What Is PQC (Post-Quantum Cryptography)?

Also called: Quantum-safe encryption, Quantum-resistant cryptography, Quantum-safe cryptography

Related problems: Board or auditors asking what our plan is for quantum computing risk; Don't know where we use public-key encryption or which systems would need to change; Sensitive data with a long shelf life that could be recorded now and decrypted later; Vendors and government customers starting to ask about quantum readiness

Post-quantum cryptography (PQC) is a family of public-key algorithms for key establishment and digital signatures, designed to remain secure even against attackers with large, capable quantum computers. It runs on today’s ordinary hardware and software. The keys it helps establish are then used with symmetric encryption, as today. The goal is to replace the public-key methods, mainly RSA and elliptic-curve cryptography, that protect key exchange, certificates and signatures across the internet, because a sufficiently powerful quantum computer is expected to be able to break them.

At a glance

  • PQC is new math for public-key cryptography, not a quantum technology; it runs on conventional computers.
  • NIST approved its first three PQC standards in August 2024: FIPS 203, FIPS 204 and FIPS 205.
  • The main concern is “harvest now, decrypt later”: data captured today could be decrypted once quantum computers are capable enough.
  • Migration is mostly an inventory and vendor-upgrade project, since most cryptography lives inside products you buy.
  • Timelines for both the quantum threat and government migration targets are uncertain and change; check current guidance.

What problem it solves

Much of the security of modern IT rests on public-key cryptography. When a browser connects to a website over Transport Layer Security (TLS), when a VPN sets up a tunnel, or when software updates are signed, algorithms such as RSA and elliptic-curve cryptography do the work. Researchers have long known that a large enough quantum computer could solve the math problems those algorithms rely on.

No one knows when such a machine will exist, but two facts make it a present-day planning issue. First, an attacker can record encrypted traffic today and store it until it can be decrypted, which matters for data that must stay confidential for many years, such as health records, intellectual property or government information. Second, replacing cryptography across an organization is slow: it is built into applications, network devices, certificates, hardware security modules (HSMs) and third-party services. PQC gives organizations replacement algorithms to move to before the threat becomes real.

How it works

New algorithms. Post-quantum algorithms are built on math problems that are believed to be hard for both classical and quantum computers, such as problems involving lattices or hash functions. NIST ran a multi-year public competition to select them. FIPS 203 (ML-KEM) covers key establishment, FIPS 204 (ML-DSA) covers digital signatures, and FIPS 205 (SLH-DSA) is a hash-based signature scheme.

Hybrid deployment. During the transition, many implementations combine a classical algorithm with a post-quantum one, so a connection stays secure as long as either holds. Some browsers, operating systems and cloud services already use hybrid key exchange for TLS.

Larger keys and signatures. Many post-quantum algorithms use bigger keys or signatures than the ones they replace, which can affect performance, bandwidth and older devices with limited memory.

Migration work. For most organizations, PQC adoption means building a cryptographic inventory (where public-key cryptography is used, and by which systems and vendors), ranking systems by how long their data needs to stay secret, asking vendors for their roadmaps, and updating public key infrastructure (PKI) and certificate lifecycle management processes so algorithms can be swapped more easily in future, often called crypto-agility.

When it matters for buyers

  • When the board or auditors ask. Quantum risk increasingly appears in board and audit questions, and a documented inventory and roadmap is the usual answer. See our governance, risk and compliance overview for how risk programs are typically supported.
  • When you hold long-lived sensitive data. The longer data must stay confidential, the more harvest-now-decrypt-later matters.
  • When selling to government or regulated customers. Supplier questionnaires may ask about PQC plans; requirements vary by sector and country.
  • When replacing long-lived equipment. Network devices, HSMs and embedded systems bought now may still be in service when PQC is expected; ask about upgrade paths.
  • When renewing PKI or certificate platforms. It is a natural time to require support for new algorithms.

Questions to ask vendors

  • Which NIST post-quantum algorithms do your products support today, and which are on the roadmap with dates?
  • Do you support hybrid key exchange, and is it on by default?
  • Can your products swap algorithms through configuration or a software update, or does it require new hardware?
  • How do larger keys and signatures affect performance and compatibility with older clients?
  • Can you help us inventory where cryptography is used in your product and in our environment?
  • Which government or industry guidance are you aligning with?

How it differs from quantum computing and quantum cryptography

Post-quantum cryptography is defensive math that runs on ordinary computers. Quantum computing, including cloud access to quantum hardware through quantum computing as a service (QCaaS), is the technology that creates the threat, along with uses in research and optimization. Quantum cryptography, such as quantum key distribution, is a different approach that uses physical quantum effects and specialized hardware, often over dedicated fiber links, to exchange keys. PQC is the route most organizations are expected to take because it fits into existing software, networks and encryption practices.

Frequently Asked Questions

Do we need quantum computers to use post-quantum cryptography?
No. Post-quantum algorithms run on ordinary computers, servers and network devices. They are math designed to be hard for both classical and quantum computers to break, so they can be deployed in today's software and hardware.
When will quantum computers break today's encryption?
Nobody can say with confidence. Estimates vary widely and change as research progresses. Because migrating cryptography across an organization takes years, many security bodies recommend starting the inventory and planning work now rather than waiting for a firm date.
Has NIST published post-quantum standards?
Yes. In August 2024 NIST approved its first three post-quantum standards: FIPS 203 (ML-KEM, for key establishment), FIPS 204 (ML-DSA, for digital signatures) and FIPS 205 (SLH-DSA, a hash-based signature scheme). More are in development, so check NIST for the current list.
Is there a deadline for moving to post-quantum cryptography?
It depends on your sector and country. Some governments have published migration targets for their own agencies and suppliers, and those targets vary and have changed over time. Check current guidance from the relevant authority, and ask large customers what they expect from suppliers.
Does post-quantum cryptography replace AES?
Mostly not. The main quantum threat is to public-key algorithms such as RSA and elliptic-curve cryptography, which are used to exchange keys and sign data. Symmetric encryption such as AES is considered far less affected, though some guidance recommends longer key lengths.

You Don’t Need Another Sales Call. You Need an Answer.

30 minutes. No pitch. Just an honest conversation about where you are, what you need, and whether working together makes sense.

We use your details to set up and prepare for the call, and send the newsletter only if you ask for it. Privacy policy.