← All Terms

Post-Quantum Cryptography

PQC

Public-key encryption and signature algorithms designed to resist attack by a large quantum computer, standardised by NIST in 2024 to replace RSA and elliptic-curve cryptography.

Governance & Risk

Post-quantum cryptography is the set of algorithms built to replace RSA, Diffie-Hellman and elliptic-curve cryptography, which a large quantum computer running Shor’s algorithm would break. NIST published the first three standards in August 2024: ML-KEM (FIPS 203) for agreeing keys, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for digital signatures. They run on ordinary computers and rest on mathematical problems that quantum computers are not known to solve efficiently.

The algorithms are the easy part. The work is finding every place an organisation uses the old ones, in TLS connections, VPNs, certificates, code signing, identity tokens and the products of every supplier, and replacing them without breaking anything. Most deployments start with hybrid key exchange, which pairs ML-KEM with a classical algorithm so the connection stays secure if either one holds.

Symmetric encryption such as AES-256 is not part of the migration. It stays secure against quantum attack, so encrypted data at rest is mostly safe once the keys that protect it are exchanged and wrapped with post-quantum methods.