What Is Post-Quantum Cryptography? NIST’s New Encryption Standards Explained

Cybersecurity
Aug 20, 2024
Digital brain made of glowing blue network lines with binary code and circuit board patterns.
No Authors found.

What is post-quantum cryptography?

Post-quantum cryptography (PQC), also called quantum-safe encryption, is a family of cryptographic algorithms designed to stay secure against attacks from both classical and quantum computers. It replaces today’s standards like RSA — which a powerful quantum computer running Shor’s algorithm could break — with schemes based on harder mathematical problems such as lattices, error-correcting codes, and hash functions. In 2024, NIST finalized its first three PQC standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205).

The National Institute of Standards and Technology (NIST) has recently finalized its first three post-quantum encryption standards. It’s crucial for organizations to understand how quantum computing can potentially break current encryption methods, what NIST is doing to support the industry, and the steps needed to enhance data protection.

Just as AI has transformed markets and revolutionized daily tasks, quantum computing is poised to have a similarly profound impact. However, it also presents significant risks to data security. To address these challenges, NIST published the new standards to guide companies worldwide in safeguarding their data before it’s too late. In this blog, we will explore NIST’s efforts, how attackers are preparing for the advent of quantum computers, and what organizations can do to protect themselves.

Quantum Computing: The Basics

Quantum computing is an exciting and rapidly developing field with the potential to revolutionize various industries by harnessing the principles of quantum mechanics. Unlike classical computers, which use bits to represent data as either 0s or 1s, quantum computers utilize quantum bits, or qubits. Qubits can exist in multiple states simultaneously due to a phenomenon known as superposition, and they can also be entangled, meaning the state of one qubit is directly related to the state of another, regardless of distance. These unique properties enable quantum computers to solve complex problems that are currently beyond the reach of classical computers, such as factoring large numbers at unprecedented speeds.

Quantum Computing: A New Cybersecurity Challenge

The immense power of quantum computing poses a significant threat to cybersecurity, primarily due to its potential to break widely used cryptographic systems. NIST Special Publications, such as SP 800-56A and SP 800-56B, which outline effective key management and distribution mechanisms for current computing systems, are likely to be rendered obsolete by the advent of quantum computers. Recognizing this impending threat, NIST has prioritized the development and standardization of new quantum-safe algorithms to ensure robust security in the quantum era. RSA, one of the most common encryption algorithms currently used around the world, could be compromised by a sufficiently powerful quantum computer running Shor’s algorithm. This would allow attackers to decrypt sensitive data, impersonate digital signatures, and forge digital identities, posing a substantial risk to data security. As encrypted data is transmitted across the Internet and global networks every second, the infrastructure we currently consider secure could become vulnerable once quantum computers reach a certain level of development.

The threat of quantum computing is not merely theoretical. The ‘harvest now, decrypt later’ approach involves adversaries intercepting and storing encrypted data with the expectation that future quantum computers will be able to decrypt it. This makes sensitive information vulnerable now, even if quantum computers are not yet fully realized and accessible. This future prospect of quantum-enabled decryption raises significant concerns for industries dealing with highly confidential information, such as finance, healthcare, critical national infrastructure, research, and national security.

Additionally, transitioning to quantum-safe encryption presents its own set of challenges. This shift could require a costly and complex overhaul of digital infrastructure, as legacy systems built on classical cryptography would need significant updates to remain secure in a quantum era. This transition could create logistical challenges and temporary vulnerabilities.

Quantum-Safe Encryption: An Essential Measure

The rise of quantum computing presents a significant challenge to traditional encryption methods. In response, NIST has been proactive in addressing these potential threats by developing quantum-safe, or post-quantum, encryption algorithms. These algorithms are designed to withstand both classical and quantum attacks, shifting away from conventional techniques based on number factoring or logarithmic problems. Instead, quantum-safe cryptographic methods leverage advanced mathematical structures, such as lattice-based, code-based, and multivariate polynomial cryptography. These techniques are considered robust against the capabilities of current fault-tolerant quantum computers and are anticipated to remain secure as quantum technology evolves.

NIST has undertaken a transparent and rigorous process to develop these quantum-safe encryption standards. Beginning in 2016, NIST invited researchers and organizations worldwide to submit their quantum-safe cryptographic solutions, resulting in an impressive response with 82 algorithms submitted from 25 countries. After thorough evaluation, NIST, in collaboration with global cryptography experts, has selected three algorithms for general encryption and identity authentication. Additionally, one more algorithm is expected to be included in a draft standard by the end of 2024. To prepare for the future, NIST is also working on backup standards, acknowledging the uncertainties surrounding the full impact of quantum computing on mathematics and cryptography.

Encryption Algorithms for the Quantum Era

The Federal Information Processing Standards (FIPS) and NIST have rigorously evaluated algorithms to establish new standards aimed at safeguarding two critical aspects of modern infrastructure: general encryption and identity authentication. The selected algorithms are designed to withstand the potential threats posed by quantum computing, ensuring robust security for the future.

  • Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM): a highly secure method for key establishment in encrypted communications, even against attackers equipped with fault-tolerant quantum computers. ML-KEM is derived from the CRYSTALS-KYBER KEM, which has been extensively tested and refined over several years. It offers three parameter sets: ML-KEM-512, ML-KEM-768, and ML-KEM-1024.
  • Module-Lattice-Based Digital Signature Algorithm (ML-DSA): a robust algorithm for generating digital signatures, ensuring the authenticity and integrity of digital communications. It is based on the CRYSTALS-Dilithium algorithm and can be used for both the creation and verification of digital signatures.
  • Stateless Hash-Based Digital Signature Standard (SLH-DSA): a powerful standard for digital signature generation that verifies the authenticity of digital signatures. It is particularly useful in scenarios where maintaining state information is challenging or undesirable.

Nist’s Post-Quantum Standards at a Glance

The finalized standards — plus the two newer algorithms still moving through the process — at a glance:

Standard Purpose Based on Status
ML-KEM (FIPS 203) Key encapsulation for general encryption Module-lattice (CRYSTALS-KYBER) Finalized 2024 — primary KEM
ML-DSA (FIPS 204) Digital signatures — authenticity & integrity Module-lattice (CRYSTALS-Dilithium) Finalized 2024 — primary signature
SLH-DSA (FIPS 205) Digital signatures — stateless, conservative Hash-based (SPHINCS+) Finalized 2024
FN-DSA (FIPS 206) Compact digital signatures (small size) NTRU-lattice (FALCON) Draft submitted 2025 — not yet final
HQC Key encapsulation — non-lattice backup to ML-KEM Code-based (error-correcting codes) Selected 2025 — in development

Update since this post was published: NIST has continued the process. In March 2025, it selected a fourth algorithm — HQC, a code-based key-encapsulation mechanism — as a non-lattice backup to ML-KEM, and the FALCON-based signature standard FN-DSA (FIPS 206) has since been submitted in draft. ML-KEM, ML-DSA, and SLH-DSA remain the finalized standards ready to use today.

What Your Organization Can Do

Adopting quantum-safe encryption is a proactive measure that organizations should implement well in advance of quantum computers becoming a substantial threat. To ensure global digital infrastructure remains secure, it is crucial for organizations to collaborate across industries and prepare for this transition.

Immersive advises organizations to begin by taking stock of their most critical information. Identify key data that needs protection and assess where quantum computers might pose a risk. As quantum computers are initially expected to be expensive and primarily accessible to governments or large organizations, staying informed about advancements in quantum technology and understanding which encryption algorithms may become vulnerable is essential.

Once you have assessed your data and potential vulnerabilities, prioritize and plan to transition to quantum-safe algorithms over the coming years. Implementing these new standards for your most critical information should be a priority.

A practical post-quantum readiness checklist:

  • Inventory your cryptography. Map where and how encryption is used across your applications, data stores, and third parties — you can’t migrate what you can’t see — and aim for crypto-agility so algorithms can be swapped without re-architecting.
  • Prioritize critical and long-life data. Because of ‘harvest now, decrypt later,’ information that must stay confidential for years (finance, healthcare, critical national infrastructure, national security) should migrate first.
  • Plan a phased transition. Adopt the finalized standards — ML-KEM, ML-DSA, SLH-DSA — for your highest-priority systems, and track NIST guidance as FN-DSA and HQC are finalized.
  • Upskill your teams. Engineers and developers need hands-on familiarity with post-quantum algorithms and secure implementation. Immersive’s hands-on labs — including quantum and cryptography labs — and secure coding for developers build that capability.

“Quantum computing is disruptive because it creates such powerful computational power that we can break things like classical encryption and process problems far faster than before. That’s exactly why we wanted people to be able to understand quantum computing — and start preparing — before it even becomes a big thing affecting the industry.”

— Ben McCarthy, Lead Cyber Threat Intelligence Engineer, Immersive

To learn more about the latest cybersecurity news and potential impacts on your organization, visit the Immersive Resources Center. Or see how Immersive One helps teams build and prove the skills to stay ahead of emerging threats like quantum — book a demo.

Frequently Asked Questions

What Is Post-Quantum Cryptography?

Post-quantum cryptography (PQC), also called quantum-safe encryption, is a family of cryptographic algorithms designed to stay secure against attacks from both classical and quantum computers. It replaces today’s standards like RSA with schemes based on harder mathematical problems such as lattices, error-correcting codes, and hash functions. In 2024, NIST finalized its first three PQC standards: ML-KEM (FIPS 203), ML-DSA (FIPS 204), and SLH-DSA (FIPS 205).

How Does Quantum Computing Threaten Current Encryption?

Quantum computers use qubits, which can represent many states at once, letting them solve certain problems — like factoring large numbers — far faster than classical computers. A sufficiently powerful quantum computer running Shor’s algorithm could break RSA, allowing attackers to decrypt sensitive data and forge digital signatures, and rendering key-establishment methods such as NIST SP 800-56A and 56B obsolete.

What Is ‘Harvest Now, Decrypt Later’?

‘Harvest now, decrypt later’ is when adversaries intercept and store encrypted data today, expecting that future quantum computers will be able to decrypt it. It means long-life sensitive data — in finance, healthcare, critical national infrastructure, research, and national security — is already at risk, even before quantum computers are fully realized.

What Are Nist’s Post-Quantum Encryption Standards?

NIST finalized its first three standards in 2024: ML-KEM (FIPS 203) for key encapsulation, ML-DSA (FIPS 204) for digital signatures, and SLH-DSA (FIPS 205), a hash-based signature scheme. A fourth signature standard, FN-DSA (FIPS 206, based on FALCON), has since been submitted in draft, and HQC was selected in 2025 as a code-based backup to ML-KEM.

What Should Organizations Do to Prepare for the Quantum Age?

Inventory where cryptography is used and adopt crypto-agility; identify the critical and long-life data most exposed to ‘harvest now, decrypt later’; prioritize and plan a phased migration to the new standards for the highest-risk systems; upskill engineering and development teams; and track NIST guidance as further algorithms are finalized.

Published:
Aug 20, 2024

See how to prove readiness with one platform.

See how Immersive One helps technical teams and leaders prove readiness, close capability gaps, benchmark progress, and report cyber resilience with confidence.