What Is Post-Quantum Cryptography (PQC)?
Post-quantum cryptography protects data from quantum and classical attacks. NIST finalized standards in 2024. Migration starts with cryptographic visibility. Explore our full PQC glossary for deeper dives on every topic.
What Is Post-Quantum Cryptography (PQC)?
Post-quantum cryptography is the full set of cryptographic systems designed to withstand attacks from both classical computers and quantum computers. It spans three capabilities:
Encryption for keeping data confidential
Digital signatures for proving authenticity
Key exchange for agreeing on shared secrets across untrusted networks
NIST defines PQC as methods that protect data from both current conventional computers and the quantum computers of tomorrow. The "both" is deliberate; a post-quantum algorithm that resisted quantum attacks but fell to a laptop would be useless.
What It Replaces
Today's public-key cryptography relies on math problems that are hard for classical computers to reverse. RSA multiplies two very large prime numbers together. Going backward from the product to the original primes would take a classical machine billions of years.
A quantum computer changes that equation. Shor's algorithm can solve both integer factorization and discrete logarithms efficiently, not by running the same operations faster, but by evaluating many candidate solutions simultaneously. Instead of weakening RSA or elliptic-curve schemes, it breaks them outright.
What Shor's algorithm threatens:
RSA (all key sizes)
ECDSA and EdDSA
Diffie-Hellman and elliptic-curve key exchange
What stays safe:
AES-256 symmetric encryption
SHA-2 and SHA-3 hash functions
These are not vulnerable to Shor's algorithm and are not part of the PQC migration.
What It Is Not
PQC or post-quantum cryptography is frequently confused with quantum cryptography, but the two share almost nothing. Post-quantum cryptography is math that runs on existing infrastructure. Quantum cryptography, practically, is when quantum key distribution runs on quantum physics and requires dedicated fiber or free-space transmitters. The NSA has declined to recommend QKD for National Security Systems, citing authentication gaps, relay costs, insider-threat risk, and denial-of-service vulnerability. For most enterprises, PQC is what a cloud estate actually needs.

The NIST Standards
NIST ran an eight-year open competition, starting in 2016 with 69 candidate algorithms submitted by cryptographers from dozens of countries. In August 2024, NIST finalized the first three standards:
ML-KEM (FIPS 203) handles key encapsulation for confidentiality, derived from the CRYSTALS-Kyber submission.
ML-DSA (FIPS 204) handles digital signatures, derived from CRYSTALS-Dilithium. Both are lattice-based.
SLH-DSA (FIPS 205) is a stateless hash-based signature scheme derived from SPHINCS+, serving as a conservative fallback built on different mathematical assumptions.
In March 2025, NIST selected HQC, a code-based scheme as a backup for ML-KEM, with finalization planned for 2027. The diversity is intentional: if a structural weakness were found in lattices, hash-based and code-based alternatives would be unaffected.
Why Migration Is Urgent Now
Harvest now, Decrypt Later means adversaries are already collecting encrypted traffic for future quantum decryption. The deadline is not when a cryptographically relevant quantum computer arrives, but whether one arrives within the confidentiality lifetime of data captured today.
NIST's draft transition guidance deprecates quantum-vulnerable public-key algorithms (including RSA-2048) after 2030 and disallows them after 2035. Historically, cryptographic migrations have taken 10–20 years. Standards landed in 2024. That leaves six years to do work that has never been done in fewer than ten.
Where Migration Actually Starts: The Network
Every serious migration guide begins in the same place: cryptographic visibility.
What algorithms are your systems actually negotiating?
Where does encryption terminate?
Which keys sit at each termination point?
Which paths carry data with long confidentiality requirements?
You cannot replace encryption you have not found.
In a multicloud environment, encryption is more than a single thing you upgrade. It is thousands of workload communication paths negotiating independently. East-west traffic between workloads, cross-cloud connections, Kubernetes pod egress, serverless function calls. A readiness claim scoped to whatever a perimeter firewall happens to see is not a readiness claim about the estate.
This is why Aviatrix approaches quantum readiness network-first. Harvest and Decrypt Protection delivers crypto-agile High-Performance Encryption and egress governance today. Crypto visibility and a full Cryptographic Bill of Materials (CBOM) map every flow's posture so you know exactly what is exposed and where to start.
Network first; applications at your pace. See the Aviatrix Quantum-Safe Roadmap.
Scroll to browse all 8 articles
Become the cloud networking hero of your business.
See how Aviatrix can increase security and resiliency while minimizing cost, skills gap, and deployment time.
Get a DemoThe Era Has Shifted. Has Your Architecture?
Download the three-part Containment Era whitepaper series. Then see your own blast radius with a Workload Attack Path Assessment.

