---
title: "Post-Quantum Cryptography"
date: 2026-06-01
description: Encrypted data stolen today may be read when quantum computers mature. Standards are published, migration targets set, and the transition is Board business.
author: Mario Thomas
canonical: https://mariothomas.com/signals/post-quantum-cryptography/
---

## What is Post-Quantum Cryptography? {#what-it-is data-toc="What it is"}

Post-quantum cryptography is public-key cryptography rebuilt to withstand attack by a quantum computer: new mathematical schemes for establishing encryption keys and creating digital signatures. Despite the name, there is nothing quantum about it. These algorithms run on ordinary computers, servers, and devices, replacing public-key mechanisms whose underlying mathematics a sufficiently capable quantum machine could eventually solve. NIST published the first three finalised standards in August 2024, and the UK and EU have since published migration targets against them. The strategic direction is settled, and the standards make the migration actionable even while protocols and products mature. What remains is a large, slow re-plumbing of every system that uses public-key cryptography, and that is a programme, not a patch.

The migration is further along than many Boards may realise, and less finished than that suggests. By October 2025, more than **half** of human-initiated web traffic reaching [Cloudflare's network](https://blog.cloudflare.com/pq-2025/) was already protected by hybrid post-quantum key agreement, up from under 3% at the start of 2024. That is the centrally upgradeable layer, and it protects connection keys rather than the certificates and signatures beneath them. What remains is the enterprise estate: VPNs, supplier connections, embedded devices, payment rails, and internal systems where cryptography is buried in products an organisation bought rather than built. The browser-to-edge layer can move through software updates; the enterprise estate belongs to the organisations that own it, and none of it upgrades by default.

## Why it matters to Boards {#board-implications data-toc="Board implications"}

The exposure predates the computer. 'Harvest now, decrypt later' is the practice of capturing encrypted traffic and material whose keys depend on quantum-vulnerable public-key cryptography, and holding it until a quantum machine can recover those keys, which means anything with a long confidentiality life, such as customer records, health data, intellectual property, and state-adjacent contracts, is already in scope. The question I would put to management is not when a quantum computer arrives but how long our data must stay secret, whether that period outlasts the cryptography protecting it, and where it travelled while those keys were doing the protecting. On timing, the honest answer is that nobody knows. IBM has published a target for a large-scale fault-tolerant machine by **2029**, which would be a landmark of engineering rather than a demonstrated code-breaking machine, and vendor roadmaps are ambitions, not arrival forecasts. The migration case does not depend on believing any of the dates: long confidentiality periods and long replacement cycles are reason enough to begin, and in the spring of 2026 parts of the industry brought their own security targets forward anyway.

The dates are multiplying and the money is real. The UK's NCSC recommends that large organisations complete discovery and initial planning by 2028, migrate their highest-priority systems by 2031, and complete the wider transition by **2035**. The EU roadmap asks Member States to begin their transitions by the end of 2026 and critical infrastructure to complete the move no later than the end of 2030. Cryptography is buried in supplier connections, payment rails, embedded devices, identities, and internal systems, so this is a multi-year, cross-functional programme. An inventory now reduces uncertainty, exposes long-lead dependencies, and gives the organisation more choice over how migration is sequenced and funded.

## Questions Boards are asking {#questions data-toc="Questions"}

### Why does this matter before a quantum computer exists?

Because the exposure starts before the machine does. 'Harvest now, decrypt later' means an adversary can steal encrypted data today and read it whenever a capable quantum computer arrives, so anything that must stay confidential for a decade is already in scope. The migration itself takes years, which is why the timelines run from 2028, not from the day a quantum computer is announced.

### Is this the same as quantum encryption or quantum key distribution?

No. Post-quantum cryptography uses new mathematical algorithms on conventional hardware. Quantum key distribution uses specialised hardware and quantum effects to generate and distribute keys. The NCSC identifies post-quantum cryptography as the primary mitigation and advises organisations not to rely on QKD alone. QKD also addresses key distribution rather than the wider estate of signatures, certificates, identities, code signing, and data at rest. Modern symmetric encryption is affected differently from public-key cryptography; with suitable key sizes, algorithms such as AES can continue to be used. The main migration is therefore the public-key layer and everything built on it.

### Is this hype, or is it real? It feels like Y2K.

Separate the two questions. When a cryptographically relevant quantum computer will arrive is uncertain, and confident dates deserve scepticism. Whether organisations need to migrate is much less uncertain: the standards are published, national bodies have set transition targets, and the harvest-now exposure exists before the machine does. The Y2K comparison cuts the opposite way to how it is usually meant. Y2K passed quietly because organisations funded years of inventory and remediation. This migration has three harder edges: there is no single date, there is an adversary rather than a bug, and the exposure reaches backwards because encrypted material captured today may become readable later.

### If more than half of Cloudflare's human traffic is already protected, is the job mostly done?

No, because Cloudflare's network is not the whole internet and the migrated traffic represents only part of the cryptographic estate. Cloudflare's published measure covers human-initiated traffic reaching its network and principally reflects hybrid post-quantum key agreement. The remaining estate includes VPNs, supplier connections, machine-to-machine traffic, embedded devices, and certificate infrastructure, none of which upgrades by default. Key establishment generally comes first because harvested traffic may be decrypted retrospectively; signatures can often follow because a signature cannot be forged retrospectively in the same way. Long-lived roots of trust, including firmware, secure boot, and devices expected to remain in the field for a decade, may need post-quantum verification earlier.

### What about data that has already been stolen?

Migration protects what you encrypt from now on; it cannot recall what harvest-now-decrypt-later has already taken. That makes this partly a disclosure question rather than purely a security one. The practical response is an inventory of long-life data, an honest view of what may already have been exfiltrated in past incidents, and early legal advice on what legal, contractual, and customer consequences could arise if previously captured encrypted material later became readable. Boards that have thought this through before the first decryption headlines arrive will handle them considerably better than Boards meeting the idea on the day.

### What should management be able to show the Board today?

Three things: a cryptographic inventory showing where quantum-vulnerable cryptography sits across systems, products, and suppliers, which data and processes depend on it, and how long each must stay secret; a named owner for the migration; and a plan mapped against the published timelines, sequenced by exposure and by which dependencies cannot change before their current end of life. If none of these exist yet, the inventory is the place to start, because nothing else can be scoped or costed without it.

### What should we ask our suppliers?

Most of an organisation's cryptography arrives embedded in products it bought, so migration is substantially a procurement exercise. Ask every material supplier for a post-quantum roadmap with dates, contractual commitments on cryptographic upgradeability in new agreements, and evidence of crypto-agility, meaning the ability to replace algorithms and parameters through a controlled upgrade rather than by replacing the product. Suppliers selling into the US federal government now carry their own 2030 obligations, which gives you useful leverage: the question is no longer whether they have a plan but whether your systems are in it.

### Who should own the migration?

Execution sits with the CISO or CTO, but the programme belongs in the Board's line of sight because it runs for years, crosses every supplier relationship, and carries external milestones that are hardening into requirements. I would have it report through the audit or risk committee with the same discipline as any major transformation, with progress measured against the 2028, 2031, and 2035 milestones.

## References

- **NIST** (13 August 2024): [NIST Releases First 3 Finalized Post-Quantum Encryption Standards](https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards). The August 2024 announcement of FIPS 203, 204, and 205, with NIST's direction to begin integration immediately.
- **NIST** (13 August 2024): [Module-Lattice-Based Key-Encapsulation Mechanism Standard](https://csrc.nist.gov/pubs/fips/203/final). The primary general-encryption standard, ML-KEM, that replaces quantum-vulnerable key exchange.
- **Cloudflare** (2025): [State of the post-quantum Internet in 2025](https://blog.cloudflare.com/pq-2025/). First-party confirmation that more than half of human web traffic reaching Cloudflare's network is post-quantum protected, and a clear account of what remains.
- **IBM** (2025): [IBM lays out clear path to fault-tolerant quantum computing](https://www.ibm.com/quantum/blog/large-scale-ftqc). IBM's published commitment to deliver Starling, a large-scale fault-tolerant quantum computer, by 2029.
- **NCSC** (2025): [Timelines for migration to post-quantum cryptography](https://www.ncsc.gov.uk/guidance/pqc-migration-timelines). The UK migration timeline: discovery and planning by 2028, priority systems by 2031, full migration by 2035.
- **NCSC** (2020): [Quantum security technologies](https://www.ncsc.gov.uk/paper/quantum-security-technologies). The NCSC's position on quantum key distribution: not endorsed for government or military use, with advice against replacing public-key cryptography with QKD commercially.
- **NCSC** (March 2025): [Quantum networking technologies](https://www.ncsc.gov.uk/paper/quantum-networking-technologies). A white paper outlining the NCSC’s approach to quantum security technologies.
- **European Commission** (2025): [A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography](https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography). The EU roadmap: member states publish strategies and begin inventories by end 2026, with high-risk use cases moved by end 2030.
- **The White House** (2026): [Securing the Nation Against Advanced Cryptographic Attacks](https://www.whitehouse.gov/presidential-actions/2026/06/securing-the-nation-against-advanced-cryptographic-attacks/). The June 2026 order setting 2030 and 2031 federal deadlines for post-quantum key establishment and signatures, and extending post-quantum FIPS compliance to federal contractors.
- **NIST** (2024): [IR 8547, Transition to Post-Quantum Cryptography Standards](https://csrc.nist.gov/pubs/ir/8547/ipd). NIST's transition plan: quantum-vulnerable algorithms including RSA-2048 and ECC P-256 deprecated after 2030 and disallowed after 2035.
- **Cloudflare** (2026): [The White House's post-quantum executive order is an important milestone. It’s time to get to work](https://blog.cloudflare.com/post-quantum-eo-2026/). Analysis of EO 14412, and the record of Cloudflare bringing its own target for full post-quantum security forward to 2029.
