# Post-quantum cryptography: the standards are done, the migration is not

In August 2024 NIST finalized the first three post-quantum cryptographic
standards. They are no longer drafts, candidates or research directions. They
are the algorithms that federal systems will be required to use, and the ones
most commercial deployments will follow.

- **FIPS 203** — Module-Lattice-Based Key-Encapsulation Mechanism Standard,
  specifying **ML-KEM**, derived from CRYSTALS-Kyber. This is the one that
  replaces the key exchange protecting a TLS session.
- **FIPS 204** — Module-Lattice-Based Digital Signature Standard, specifying
  **ML-DSA**, derived from CRYSTALS-Dilithium. The general-purpose signature
  algorithm.
- **FIPS 205** — Stateless Hash-Based Digital Signature Standard, specifying
  **SLH-DSA**, derived from SPHINCS+. Slower and larger, but its security rests
  only on hash functions, which makes it a structurally independent backup if
  lattice assumptions are ever weakened.

Two more are still in progress: **FN-DSA** (from Falcon), a lattice signature
with much smaller signatures than ML-DSA, and **HQC**, a code-based key
encapsulation mechanism selected in 2025 as a mathematically distinct
alternative to ML-KEM. The diversity is deliberate. Standardizing two families
that fail for different reasons is insurance against a break in either one.

## Why the timeline is shorter than it looks

The obvious reading is that nothing needs to happen until a cryptographically
relevant quantum computer exists, and that such a machine is years away. For
signatures, that reading is roughly correct: a signature verified today and
never again is not threatened by a machine built in 2035.

For confidentiality it is wrong, and the reason is **harvest now, decrypt
later**. An adversary who records encrypted traffic today can decrypt it
whenever the capability arrives. The question is not when quantum computers
arrive, but how long the data in your traffic stays sensitive. Medical records,
identity documents, sealed legal material and long-lived credentials all outlast
the gap comfortably. For that data the exposure started the day it crossed the
wire.

NIST IR 8547 sets the direction: quantum-vulnerable algorithms are to be
deprecated and ultimately removed from NIST standards by 2035, with higher-risk
systems expected to move earlier.

## What migration actually involves

The algorithm swap is the easy part. The hard parts are structural.

**Inventory first.** Most organizations cannot answer, from records, where
RSA and elliptic-curve cryptography is used across their systems. It is in TLS
terminators, code signing, firmware verification, document signing, VPNs,
hardware security modules, and embedded devices with a decade of remaining
service life. Migration cannot be planned against an unknown surface, and
building that inventory is usually the longest single step.

**Sizes change, and things break.** ML-KEM and ML-DSA keys and signatures are
substantially larger than their elliptic-curve equivalents. That collides with
fixed-size fields, embedded flash budgets, single-packet handshake assumptions
and protocol buffers sized years ago. These failures surface in integration,
not in cryptographic review.

**Hybrid is the realistic transition.** Combining a classical key exchange with
a post-quantum one means the session is secure unless both are broken. Major
browsers and TLS libraries have already deployed hybrid key exchange, which is
why a meaningful share of web traffic is post-quantum protected today without
anyone having chosen it explicitly.

**Crypto-agility is the durable lesson.** Systems that hardcoded RSA are the
expensive ones now. FN-DSA and HQC are still arriving, and the standards will
change again. The property worth building is the ability to change algorithm
without changing architecture.

## Where to start

Inventory what you use, classify data by how long it must stay confidential,
enable hybrid key exchange where your stack supports it, and treat algorithm
choice as configuration rather than as a structural commitment.

---

*Sources: NIST FIPS 203, 204 and 205 (August 2024); NIST IR 8547; NIST
Post-Quantum Cryptography project. Publications authored by NIST employees are
in the public domain in the United States under 17 U.S.C. § 105, with worldwide
reprint and derivative rights granted. This article is an original summary of
that material.*
