# Post-quantum cryptography: the standards are done, the migration is not In August 2024 NIST finalized the first three post-quantum cryptographic standards. They are no longer drafts, candidates or research directions. They are the algorithms that federal systems will be required to use, and the ones most commercial deployments will follow. - **FIPS 203** โ€” Module-Lattice-Based Key-Encapsulation Mechanism Standard, specifying **ML-KEM**, derived from CRYSTALS-Kyber. This is the one that replaces the key exchange protecting a TLS session. - **FIPS 204** โ€” Module-Lattice-Based Digital Signature Standard, specifying **ML-DSA**, derived from CRYSTALS-Dilithium. The general-purpose signature algorithm. - **FIPS 205** โ€” Stateless Hash-Based Digital Signature Standard, specifying **SLH-DSA**, derived from SPHINCS+. Slower and larger, but its security rests only on hash functions, which makes it a structurally independent backup if lattice assumptions are ever weakened. Two more are still in progress: **FN-DSA** (from Falcon), a lattice signature with much smaller signatures than ML-DSA, and **HQC**, a code-based key encapsulation mechanism selected in 2025 as a mathematically distinct alternative to ML-KEM. The diversity is deliberate. Standardizing two families that fail for different reasons is insurance against a break in either one. ## Why the timeline is shorter than it looks The obvious reading is that nothing needs to happen until a cryptographically relevant quantum computer exists, and that such a machine is years away. For signatures, that reading is roughly correct: a signature verified today and never again is not threatened by a machine built in 2035. For confidentiality it is wrong, and the reason is **harvest now, decrypt later**. An adversary who records encrypted traffic today can decrypt it whenever the capability arrives. The question is not when quantum computers arrive, but how long the data in your traffic stays sensitive. Medical records, identity documents, sealed legal material and long-lived credentials all outlast the gap comfortably. For that data the exposure started the day it crossed the wire. NIST IR 8547 sets the direction: quantum-vulnerable algorithms are to be deprecated and ultimately removed from NIST standards by 2035, with higher-risk systems expected to move earlier. ## What migration actually involves The algorithm swap is the easy part. The hard parts are structural. **Inventory first.** Most organizations cannot answer, from records, where RSA and elliptic-curve cryptography is used across their systems. It is in TLS terminators, code signing, firmware verification, document signing, VPNs, hardware security modules, and embedded devices with a decade of remaining service life. Migration cannot be planned against an unknown surface, and building that inventory is usually the longest single step. **Sizes change, and things break.** ML-KEM and ML-DSA keys and signatures are substantially larger than their elliptic-curve equivalents. That collides with fixed-size fields, embedded flash budgets, single-packet handshake assumptions and protocol buffers sized years ago. These failures surface in integration, not in cryptographic review. **Hybrid is the realistic transition.** Combining a classical key exchange with a post-quantum one means the session is secure unless both are broken. Major browsers and TLS libraries have already deployed hybrid key exchange, which is why a meaningful share of web traffic is post-quantum protected today without anyone having chosen it explicitly. **Crypto-agility is the durable lesson.** Systems that hardcoded RSA are the expensive ones now. FN-DSA and HQC are still arriving, and the standards will change again. The property worth building is the ability to change algorithm without changing architecture. ## Where to start Inventory what you use, classify data by how long it must stay confidential, enable hybrid key exchange where your stack supports it, and treat algorithm choice as configuration rather than as a structural commitment. --- *Sources: NIST FIPS 203, 204 and 205 (August 2024); NIST IR 8547; NIST Post-Quantum Cryptography project. Publications authored by NIST employees are in the public domain in the United States under 17 U.S.C. ยง 105, with worldwide reprint and derivative rights granted. This article is an original summary of that material.*