Post-Quantum Cryptography

Post-Quantum Cryptography, or PQC, is a new generation of cryptographic algorithms designed to remain secure even against powerful future quantum computers.

Today, much of the internet relies on public-key cryptography such as RSA, Diffie-Hellman, and elliptic-curve cryptography. These systems protect secure websites, VPNs, email, software updates, digital signatures, identity systems, telecom infrastructure, and cloud services.

A sufficiently powerful quantum computer could break many of these classical public-key systems. That is why governments, standardization bodies, and companies are preparing the transition to quantum-safe cryptography now. NIST has finalized the first post-quantum cryptographic standards and recommends that organizations begin integrating them because full migration will take time [1].

PQC does not usually mean using quantum computers. In most cases, it means using new cryptographic algorithms that run on today’s classical computers, servers, mobile devices, chips, routers, cloud platforms, and embedded systems.

One major reason to act early is the “harvest now, decrypt later” threat. Attackers may collect encrypted data today and decrypt it in the future once quantum computers become powerful enough. This is especially relevant for data that must remain confidential for many years, such as government, healthcare, financial, industrial, telecom, and critical infrastructure information.


Standardized PQC algorithms

The most important standardized PQC algorithms currently come from the NIST Post-Quantum Cryptography Standardization Process.

Algorithm

Standard

Main purpose

Original name

Cryptographic family

ML-KEM

FIPS 203

Key establishment / encryption

CRYSTALS-Kyber

Lattice-based

ML-DSA

FIPS 204

Digital signatures

CRYSTALS-Dilithium

Lattice-based

SLH-DSA

FIPS 205

Digital signatures

SPHINCS+

Hash-based

FN-DSA

In progress, FIPS 206

Digital signatures

FALCON

Lattice-based

HQC

Selected, final standard expected in 2027

Key establishment / encryption

HQC

Code-based

NIST finalized the first three PQC standards in August 2024: ML-KEM, ML-DSA, and SLH-DSA [1]. These algorithms are intended to replace or complement vulnerable classical public-key algorithms in encryption, key exchange, and digital signatures.

NIST has also announced FN-DSA, based on FALCON, as an additional digital signature standard in progress [1]. In 2025, NIST selected HQC as an additional post-quantum encryption algorithm. HQC is intended to provide algorithmic diversity as a backup to ML-KEM because it is based on different mathematical assumptions [2].


EU roadmap for PQC migration

The European Union is treating PQC migration as a coordinated cybersecurity transition. In April 2024, the European Commission issued a recommendation encouraging Member States to develop a coordinated approach for the transition to post-quantum cryptography [3].

In June 2025, EU Member States, supported by the European Commission and the NIS Cooperation Group, published “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography.” The roadmap defines a phased approach for public authorities, critical infrastructure, and other high-risk sectors [4].

EU migration timeline

Timeline

EU migration focus

By end of 2026

Member States should start national PQC strategies, pilot projects, cryptographic inventories, and identification of high-risk applications.

By end of 2030

High-risk applications should be migrated to PQC, especially systems in critical infrastructure and systems with long confidentiality or authenticity lifetimes.

By end of 2035

PQC migration should be largely completed for remaining systems where technically and economically feasible.

The EU roadmap emphasizes that migration is not only a technical replacement of algorithms. It also requires planning, prioritization, procurement changes, interoperability testing, and long-term crypto-agility [4].


Germany’s PQC migration direction

Germany’s PQC migration is strongly shaped by the Federal Office for Information Security, the BSI. Germany is actively involved in the European coordination of PQC migration and has contributed to the EU roadmap together with European partners [5].

The BSI has been preparing for quantum-safe cryptography for several years. Its technical guideline TR-02102-1 has included post-quantum cryptographic mechanisms since 2020 and was updated to reflect the new NIST standards [5].

For organizations in Germany, the practical direction is clear:

1. Build a cryptographic inventory

Organizations need to identify where classical public-key cryptography is used. This includes TLS, VPNs, SSH, PKI, certificates, digital signatures, software signing, email encryption, device authentication, APIs, and embedded systems.

2. Prioritize high-risk systems

Priority should be given to systems with long-lived confidentiality requirements, critical infrastructure, public administration, telecom networks, finance, healthcare, energy, transport, and industrial environments.

3. Use hybrid migration models

During the transition period, many systems will combine classical algorithms with PQC algorithms. Hybrid approaches can reduce migration risk while new standards, implementations, and compliance requirements mature.

4. Establish crypto-agility

Systems should be designed so cryptographic algorithms can be replaced without major redesign. Crypto-agility is essential because standards, libraries, hardware support, compliance rules, and threat assessments will continue to evolve.

5. Align procurement and product lifecycles

New products and systems with long lifetimes should support PQC migration from the beginning. This is especially important for network equipment, embedded systems, smart meters, routers, vehicles, industrial devices, and telecom infrastructure.


Where PQC is used

PQC is relevant wherever public-key cryptography is used today.

Secure web traffic

PQC will protect TLS, the protocol behind HTTPS. This affects websites, APIs, mobile apps, cloud services, e-commerce, online banking, enterprise portals, and machine-to-machine communication.

VPNs and enterprise networks

VPNs, zero-trust access systems, SD-WAN, private 5G networks, and enterprise connectivity rely on secure key exchange and authentication. These systems are important PQC migration targets.

Public Key Infrastructure and certificates

PKI is one of the most important migration areas. Certificates are used for websites, servers, users, organizations, devices, and software. PQC affects certificate authorities, certificate formats, hardware security modules, smart cards, and certificate lifecycle management.

Digital signatures

PQC signatures protect software updates, firmware updates, documents, contracts, identity systems, secure boot, code signing, and audit logs. This is where algorithms such as ML-DSA, SLH-DSA, and eventually FN-DSA become important.

Email and messaging

Secure email systems such as S/MIME and OpenPGP, as well as enterprise messaging platforms, need quantum-safe encryption and signatures to protect long-lived communications.

Critical infrastructure

Energy, telecommunications, transport, healthcare, water, finance, public administration, and defense systems often have long lifecycles and high security requirements. These sectors are therefore priority areas in the EU roadmap [4].

IoT, embedded systems, and firmware

Many connected devices remain in operation for 10 to 20 years. PQC is relevant for secure firmware updates, device authentication, connected vehicles, industrial sensors, routers, smart meters, and medical devices.

Telecom networks

Telecom networks use cryptography across core networks, access networks, subscriber identity systems, management interfaces, cloud-native network functions, roaming, APIs, and operational support systems. PQC migration is particularly important because telecom networks are long-lived, distributed, and part of critical infrastructure.


Key message

Post-Quantum Cryptography is not a future topic. It is a migration program that needs to start before large-scale quantum computers become available.

The algorithms are now standardized, the EU roadmap is in place, and Germany’s BSI guidance already supports the transition toward quantum-safe cryptography.

The practical goal is simple:

Identify where vulnerable cryptography is used, prioritize the highest-risk systems, introduce standardized PQC algorithms, and make systems crypto-agile enough to adapt over time.


Quellenangaben

[1] NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 2024.
https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards

[2] NIST, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption,” March 2025.
https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption

[3] European Commission, “Recommendation on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography,” April 2024.
https://digital-strategy.ec.europa.eu/en/library/recommendation-coordinated-implementation-roadmap-transition-post-quantum-cryptography

[4] European Commission, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,” June 2025.
https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography

[5] Bundesamt für Sicherheit in der Informationstechnik, “EU-Roadmap zur Quantenkryptografie,” July 2025.
https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/EU-Roadmap_Quantenkryptografie_250711.html