
HashingSHA-2, SHA-3Weakened, not brokenKeep SHA-2 or SHA-3 at suitable output sizes
Where the quantum threat lands. Public-key algorithms need replacing; symmetric algorithms and hashes stay, often at larger sizes.

The New Standards Are Ready

In August 2024 NIST published its first three post-quantum standards. FIPS 203 defines ML-KEM for key establishment. FIPS 204 defines ML-DSA for signatures, and FIPS 205 defines SLH-DSA, a second signature scheme built on different mathematics as a backup.3 NIST’s project page states that these standards “can and should be put into use now”.4

Two more are in preparation: FN-DSA, a compact signature scheme based on the Falcon submission, and HQC, a second key establishment scheme. NIST’s project page lists both as selected for standardisation, with that work under way.4 Later articles in this section cover each standard, how NIST chose them, and what they cost in size and speed.

Why The Work Starts Now

NIST’s draft transition guidance, published in November 2024, notes that no cryptographically relevant quantum computer exists yet, meaning no machine able to break the public-key cryptography in use today.2 So the timing can seem early. There are three reasons to move anyway, and none of them depend on predicting the exact year such a machine arrives.

  1. Data Captured Today Can Be Read Later

    An attacker can record encrypted traffic now and decrypt it once a capable quantum computer exists. NIST's draft guidance names this harvest now, decrypt later threat directly.

  2. Some Systems Live For Decades

    Devices, firmware and embedded systems shipped this year may still be in service when the threat becomes real, and many cannot easily be updated.

  3. Migration Is Slow

    Finding every use of public-key cryptography, upgrading libraries, replacing certificates and testing partner systems takes years in a large organisation.

Three reasons organisations are told to start migrating before a quantum computer exists.

The first reason applies to confidentiality. NIST IR 8547 notes that information sent today with quantum-vulnerable key establishment is already at risk from adversaries who collect it now and decrypt it later.2 Our article on harvest now, decrypt later covers that risk in detail.

Signatures are a slightly different case. A forged signature only matters once someone can forge it, so there is no harvesting risk for signatures themselves. The problem is lifetime: a device that checks firmware signatures with RSA in 2035 is exposed, and that device may be shipping now.

NIST proposes, in its still-draft IR 8547, to deprecate quantum-vulnerable algorithms at the 112-bit security level after 2030 and disallow all of them in its standards after 2035.2 Several national roadmaps also point to 2035, as the Regulatory Deadline Tracker shows.

What Changes For Your Organisation

For most organisations, PQC arrives through upgrades to software they already use: TLS libraries, browsers, operating systems, VPNs, hardware security modules and certificate authorities. Several have already switched on post-quantum key establishment by default. OpenSSL 3.5, released in April 2025, offers the hybrid group X25519MLKEM768 among its default TLS key shares,5 and OpenSSH 10.0 made the hybrid mlkem768x25519-sha256 method its default in the same month.6 Our article on hybrid post-quantum cryptography covers more examples.

The harder part is everything that does not upgrade itself. That includes custom applications that call cryptographic libraries directly, long-lived devices, partner integrations and data stores protected by keys that were agreed with RSA. Government guidance usually puts discovery first: find out where and how you use cryptography. The UK National Cyber Security Centre (NCSC), for example, sets 2028 as the date by which organisations should finish discovery and draw up an initial migration plan.7 The Preparing For Migration section covers that work.

Footnotes

  1. NSA, “The Commercial National Security Algorithm Suite 2.0 and Quantum Computing FAQ”, version 2.1, December 2024. media.defense.gov ↩ ↩2

  2. NIST, IR 8547 (initial public draft), “Transition to Post-Quantum Cryptography Standards”, November 2024. nvlpubs.nist.gov ↩ ↩2 ↩3 ↩4 ↩5

  3. NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards”, 13 August 2024. nist.gov ↩

  4. NIST Computer Security Resource Center, “Post-Quantum Cryptography” project page, updated 5 August 2026. csrc.nist.gov ↩ ↩2

  5. OpenSSL Project, “NEWS for OpenSSL 3.5”, OpenSSL 3.5.0 entry, 8 April 2025. github.com ↩

  6. OpenSSH, “OpenSSH 10.0 release notes”, 9 April 2025. openssh.org ↩

  7. UK National Cyber Security Centre, “Timelines for migration to post-quantum cryptography”, 20 March 2025. ncsc.gov.uk ↩

Knowledge Hub content is general information. It is not legal advice, a compliance certification, a guarantee of security or a substitute for an assessment of your own systems. Standards and rules change; check the sources for the latest position.