Post-Quantum Cryptography

The Quantum Threat is Here — Now

Quantum computers capable of breaking RSA and ECC are expected within the decade. But the threat is already active: adversaries are harvesting encrypted data today to decrypt later. Organizations must begin migrating to NIST-standardized post-quantum cryptography (PQC) algorithms immediately.

Quantum Threat Timeline

Now

Harvest Now, Decrypt Later

Nation-state actors are actively exfiltrating encrypted data today — to decrypt once quantum computers arrive. TLS sessions, VPN traffic, and email are primary targets.

2025–2026

NIST FIPS Standards Finalized

FIPS 203–206 are now final. CISA, NSA, and OMB have issued directives for federal agencies and critical infrastructure to begin migration inventories.

2026–2028

Federal Compliance Deadlines

NSA CNSA 2.0 mandates PQC for National Security Systems. OMB M-23-02 requires agencies to submit cryptographic inventories. Non-compliance risks contract and clearance implications.

2029

NIST Deprecation Deadline

NIST plans to fully deprecate RSA, ECC, and classic DH by 2029. Systems still using legacy cryptography will be considered non-compliant.

2030+

Cryptographically-Relevant Quantum Computer

Conservative estimates suggest CRQC capable of breaking RSA-2048 may arrive between 2030–2035. Systems with long data-sensitivity lifespans need to be migrated now.

Cryptographic Algorithm Risk Assessment

RSA (all key sizes)
critical

Broken by Shor's algorithm — all RSA-encrypted data at risk

ECC / ECDSA / ECDH
critical

Elliptic curve discrete log problem solved by Shor's algorithm

Diffie-Hellman (DH)
critical

Discrete log vulnerable — classic and finite field variants

AES-128
medium

Grover's algorithm halves effective key length to ~64-bit — upgrade to AES-256

AES-256
low

128-bit quantum security margin — considered quantum-safe

SHA-256
low

~128-bit quantum collision resistance — acceptable for near-term

SHA-384 / SHA-512
none

Quantum-safe — sufficient security margin against Grover

HMAC-SHA256
low

Key security halved by Grover — use HMAC-SHA384+ for long-term data

PQC Migration Roadmap

1

Cryptographic Inventory

Immediate

Identify all systems, protocols, certificates, and data stores using RSA, ECC, or DH. Include third-party dependencies, APIs, and hardware security modules (HSMs).

2

Prioritize by Data Sensitivity

Immediate

Rank assets by how long data needs to remain confidential. Classified, healthcare, financial, and IP data with 10+ year sensitivity windows are highest priority.

3

Adopt Hybrid Cryptography

6–12 months

Deploy hybrid schemes combining classical (e.g. X25519) + PQC (ML-KEM) simultaneously. This provides protection against both classical attacks and quantum harvest attacks now.

4

Update PKI & Certificate Infrastructure

12–24 months

Replace RSA/ECC root and intermediate CAs with ML-DSA or SLH-DSA. Update certificate lifecycle management, OCSP, and revocation infrastructure.

5

Update Protocols & Libraries

12–24 months

Migrate TLS to support ML-KEM key exchange (TLS 1.3 + Kyber draft). Update OpenSSL, BoringSSL, or NSS. Patch SSH, IPsec/IKEv2, and S/MIME configurations.

6

Hardware & IoT Uplift

18–36 months

Evaluate HSMs, TPMs, and embedded controllers for PQC support. Devices with 10+ year lifecycles (medical, industrial) require hardware replacement or secure enclave upgrades.

Information sourced from NIST, NSA, CISA, and public PQC research. Updated to reflect FIPS 203–206 final standards (August 2024).