A plain-language but technically correct primer for security leaders and practitioners. Three parts: how today's cryptography works, what post-quantum cryptography is, and why your organization needs to act before a quantum computer arrives.
Cryptography protects three things: confidentiality (only the intended party can read the data), integrity (the data hasn't been altered), and authenticity (you're really talking to who you think you are). Nearly every modern system relies on two very different families of algorithms working together.
The same secret key both encrypts and decrypts. It is fast and used for the bulk of actual data encryption. The workhorse is AES (with key sizes 128 or 256 bits); message integrity comes from MACs such as HMAC, and hashing from the SHA-2 and SHA-3 families. The catch: both parties must already share the secret key.
Each party has a public key (shared freely) and a private key (kept secret). This solves the "how do two strangers agree on a secret over an open network?" problem and enables digital signatures. It underpins:
Diffie-Hellman (DH) and ECDH let two parties derive a shared symmetric key over a public channel.RSA, ECDSA, and EdDSA prove authenticity and integrity (code signing, certificates, documents).Public-key security rests on math problems that are easy to compute one way but believed to be infeasible to reverse on classical computers:
| Algorithm | Hard problem it relies on |
|---|---|
| RSA | Integer factorization — factoring a large number back into its two prime factors |
| Diffie-Hellman / DSA | Discrete logarithm problem |
| ECDH / ECDSA | Elliptic-curve discrete logarithm problem |
It is everywhere — often invisibly, inside products you don't control:
TLS/HTTPS, VPNs & IPsec, SSH, Wi-Fi (WPA), email transport, API calls, service mesh.
PKI & X.509 certificates, code signing, secure boot / firmware signing, SSO tokens, smartcards, TPMs.
Database TDE, disk/volume encryption, backups, object storage, secrets vaults, HSMs.
S/MIME & PGP email, blockchain/wallets, DRM, messaging (Signal protocol), payment (EMV, PCI).
Because the same primitives (RSA, ECC, DH) are embedded in all of these, a single algorithm becoming breakable has enormous blast radius — which is exactly the post-quantum problem.
Post-Quantum Cryptography (PQC) — also called quantum-resistant or quantum-safe cryptography — is a new generation of algorithms designed to run on today's ordinary computers while resisting attacks from both classical and future quantum computers. It is not quantum key distribution (QKD), which needs special hardware; PQC is just new math you deploy in software.
Two quantum algorithms matter, and they matter very differently:
A large, error-corrected quantum computer running Shor's algorithm can efficiently solve integer factorization and discrete logarithms. That breaks RSA, Diffie-Hellman, ECDH, and ECDSA entirely — the entire public-key layer. This is the core threat.
Grover's algorithm gives a quadratic speed-up on brute-force search, effectively halving the security of symmetric keys and hashes. The fix is simply larger sizes: AES-256 stays safe, AES-128 is weakened, and SHA-256/SHA-3 remain fine.
PQC replaces "factoring is hard" with other problems believed hard even for quantum computers:
| Family | Examples | Notes |
|---|---|---|
| Lattice-based | ML-KEM (Kyber), ML-DSA (Dilithium), FN-DSA (Falcon) | The primary choice — good balance of speed and size. Basis of the first NIST standards. |
| Hash-based | SLH-DSA (SPHINCS+), LMS, XMSS | Signatures only. Very conservative security (relies only on hash functions) but larger/slower — good for long-lived roots & firmware. |
| Code-based | HQC, Classic McEliece | Long-studied. HQC chosen as a backup KEM; McEliece has huge public keys but tiny ciphertexts. |
| Isogeny-based | SIKE (broken) | A cautionary tale: SIKE was a NIST finalist but was broken on a classical computer in 2022 — why diversity of families matters. |
In August 2024 NIST finalized the first three post-quantum standards, and selected a backup KEM in March 2025:
Module-Lattice Key-Encapsulation Mechanism (from CRYSTALS-Kyber). The default for key exchange — replacing ECDH/RSA key transport. Parameter sets: ML-KEM-512/768/1024.
Module-Lattice Digital Signature Algorithm (from CRYSTALS-Dilithium). The default for signatures — replacing RSA/ECDSA. Parameter sets: ML-DSA-44/65/87.
Stateless Hash-based Signatures (from SPHINCS+). A conservative backup signature for high-assurance / long-lived use such as firmware signing.
Also in the pipeline: HQC (a code-based backup KEM selected March 2025, standard expected ~2027) and FN-DSA / FIPS 206 (Falcon, a compact lattice signature, still in draft). Treat these as forthcoming, not yet deployable.
X25519MLKEM768.No cryptographically-relevant quantum computer exists yet. So why is every major government and cloud provider telling enterprises to start today? Three reasons.
An adversary doesn't need a quantum computer today to attack you today. They can capture and store your encrypted traffic now — VPN sessions, database backups, TLS flows — and simply wait. When a quantum computer arrives, they decrypt the archive retroactively. This means any data with a long confidentiality lifetime is already at risk right now: health records, financial and legal data, government secrets, intellectual property, biometrics, and long-lived keys.
"Q-Day" is the hypothetical day a quantum computer can break RSA-2048. Estimates range widely, but the direction of travel is what matters: authorities and vendors report that credible timelines have been pulled forward from the classic "2035+" figure, and the consistent official message is plan now, don't wait. You cannot schedule a multi-year migration around a threat whose arrival date you don't control.
Cryptographer Michele Mosca framed the risk as a simple inequality. Let:
If X + Y > Z, you have a problem: some of your data will still need protecting after the point at which it can be broken. Because you control only Y — the migration — the only lever you have is to start early and shrink it.
Beyond the threat itself, mandates are turning PQC into a hard requirement — see the deadline timeline and the migration guide for detail. In brief:
| When | Milestone | Source |
|---|---|---|
| 2027 | New U.S. national-security-system acquisitions must be quantum-resistant | NSA CNSA 2.0 |
| 2030 | 112-bit algorithms (RSA-2048, ECC P-256) deprecated for new federal systems | NIST IR 8547 (draft) |
| 2035 | Quantum-vulnerable algorithms disallowed; broad migration target | NIST IR 8547 / NSM-10 / EU roadmap |
| Annual | U.S. federal agencies must maintain a cryptographic inventory | OMB M-23-02 |
Even organizations outside these mandates inherit them through the supply chain: customers, partners, and procurement gates increasingly push PQC requirements downstream.
Move from understanding to action with a comprehensive, NIST-aligned migration process — and discovery methods for the hardest first step: finding where your cryptography actually lives.