Blog

PQC Explained: Why Every Cipher Has an Expiry Date

Every cipher eventually fails. See how DES, MD5 and SHA-1 fell, how long each took, and why the ability to break encryption is a question of when.

Why every encryption algorithm eventually fails

Every cryptographic algorithm has a finite service life. Advances in cryptanalysis, growth in available computing power, and flaws found in implementation steadily reduce the cost of attack until the algorithm no longer provides the security margin it was designed for. The ability to break encryption is a question of when, not whether.

What is cryptographic obsolescence?

Cryptographic obsolescence is the process by which an algorithm ceases to provide its intended security margin and must be withdrawn from use. It is a normal part of the lifecycle of every cipher, hash function and signature scheme, and it is anticipated by the standards bodies that publish them.

Algorithms are designed to resist attack by the computing power and mathematical techniques expected over a defined period, usually two to three decades. They are not designed to last indefinitely. NIST maintains explicit transition schedules for this reason, and publishes them in SP 800-131A, which sets out when specific key lengths and algorithms move from acceptable, to deprecated, to disallowed.

The practical consequence is that an organisation's cryptographic estate is a depreciating asset. Algorithms that were compliant when deployed become deprecated during the service life of the systems that use them.

What it means to break encryption in practice

An algorithm is rarely broken in a single event. In almost every case the security margin erodes across three distinct mechanisms, and the point at which the algorithm is formally withdrawn arrives years after the first credible warning.

Mathematical cryptanalysis

Researchers find a method that recovers keys, or produces collisions, at a cost significantly below brute force. The first result is usually theoretical and expensive. It establishes that the algorithm no longer delivers its advertised strength, even if no one can yet exploit it.

Growth in available computation

Attacks that were economically infeasible become routine. Brute force against a 56-bit key required specialist hardware in 1998 and is trivial today. Key lengths and hash outputs that were adequate for a given threat model become inadequate without any new mathematics being discovered at all.

Implementation and protocol failure

The algorithm may remain sound while the way it is used does not. Padding oracle attacks, weak random number generation, downgrade attacks and misuse of block cipher modes have all forced withdrawals. These failures are frequently faster and more damaging than pure cryptanalysis, because they are exploitable immediately.

A record of algorithms already withdrawn

The pattern is consistent and well documented. The table below records the interval between the first significant published weakness and the practical break, and the point at which the algorithm was formally disallowed.

A record of algorithms already withdrawn

Two patterns emerge. First, the warning is always published well before the break. In the case of SHA-1, twelve years separated the 2005 cryptanalysis from the 2017 collision, and certificate authorities had ceased issuance a year before the collision was demonstrated. Second, formal withdrawal follows the practical break, not the theoretical one, which means organisations relying on compliance deadlines as their trigger are structurally late.

Post-quantum algorithms are subject to the same pattern

Candidate replacements have already failed. During the NIST standardisation process, two algorithms that had progressed a long way were broken by classical mathematics rather than by quantum computers. Rainbow, a signature finalist, was broken by Ward Beullens in 2022 using a laptop over a weekend. SIKE, a fourth-round key encapsulation candidate, was broken by Castryck and Decru in the same year, in approximately one hour on a single classical core.

Neither failure invalidates the standardisation process; both demonstrate that it works. The relevant point for planning is that ML-KEM, ML-DSA and SLH-DSA are subject to the same lifecycle as every algorithm before them. They are the current best answer, not a permanent one. NIST's selection of HQC as a backup key encapsulation mechanism, based on different mathematical assumptions to ML-KEM, is an explicit acknowledgement of that risk.

Why the quantum threat is the same pattern at a different scale

Shor's algorithm was published in 1994. The mathematics that will break RSA and elliptic curve cryptography has therefore been public for over three decades, which makes this the longest advance warning in the history of applied cryptography.

What differs is scope. Previous transitions replaced one algorithm at a time, usually with a drop-in successor of similar key size and performance. The move to post-quantum cryptography replaces an entire class of asymmetric algorithms simultaneously, with successors that have materially different key sizes, signature sizes and performance characteristics. Symmetric cryptography is affected differently: Grover's algorithm reduces effective strength, which is addressed by using AES-256 rather than by replacing AES.

The consequence is that the migration cannot be treated as a like-for-like substitution, and the timelines that applied to previous algorithm retirements are not a useful guide.

Migration always takes longer than the break

The recurring failure in every historical transition is not detecting the weakness. It is completing the migration afterwards.

In practice, algorithms persist in production long past their withdrawal date because they are embedded in places the organisation cannot see. MD5 and SHA-1 continued to appear in internal certificate authorities, appliance firmware, legacy integrations and hardcoded trust stores for years after browser and certificate authority deadlines had passed. On assessment engagements it is common to find deprecated algorithms still in active use, not because a decision was taken to retain them, but because no inventory existed that would have identified them.

That is the operational lesson. The organisations that completed the SHA-1 transition cleanly were those that already knew where their certificates and cryptographic dependencies were. The organisations that struggled spent most of the transition period on discovery rather than on migration.

A current cryptographic inventory is what converts an algorithm withdrawal from a programme into a change request.

Designing for obsolescence rather than against it

Because obsolescence is certain, the durable control is not algorithm choice but the ability to change algorithms. This is crypto agility, and it has several concrete requirements.

Systems should reference cryptographic classes rather than named algorithms, so that the underlying primitive can be substituted without changing application logic. Certificate lifetimes should be short enough that a rotation clears the estate within an acceptable window, which is one reason public TLS lifetimes continue to fall. Cryptographic parameters should be held in configuration rather than compiled into binaries. Suppliers should be contractually required to state their algorithm support and upgrade path.

An organisation with these properties treats an algorithm withdrawal as a scheduled operation. An organisation without them treats it as an incident, every time.

Common misconceptions

The first is that an algorithm is safe until a practical break is demonstrated. It is not. The security margin is reduced at the point the cryptanalysis is published, and adversaries with resources are not obliged to publish their results.

The second is that longer keys solve the problem. Increasing key length addresses erosion from computing power. It does not address structural cryptanalysis, and it does nothing against Shor's algorithm, which scales polynomially rather than exponentially in key size.

The third is that compliance deadlines mark the point at which action is required. They mark the point at which use becomes non-compliant, which is the end of the migration window rather than the start of it.

The fourth is that an algorithm removed from new deployments has been removed from the estate. Withdrawal from procurement and removal from production are separated by the full service life of the systems already deployed.

How Unsung helps

Unsung is a UK-based, vendor-neutral consultancy specialising exclusively in public key infrastructure and cryptographic systems, working across central government, defence, healthcare, financial services and critical national infrastructure.

We identify where deprecated and quantum-vulnerable algorithms remain in use through our PKI health check and cryptographic bill of materials services, then design the target architecture and certificate lifecycle management capability required to make future algorithm changes routine rather than exceptional.

For the timing question that follows from this one, see our analysis of the three timelines used in quantum risk assessment.

‍

Frequently asked questions

Can quantum computers break all encryption?

No. Shor's algorithm breaks RSA, ECDSA, ECDH and Diffie-Hellman, which rely on integer factorisation or discrete logarithms. Grover's algorithm weakens symmetric ciphers and hash functions, but only by reducing effective strength, which AES-256 and SHA-384 already accommodate. Symmetric cryptography requires review of key length, not replacement.

How long does it take to break encryption once a weakness is published?

Historically between five and fifteen years from the first cryptanalytic result to a demonstrated practical break. SHA-1 took twelve years, MD5 took eight. The interval is shortening as computing power becomes cheaper to rent, and it provides no guarantee, since non-public advances are not announced.

Is AES-256 going to become obsolete?

Eventually, though not on current evidence and not because of quantum computing. Grover's algorithm halves the effective key strength of a symmetric cipher, leaving AES-256 with a 128-bit security level, which remains sound. AES-256 is the recommended symmetric algorithm under NIST and NCSC post-quantum guidance.

Why were Rainbow and SIKE removed from the NIST process?

Both were broken by classical cryptanalysis during the standardisation process, in 2022. Rainbow fell to an attack by Ward Beullens, and SIKE to work by Castryck and Decru that recovered keys in about an hour on a single processor core. Public scrutiny found the flaws before the algorithms were standardised.

Do I need to remove deprecated algorithms if nothing has been exploited?

Yes. Deprecated algorithms are non-compliant under NIST SP 800-131A and equivalent guidance, and their presence is usually a finding at audit. More practically, an algorithm still present in production has not been inventoried, which means the estate cannot be migrated predictably when the next transition arrives.

What is the difference between deprecated and disallowed?

Deprecated means the algorithm may still be used, with the associated risk accepted and documented, usually for a defined transition period. Disallowed means use is no longer permitted for the stated purpose. NIST publishes both statuses, with dates, in SP 800-131A.
Author
Unsung Ltd
September 16, 2026
-