A large, fault-tolerant quantum computer would be able to break the public-key cryptography — RSA and elliptic-curve algorithms — that protects most of today’s digital communication. Nobody knows exactly when such a machine will exist, but the work to prepare takes years, and some data is already at risk. That is why post-quantum cryptography (PQC) has moved from research topic to board-level agenda.
Why act before quantum computers arrive?
- Harvest now, decrypt later. Adversaries can record encrypted traffic today and decrypt it once quantum capability exists. Data that must stay confidential for many years — health records, financial data, intellectual property, government information — is exposed now.
- Migrations are slow. Cryptography is embedded in applications, protocols, devices, certificates, hardware security modules and third-party products. Previous transitions, such as retiring SHA-1, took many years.
- Timelines are being set. NIST has proposed deprecating today’s quantum-vulnerable public-key algorithms over the coming decade, and governments are publishing migration guidance and deadlines for their agencies and suppliers.
What NIST standardised
In August 2024 NIST published its first three post-quantum cryptography standards:
| Standard | Algorithm | Purpose |
|---|---|---|
| FIPS 203 | ML-KEM (based on CRYSTALS-Kyber) | Key establishment / encryption |
| FIPS 204 | ML-DSA (based on CRYSTALS-Dilithium) | Digital signatures |
| FIPS 205 | SLH-DSA (based on SPHINCS+) | Hash-based digital signatures |
Additional algorithms are being standardised as alternatives. Symmetric cryptography such as AES is far less affected; using sufficiently long keys (for example AES-256) is generally considered adequate.
Step 1: Build a cryptographic inventory
You cannot migrate what you cannot see. Identify where public-key cryptography is used: TLS on websites and APIs, VPNs, SSH, code signing, document signing, PKI and certificates, databases and storage encryption, identity systems, IoT devices and third-party software. Record the algorithm, key length, owner, and how long the protected data must stay confidential.
Step 2: Prioritise by risk
Rank systems by the sensitivity and lifetime of the data they protect, their exposure to the internet, and how hard they are to change. Long-lived confidential data in transit across public networks usually comes first; short-lived internal data can wait.
Step 3: Design for crypto-agility
Crypto-agility means being able to change algorithms and keys through configuration rather than code rewrites. Centralise cryptographic libraries and services, avoid hard-coded algorithms, and make certificate and key management automated. Agility protects you not only during the PQC transition but against future algorithm weaknesses too.
Step 4: Start with hybrid deployments
A common first step is hybrid key exchange, which combines a classical algorithm with ML-KEM so a connection stays secure as long as either remains unbroken. Major browsers, cloud providers and TLS libraries have begun supporting hybrid post-quantum key exchange, making it a practical way to protect data in transit early.
Step 5: Engage vendors and plan the long tail
Much of your cryptography lives inside products you buy. Ask vendors for their PQC roadmaps — especially for HSMs, PKI, VPNs, network equipment and critical SaaS — and build PQC requirements into new procurements. Plan for devices and systems that can’t be upgraded and will need replacement.
A realistic timeline
- First months: awareness, ownership, inventory tooling, vendor questionnaires.
- Year one: complete inventory for critical systems, roadmap, crypto-agility patterns, hybrid TLS pilots.
- Following years: phased migration by priority, PKI and signing upgrades, retirement of quantum-vulnerable algorithms in line with regulatory timelines.
Our Quantum Computing practice runs cryptographic inventories and PQC migration roadmaps — and helps teams explore quantum use cases on cloud quantum services.
This article is general information, not security or legal advice for your specific environment.
Frequently asked questions
What is post-quantum cryptography?
Post-quantum cryptography is public-key cryptography designed to resist attacks from future quantum computers while running on today's classical computers.
Which PQC standards has NIST published?
In August 2024 NIST published FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). Further algorithms are being standardised as alternatives.
Do we need to replace AES?
Generally no. Symmetric algorithms like AES are much less affected by quantum attacks; using adequately long keys such as AES-256 is the usual recommendation. The main priority is replacing quantum-vulnerable public-key algorithms like RSA and ECC.