Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Your business can start preparing for quantum-resistant cryptography now, without assuming that a quantum computer capable of breaking today’s public-key cryptography exists or is arriving on a known schedule. Begin by discovering where cryptography is used, prioritizing information that must remain confidential for years, and planning a tested transition with your technology suppliers.

The eight actions below are a practical migration framework, not an official NIST checklist or a set of products. NIST finalized three post-quantum cryptography standards on August 13, 2024, and says organizations should begin applying them. The standards address different cryptographic functions, so choosing the right one depends on what a system needs to do.

What post-quantum standards should a business plan around?

NIST’s finalized standards cover key establishment and digital signatures. They are designed to address risks from future quantum computers, but they are not interchangeable.

Standard Scheme Function
FIPS 203 ML-KEM Key establishment: enables parties to establish a shared secret over a public channel.
FIPS 204 ML-DSA Digital signatures: support authenticity and detection of unauthorized modification.
FIPS 205 SLH-DSA Digital signatures: a stateless hash-based scheme with a different mathematical approach from ML-DSA.

NIST announced the standards on August 13, 2024. FIPS 203 is derived from CRYSTALS-KYBER, FIPS 204 from CRYSTALS-Dilithium, and FIPS 205 from SPHINCS+. NIST describes SLH-DSA as a distinct approach and a backup method if ML-DSA proves vulnerable; that is not a claim that SLH-DSA is the best choice for every deployment. These descriptions are consistent with NIST’s announcement and its August 2024 overview of the standards.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

A key-encapsulation mechanism such as ML-KEM helps establish a shared secret; it is not a symmetric encryption cipher. The systems that use that secret still need appropriate encryption and protocol implementations.

What should a business do first to prepare?

1. Build a cryptographic inventory

Find where cryptography is used across applications, infrastructure, devices, and services. Record public-key algorithms, protocols, libraries, certificates, key-establishment paths, signing systems, and the suppliers responsible for them. Include dependencies you do not operate directly, such as cloud services, managed platforms, embedded equipment, and externally maintained software.

For each item, capture its business owner, technical owner, purpose, environment, supplier, upgrade path, and known cryptographic dependencies. Mark unknowns explicitly rather than treating an unverified product as ready. NIST’s National Cybersecurity Center of Excellence identifies cryptographic visibility, risk management, and a comprehensive inventory as migration work.

2. Prioritize by confidentiality lifetime and exposure

Identify information that must remain confidential long after it is created: for example, sensitive customer, health, legal, financial, or strategic records. Then consider where that information could be intercepted or collected while in transit or stored in systems outside your direct control.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Thetis Nano-C for Business - USB C FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • USB TYPE C Connectivity & DONGLE Design: Designed for PCs, Macs, laptops, iPhones, and Android devices that utilize a USB-C port. Plug and stay, or carry it on a keychain. (Item Size: 0.73 x 0.60 x 0.30 inches)
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC functionality is not supported.

“Harvest now, decrypt later” describes a risk scenario in which encrypted data is collected today in the hope that it can be decrypted later. It is a reason to examine long-lived confidentiality needs, not evidence that a cryptographically relevant quantum computer exists now or a basis for assigning a date or probability to its arrival. Use this assessment to rank migration work alongside your other security and business risks.

3. Design for cryptographic agility

Plan how your organization can change algorithms, certificates, libraries, and protocol choices without rebuilding every application. That may require configurable cryptographic components, managed key and certificate lifecycles, documented dependencies, and clear ownership of upgrade decisions.

Agility is an architectural goal, not a certification or guarantee attached to a particular product. Ask suppliers how their systems support algorithm changes, how those changes are delivered, and what parts of your integration would need updating. Avoid hard-coding a single algorithm choice into new designs when a maintainable, standards-based configuration is practical.

4. Map key establishment to ML-KEM (FIPS 203)

Once the inventory shows where systems establish shared secrets, assess whether and how those protocols and products can support ML-KEM. A KEM lets communicating parties establish a shared secret over a public channel; the protocol then uses that secret as part of its security design.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Sale
Thetis Nano-A FIDO2 Security Key Hardware Passkey Device with USB Type A, TOTP/HOTP, FIDO2.0 Two Factor Authentication 2FA MFA, Works with Windows/mac/iOS/Android/Linux/Gmail/Facebook/GitHub/Coinbase
  • Ultra-Compact FIDO2 Security Key - Plug-and-stay or carry on a keychain. This USB-A hardware security key offers portable, always-on protection for desktop and mobile use. (Item Size: 0.75 X 0.74 IN x 0.25 IN)
  • USB-A Hardware Key for All Devices - Works with USB-A ports on PC, Mac, Android, and other laptop/notebook device. Enables secure, cross-platform login with FIDO2.0 passkey support.
  • FIDO Certified Security Key - Meets FIDO and FIDO2 standards. Works with Google, Microsoft, GitHub, Dropbox, and more. Please check service compatibility before purchase.
  • Passwordless Login with Passkey - Supports passkey login via WebAuthn and CTAP2. Enjoy password-free sign-ins where supported. Not all websites or services currently support passkeys.
  • Advanced Multi-Factor Authentication - Offers 200 FIDO2 passkey slots and 50 OATH-TOTP slots. Strong, flexible 2FA/MFA support across various apps and authentication platforms.

Do not assume that a product supports FIPS 203 because it advertises “post-quantum” capability. Verify the implemented standard, supported protocol and configuration, interoperability with the other endpoint, and the supplier’s validation and update details before choosing a deployment path.

5. Map signature use to ML-DSA (FIPS 204)

Find systems that sign or verify software updates, documents, identities, certificates, messages, or other records. Evaluate ML-DSA for the signature role where the relevant applications, standards, and products support the finalized scheme.

Before deployment, confirm the application profile and lifecycle requirements: what is being signed, who verifies it, how keys are protected and rotated, and how signatures remain verifiable over time. A standards-based algorithm does not by itself resolve those operational questions.

6. Evaluate SLH-DSA (FIPS 205) where its different design matters

Consider SLH-DSA as a separate digital-signature option when its stateless hash-based construction fits the system’s needs or risk strategy. Its mathematical approach differs from ML-DSA, which may make it relevant to organizations considering diversity in signature mechanisms.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
Kensington VeriMark NFC+ USB‑C Security Key, FIDO2/WebAuthn Hardware Authenticator for Passwordless Login, Works with Windows, macOS & Chrome OS, K64739WW
  • USB-C or tap via NFC for easy authentication on any compatible device. No drivers needed; optional Kensington software available for advanced management features.
  • Works across Windows, macOS, iOS, Android, ChromeOS, and supports Passkeys and Apple ID.
  • Slim, keychain-ready form for easy carry and on-the-go authentication
  • IP68-rated for dependable performance
  • FIDO CTAP 2.1 for enhanced security features (e.g. resident credentials, Passkey support) and backwards compatibility with CTAP 2. FIDO2 L2 certified security for phishing resistant protection against identity theft and unauthorized access.

Compare the actual implementation and application requirements rather than treating one scheme as universally superior. Confirm support, performance, resource constraints, key and signature sizes, and operational suitability in the intended environment.

7. Test interoperability and operational effects

Test the full path, not just one library or endpoint. A change may affect both parties to a connection, certificate handling, message formats, network behavior, constrained devices, and systems that inspect or relay traffic.

  • Confirm both endpoints and required intermediaries support the selected algorithms and protocol profile.
  • Measure certificate, key, and signature sizes and check whether devices, gateways, and applications can handle them.
  • Measure latency and resource use under representative workloads.
  • Check logging, monitoring, backups, key management, certificate renewal, and incident-response procedures.
  • Define a rollback or recovery path and test it before production rollout.

NIST’s migration work identifies interoperability and benchmarking as areas to address. Results from a lab or vendor demonstration should not be assumed to represent your production environment.

8. Coordinate a staged rollout with suppliers and governance owners

Turn the inventory and test results into a sequence of changes with named owners. For each system, record supplier support, dependencies, validation requirements, planned change windows, exceptions, and the business team accountable for accepting residual risk.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Thetis PRO-A for Business - USB A FIDO2 Security Key L1 MFA & Passkey Access for School ERP, Employee Online Account, Compatible with Coinbase Google Workspace Apple ID Window Salesfore - 2 Pack
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Universal Connectivity (USB-A & NFC): The Thetis PRO-A features integrated USB Type A and NFC for a near-instant account unlock. Simply unfold the key and hold it to your smartphone’s NFC antenna to authenticate on the go.
  • Enhanced MFA (FIDO2 & TOTP/HOTP): Strengthen your security with flexible options. Use the Manager App to access TOTP/HOTP features for accounts that do not yet support FIDO2.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID. NFC is supported only through mobile authentication, Not MacOS/windows.

Ask suppliers for specific information: which finalized standards and versions are supported, when support is available, what configurations are required, what components or interfaces change, and how compatibility will be maintained. Schedule rollout in stages so that the organization can validate each change, address failures, and update dependent systems before expanding deployment.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How should a business set its migration timeline?

Set timing based on your inventory, data sensitivity, exposure, system dependencies, supplier roadmaps, and the time required to test safely. Start with discovery and ownership; then prioritize systems, confirm vendor and protocol support, run compatibility tests, and schedule controlled rollouts.

NIST’s IR 8547 page describes an initial public draft of transition guidance, published November 12, 2024. It should not be treated as a current final transition schedule or converted into a universal private-sector deadline. NIST’s post-quantum cryptography overview advises organizations to begin applying the finalized standards and identify where vulnerable algorithms are used, while planning replacements or updates.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.