Post-quantum cryptography (PQC) is a set of encryption and signature algorithms designed to stay secure even against a large quantum computer. The U.S. executive order on the subject defines it as cryptographic algorithms or methods “designed to be resistant to attack by both a quantum computer and a classical computer” (Executive Order 14412).
Despite the name, post-quantum cryptography does not need a quantum computer. As Apple’s security team puts it, these are new public-key algorithms that run on “the classical, non-quantum computers we’re all using today”. Your phone, browser and messaging apps can use them through ordinary software updates.
Why today’s encryption needs replacing
Much of the internet’s security rests on public-key cryptography, mainly RSA and elliptic-curve cryptography (ECC). These systems depend on math problems that conventional computers find extremely hard to solve. NIST explains that “a sufficiently capable quantum computer” would be able to work through those problems very quickly, “thereby defeating current encryption.”
Public-key cryptography does two jobs, and both are affected:
- Key establishment. Two devices agree on a secret key over a public network, for example when your browser opens an HTTPS connection.
- Digital signatures. A signature proves who sent something and that it was not changed. Software updates, website certificates and sign-in methods such as passkeys rely on signatures.
Symmetric encryption, the kind that scrambles the data itself once a key is agreed, is in a better position. The NSA’s quantum computing FAQ says quantum techniques are “much less effective” against symmetric algorithms, which are believed to be secure “provided a sufficiently large key size is used”, and it describes AES-256 as safe against a large quantum computer. So the migration is mainly about replacing the public-key parts.
Why it matters before quantum computers arrive
No quantum computer that can break RSA or ECC exists today. The concern is timing. Attackers can record encrypted traffic now and keep it until they can decrypt it, a strategy known as “harvest now, decrypt later.” The NSA describes it in three steps: harvest encrypted data, store it for years, decrypt it once quantum capabilities exist. In the NSA’s words, data that needs to remain secure for decades, “such as national security information and financial records, is already at risk.”
Signatures face a different problem, which the same NSA article calls “trust now, forge later.” Once quantum-vulnerable signature algorithms can be broken, an attacker could forge the certificates and signatures that systems use to decide whom to trust. That is why the NSA’s timetable asks for software and firmware signing to move first.
The new standards
NIST ran a public selection process from 2016. It assessed 82 algorithms from 25 countries, and on August 13, 2024 it published its first three finished post-quantum standards:
| Standard | Algorithm | Job | Based on |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key establishment (general encryption) | Structured lattices |
| FIPS 204 | ML-DSA | Digital signatures | Lattices |
| FIPS 205 | SLH-DSA | Digital signatures | Hash functions |
NIST said these standards “are ready for immediate use” and urged administrators to start integrating them because “full integration will take time.”
NIST is also building backups. On March 11, 2025 it selected HQC, an algorithm based on error-correcting codes rather than lattices, as a second line of defense in case a weakness is ever found in ML-KEM. At the time, NIST planned a draft HQC standard in about a year and a final standard in 2027, and said ML-KEM “will remain the recommended choice for general encryption.” It also said a further signature standard, built on the FALCON algorithm, would be released in draft as FIPS 206.
How post-quantum encryption reaches users
The new algorithms are already in widely used products, often in a hybrid form that combines a classical algorithm with a post-quantum one, so a connection stays protected as long as either one holds.
- Web browsing. Google’s Chrome team announced that Chrome 131 would switch its hybrid key exchange to ML-KEM768 combined with X25519, a classical elliptic-curve method.
- Messaging. Signal added PQXDH, a post-quantum layer for its protocol’s initial key agreement, in September 2023. Apple introduced PQ3 for iMessage in February 2024, citing “harvest now, decrypt later” attacks as the reason.
- Blockchains. Networks that rely on signatures for accounts face the same question. Tezos, for example, launched an experimental Quantumnet to test post-quantum components; it is a test network, not a production upgrade.
For most people, the practical step is the usual one: keep your operating system, browser and apps updated. The changes happen inside protocols you do not see.
Government deadlines
Governments are setting dates for their own systems. In the United States, Executive Order 14412, signed on June 22, 2026, requires guidance under which agencies move high-value assets and high-impact systems to post-quantum key establishment by December 31, 2030, and to post-quantum signatures by December 31, 2031. It also directs a proposed rule requiring covered federal contractors to comply with NIST’s standards, including the post-quantum ones, by the end of 2030.
For National Security Systems, the NSA’s CNSA 2.0 advisory expects the transition to be complete by 2035, with earlier dates for specific product types. On October 1, 2026, the NSA opened a resource hub and restated that new commercial National Security Systems must support quantum-resistant algorithms from 2027.
What post-quantum cryptography is not
It is not quantum key distribution (QKD), which uses physics and special hardware to share keys. The NSA states that it views quantum-resistant algorithms as “a more cost effective and easily maintained solution” than QKD and does not support QKD for protecting National Security Systems.
It is also not a guarantee. NIST selected a backup algorithm based on different math precisely because confidence in any one design can change. The point of the migration is to remove a known future weakness from systems that will still be running when quantum hardware matures. For how that hardware is progressing, see our coverage of logical qubits and quantum error decoding.





