Post-quantum cryptography (PQC) is a family of public-key algorithms for key establishment and digital signatures, designed to remain secure even against attackers with large, capable quantum computers. It runs on today’s ordinary hardware and software. The keys it helps establish are then used with symmetric encryption, as today. The goal is to replace the public-key methods, mainly RSA and elliptic-curve cryptography, that protect key exchange, certificates and signatures across the internet, because a sufficiently powerful quantum computer is expected to be able to break them.
At a glance
- PQC is new math for public-key cryptography, not a quantum technology; it runs on conventional computers.
- NIST approved its first three PQC standards in August 2024: FIPS 203, FIPS 204 and FIPS 205.
- The main concern is “harvest now, decrypt later”: data captured today could be decrypted once quantum computers are capable enough.
- Migration is mostly an inventory and vendor-upgrade project, since most cryptography lives inside products you buy.
- Timelines for both the quantum threat and government migration targets are uncertain and change; check current guidance.
What problem it solves
Much of the security of modern IT rests on public-key cryptography. When a browser connects to a website over Transport Layer Security (TLS), when a VPN sets up a tunnel, or when software updates are signed, algorithms such as RSA and elliptic-curve cryptography do the work. Researchers have long known that a large enough quantum computer could solve the math problems those algorithms rely on.
No one knows when such a machine will exist, but two facts make it a present-day planning issue. First, an attacker can record encrypted traffic today and store it until it can be decrypted, which matters for data that must stay confidential for many years, such as health records, intellectual property or government information. Second, replacing cryptography across an organization is slow: it is built into applications, network devices, certificates, hardware security modules (HSMs) and third-party services. PQC gives organizations replacement algorithms to move to before the threat becomes real.
How it works
New algorithms. Post-quantum algorithms are built on math problems that are believed to be hard for both classical and quantum computers, such as problems involving lattices or hash functions. NIST ran a multi-year public competition to select them. FIPS 203 (ML-KEM) covers key establishment, FIPS 204 (ML-DSA) covers digital signatures, and FIPS 205 (SLH-DSA) is a hash-based signature scheme.
Hybrid deployment. During the transition, many implementations combine a classical algorithm with a post-quantum one, so a connection stays secure as long as either holds. Some browsers, operating systems and cloud services already use hybrid key exchange for TLS.
Larger keys and signatures. Many post-quantum algorithms use bigger keys or signatures than the ones they replace, which can affect performance, bandwidth and older devices with limited memory.
Migration work. For most organizations, PQC adoption means building a cryptographic inventory (where public-key cryptography is used, and by which systems and vendors), ranking systems by how long their data needs to stay secret, asking vendors for their roadmaps, and updating public key infrastructure (PKI) and certificate lifecycle management processes so algorithms can be swapped more easily in future, often called crypto-agility.
When it matters for buyers
- When the board or auditors ask. Quantum risk increasingly appears in board and audit questions, and a documented inventory and roadmap is the usual answer. See our governance, risk and compliance overview for how risk programs are typically supported.
- When you hold long-lived sensitive data. The longer data must stay confidential, the more harvest-now-decrypt-later matters.
- When selling to government or regulated customers. Supplier questionnaires may ask about PQC plans; requirements vary by sector and country.
- When replacing long-lived equipment. Network devices, HSMs and embedded systems bought now may still be in service when PQC is expected; ask about upgrade paths.
- When renewing PKI or certificate platforms. It is a natural time to require support for new algorithms.
Questions to ask vendors
- Which NIST post-quantum algorithms do your products support today, and which are on the roadmap with dates?
- Do you support hybrid key exchange, and is it on by default?
- Can your products swap algorithms through configuration or a software update, or does it require new hardware?
- How do larger keys and signatures affect performance and compatibility with older clients?
- Can you help us inventory where cryptography is used in your product and in our environment?
- Which government or industry guidance are you aligning with?
How it differs from quantum computing and quantum cryptography
Post-quantum cryptography is defensive math that runs on ordinary computers. Quantum computing, including cloud access to quantum hardware through quantum computing as a service (QCaaS), is the technology that creates the threat, along with uses in research and optimization. Quantum cryptography, such as quantum key distribution, is a different approach that uses physical quantum effects and specialized hardware, often over dedicated fiber links, to exchange keys. PQC is the route most organizations are expected to take because it fits into existing software, networks and encryption practices.
