Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Post-quantum cryptography (PQC) is a set of cryptographic algorithms designed to protect information from both conventional computers and sufficiently capable future quantum computers. It runs on the conventional computers we use today: the algorithms change, but the computers running them do not.

What does post-quantum cryptography mean?

“Post-quantum” describes the attacks these algorithms are designed to withstand, not the machines that use them. NIST explains that PQC algorithms use mathematical techniques and can run on today’s computers. They are intended to resist attacks from conventional computers as well as future quantum computers capable of threatening some of today’s public-key cryptography. NIST says it is not possible to predict exactly when—or even whether—such a computer will break current encryption. NIST’s PQC explainer provides its overview.

PQC is not quantum cryptography

PQC and quantum cryptography are different approaches. PQC uses mathematical algorithms as a defense against potential attacks by quantum computers; quantum cryptography is based on quantum physics. PQC does not require quantum hardware.

What are the first NIST post-quantum standards?

In August 2024, NIST released three principal finalized PQC standards. They address two different tasks: establishing shared secret keys and creating digital signatures.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Standard Purpose Mathematical family
FIPS 203, ML-KEM Key establishment: helps parties establish a shared secret key. Module-lattice-based
FIPS 204, ML-DSA Digital signatures: supports authentication and detection of unauthorized modification. Module-lattice-based
FIPS 205, SLH-DSA Digital signatures: supports authentication and detection of unauthorized modification. Stateless hash-based

These are the first three principal finalized standards, not the final word on every PQC option. NIST continues to evaluate additional algorithms as potential alternatives or backups. See the NIST post-quantum cryptography project for its standards and transition information.

If quantum computers that can break cryptography do not exist yet, why start now?

The arrival date of a cryptographically relevant quantum computer is unknown. But organizations cannot assume that migration will be immediate once the threat is established: NIST says integrating a newly standardized algorithm into information systems has historically taken 10 to 20 years. NIST’s explainer does not state a publication year for that estimate, so it should be understood as a historical range, not a current deadline or a forecast of when a quantum computer will arrive.

What is “harvest now, decrypt later”?

“Harvest now, decrypt later” describes the risk that an adversary could collect encrypted data today and keep it in the hope that future capabilities will make it readable. The concern is most relevant to information that must remain confidential for many years. It does not establish that all encrypted traffic is being collected, or that future decryption is guaranteed.

NIST’s project began with a broad evaluation effort: it says experts from dozens of countries submitted 69 candidate algorithms by the 2017 submission deadline, about a year after the project solicitation. The standards process and the time needed to update deployed systems help explain why planning is underway before a breaking quantum computer is available. Mathematician Dustin Moody, who leads NIST’s PQC standardization project, said: “We encourage organizations to begin their transition to these standards immediately to ensure their data remains secure in the quantum era,” NIST’s explainer.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How should an organization prepare for PQC?

NIST’s National Cybersecurity Center of Excellence (NCCoE) frames migration as work spanning hardware, software, and services. Its post-quantum cryptography migration project emphasizes discovering where cryptography is used, assessing risk, preparing replacement or update roadmaps, and testing interoperability. The exact sequence depends on an organization’s systems and dependencies; there is no one migration order that fits every organization.

  1. Build a cryptographic inventory. Find where public-key cryptography is used across hardware, software, services, and the systems that protect important data.
  2. Prioritize data and systems. Identify which information must remain confidential for many years and assess the importance and risk of the systems and dependencies that protect it.
  3. Plan updates with vendors and system owners. Ask which relevant standards are supported, what update plans exist, and how changes will affect dependent systems.
  4. Test interoperability before production changes. Validate that updated components work together in the relevant environment, and address compatibility issues before deployment.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What do the 2035 and U.S. federal deadlines mean?

NIST’s 2026 project page says its transition timeline aims to deprecate and ultimately remove quantum-vulnerable algorithms from NIST standards by 2035, with high-risk systems transitioning earlier. That is a standards-transition goal, not a prediction that quantum computers will arrive in 2035.

A separate U.S. Executive Order dated June 22, 2026 sets deadlines for covered federal systems. For covered high-value assets and high-impact systems—excluding National Security Systems in the referenced section—it directs transition to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. These dates apply to the order’s specified federal scope; they are not universal deadlines for private companies or other countries. The White House Executive Order sets out the directives.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.