The Quantum Threat is Here — Now
Quantum computers capable of breaking RSA and ECC are expected within the decade. But the threat is already active: adversaries are harvesting encrypted data today to decrypt later. Organizations must begin migrating to NIST-standardized post-quantum cryptography (PQC) algorithms immediately.
NIST PQC Standards (Finalized 2024)
ML-KEM
Module-Lattice-Based Key-Encapsulation Mechanism
ML-DSA
Module-Lattice-Based Digital Signature Algorithm
SLH-DSA
Stateless Hash-Based Digital Signature Algorithm
FN-DSA
FFT over NTRU-Lattice-Based Digital Signature Algorithm
Quantum Threat Timeline
Harvest Now, Decrypt Later
Nation-state actors are actively exfiltrating encrypted data today — to decrypt once quantum computers arrive. TLS sessions, VPN traffic, and email are primary targets.
NIST FIPS Standards Finalized
FIPS 203–206 are now final. CISA, NSA, and OMB have issued directives for federal agencies and critical infrastructure to begin migration inventories.
Federal Compliance Deadlines
NSA CNSA 2.0 mandates PQC for National Security Systems. OMB M-23-02 requires agencies to submit cryptographic inventories. Non-compliance risks contract and clearance implications.
NIST Deprecation Deadline
NIST plans to fully deprecate RSA, ECC, and classic DH by 2029. Systems still using legacy cryptography will be considered non-compliant.
Cryptographically-Relevant Quantum Computer
Conservative estimates suggest CRQC capable of breaking RSA-2048 may arrive between 2030–2035. Systems with long data-sensitivity lifespans need to be migrated now.
Cryptographic Algorithm Risk Assessment
Broken by Shor's algorithm — all RSA-encrypted data at risk
Elliptic curve discrete log problem solved by Shor's algorithm
Discrete log vulnerable — classic and finite field variants
Grover's algorithm halves effective key length to ~64-bit — upgrade to AES-256
128-bit quantum security margin — considered quantum-safe
~128-bit quantum collision resistance — acceptable for near-term
Quantum-safe — sufficient security margin against Grover
Key security halved by Grover — use HMAC-SHA384+ for long-term data
PQC Migration Roadmap
Cryptographic Inventory
ImmediateIdentify all systems, protocols, certificates, and data stores using RSA, ECC, or DH. Include third-party dependencies, APIs, and hardware security modules (HSMs).
Prioritize by Data Sensitivity
ImmediateRank assets by how long data needs to remain confidential. Classified, healthcare, financial, and IP data with 10+ year sensitivity windows are highest priority.
Adopt Hybrid Cryptography
6–12 monthsDeploy hybrid schemes combining classical (e.g. X25519) + PQC (ML-KEM) simultaneously. This provides protection against both classical attacks and quantum harvest attacks now.
Update PKI & Certificate Infrastructure
12–24 monthsReplace RSA/ECC root and intermediate CAs with ML-DSA or SLH-DSA. Update certificate lifecycle management, OCSP, and revocation infrastructure.
Update Protocols & Libraries
12–24 monthsMigrate TLS to support ML-KEM key exchange (TLS 1.3 + Kyber draft). Update OpenSSL, BoringSSL, or NSS. Patch SSH, IPsec/IKEv2, and S/MIME configurations.
Hardware & IoT Uplift
18–36 monthsEvaluate HSMs, TPMs, and embedded controllers for PQC support. Devices with 10+ year lifecycles (medical, industrial) require hardware replacement or secure enclave upgrades.
Information sourced from NIST, NSA, CISA, and public PQC research. Updated to reflect FIPS 203–206 final standards (August 2024).