Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

IoT security teams should start preparing for post-quantum cryptography (PQC) now, even though large, cryptographically relevant quantum computers do not yet exist. Devices often remain deployed for many years, and replacing public-key algorithms in firmware, gateways, certificates, cloud services and update systems can take longer than the cryptographic standards process. NIST says, “Organizations should begin applying these standards now to migrate their systems to quantum-resistant cryptography.” NIST’s PQC overview frames migration as a current planning and engineering task, not a project to begin only after a quantum computer demonstrates an attack.

What has NIST standardized?

On August 13, 2024, NIST approved three Federal Information Processing Standards for post-quantum cryptography. They cover different cryptographic jobs and are not interchangeable names for one encryption technology.

Standard Algorithm Purpose in an IoT system
FIPS 203 ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) Establishes a shared secret between parties communicating over a public channel. That secret can then protect a session with symmetric cryptography.
FIPS 204 ML-DSA (Module-Lattice-Based Digital Signature Algorithm) Provides digital signatures for authentication and for detecting unauthorized changes to data such as firmware or configuration.
FIPS 205 SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) Provides another standardized post-quantum signature option, also suited to authentication and integrity use cases.

Read the approval announcement and the standards’ scope in NIST’s August 13, 2024 announcement. A product that adds ML-KEM for session establishment still needs a post-quantum signature strategy for identities, secure boot and firmware signing.

Why IoT teams cannot wait for a quantum computer

Long-lived devices create a migration deadline of their own

An industrial controller, utility sensor, building-management gateway or vehicle component may remain in service for years. Procurement, certification, field access, firmware release cycles and replacement logistics can consume much of that life. Cryptography chosen today therefore has to account for the period in which data, identities and update paths will remain exposed.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Public-key cryptography appears in more places than the application payload

Inventory work should look beyond encrypted telemetry. Public-key algorithms may support device identity, certificate enrollment, secure boot, firmware signatures, onboarding, administrator access, gateway-to-cloud connections, remote management and software-update verification. A vulnerable algorithm in any of those trust paths can undermine an otherwise modern device.

NIST’s transition horizon is not a universal IoT cutoff

NIST’s PQC overview describes a transition in which quantum-vulnerable algorithms are deprecated and ultimately removed from NIST standards by 2035, with high-risk systems moving earlier. That is NIST’s transition timeline, not a single legal or technical deadline that automatically applies to every private IoT product or deployment. Organizations need schedules based on device lifetime, exposure, updateability and risk.

Are standards finalized the same as IoT implementation readiness?

No. The three FIPS standards are final, but that does not mean every endpoint, protocol stack, certificate service or hardware security module is ready to deploy them.

Rank #2
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

IoT spans very different platforms. A gateway with ample memory and reliable power has options that may not fit a coin-cell sensor, a low-cost endpoint or a controller with a fixed boot ROM. Network packet limits, certificate formats, processor capacity, power budgets, radio behavior, secure-element support and update mechanisms all affect the design. The right question is whether a particular device class and its surrounding system can implement, validate and operate the required algorithms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

An October 2024 NIST Internet of Things Advisory Board report said that, at that time, there were no candidate low-complexity post-quantum encryption algorithms that would work for smaller IoT devices and called for further research. This is a dated, qualified observation about constrained devices—not proof that no IoT product can use PQC today, nor a permanent conclusion about current implementations.

How to start a PQC readiness assessment

NIST’s migration work emphasizes cryptographic visibility, risk management, interoperability and benchmarking. Apply that approach by assessing each device class and deployment rather than declaring the whole IoT estate “PQC-ready” or “not ready.”

Rank #3
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
  1. Build a cryptographic inventory. Record algorithms, key types, certificates, libraries, protocol versions and trust anchors used by devices, gateways, mobile applications, cloud services, update servers and manufacturing systems. Include algorithms embedded in vendor components and boot firmware.
  2. Map each use to a security function. Mark whether public-key cryptography is used for key establishment, device authentication, secure boot, firmware signing, administrative access, onboarding, telemetry transport or management. This prevents a KEM replacement from being mistaken for a complete migration.
  3. Classify devices by constraints and service life. Capture processor and memory limits, power source, link characteristics, expected deployment duration, physical access, replacement cost and whether the device can receive authenticated firmware updates.
  4. Prioritize exposure and irreversibility. Move earlier on systems protecting safety, critical operations, sensitive long-lived data or large fleets that are difficult to visit. Give special attention to devices that cannot be updated or replaced without major disruption.
  5. Define a target architecture. Decide where ML-KEM, ML-DSA and/or SLH-DSA fit in the protocol, certificate, boot and signing designs. Specify key-generation ownership, trust-anchor rotation, downgrade behavior and how legacy devices coexist during a transition.
  6. Prototype on representative hardware. Measure memory use, code size, computation time, energy impact, message and certificate sizes, radio retries and boot or update duration under the intended workload. The available material does not establish universal IoT RAM, flash, latency or energy figures, so measurements must come from the actual device and protocol.
  7. Test the complete trust chain. Exercise device firmware, gateways, cloud endpoints, certificate authorities, provisioning tools, update services and monitoring. Confirm that algorithm negotiation, certificate validation, key rotation, recovery and revocation work across vendors and firmware generations.
  8. Document a replacement or containment plan. For endpoints that cannot accept the required algorithms, identify compensating controls, gateway termination, segmented operation, shortened service life or a physical replacement program. Record the decision and its review date.

What should be compared before choosing an implementation?

No single benchmarked PQC option can be declared best for all IoT endpoints from the available evidence. Engineering reviews should compare:

  • Device resource requirements and energy behavior under the real workload.
  • Protocol, certificate and secure-element compatibility.
  • Firmware updateability, rollback protection and trust-anchor rotation.
  • Expected service life, field-replacement difficulty and operational cost.
  • Interoperability with gateways, cloud services and neighboring legacy systems.
  • Validation status, implementation maturity and support for the organization’s required assurance level.
  • Effects on packet size, connection setup, boot time and radio reliability measured on the intended network.

These are assessment axes, not published conclusions that one algorithm or product wins every category.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How do interoperability and migration governance affect the result?

A PQC library installed on one endpoint does not secure a system by itself. A firmware signer, certificate authority, gateway, cloud API and update client must agree on algorithms, encodings, policy and lifecycle operations. Mixed fleets also need a controlled transition: devices may have different firmware generations, certificates and cryptographic capabilities.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

NIST’s Migration to Post-Quantum Cryptography project treats inventory, interoperability and benchmarking as explicit workstreams. Use those workstreams to assign ownership, establish test environments, track exceptions and collect evidence before changing production trust paths.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What timeline should an IoT organization use?

There is no one deadline for every IoT product. A practical schedule is risk-based:

  • Now: inventory public-key use, identify unupdateable and long-lived devices, and begin lab evaluation against the finalized FIPS standards.
  • Near term: test representative hardware and end-to-end interoperability; update procurement requirements and architecture decisions so new systems do not extend avoidable quantum-vulnerable dependencies.
  • Before high-risk deployments reach their next major refresh: deploy validated migration steps for identities, signatures, key establishment and update infrastructure.
  • Through 2035: align internal milestones with NIST’s stated objective to deprecate and ultimately remove quantum-vulnerable algorithms from its standards, while moving high-risk systems earlier.

For a discussion of organizational timelines, policies and standards, consult NIST’s Frequently Asked Questions about Post-Quantum Cryptography. Its dates and policy references should be applied according to the organization’s jurisdiction, contracts and sector requirements.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

Where does draft guidance fit?

NIST’s IR 8547, Transition to Post-Quantum Cryptography Standards, published as an initial public draft on November 12, 2024, outlines an expected move from quantum-vulnerable algorithms toward post-quantum signatures and key-establishment schemes. It is draft guidance, not a finalized transition standard. Teams can use it to anticipate direction while treating final requirements and dates as subject to change.

Can an HSM solve an IoT PQC problem?

A hardware security module is a purpose-built physical security device for protecting organizational keys and performing controlled cryptographic operations. NIST’s PQC FAQ includes HSMs in its migration discussion. An HSM can therefore matter in certificate-authority, firmware-signing or key-management infrastructure, but it is not an automatic PQC upgrade for a sensor or controller. Any HSM selection requires checking supported algorithms, interfaces, deployment design, assurance requirements and current availability against the organization’s architecture.

What “ready” should mean

An IoT deployment is meaningfully PQC-ready when its owners can locate quantum-vulnerable public-key uses, explain the risk of each device class, test suitable replacements on representative hardware, interoperate across the full trust chain and update or replace endpoints on a controlled schedule. NIST’s finalized standards provide the cryptographic foundation; inventory, engineering validation and lifecycle planning determine whether a real IoT system can use it safely.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.