Skip to content

What Is Post-Quantum Cryptography: NIST Standards and Migration Guide

Post-quantum cryptography (PQC): FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA. NIST standards that replace RSA and ECC before quantum computers break them.

Concept diagram explaining Post-Quantum Crypto: lattice-based, hash-based, key exchange, migration.

Post-quantum cryptography is a family of cryptographic algorithms that resist attacks from quantum computers. Where today's public-key cryptography derives its security from problems classical machines cannot solve in practical time, a sufficiently powerful quantum computer changes those odds. Shor's algorithm, in particular, can factor large integers and solve discrete-logarithm problems exponentially faster than any classical approach, making the quantum threat to current encryption concrete rather than theoretical. NIST finalized three post-quantum cryptography (PQC) standards in August 2024, giving organizations concrete migration targets for the first time.

Why Quantum Computers Threaten Current Encryption

Quantum computers running Shor's algorithm can factor the large integers that underpin RSA and break the discrete-logarithm problems that secure elliptic-curve cryptography (ECC). Public-key cryptography, including RSA and ECC, derives its hardness from computational problems that classical computers cannot solve at scale. A cryptographically relevant quantum computer changes that calculus. For context on how quantum hardware achieves this, the classical vs quantum computing fundamentals article explains how quantum superposition and entanglement enable this class of speedup.

The quantum threat is not limited to RSA. Any system that relies on integer factorization or discrete logarithms, including Diffie-Hellman key exchange and most ECC variants, is vulnerable. The practical question for security architects is not whether quantum hardware will eventually be powerful enough, but how long it will take. The Shor's algorithm and Grover's algorithm compared explainer details each algorithm's actual complexity and the scale of quantum hardware required.

Systems most at risk today include:

  • Long-lived government communications encrypted with RSA or ECC key exchange
  • Financial transaction records signed with elliptic-curve cryptography
  • Medical records transmitted over TLS sessions using classical key agreement
  • Critical infrastructure control channels secured with public-key cryptography
  • Software supply-chain artifacts protected by RSA or ECC digital signatures

How Post-Quantum Cryptography Works

Post-quantum cryptography builds security on mathematical problems that quantum computers cannot solve efficiently, most notably the shortest-vector problem in high-dimensional lattices. Lattice-based cryptography is the dominant family among the NIST-standardized approaches because lattice problems remain hard for both classical and quantum adversaries. The core intuition is that finding the shortest vector in a lattice of high dimension requires exponential time regardless of the computational model used.

Several mathematical families underpin PQC, each offering different performance and security tradeoffs:

Lattice-based cryptography
Relies on the hardness of the Learning With Errors (LWE) and Module-Lattice problems. Enables both key encapsulation mechanisms and digital signatures. Forms the basis of FIPS 203 and FIPS 204.
Hash-based signature schemes
Build digital signatures entirely from cryptographic hash functions, whose quantum resistance is well understood. Security depends only on the collision resistance of the underlying hash. Forms the basis of FIPS 205.
Code-based cryptography
Relies on the hardness of decoding random linear codes, a problem studied since the 1970s. Slower and produces larger keys than lattice schemes, but carries a long security pedigree.
Multivariate cryptography
Bases security on the difficulty of solving systems of multivariate polynomial equations over finite fields. Primarily used for signatures; not among the three finalized NIST standards.

Among these families, lattice-based cryptography achieves the best balance of key size, ciphertext size, and computational speed, which is why NIST selected it for two of its three finalized standards. Hash-based signatures carry a different appeal: their security reduces entirely to the collision resistance of a well-audited hash function, making the security argument simpler to verify. A hash-based signature scheme produces larger signatures than lattice alternatives, but that tradeoff is acceptable for applications where long-term auditability matters more than bandwidth.

The Three NIST PQC Standards Published in August 2024

In August 2024, NIST approved its first three post-quantum cryptography standards, establishing concrete migration targets for government and industry. The three finalized standards are FIPS 203, FIPS 204, and FIPS 205, collectively covering key encapsulation and digital signatures (NIST news release, August 2024). Full standard specifications and supporting documentation are available on the CSRC post-quantum cryptography project page.

StandardAlgorithmFunctionMathematical Basis
FIPS 203ML-KEMKey encapsulation mechanism (KEM)Module-Lattice (LWE variant)
FIPS 204ML-DSADigital signatureModule-Lattice (Dilithium lineage)
FIPS 205SLH-DSADigital signatureHash-based (SPHINCS+ lineage)

FIPS 203 (ML-KEM) standardizes a Module-Lattice-based key encapsulation mechanism. A KEM is the cryptographic primitive that negotiates a shared secret over an untrusted channel, replacing classical Diffie-Hellman and ECDH in protocols like TLS. ML-KEM is the direct replacement for ECDH-based key agreement in quantum-resistant deployments.

FIPS 204 (ML-DSA) standardizes a Module-Lattice-based digital signature algorithm. It covers the use cases where RSA and ECDSA operate: code signing, certificate issuance, and authentication tokens. FIPS 205 (SLH-DSA) offers a second quantum-resistant digital signature option built on hash-based signatures, providing an alternative whose security depends solely on hash function properties rather than lattice hardness assumptions. All three standards are detailed on the CSRC FIPS approval announcement.

PQC vs Classical Encryption: Key Differences

PQC algorithms differ from classical counterparts in key size, computational cost, and the mathematical hardness assumption each relies on. Classical public-key cryptography, including RSA and elliptic-curve cryptography, produces compact keys because the security derives from the multiplicative difficulty of factoring or computing discrete logarithms. PQC schemes, particularly lattice-based ones, carry larger public keys and ciphertexts because the underlying hard problems require more structured data. The tradeoff is acceptable given that the classical alternatives will not survive a cryptographically relevant quantum computer.

PropertyClassical (RSA / ECC)PQC (ML-KEM / ML-DSA)
Quantum resistanceNone (broken by Shor's algorithm)Yes (lattice and hash hardness)
Key / ciphertext sizeCompact (256 bytes typical for ECC)Larger (ML-KEM public key ~1,184 bytes)
PerformanceFast on current hardwareComparable; some overhead in TLS handshake
Backward compatibilityWidely deployed in TLS, SSH, PKIRequires hybrid key establishment or protocol update
Cryptographic agilityLimited; algorithm swaps require reconfigurationDesigned for modular replacement in agile systems

Cryptographic agility, the ability to swap algorithms without redesigning the surrounding protocol, is a design principle that organizations should build into their systems now. A system built for cryptographic agility can adopt new PQC algorithms as the field matures without wholesale infrastructure replacement. Teams that hard-code RSA or ECC assumptions into key derivation pipelines will face the highest remediation cost during migration.

Harvest-Now-Decrypt-Later: Why Migration Cannot Wait

Adversaries with access to encrypted government or medical records are archiving that traffic today, betting that quantum hardware will let them decrypt it within the decade. The harvest-now-decrypt-later (HNDL) attack model does not require a quantum computer to exist yet. An adversary stores ciphertext captured over classical networks and waits for the hardware to mature. Any data encrypted today with RSA or ECC key exchange is already at risk under this model if the data's sensitivity will persist beyond the expected quantum-hardware timeline.

The categories of data most exposed to harvest-now-decrypt-later attacks include:

  1. Classified government communications with multi-decade sensitivity windows
  2. Patient health records subject to long regulatory retention periods
  3. Intellectual property such as trade secrets and R&D data transmitted over TLS
  4. Financial transaction histories that could inform future market manipulation
  5. Authentication credentials and private keys whose compromise enables future system access

For systems handling any of these categories, the migration timeline is not tied to when quantum computers arrive. It is tied to how long the data must remain confidential. A government record classified for 25 years needs quantum-resistant encryption now, not once quantum hardware becomes available.

How to Start a PQC Migration Roadmap

Diagram illustrates How to Start a PQC Migration Roadmap: classical, quantum-safe algorithms.

A practical PQC migration roadmap begins with a cryptographic inventory: identifying every system that performs key exchange or digital signing and ranking it by data-sensitivity and expected lifespan. Without a complete inventory, teams cannot prioritize which systems to migrate first or assess their exposure to the harvest-now-decrypt-later risk. For background on how transport-layer key exchange works, the how TLS protects data in transit article covers the TLS 1.3 handshake mechanics that PQC algorithms will augment.

  1. Cryptographic inventory. Catalog every service, library, and protocol that uses public-key cryptography. Tag each with its algorithm, key type, and data classification.
  2. Risk ranking. Prioritize systems that handle long-lived sensitive data or that authenticate high-value actions. These face the most immediate quantum threat.
  3. Deploy hybrid key establishment. Enable hybrid key establishment in TLS 1.3 connections by combining a classical algorithm with ML-KEM. This protects sessions against future quantum decryption while maintaining compatibility with classical peers. IETF guidance on hybrid modes is available at RFC 9794 and the IETF PQC application migration draft.
  4. Update certificate infrastructure. Plan rotation of certificate authority chains to include ML-DSA or SLH-DSA digital signatures as certificate lifetimes expire.
  5. Build for cryptographic agility. Abstract algorithm selection behind configuration parameters so future NIST updates can be adopted without code changes.
  6. Test PQC overhead. Benchmark ML-KEM key encapsulation and ML-DSA signing in staging environments to assess latency and bandwidth impact before production rollout.

The IETF migration draft provides application-specific guidance for integrating quantum-resistant algorithms into common protocols, making it a useful complement to the NIST standards when building a migration roadmap for networked systems.

PQC in Practice: Real-World Adoption Signals

Several major deployments already test PQC in production: Google enabled ML-KEM hybrid key exchange in Chrome, and Cloudflare runs PQC experiments across its TLS termination fleet. These deployments use hybrid key establishment, pairing ML-KEM with the classical X25519 key agreement so that session security holds even if one primitive is later found vulnerable. The NIST PQC project page documents the broader ecosystem of implementations and transition guidance (nist.gov/pqc).

Other adoption signals worth noting:

  • Major cloud providers are adding ML-KEM support to their TLS termination infrastructure
  • PKI vendors are building ML-DSA and SLH-DSA into certificate issuance pipelines alongside RSA
  • Government procurement frameworks in the United States are incorporating PQC algorithm requirements for new systems
  • Hardware security module vendors are adding ML-KEM and ML-DSA to their supported key encapsulation mechanism and digital signature algorithm sets

The practical implication is that the PQC ecosystem is moving faster than typical standards transitions. Organizations that begin their cryptographic inventory and pilot hybrid key establishment now will be positioned to complete migration before quantum-resistant algorithm requirements become mandatory in regulated sectors. The quantum-resistant algorithm ecosystem is still maturing, and additional NIST standards are expected in subsequent rounds, so systems built with cryptographic agility will absorb those updates with minimal friction.

Further reading

Primary sources and standards referenced in this article:

Frequently Asked Questions

Which NIST standards define the first post-quantum cryptography algorithms?

NIST finalized three PQC standards in August 2024: FIPS 203 (ML-KEM for key encapsulation), FIPS 204 (ML-DSA for digital signatures), and FIPS 205 (SLH-DSA for hash-based signatures). These replace RSA and elliptic-curve cryptography for applications that must be quantum-resistant. Organizations can begin migration planning using these standards as the target algorithm set.

Does post-quantum cryptography protect against current attacks, or only future quantum threats?

PQC algorithms are designed to resist attacks from quantum computers that do not yet exist at cryptographically relevant scale. They are also strong against classical computers, so adopting them now does not weaken present-day security. The main risk driving early adoption is harvest-now-decrypt-later: adversaries storing encrypted data today and decrypting it once quantum hardware matures.

Can post-quantum cryptography coexist with existing TLS and key-exchange protocols during migration?

Yes. Hybrid key establishment combines a classical algorithm such as ECDH with a PQC algorithm such as ML-KEM in the same TLS handshake, so security holds even if one primitive is later broken. IETF drafts and early TLS 1.3 implementations already specify hybrid modes, making incremental migration practical without breaking backward compatibility.

Share this guide

Kenji Sato

Kenji Sato edits techshooked's coverage of artificial intelligence and emerging technology, following the path from research to production systems. His standard is anti-hype: ask what a model actually does, what data trained it, how it fails in practice, and whether a benchmark measures what the marketing says it does.