Post-Quantum Cryptography (PQC) is an important internet security technology being developed to protect digital information from future powerful quantum computers.
Today, banking, online shopping, email, messaging, and many websites on the internet use encryption. The main purpose of encryption is to protect data from unauthorized access. However, in the future, sufficiently powerful quantum computers could create a serious threat to some commonly used public-key cryptographic systems.
Post-Quantum Cryptography is being developed specifically to address this future risk.
In simple terms, Post-Quantum Cryptography is a group of cryptographic algorithms that are designed to resist future quantum-computing attacks while operating on traditional computers.
This does not mean that quantum computers are breaking internet encryption today. Practical, large-scale quantum computers are still in the development stage.
The concern is that sufficiently powerful quantum computers in the future could challenge some existing cryptographic methods. That is why security researchers, technology companies, and organizations are working on preparation for quantum-resistant cryptography.
Public-key cryptographic systems such as RSA and Elliptic Curve Cryptography (ECC) are widely used in modern internet security.
In the case of sufficiently powerful quantum computers, some of the mathematical problems that these systems depend on could be attacked using different computational approaches compared to traditional computers.
Shor's algorithm is a quantum algorithm developed by mathematician Peter Shor in 1994.
Theoretically, sufficiently powerful and fault-tolerant quantum computers could use it to break certain public-key cryptographic systems, including RSA and ECC. This algorithm can factor large integers in polynomial time, which poses a serious future threat to systems like RSA.
One important clarification: Today's available quantum computers are not capable of practically breaking RSA or ECC. Running Shor's algorithm requires a fault-tolerant quantum computer with millions of reliable logical qubits, which does not exist yet.
Grover's algorithm — devised by Lov Grover in 1996 — provides quantum computers with a theoretical speedup for certain types of search problems.
In the context of symmetric cryptography, its potential impact is related to key-search security. This algorithm effectively reduces the key-search space quadratically — the practical meaning of this is that the effective security of an algorithm like AES-128 could be halved. That is why longer key sizes, such as AES-256, provide a greater security margin against quantum-related risks.
This is why quantum security is not just an issue for public-key cryptography; different approaches may be needed for different cryptographic systems.
One important concern is commonly called "Harvest Now, Decrypt Later."
In this scenario, an attacker can collect and store encrypted information today, and attempt to decrypt that data in the future if sufficiently capable quantum technology becomes available.
This is why preparation for quantum-resistant cryptography is becoming important for long-term sensitive information — because data encrypted today could potentially be vulnerable decades from now.
The U.S. National Institute of Standards and Technology (NIST) published its first three finalized post-quantum cryptography standards on August 13, 2024. This was the result of an 8-year global standardization process that began in 2016.
ML-KEM (Module-Lattice-Based Key-Encapsulation Mechanism) is designed for secure key establishment. It is based on the CRYSTALS-Kyber algorithm.
It helps parties in cryptographic communication establish a shared secret — meaning two systems on the internet can share a common encrypted key to communicate securely.
ML-KEM has been standardized as FIPS 203 and is NIST's primary recommended algorithm for general encryption.
ML-DSA (Module-Lattice-Based Digital Signature Algorithm) is designed for digital signatures. It is based on the CRYSTALS-Dilithium algorithm.
Digital signatures help verify the source and integrity of information — meaning the receiver can confirm that a message came from an authorized source and that no unauthorized modification was made to the data.
ML-DSA has been standardized as FIPS 204.
SLH-DSA (Stateless Hash-Based Digital Signature Algorithm) is a hash-based digital signature standard. It is based on the SPHINCS+ submission.
It uses a different cryptographic approach from ML-DSA — its security is based on hash function properties rather than lattice math. This diversity is important so that if a vulnerability is ever found in one mathematical approach in the future, another option is available.
SLH-DSA has been standardized as FIPS 205.
NIST's PQC standards did not stop there. On March 11, 2025, NIST selected HQC (Hamming Quasi-Cyclic) as a new algorithm for post-quantum cryptography standardization.
HQC has not come to replace ML-KEM — ML-KEM remains NIST's primary recommended algorithm for general encryption. NIST mathematician Dustin Moody explained: "We are announcing the selection of HQC because we want to have a backup standard that is based on a different math approach than ML-KEM. As we advance our understanding of future quantum computers and adapt to emerging cryptanalysis techniques, it's essential to have a fallback in case ML-KEM proves to be vulnerable."
ML-KEM is based on structured lattices, while HQC relies on error-correcting codes — a well-established cryptographic approach. This diversity strengthens overall security by avoiding complete reliance on a single encryption method. NIST plans to release a draft standard incorporating HQC in approximately one year, with a finalized version expected by 2027.
What to take away from this: Organizations should begin migration toward ML-KEM and the other 2024 standards now. There is no need to wait for HQC — it will be an additional backup option in the future.
The technical details are quite complex, but the basic idea is simple.
ML-KEM: Two computers want to communicate securely over the internet — ML-KEM helps them establish a shared cryptographic secret between them, which can be used in the broader encryption process of secure communication.
ML-DSA: Used for digital signatures. The receiver can verify that the information is associated with an authorized cryptographic key and detect any unauthorized modification to the data.
SLH-DSA: Also designed for digital signatures, but uses a hash-based cryptography approach — a different mathematical foundation that provides security independent from ML-DSA.
The use of different algorithms gives organizations options according to their security requirements and implementation needs.
Yes, the practical deployment of post-quantum cryptography has already begun.
Apple has announced a new post-quantum cryptographic protocol called PQ3 for iMessage, designed to protect the messaging platform from the threat of future quantum computers.
PQ3 combines with existing Elliptic Curve Cryptography — it is a hybrid model that ensures robust protection against both current and future quantum attacks. PQ3 also includes innovations like periodic rekeying that further strengthen security.
Important clarification: It would not be correct to claim that iMessage or PQC is "100% unbreakable." The overall protection of security systems also depends on implementation quality, device security, user behavior, and the broader security environment. PQ3 only strengthens the cryptographic layer.
Over one-third of the human-generated traffic on Cloudflare's network uses TLS 1.3 with hybrid post-quantum key agreement (X25519MLKEM768) — if you are on a Chrome, Edge, or Firefox browser, you are probably reading content right now over a PQ encrypted connection.
Google's Chrome enabled a hybrid X25519+Kyber exchange for a subset of users, and Cloudflare reported that by early 2024 approximately 1.8% of TLS 1.3 connections to its servers were being secured with post-quantum cryptography — mostly due to Chrome's 10% rollout experiment.
Hybrid cryptography means that both traditional cryptography and post-quantum cryptography can be used in combination in a communication system — such as using X25519 (a classical algorithm) and ML-KEM (a post-quantum algorithm) together.
The purpose of this approach is to make the transition practical and to gradually move from existing systems to quantum-resistant systems. If a weakness appears in either algorithm, the other still provides protection.
This approach is particularly useful when organizations want to introduce quantum-resistant protection without completely replacing their existing infrastructure.
Crypto-agility means the ability of a system to replace or update cryptographic algorithms relatively easily.
This is important for future cybersecurity because cryptographic standards and security requirements can change over time. If an organization's infrastructure is heavily dependent on a single outdated algorithm, future migration can be very difficult and expensive.
A crypto-agile architecture gives organizations the flexibility to adopt new cryptographic standards — such as NIST's new PQC standards — without rebuilding the entire system.
To understand post-quantum cryptography with a simple example:
Traditional encryption is like a strong traditional lock designed with current types of attackers in mind.
Post-Quantum Cryptography is like a new-generation lock that also considers future possible quantum-computing capabilities in its security design.
This is only an analogy. Real cryptography is based on complex mathematical algorithms and security protocols. The purpose of this analogy is to understand the concept, not to claim technical accuracy.
No — and it is important to understand this clearly.
Calling any security technology "100% unbreakable" or completely risk-free is technically incorrect. The purpose of PQC is to provide cryptographic protection against future quantum threats.
But overall cybersecurity does not depend on the encryption algorithm alone. These risks still exist even with PQC:
That is why strong cryptography + secure implementation + regular security updates + user awareness together create a strong defense.
No — and this is an important point.
Shor's algorithm cannot run on today's quantum hardware. It requires a fault-tolerant quantum computer with millions of reliable error-corrected logical qubits that can sustain millions of operations without accumulating fatal errors.
Quantum computing is developing rapidly, but a sufficiently powerful, fault-tolerant quantum computer that could practically break widely used public-key cryptography does not exist yet. The main purpose of PQC is advance preparation for a future risk — to be ready before the technology gets there.
Enormous amounts of sensitive information are exchanged on the internet every day — banking transactions, business communications, authentication systems, private messages, and long-term confidential information.
Preparation is necessary now because of the "Harvest Now, Decrypt Later" attack scenario — an attacker can store today's encrypted data and attempt to decrypt it in the future when a powerful quantum computer is available.
That is why it is important for organizations to work on cryptographic inventory, migration planning, and adoption of quantum-resistant standards now — rushing at the last minute in the future will be much more difficult and risky.
Post-Quantum Cryptography is one of the critical technologies for the future of internet security.
NIST published three finalized post-quantum cryptography standards in August 2024 — ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205). Following that, in March 2025, HQC was selected as the fifth algorithm, which will serve as a backup option alongside ML-KEM.
Technology companies like Apple, Google, and Cloudflare have already begun real-world deployment.
The goal of PQC is not to make the internet "100% unbreakable" — no technology can guarantee that. Its goal is to make cryptographic protection stronger against future quantum threats and to prepare internet infrastructure for long-term security challenges.
Security is a layered approach — strong cryptography is a necessary layer, but not sufficient on its own. Secure implementation, regular updates, and informed users together build a strong defense.