RSA & ECC (TLS, PKI, signing)
Broken by Shor's algorithm on a cryptographically relevant quantum computer. Requires migration to ML-KEM, ML-DSA, or SLH-DSA (often via hybrid transition).
Large-scale quantum computers — when they arrive — threaten the public-key math that secures TLS, PKI, code signing, and most digital trust today.
TLS sessions, VPN tunnels, encrypted email, and archived backups can be stored at scale — even when breaking RSA or ECC is impossible with classical hardware.
Broken by Shor's algorithm on a cryptographically relevant quantum computer. Requires migration to ML-KEM, ML-DSA, or SLH-DSA (often via hybrid transition).
Grover's algorithm halves effective key strength. AES-256 remains the practical target for 128-bit quantum security; AES-128 needs reassessment for long-lived data.
Hash functions are less impacted than public-key schemes. Still monitor parameter sizes and protocol binding as part of a full crypto inventory.
After an eight-year global evaluation, NIST finalized three primary post-quantum standards in August 2024. They are ready for production planning now.
Falcon (FN-DSA) and HQC remain on NIST's ongoing standardization path as additional options.
Governments worldwide are publishing coordinated timelines. U.S. federal guidance (OMB M-26-15, June 2026) is the most detailed phased schedule published to date.
Build a cryptographic bill of materials (CBOM). Map RSA, ECC, and protocol dependencies across applications, PKI, HSMs, and vendors.
Five-phase federal schedule; Oct 2026 migration plans; 2030/2031 priority targets.
Phased PQC migration across federal departments, agencies, and Crown corporations.
Member-state alignment on PQC transition timelines, standards adoption, and interoperability.
Allied coordination on post-quantum cryptography migration — including financial sector roadmaps.
Post-quantum schemes are built on distinct mathematical problems — lattice, hash, code, and others. NIST's multi-round process tested each family; only the strongest candidates became FIPS standards.
The dominant family in deployed PQC — built on hard problems over structured lattices such as Module-LWE and Module-SIS.
Signatures whose security reduces to the collision and preimage resistance of standard hash functions — no lattice or number-theoretic assumptions.
Cryptography based on the difficulty of decoding random linear error-correcting codes — one of the oldest PQC research directions (McEliece, 1978).
Schemes built on the difficulty of solving systems of multivariate quadratic equations over finite fields — once a major NIST candidate category.
Protocols using morphisms (isogenies) between elliptic curves — attracted interest for compact keys before a breakthrough break.
| Family | Primary KEM | Primary signature | Key / sig size | Deployment status |
|---|---|---|---|---|
| Lattice | ML-KEM | ML-DSA | Moderate | Production planning |
| Hash-based | — | SLH-DSA | Large signatures | Production planning |
| Code-based | McEliece / HQC | Limited | Very large PK | Niche / ongoing |
| Multivariate | — | Withdrawn | — | Not recommended |
| Isogeny | Withdrawn | — | — | Not recommended |
This page is educational — not legal or compliance advice. Timelines evolve; validate against current NIST and agency guidance.
Use our interactive PQC Readiness tool or talk to our team about a migration program.