Almost every secure connection on the internet depends on public-key cryptography, mainly RSA and elliptic curve cryptography (ECC). A sufficiently large, error-corrected quantum computer running Shor’s algorithm could break both. No such machine exists yet, but the migration to replacement algorithms takes years, and some of the data you are encrypting today needs to stay secret for longer than that.
That is why the security world treats quantum computing as a turning point now rather than later. In August 2024 the US National Institute of Standards and Technology (NIST) published the first finalized post-quantum cryptography (PQC) standards, and governments have begun setting deadlines for retiring vulnerable algorithms. This article explains what is actually at risk, what the new standards are, and how to plan a migration that will take most organizations several years.
What quantum computers threaten, and what they do not
Not all cryptography is equally exposed. Public-key algorithms used for key exchange and digital signatures, including RSA, Diffie-Hellman and ECC variants such as ECDSA and ECDH, rely on mathematical problems that Shor’s algorithm solves efficiently on a large enough quantum computer. These protect TLS web connections, VPNs, code signing, email encryption, digital certificates and much of identity infrastructure.
Symmetric encryption such as AES and hash functions such as SHA-256 are far more resilient. Grover’s algorithm gives only a quadratic speedup against them, which is generally addressed by using larger key sizes, such as AES-256. The urgent work is therefore replacing public-key algorithms, not rebuilding all of cryptography.
How soon is uncertain, and claims that quantum computers “break encryption in minutes” overstate today’s reality. What has changed is the estimated size of the machine required. In May 2025, Google researcher Craig Gidney published an estimate that RSA-2048 could be factored in under a week by a quantum computer with fewer than one million noisy qubits, down from about 20 million in his 2019 estimate. Today’s largest machines have at most a few thousand physical qubits and high error rates, so the gap is still large, but it is shrinking from both directions.
Harvest now, decrypt later
The reason to act before a cryptographically relevant quantum computer exists is a strategy known as “harvest now, decrypt later.” Adversaries, particularly state intelligence services, can capture encrypted traffic and stored data today and hold it until they can decrypt it. Anything that must remain confidential for ten or more years, such as health records, trade secrets, legal files, government information and long-lived credentials, is already at risk if it travels over connections protected only by RSA or ECC.
A useful way to judge urgency is to add two numbers: how long your data must stay secret, and how long your migration will take. If that total extends past the point when a capable quantum computer might appear, you are already late. Signatures have a different timeline, since a forged signature only matters once an attacker can forge it, but long-lived signing keys in devices and firmware need planning too.
The new standards and government deadlines
After an eight-year public competition, NIST finalized three standards on August 13, 2024:
- FIPS 203 (ML-KEM), based on CRYSTALS-Kyber, for key encapsulation, the job RSA and ECDH do in establishing shared keys.
- FIPS 204 (ML-DSA), based on CRYSTALS-Dilithium, the primary standard for digital signatures.
- FIPS 205 (SLH-DSA), based on SPHINCS+, a hash-based signature scheme offered as a backup built on different mathematics.
In March 2025 NIST also selected HQC as an additional, backup key-encapsulation algorithm, and a further signature standard based on FALCON is in development. On timing, NIST’s draft transition guidance, published in November 2024, proposes deprecating RSA and ECC at current common strengths after 2030 and disallowing them entirely after 2035. The US National Security Agency’s CNSA 2.0 guidance sets similar or earlier dates for national security systems, and federal agencies have been directed to inventory their cryptography.
Vendors are moving. Major browsers and cloud providers have enabled hybrid key exchange that combines a classical algorithm with ML-KEM for TLS connections, so a growing share of web traffic is already protected against harvest-now attacks without users noticing.
A practical post-quantum migration plan
For most organizations, PQC migration is less about mathematics and more about inventory, vendor management and change control. A workable sequence:
- Build a cryptographic inventory. Identify where public-key cryptography is used: certificates, TLS endpoints, VPNs, SSH, code signing, databases, hardware security modules, IoT devices and third-party services.
- Classify data by secrecy lifetime. Flag systems that handle data needing protection for many years; they move first.
- Ask vendors for their roadmap. Much of your cryptography lives inside products you buy. Add PQC support and timelines to procurement and renewal questions.
- Design for crypto-agility. Centralize cryptographic libraries and configuration so algorithms can be swapped without rewriting applications. The first PQC standards will not be the last change.
- Adopt hybrid modes where available. Enable hybrid classical-plus-PQC key exchange in TLS and VPNs as vendors support it, which protects against harvest-now attacks while the new algorithms mature.
- Test performance and compatibility. PQC keys and signatures are larger than RSA and ECC equivalents, which can affect older devices, constrained networks and protocols with size limits.
- Set a timeline aligned with 2030 and 2035. Plan phased replacement so high-priority systems are done well before deprecation dates.
The trade-off is cost now for risk later, and much of that cost is ordinary modernization you would eventually need anyway. Starting with an inventory is cheap and useful on its own. Our cybersecurity compliance and regulatory framework services include cryptographic inventories and PQC readiness roadmaps. For the business opportunity side of quantum, see Quantum Computing: Cracking the “Unsolvable”, and for an overview of where the technology stands, Quantum Computing: The Next Frontier of Technology.
Frequently asked questions
Can quantum computers break encryption today?
No. Current quantum computers are far too small and error-prone to break RSA or ECC. The concern is data captured today being decrypted later, and the long lead time required to migrate systems.
Is AES still safe?
Yes, with adequate key sizes. Quantum attacks only weaken symmetric encryption modestly, and AES-256 is generally considered sufficient. The migration focus is on public-key algorithms.
Where should a mid-sized business start?
Start with an inventory of where you use certificates and encryption, identify data that must stay confidential for many years, and ask your key vendors, including cloud, VPN, firewall and identity providers, about their PQC plans. Most of your migration will arrive through vendor updates, so tracking them is the core task.
Getting quantum-ready
Delana Technologies helps organizations inventory their cryptography, prioritize systems by data sensitivity, and build a post-quantum migration roadmap aligned with NIST and federal timelines. To start your quantum readiness assessment, call 239.414.5126 or contact us.
Sources: NIST, FIPS 203, 204 and 205 (August 2024); NIST announcement selecting HQC (March 2025); NIST IR 8547 initial public draft, “Transition to Post-Quantum Cryptography Standards” (November 2024); NSA, Commercial National Security Algorithm Suite 2.0; Craig Gidney, “How to factor 2048 bit RSA integers with less than a million noisy qubits” (May 2025).
