Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Sometimes, but not in the way the question may suggest. Post-quantum cryptography (PQC) can add bytes to a connection’s public-key handshake and affect setup time, especially on slow or lossy networks. In a 2024 TLS 1.3 study, the increase in time to finish a transfer stayed below 5% on stable, high-bandwidth networks. PQC does not automatically make your documents, photos, or database records larger; the additional storage, where it applies, is for cryptographic material such as keys and signatures.

Where PQC can affect performance

PQC is designed to replace public-key cryptography that could be vulnerable to future quantum computers. It does not encrypt every application byte with a larger form of data. In protocols such as TLS, the most visible network cost is typically in key exchange and authentication material: public keys, ciphertexts, certificates, and signatures.

Those objects can be larger than familiar classical equivalents. Sending more bytes during connection setup can increase bandwidth use and, depending on the network and implementation, add delay. That does not mean every application will feel slower: the impact depends on how much data the connection sends, how often it establishes connections, whether keys are reused or cached, and network conditions.

What the TLS performance measurements show

A 2024 study by Panos Kampanakis and Will Childs-Klein measured TLS 1.3 connections with ML-KEM-768 and ML-DSA-44 or ML-DSA-65 authentication configurations. It found that the effect varied by network and transfer size:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • On stable, high-bandwidth networks, the increase in time-to-last-byte stayed below 5% in the study.
  • On stable, low-bandwidth networks, handshake time rose by 32%, but the time-to-last-byte increase was under 15% when the transfer was at least 50 KiB.

These are results for the study’s tested configurations and conditions, not a guarantee for all applications or networks. The researchers also found that the relative effect diminished as more data was transferred. Read the 2024 TLS 1.3 study.

Handshake time is not the same as total transfer time

Handshake time measures the connection setup. Time-to-last-byte includes setup and the transfer of a specified payload, making it a closer measure of how long that connection takes to complete. For a small request, setup can be a large part of the wait. For a larger transfer, the same extra handshake bytes are a smaller fraction of the total work.

When network conditions make the difference more noticeable

Bandwidth is only one factor. Latency, packet limits, packet loss, implementation, certificate-chain size, and whether a connection is reused can all affect the outcome. Larger handshake messages may be more exposed to packet loss and retransmission on unstable links. A mobile client, a constrained device, and a high-volume server can therefore have different bottlenecks.

Does PQC increase data storage requirements?

It helps to distinguish stored application data from cryptographic material and network traffic:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  • Files and database records: The available evidence does not establish that PQC generally makes users’ stored documents, images, messages, or other application payloads larger.
  • Cryptographic material: Some PQC public keys and signatures are larger than their classical counterparts. Systems that store many keys, certificates, or signatures may therefore need more space for those objects. The actual impact depends on the algorithms, parameters, and how the system stores them.
  • Network traffic: Larger key-exchange and authentication objects can increase handshake bytes. That is additional data sent over a connection, not automatically additional long-term application storage.

NIST’s evaluation criteria identify public-key, ciphertext, and signature sizes, alongside bandwidth, packet limits, caching, and operation efficiency, as factors to assess when selecting and deploying cryptography. Cached keys can make public-key size less important; protocols that frequently transmit new keys can be more sensitive. See NIST’s PQC evaluation criteria.

Why there is no single PQC performance figure

PQC is a family of approaches, not one algorithm with one cost profile. The TLS study’s numbers apply to its tested algorithms, parameters, configurations, payloads, and networks. They should not be read as a universal prediction for a website, app, or other protocol.

NIST says ML-KEM is its recommended general-encryption choice. It selected HQC as a backup based on different mathematics; NIST says HQC is longer and requires more computing resources than ML-KEM. HQC is not a replacement for the finalized standards or NIST’s recommended general-encryption choice. Read NIST’s HQC announcement.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What individuals and organizations should do

For individual users

PQC’s potential performance and storage costs are generally not a reason to change device settings or buy new hardware. The transition is handled through software, protocols, and services. Users may encounter changes as providers update their systems, but the sources do not establish that every application or service has already migrated.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

For organizations planning a migration

NIST says three PQC standards are finalized and ready to implement, and advises organizations to identify where vulnerable cryptography is used and plan replacements or updates. Standards groups, including the IETF, are incorporating PQC into protocols such as TLS; that does not mean every deployment has completed the transition. See NIST’s post-quantum cryptography program guidance.

For performance planning, test systems and networks that reflect real use rather than relying on one headline benchmark. Measure connection setup separately from application-level completion, and include constrained or lossy network paths. Also account for certificate and key sizes, connection reuse or caching, CPU costs, device limitations, and the volume and duration of traffic. NIST’s National Cybersecurity Center of Excellence provides migration resources for organizations. See the NCCoE’s crypto-agility project.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.