Quantum computing could eventually break widely used public-key cryptography, but cryptographically relevant quantum computers do not yet exist. The practical response underway is post-quantum cryptography (PQC): new algorithms designed to resist quantum attacks and run on conventional systems. Quantum cryptography can also mean quantum-enabled techniques such as quantum key distribution (QKD), which is different from PQC.
What are quantum cryptography and post-quantum cryptography?
Public-key encryption and digital signatures help protect confidentiality, authenticity, and integrity in digital communications. Large-scale, fault-tolerant quantum computers could use quantum algorithms to break some widely used cryptographic systems. A 2024 review by NIST researchers notes that such computers do not yet exist.
PQC uses algorithms designed to withstand quantum attacks while running in ordinary software, hardware, and protocols. “Quantum cryptography” is a broader term that may refer to techniques using quantum technologies or protocols, including QKD. The terms are related, but they do not describe the same migration approach.
Why does migration matter now?
Encrypted communications intercepted today could potentially be decrypted in the future—a concern often described as “harvest now, decrypt later.” The case for early preparation is strongest when information must remain confidential for many years or when an organization will need substantial time to inventory and update its systems. NIST researchers Liu and Moody describe this future-decryption risk in their 2024 review.
Do these 3 things before closing this tab:
1Repair Windows errors before they cause bigger problems2Fix the driver behind crashes, sound loss and screen glitches3Clear out junk files and repair common Windows errorsShopping ad
Which PQC standards has NIST finalized?
NIST finalized three PQC standards in 2024 and says they are ready for implementation. They serve different purposes and are not interchangeable:
| Standard | Function | Basis |
|---|---|---|
| FIPS 203, ML-KEM | Key encapsulation to establish shared secrets | Module lattice |
| FIPS 204, ML-DSA | Digital signatures | Module lattice |
| FIPS 205, SLH-DSA | Digital signatures | Stateless hash-based |
NIST describes development of the three standards as an eight-year effort; they were released on August 13, 2024. NIST says they are expected to form the foundation for most PQC deployments. In March 2025, NIST selected HQC for standardization as an additional key-encapsulation algorithm intended as a backup; it is separate from the three finalized standards. NIST’s overview, as accessed October 7, 2026, also reports that the HAWK development team withdrew that candidate after a vulnerability discovery in July 2026. NIST says this does not affect its finalized standards; this is a dated update, not a guarantee about future cryptanalysis.
Shopping ad
How can organizations prepare for PQC?
NIST’s NCCoE describes cryptographic discovery and interoperability testing as parts of migration work. A practical planning sequence is:
- Identify systems, services, devices, certificates, and protocols that use public-key cryptography.
- Build an inventory that records owners, protected data, dependencies, and how long the data must remain confidential.
- Prioritize systems based on data sensitivity and longevity, operational criticality, and migration complexity.
- Develop a roadmap for updating algorithms, products, protocols, and trust infrastructure.
- Test interoperability in a controlled environment and coordinate with vendors and standards bodies before production changes.
This sequence synthesizes NIST and NCCoE guidance; it is not a substitute for an organization’s engineering work or risk assessment. NIST’s Computer Security Resource Center project page summarizes a transition timeline under which quantum-vulnerable algorithms are to be deprecated and ultimately removed from NIST standards by 2035, with high-risk systems moving earlier. NIST IR 8547, which describes the transition, is an initial public draft—not a final regulation or a universal deadline for every organization.
Recommended Free Tools
How is QKD different from PQC?
QKD uses quantum technology in the key-distribution process. PQC, by contrast, updates public-key algorithms in conventional software, devices, and protocols. The cited sources describe QKD and other quantum-security techniques as active research, including experimental demonstrations of device-independent QKD, quantum memories, and device-independent random number generators. QKD is not a general-purpose replacement for PQC: the two approaches differ in how they work and what parts of cryptographic systems they address.
| Approach | What it does | Role in security |
|---|---|---|
| PQC | Uses quantum-resistant algorithms in conventional systems | Supports migration of key establishment and digital signatures |
| QKD | Uses quantum technology for key distribution | A distinct quantum-security technique; not a replacement for all PQC functions |
FAQ
Can a quantum computer break today’s encryption?
Large-scale, fault-tolerant quantum computers could break some widely used public-key cryptography, according to the 2024 NIST-authored review. Such computers do not yet exist, but preparing for the risk can take time.
Shopping ad
What is post-quantum cryptography?
PQC is cryptography designed to resist quantum attacks while running on conventional computing systems. NIST’s finalized standards include ML-KEM for key encapsulation and ML-DSA and SLH-DSA for digital signatures.
Is QKD the same as post-quantum cryptography?
No. QKD uses quantum technology in key distribution, while PQC uses new algorithms in conventional systems. They are distinct approaches.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallShopping ad
When should an organization start migrating?
NIST recommends that organizations begin applying its standards and migrating their systems. The urgency depends partly on how long protected data must remain confidential, the systems involved, and the time needed to make and test changes.
Quick Recap
Sources
- NIST, “Post-quantum cryptography”
- NIST Computer Security Resource Center, “Post-Quantum Cryptography”
- NIST NCCoE, “Migration to Post-Quantum Cryptography”
- Yi-Kai Liu and Dustin Moody, “Post-Quantum Cryptography, and the Quantum Future of Cybersecurity”
- NIST IR 8547 initial public draft, “Transition to Post-Quantum Cryptography Standards”





