What Is Post-Quantum Cryptography (PQC)?

Post-quantum cryptography protects data from quantum and classical attacks. NIST finalized standards in 2024. Migration starts with cryptographic visibility. Explore our full PQC glossary for deeper dives on every topic.

8 articles
View Category

What Is Post-Quantum Cryptography (PQC)?

Post-quantum cryptography is the full set of cryptographic systems designed to withstand attacks from both classical computers and quantum computers. It spans three capabilities:

  • Encryption for keeping data confidential

  • Digital signatures for proving authenticity

  • Key exchange for agreeing on shared secrets across untrusted networks

NIST defines PQC as methods that protect data from both current conventional computers and the quantum computers of tomorrow. The "both" is deliberate; a post-quantum algorithm that resisted quantum attacks but fell to a laptop would be useless.

Post-Quantum Cryptography (PQC)
Post-Quantum Cryptography (PQC)

What It Replaces

Today's public-key cryptography relies on math problems that are hard for classical computers to reverse. RSA multiplies two very large prime numbers together. Going backward from the product to the original primes would take a classical machine billions of years.

A quantum computer changes that equation. Shor's algorithm can solve both integer factorization and discrete logarithms efficiently, not by running the same operations faster, but by evaluating many candidate solutions simultaneously. Instead of weakening RSA or elliptic-curve schemes, it breaks them outright.

What Shor's algorithm threatens:

  • RSA (all key sizes)

  • ECDSA and EdDSA

  • Diffie-Hellman and elliptic-curve key exchange

What stays safe:

  • AES-256 symmetric encryption

  • SHA-2 and SHA-3 hash functions

These are not vulnerable to Shor's algorithm and are not part of the PQC migration.

What It Is Not

PQC or post-quantum cryptography is frequently confused with quantum cryptography, but the two share almost nothing. Post-quantum cryptography is math that runs on existing infrastructure. Quantum cryptography, practically, is when quantum key distribution runs on quantum physics and requires dedicated fiber or free-space transmitters. The NSA has declined to recommend QKD for National Security Systems, citing authentication gaps, relay costs, insider-threat risk, and denial-of-service vulnerability. For most enterprises, PQC is what a cloud estate actually needs.

PQC vs Quantum Key Distribution
PQC vs Quantum Key Distribution

The NIST Standards

NIST ran an eight-year open competition, starting in 2016 with 69 candidate algorithms submitted by cryptographers from dozens of countries. In August 2024, NIST finalized the first three standards:

  • ML-KEM (FIPS 203) handles key encapsulation for confidentiality, derived from the CRYSTALS-Kyber submission.

  • ML-DSA (FIPS 204) handles digital signatures, derived from CRYSTALS-Dilithium. Both are lattice-based.

  • SLH-DSA (FIPS 205) is a stateless hash-based signature scheme derived from SPHINCS+, serving as a conservative fallback built on different mathematical assumptions.

NIST PQC Standards at a Glance
NIST PQC Standards at a Glance

In March 2025, NIST selected HQC, a code-based scheme as a backup for ML-KEM, with finalization planned for 2027. The diversity is intentional: if a structural weakness were found in lattices, hash-based and code-based alternatives would be unaffected.

Why Migration Is Urgent Now

Harvest now, Decrypt Later means adversaries are already collecting encrypted traffic for future quantum decryption. The deadline is not when a cryptographically relevant quantum computer arrives, but whether one arrives within the confidentiality lifetime of data captured today.

NIST's draft transition guidance deprecates quantum-vulnerable public-key algorithms (including RSA-2048) after 2030 and disallows them after 2035. Historically, cryptographic migrations have taken 10–20 years. Standards landed in 2024. That leaves six years to do work that has never been done in fewer than ten.

The Clock Started Before the Quantum Computer Did
The Clock Started Before the Quantum Computer Did

Where Migration Actually Starts: The Network

Every serious migration guide begins in the same place: cryptographic visibility.

  • What algorithms are your systems actually negotiating?

  • Where does encryption terminate?

  • Which keys sit at each termination point?

  • Which paths carry data with long confidentiality requirements?

You cannot replace encryption you have not found.

In a multicloud environment, encryption is more than a single thing you upgrade. It is thousands of workload communication paths negotiating independently. East-west traffic between workloads, cross-cloud connections, Kubernetes pod egress, serverless function calls. A readiness claim scoped to whatever a perimeter firewall happens to see is not a readiness claim about the estate.

This is why Aviatrix approaches quantum readiness network-first. Harvest and Decrypt Protection delivers crypto-agile High-Performance Encryption and egress governance today. Crypto visibility and a full Cryptographic Bill of Materials (CBOM) map every flow's posture so you know exactly what is exposed and where to start.

Network first; applications at your pace. See the Aviatrix Quantum-Safe Roadmap.

Share

The Era Has Shifted. Has Your Architecture?

Download the three-part Containment Era whitepaper series. Then see your own blast radius with a Workload Attack Path Assessment.

Cta pattren Image