Driver FixRecommendedSound, Wi-Fi or graphics acting up? Check drivers firstFind missing or outdated drivers fast.Check DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan Now×
Skip to content
World desk4 min

Post-Quantum Cryptography Is Not an Algorithm Upgrade

Post-quantum cryptography migration begins with finding where cryptography is used. Learn what to inventory, which NIST standards are finalized and how to plan the transition.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Post-quantum cryptography (PQC) migration is an organization-wide change, not a one-for-one replacement of an algorithm. Cryptography is built into applications, protocols, certificates, keys, libraries, hardware security modules, services and data flows. A new algorithm in one component will not make the systems that depend on it ready. The practical starting point is to find where cryptography is used, map dependencies and prioritize what to change.

What post-quantum cryptography changes

Post-quantum cryptography refers to cryptographic methods designed to resist attacks from both conventional computers and quantum computers. The migration challenge is broader than selecting a new algorithm: organizations need to identify cryptographic use, understand which systems depend on it, decide what to move first, and coordinate implementation across their own products and suppliers.

As an Amazon Associate I earn from qualifying purchases.

The risk is not limited to systems that might be attacked in the future. Data encrypted today could be collected and stored for attempted decryption later—a concern often called “harvest now, decrypt later.” That makes the expected sensitivity and useful lifetime of protected data relevant to migration priorities. It does not require predicting when a cryptographically relevant quantum computer will exist.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST mathematician Dustin Moody, who leads its post-quantum cryptography standardization project, has urged organizations to begin transitioning to the new standards to help keep data secure in the quantum era. Publishing standards provides a destination for that work; it does not discover or update an organization’s systems for it.

Which NIST post-quantum cryptography standards are finalized?

The U.S. Secretary of Commerce approved three NIST post-quantum cryptography standards on August 13, 2024. They serve different functions and should not be treated as interchangeable.

Standard Algorithm Function Origin name
FIPS 203 ML-KEM Key establishment using a key-encapsulation mechanism CRYSTALS-KYBER
FIPS 204 ML-DSA Digital signatures CRYSTALS-Dilithium
FIPS 205 SLH-DSA Digital signatures; stateless hash-based SPHINCS+

Use ML-KEM, ML-DSA and SLH-DSA—the names in the finalized standards—when discussing current implementation. The earlier names are useful for understanding the standards’ origins, not as substitutes for their final names.

Why replacing an algorithm is not enough

An algorithm is only one part of a cryptographic system. It is used through implementations, interfaces and dependencies that may span products and organizational boundaries. Replacing a component without checking those connections can leave another system using an old protocol, certificate or library, or unable to interoperate with the updated component.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

That is why NIST’s National Cybersecurity Center of Excellence (NCCoE) describes migration work in two connected areas: cryptographic visibility and risk management, including an inventory; and interoperability and benchmarking to help providers embed PQC in products and services. An organization needs both an understanding of its own environment and a way to assess whether updated components work together.

What to include in a cryptographic inventory

Inventory the places and purposes where cryptography is used, not just the algorithm names in a software list. NIST NCCoE emphasizes that organizations cannot effectively prioritize or migrate cryptography they have not identified.

  • Algorithms and protocols: record what is used and where, including the function it serves.
  • Certificates and keys: track relevant metadata and system relationships, not secret key material.
  • Systems and components: include applications, services, libraries, hardware security modules and other components that implement or rely on cryptography.
  • Dependencies and data flows: map which systems, interfaces and suppliers rely on each cryptographic component, and what information it protects.
  • Protected data and its lifetime: identify sensitive information that may remain valuable long enough to be exposed to a future decryption risk.

Keep the inventory current as systems change. A one-time list can quickly become incomplete when applications, vendors or infrastructure are updated.

How to plan a PQC migration

  1. Establish ownership and scope. Assign responsibility across the teams that manage applications, infrastructure, security, procurement and suppliers. Treat the work as a program that spans systems and services, rather than as an isolated cryptography upgrade.
  2. Build the inventory and dependency map. Identify cryptographic use, the systems and interfaces involved, the data protected, and the vendors or providers that control relevant components.
  3. Prioritize by risk. Consider the sensitivity and expected lifetime of data, the consequences of a system failing, and the dependencies that make a change difficult. Give earlier attention to high-risk systems and long-lived sensitive data.
  4. Coordinate suppliers and implementation plans. Ask providers how their products and services will support the finalized standards, what components or interfaces will change, and how those changes affect connected systems. Plan around the full dependency chain, not just the product receiving an update.
  5. Test interoperability and performance in context. Verify that updated components work with the protocols, applications, services and infrastructure they must connect to. Benchmarking is part of migration planning because a standard’s publication alone does not demonstrate that a particular deployment will work as required.
  6. Deploy in phases and maintain visibility. Move systems in a controlled sequence, track unresolved dependencies, and update the inventory as changes are made. Reassess priorities as systems and vendor capabilities evolve.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What NIST’s transition timeline means

NIST’s project page describes a transition timeline to deprecate and ultimately remove quantum-vulnerable algorithms from NIST standards by 2035, with high-risk systems transitioning earlier. That is a milestone for NIST standards, not a universal statutory deadline for every private organization. It is not a reason to wait until 2035: organizations need time to discover dependencies, coordinate suppliers and carry out changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

NIST IR 8547, “Transition to Post-Quantum Cryptography Standards,” was published as an initial public draft on November 12, 2024; its comment period closed January 10, 2025. It describes an expected transition from quantum-vulnerable cryptographic algorithms to post-quantum digital-signature and key-establishment schemes. Those dates and its draft status describe the document’s publication record; they do not create a single compliance date for all organizations.

What to take away

The finalized standards establish important technical choices: ML-KEM for key establishment, and ML-DSA and SLH-DSA for digital signatures. The harder work is organizational—finding cryptography throughout the environment, understanding its dependencies, prioritizing risk, coordinating suppliers and validating that updated systems interoperate. A migration plan should begin with visibility, not with an isolated algorithm swap.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Outdated Drivers Are Slowing You DownFree scan - exact matches
Windows Errors? Fix Them Before They SpreadFree repair scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.