Blog

What is post quantum cryptography?

Post-quantum cryptography resists attack by quantum computers. The NIST standards, which algorithms are at risk and what to do before 2030.

Post-quantum cryptography (PQC) is a set of cryptographic algorithms designed to remain secure against attack by both classical and quantum computers. It is also described as quantum-safe or quantum-resistant cryptography — the terms mean the same thing.

It exists because a sufficiently powerful quantum computer would break the public-key algorithms that currently protect most digital communication. NIST published the first post-quantum standards in August 2024, and the transition away from today's algorithms is now a dated programme rather than a research topic.

This article covers what quantum computing actually threatens, which algorithms replace what, the timeline organisations are working to, and what to do first.

Key points

  • The threat is concentrated on asymmetric cryptography. RSA and elliptic curve are broken; AES-256 is not.
  • NIST standards are published: ML-KEM for key exchange, ML-DSA and SLH-DSA for signatures.
  • NIST deprecates RSA and ECC from 2030 and intends to disallow them by 2035. The NCSC expects UK migration plans by 2028.
  • The risk is current, not future, because encrypted data captured today can be decrypted later.

What quantum computing actually threatens

Quantum computers operate on qubits, which can represent multiple states simultaneously rather than the binary states classical computers use. That allows certain classes of mathematical problem to be solved far more efficiently than any classical machine could manage.

Two algorithms matter for cryptography, and they behave very differently.

Shor's algorithm breaks asymmetric cryptography

RSA depends on the difficulty of factoring large numbers. Elliptic curve cryptography depends on the difficulty of the discrete logarithm problem. Shor's algorithm solves both efficiently on a sufficiently capable quantum computer, which means RSA and ECC are broken rather than weakened.

Increasing key length does not help. A cryptographically relevant quantum computer breaks RSA-4096 as readily as RSA-2048.

That affects key exchange, digital certificates, digital signatures and identity verification — the entire basis of public key infrastructure.

Grover's algorithm weakens symmetric cryptography, but not fatally

Grover's algorithm provides a quadratic speedup for brute-force search, which effectively halves the strength of a symmetric key. AES-256 drops to 128 bits of post-quantum security, which remains computationally infeasible to attack.

This is the most misunderstood part of the subject. NIST has not proposed a replacement for AES because none is required. Your bulk data encryption is not the problem.

What this means in practice

The exposure is in key exchange and signatures, not in the encryption protecting data at rest. Which is why post-quantum readiness is a PKI and key management exercise before it is an encryption one.

The NIST post-quantum standards

After an eight-year evaluation process, NIST published its first three post-quantum standards in August 2024.

  • FIPS 203 — ML-KEM (derived from CRYSTALS-Kyber). A key encapsulation mechanism replacing RSA and Diffie-Hellman key exchange. Lattice-based. ML-KEM-768 public keys are approximately 1,184 bytes against 256 bytes for RSA-2048.
  • FIPS 204 — ML-DSA (derived from CRYSTALS-Dilithium). A digital signature algorithm replacing RSA and ECDSA signatures. Lattice-based, and the general-purpose signature recommendation. ML-DSA-65 public keys are 1,952 bytes and signatures 3,309 bytes.
  • FIPS 205 — SLH-DSA (derived from SPHINCS+). A hash-based signature scheme. Slower and with much larger signatures than ML-DSA, but built on entirely different mathematical assumptions — which makes it the fallback if a weakness is found in lattice-based approaches.

NIST has continued evaluating additional candidates beyond these, including HQC as a code-based alternative to ML-KEM, for the same reason SLH-DSA exists: algorithmic diversity protects against a single class of assumption failing.

The Internet Engineering Task Force is developing the protocol specifications that put these algorithms into practical use, covering TLS key exchange, certificate formats and hybrid constructions.

Our guide to navigating the NIST PQC roadmap covers the standards and the transition guidance in detail.

The practical consequence: size

Post-quantum keys and signatures are substantially larger than their classical equivalents — often by an order of magnitude. That has direct effects on certificate sizes, TLS handshake bandwidth, storage, and any protocol or device with fixed size constraints.

This is why migration is an infrastructure exercise rather than an algorithm swap, and why vendor claims about support and performance need separating. A platform can support ML-DSA and still not sustain your issuance volumes using it.

Harvest now, decrypt later

The quantum threat is already being exploited, which is the part most organisations underestimate.

Adversaries are capturing encrypted data with long-term value, storing it, and waiting. Once a quantum computer can break the key exchange that protected it, the data becomes readable retrospectively. This requires no future capability on the attacker's part — interception and storage are both possible with conventional technology today.

Any encrypted data transmitted now remains vulnerable if its confidentiality requirement extends beyond the arrival of that capability. Organisations in government, financial services, defence, healthcare and critical infrastructure carry the highest exposure because of the lifespan and sensitivity of the data they hold.

Our article on harvest now, decrypt later covers how to assess this exposure proportionately.

The counterpart threat

Where harvest now, decrypt later targets confidentiality, Trust Now, Forge Later targets authenticity. The ability to forge digital signatures would compromise firmware updates, contracts, certificates and identity assertions — and unlike the confidentiality threat, it requires no advance collection at all. Both belong in a complete assessment.

The timeline organisations are working to

Nobody can date the arrival of a cryptographically relevant quantum computer, and anyone presenting a firm figure is guessing. The dates that matter are regulatory, and they are published.

  • 2024 — NIST publishes FIPS 203, 204 and 205.
  • 2028 — the NCSC expects UK organisations to have completed discovery and produced a migration plan.
  • 2030 — NIST deprecates RSA and elliptic curve cryptography.
  • 2031 — the NCSC expects highest-priority migration activity to be complete.
  • 2035 — NIST intends to disallow RSA and ECC entirely. The NCSC expects migration complete. The G7 Cyber Expert Group has set the same date for financial services.

The 2028 date is the operative one for most organisations. Discovery across a large estate takes months, and a credible migration plan depends on having completed it.

Why crypto agility matters

Adopting quantum-resistant cryptography is not a single change. Organisations need crypto agility: the ability to replace cryptographic algorithms quickly and safely.

That requires understanding current encryption methods, certificate usage, algorithm dependencies, PKI hierarchies and the cryptography designed into applications. Without it, organisations cannot retire current algorithms or migrate to post-quantum ones when required by regulators, standards bodies or security advisories.

It also matters beyond this transition. These standards are unlikely to be the last change — quantum computing will continue advancing, and cryptographic research does not stand still. Organisations that treat this as a destination rather than a capability will repeat the exercise.

Hybrid: the realistic transition path

Hybrid constructions combine a classical algorithm with a post-quantum one, so a session or signature remains secure if either holds.

For key exchange this is already deployable. Hybrid key exchange is supported in TLS 1.3 implementations and major browsers, and it protects against harvesting today without requiring every party to have migrated. For anything with long-lived confidentiality crossing an untrusted network, it is the most direct mitigation currently available.

For signatures the picture is more complicated, because a verifier that accepts either signature alone still trusts the classical one. That is a migration aid rather than a security control, and the distinction is worth establishing with any vendor claiming hybrid support.

Where to start

Preparing for post-quantum cryptography means assessing cryptographic assets, updating governance, modernising PKI and identifying where current algorithms are embedded in operational systems. In sequence:

1. Build the inventory

You cannot migrate cryptography you have not identified. A Cryptographic Bill of Materials catalogues every certificate, key, algorithm and library across the estate, providing the baseline without which migration planning is guesswork. Our guide to building a cryptographic inventory covers the methods.

2. Classify data by confidentiality lifespan

Existing classification tells you how sensitive data is now. This requires knowing how long it stays sensitive. Most organisations find the genuinely long-lived category is smaller than expected, which makes the work tractable.

3. Identify what cannot be changed

Operational technology, embedded devices, appliances with fixed firmware and third-party platforms outside your control. These determine the real shape of the programme, and finding them late is what turns a plan into a crisis.

4. Add crypto-agility to procurement

Every system bought or renewed from now should support algorithm and key length changes without redesign. This costs nothing to require today and is the most expensive thing to retrofit.

5. Deploy hybrid where it is available

For the highest-value data flows identified in step two, hybrid key exchange provides protection now rather than at the end of the programme.

Our guide to five practical steps to PQC readiness covers the governance side, and none of these steps require significant investment to begin.

How Unsung supports quantum readiness

Unsung specialises in PKI, cryptographic systems and digital trust. Our work spans discovery, design, implementation and managed services across complex, regulated and high-assurance environments.

We support organisations with cryptographic readiness assessments, identifying where existing algorithms are used and where quantum-resistant alternatives will be required. Our consultants design quantum-resilient PKI architectures, implement certificate lifecycle automation and support compliance with current and emerging standards.

As a vendor-neutral consultancy we work across the leading manufacturers to select appropriate technology and support crypto agility, cryptographic modernisation and secure transformation. Our consultants hold SC and DV clearance and deliver across central government, defence, financial services, healthcare and transport.

A PKI health check establishes the current position, and our PKI consultancy team takes the findings through to a phased migration plan — from initial inventory and risk assessment to hybrid deployment and production cutover.

Quantum computing is not a distant concept but a dated programme of work. Talk to our team about a readiness assessment.

Frequently Asked Questions

What is Post-Quantum Cryptography (PQC)?

Post-Quantum Cryptography encompasses cryptographic algorithms designed to resist attacks from both classical and quantum computers. Unlike current public-key systems vulnerable to quantum attacks, PQC algorithms are based on mathematical problems believed to be hard for quantum computers to solve.

When will quantum computers break current encryption?

While exact timelines are uncertain, experts estimate cryptographically relevant quantum computers (CRQCs) capable of breaking RSA and ECC could emerge within 10-15 years. However, the "harvest now, decrypt later" threat means organisations must act now to protect long-term sensitive data.

What PQC algorithms has NIST standardised?

NIST has standardised ML-KEM (formerly CRYSTALS-Kyber) for key encapsulation and ML-DSA (formerly CRYSTALS-Dilithium) for digital signatures. Additional algorithms including SLH-DSA (SPHINCS+) and FN-DSA (FALCON) are also part of the standardisation effort.

How should organisations prepare for PQC migration?

Preparation involves conducting cryptographic inventories, assessing quantum risk exposure, developing crypto-agility capabilities, piloting hybrid classical-PQC implementations, updating procurement policies, and creating migration roadmaps with realistic timelines.

What is hybrid cryptography in the PQC context?

Hybrid cryptography combines traditional algorithms (like RSA or ECC) with post-quantum algorithms in a single implementation. This approach provides protection against quantum attacks while maintaining compatibility and allowing continued confidence in well-tested classical algorithms during transition.
Author
Unsung Ltd
September 11, 2026
-
10 minutes