Post-Quantum Cryptography: Building Quantum-Resistant Security
Post-quantum cryptography (PQC) refers to cryptographic algorithms designed to remain secure against attacks from both classical and quantum computers. As quantum computing advances, PQC is how organisations will keep data confidential, authentic and trustworthy in the long term.
What is post-quantum cryptography?
Post-quantum cryptography is a new generation of encryption and digital-signature algorithms built on mathematical problems believed to be hard even for quantum computers. Unlike quantum key distribution, PQC runs on today's classical hardware and can be deployed using existing infrastructure.
PQC is the practical path to 'quantum-safe' security for most organisations, because it can replace vulnerable algorithms within current systems.
The NIST PQC standards
The US National Institute of Standards and Technology (NIST) has standardised a first set of post-quantum algorithms after a multi-year global selection process. These standards give vendors and organisations a clear, vetted foundation for migration.
- ML-KEM (based on CRYSTALS-Kyber) for key encapsulation
- ML-DSA (based on CRYSTALS-Dilithium) for digital signatures
- SLH-DSA (based on SPHINCS+) as a hash-based signature alternative
Planning a PQC migration
Migrating to post-quantum cryptography is a multi-year programme, not a single switch. The goal is crypto-agility: the ability to update algorithms quickly as standards and threats evolve.
- Inventory all cryptographic assets and dependencies
- Identify high-value, long-lived data to migrate first
- Pilot hybrid schemes that combine classical and PQC algorithms
- Engage vendors on their PQC roadmaps
- Upskill teams and share lessons through community collaboration
Frequently asked questions
What is post-quantum cryptography?
Post-quantum cryptography (PQC) is a set of cryptographic algorithms designed to be secure against both classical and quantum computers. It runs on existing hardware and is the main route to quantum-safe security.
Is post-quantum cryptography the same as quantum cryptography?
No. Post-quantum cryptography uses classical algorithms resistant to quantum attacks and runs on normal computers. Quantum cryptography (such as quantum key distribution) relies on quantum physics and specialised hardware.
What are the NIST post-quantum cryptography standards?
NIST has standardised post-quantum algorithms including ML-KEM (Kyber) for key encapsulation and ML-DSA (Dilithium) and SLH-DSA (SPHINCS+) for digital signatures, giving organisations a vetted basis for migration.
When should organisations start migrating to PQC?
Now. Because migration takes years and 'harvest now, decrypt later' attacks threaten long-lived data, organisations should begin inventorying cryptography and planning a crypto-agile migration today.