In August 2024, the National Institute of Standards and Technology (NIST) published the first finalized post-quantum cryptography (PQC) standards: FIPS 203 (CRYSTALS-Kyber for key encapsulation), FIPS 204 (CRYSTALS-Dilithium for digital signatures), and FIPS 205 (SPHINCS+ for signatures). This was the culmination of an eight-year standardization effort, and it marks the starting pistol for the most significant cryptographic migration in internet history.
This report provides a comprehensive, technically grounded migration roadmap for organizations navigating the transition from RSA, ECDSA, and Diffie-Hellman to post-quantum secure alternatives. It covers the threat model, the new NIST standards, the "harvest now, decrypt later" attack vector, and a phased migration plan that organizations of any size can execute.
Understanding the Quantum Cryptographic Threat
The quantum threat to cryptography stems from two quantum algorithms: Shor's algorithm and Grover's algorithm.
Shor's Algorithm: The RSA and ECC Killer
Peter Shor's 1994 algorithm solves the integer factorization problem and the discrete logarithm problem in polynomial time on a quantum computer. This directly breaks RSA (which relies on factoring large integers), ECC (Elliptic Curve Cryptography, which relies on the discrete logarithm), and Diffie-Hellman key exchange. These algorithms underpin essentially all of the public-key cryptography currently protecting the internet, including HTTPS, SSH, TLS, email signing, code signing, and certificate authorities.
A quantum computer running Shor's algorithm with approximately 4,000 logical qubits could factor RSA-2048 in hours. Current quantum computers have hundreds to thousands of noisy physical qubits, which translate to far fewer logical qubits after error correction overhead. Estimates for when Shor's algorithm becomes practically threatening to RSA-2048 range from 2030 to 2040+, with significant uncertainty.
Grover's Algorithm: The Symmetric Key Weakener
Grover's algorithm provides a quadratic speedup for searching unstructured databases. Applied to symmetric cryptography (AES, SHA), it effectively halves the security bit level: AES-128 provides 64-bit security against a quantum adversary; AES-256 provides 128-bit security. The standard mitigation is simply doubling key lengths. AES-256 and SHA-384/SHA-512 are considered quantum-safe for symmetric and hash operations.
The NIST Post-Quantum Cryptography Standards (2024–2025)
NIST's finalized standards represent the result of global cryptographic expertise scrutinizing algorithms under adversarial conditions for eight years. Here is what you need to know about each.
FIPS 203: CRYSTALS-Kyber (ML-KEM)
CRYSTALS-Kyber, now standardized as ML-KEM (Module Lattice-based Key Encapsulation Mechanism), is the primary algorithm for key encapsulation — the process of securely establishing shared encryption keys. It is based on the hardness of the Module Learning With Errors (MLWE) problem, a variant of lattice-based cryptography.
- Key sizes: ML-KEM-512 (128-bit security), ML-KEM-768 (192-bit security), ML-KEM-1024 (256-bit security)
- Performance: Faster key generation and encapsulation than RSA-2048; slightly larger public keys (~800–1568 bytes vs RSA's ~256 bytes)
- Primary use cases: TLS key exchange, encrypted email, VPN session establishment, file encryption
- Recommendation: ML-KEM-768 for most enterprise use cases; ML-KEM-1024 for high-security government and defense applications
FIPS 204: CRYSTALS-Dilithium (ML-DSA)
CRYSTALS-Dilithium, standardized as ML-DSA (Module Lattice-based Digital Signature Algorithm), is the primary post-quantum digital signature scheme. It replaces ECDSA and RSA signatures for code signing, certificate authorities, and authentication.
- Key sizes: ML-DSA-44 (128-bit security), ML-DSA-65 (192-bit security), ML-DSA-87 (256-bit security)
- Signature size: Larger than ECDSA (~2.4–4.6 KB vs ECDSA's ~64–72 bytes) — a significant consideration for bandwidth-constrained applications
- Primary use cases: Code signing, certificate authorities, email signing (S/MIME), blockchain transaction signing, document signing
FIPS 205: SPHINCS+ (SLH-DSA)
SPHINCS+, standardized as SLH-DSA (Stateless Hash-based Digital Signature Algorithm), provides a mathematically conservative alternative signature scheme based solely on the security of hash functions — with no dependency on lattice assumptions. It is significantly larger (8–50 KB signatures) but provides a strong backup in case lattice assumptions face unexpected cryptanalytic attacks.
The Harvest Now, Decrypt Later (HNDL) Threat
The HNDL attack model is the most urgent near-term quantum cryptographic threat, because it is almost certainly happening today. Nation-state adversaries with the resources and motivation to collect encrypted traffic (intelligence agencies, sophisticated criminal groups) are harvesting encrypted communications now, storing them, and waiting for quantum computers capable of running Shor's algorithm to decrypt them retroactively.
The implications are direct:
- Any encrypted communication today that must remain confidential for more than 5–10 years is potentially vulnerable to HNDL attacks
- This includes: government communications, trade secrets, legal privileged communications, medical records, financial transaction records, proprietary research data
- TLS traffic, SSH sessions, VPN tunnels, and encrypted email are all susceptible to HNDL if the key exchange is RSA or ECDH-based
The mitigation is deploying PQC hybrid key exchange (combining PQC and classical algorithms) now, for all high-value communications channels. Google, Cloudflare, and Apple have already deployed hybrid PQC in their products. Your organization should too.
Cryptographic Inventory: The Foundation of Migration
Before migrating, you must know what you are migrating. This is harder than it sounds. Modern enterprise environments have cryptographic dependencies in hundreds of places: TLS certificates, code signing keys, SSH host keys, VPN certificates, email encryption keys, database encryption keys, hardware security modules (HSMs), smart cards, and embedded systems.
A comprehensive cryptographic inventory includes:
- Network cryptography: TLS certificates (web servers, API endpoints, load balancers), VPN gateways, SSH configurations
- Application cryptography: Code signing infrastructure, JWT/OAuth key pairs, API authentication keys
- Data-at-rest encryption: Database encryption keys, file system encryption, backup encryption
- Identity and access management: PKI infrastructure, certificate authorities, smart card keys, HSM-stored keys
- Hardware and embedded systems: Firmware signing keys, IoT device certificates, TPM-stored keys
- Third-party dependencies: SaaS providers, cloud services, payment processors, and their cryptographic posture
Tools like NIST's Cryptographic Module Validation Program database, open-source inventory tools like Cryptosense Analyzer, and commercial solutions from Venafi and Keyfactor can accelerate this discovery process.
The Four-Phase Migration Roadmap
Phase 1: Awareness and Inventory (Now — Q2 2026)
Establish cryptographic awareness across your security, engineering, and leadership teams. Complete a cryptographic inventory of all systems. Identify high-priority assets — particularly those handling data with long confidentiality requirements. Assign ownership and budget for PQC migration.
Phase 2: Hybrid Deployment for High-Priority Systems (Q3 2026 — Q4 2027)
Deploy hybrid PQC for the highest-risk communication channels. "Hybrid" means combining ML-KEM with ECDH in a way that requires an attacker to break both algorithms — providing quantum resistance while maintaining classical security during the transition. Most major TLS libraries (OpenSSL 3.x, BoringSSL, wolfSSL) now support ML-KEM hybrids.
Priority order for hybrid deployment:
- Internet-facing TLS endpoints handling sensitive data (HTTPS, API gateways)
- VPN and remote access infrastructure
- Code signing infrastructure
- Certificate authority infrastructure
- SSH infrastructure
Phase 3: Full PQC Migration (2028 — 2030)
Transition from hybrid to pure PQC for all cryptographic systems. This phase includes the harder migration challenges: legacy systems, embedded devices, long-lived certificates, and air-gapped systems. Budget significantly more time for legacy system migration than for modern cloud-native infrastructure.
Phase 4: Crypto-Agility Infrastructure (Ongoing)
Crypto-agility — the ability to swap cryptographic algorithms quickly in response to new threats or new standards — is the long-term investment that makes all future cryptographic transitions faster and cheaper. Design systems with algorithmic agility as a first-class architectural requirement: externalize algorithm selection from application logic, use certificate management automation (ACME protocol), and invest in centralized cryptographic policy management.
Regulatory and Compliance Implications
PQC migration is rapidly moving from best practice to regulatory requirement. Key compliance frameworks to monitor:
- US Federal Government: NSM-10 (National Security Memorandum 10, 2022) requires federal agencies to inventory quantum-vulnerable cryptography and begin migration. CISA's PQC initiative provides guidance for critical infrastructure operators.
- EU NIS2 Directive: Requires entities in critical sectors to implement appropriate cryptographic controls, with PQC migration increasingly interpreted as required for compliance.
- HIPAA and healthcare: PHI encrypted with quantum-vulnerable algorithms will require migration to maintain compliance as NIST updates its guidance.
- Financial services: FFIEC and PCI-DSS are expected to incorporate PQC requirements in upcoming updates.
Practical Implementation Resources
For engineering teams beginning PQC implementation, the following resources are indispensable:
- Open Quantum Safe (OQS) project: liboqs open-source library with implementations of all NIST PQC standards, plus OpenSSL and other integration forks
- NIST Special Publication 800-208: Recommendation for Stateful Hash-Based Signature Schemes
- CISA PQC Guidance: Sector-specific implementation guidance for critical infrastructure
- CloudFlare's CIRCL library: Production-ready Go implementations of CRYSTALS-Kyber, CRYSTALS-Dilithium, and SPHINCS+
- AWS s2n-tls: Amazon's TLS implementation with ML-KEM hybrid support in production
For broader technical context on quantum computing threats, the team at DeepFutureTech's quantum readiness guide provides an excellent complementary perspective on enterprise quantum preparedness.
Get a Custom PQC Migration Assessment
Our team can help you prioritize your cryptographic inventory and build a migration timeline tailored to your risk profile.
Request Assessment