Post-Quantum Cryptography
Post-Quantum Cryptography, or PQC, is a new generation of cryptographic algorithms designed to remain secure even against powerful future quantum computers.
Today, much of the internet relies on public-key cryptography such as RSA, Diffie-Hellman, and elliptic-curve cryptography. These systems protect secure websites, VPNs, email, software updates, digital signatures, identity systems, telecom infrastructure, and cloud services.
A sufficiently powerful quantum computer could break many of these classical public-key systems. That is why governments, standardization bodies, and companies are preparing the transition to quantum-safe cryptography now. NIST has finalized the first post-quantum cryptographic standards and recommends that organizations begin integrating them because full migration will take time [1].
PQC does not usually mean using quantum computers. In most cases, it means using new cryptographic algorithms that run on today’s classical computers, servers, mobile devices, chips, routers, cloud platforms, and embedded systems.
One major reason to act early is the “harvest now, decrypt later” threat. Attackers may collect encrypted data today and decrypt it in the future once quantum computers become powerful enough. This is especially relevant for data that must remain confidential for many years, such as government, healthcare, financial, industrial, telecom, and critical infrastructure information.
Standardized PQC algorithms
The most important standardized PQC algorithms currently come from the NIST Post-Quantum Cryptography Standardization Process.
|
Algorithm |
Standard |
Main purpose |
Original name |
Cryptographic family |
|---|---|---|---|---|
|
ML-KEM |
FIPS 203 |
Key establishment / encryption |
CRYSTALS-Kyber |
Lattice-based |
|
ML-DSA |
FIPS 204 |
Digital signatures |
CRYSTALS-Dilithium |
Lattice-based |
|
SLH-DSA |
FIPS 205 |
Digital signatures |
SPHINCS+ |
Hash-based |
|
FN-DSA |
In progress, FIPS 206 |
Digital signatures |
FALCON |
Lattice-based |
|
HQC |
Selected, final standard expected in 2027 |
Key establishment / encryption |
HQC |
Code-based |
NIST finalized the first three PQC standards in August 2024: ML-KEM, ML-DSA, and SLH-DSA [1]. These algorithms are intended to replace or complement vulnerable classical public-key algorithms in encryption, key exchange, and digital signatures.
NIST has also announced FN-DSA, based on FALCON, as an additional digital signature standard in progress [1]. In 2025, NIST selected HQC as an additional post-quantum encryption algorithm. HQC is intended to provide algorithmic diversity as a backup to ML-KEM because it is based on different mathematical assumptions [2].
EU roadmap for PQC migration
The European Union is treating PQC migration as a coordinated cybersecurity transition. In April 2024, the European Commission issued a recommendation encouraging Member States to develop a coordinated approach for the transition to post-quantum cryptography [3].
In June 2025, EU Member States, supported by the European Commission and the NIS Cooperation Group, published “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography.” The roadmap defines a phased approach for public authorities, critical infrastructure, and other high-risk sectors [4].
EU migration timeline
|
Timeline |
EU migration focus |
|---|---|
|
By end of 2026 |
Member States should start national PQC strategies, pilot projects, cryptographic inventories, and identification of high-risk applications. |
|
By end of 2030 |
High-risk applications should be migrated to PQC, especially systems in critical infrastructure and systems with long confidentiality or authenticity lifetimes. |
|
By end of 2035 |
PQC migration should be largely completed for remaining systems where technically and economically feasible. |
The EU roadmap emphasizes that migration is not only a technical replacement of algorithms. It also requires planning, prioritization, procurement changes, interoperability testing, and long-term crypto-agility [4].
Germany’s PQC migration direction
Germany’s PQC migration is strongly shaped by the Federal Office for Information Security, the BSI. Germany is actively involved in the European coordination of PQC migration and has contributed to the EU roadmap together with European partners [5].
The BSI has been preparing for quantum-safe cryptography for several years. Its technical guideline TR-02102-1 has included post-quantum cryptographic mechanisms since 2020 and was updated to reflect the new NIST standards [5].
For organizations in Germany, the practical direction is clear:
1. Build a cryptographic inventory
Organizations need to identify where classical public-key cryptography is used. This includes TLS, VPNs, SSH, PKI, certificates, digital signatures, software signing, email encryption, device authentication, APIs, and embedded systems.
2. Prioritize high-risk systems
Priority should be given to systems with long-lived confidentiality requirements, critical infrastructure, public administration, telecom networks, finance, healthcare, energy, transport, and industrial environments.
3. Use hybrid migration models
During the transition period, many systems will combine classical algorithms with PQC algorithms. Hybrid approaches can reduce migration risk while new standards, implementations, and compliance requirements mature.
4. Establish crypto-agility
Systems should be designed so cryptographic algorithms can be replaced without major redesign. Crypto-agility is essential because standards, libraries, hardware support, compliance rules, and threat assessments will continue to evolve.
5. Align procurement and product lifecycles
New products and systems with long lifetimes should support PQC migration from the beginning. This is especially important for network equipment, embedded systems, smart meters, routers, vehicles, industrial devices, and telecom infrastructure.
Where PQC is used
PQC is relevant wherever public-key cryptography is used today.
Secure web traffic
PQC will protect TLS, the protocol behind HTTPS. This affects websites, APIs, mobile apps, cloud services, e-commerce, online banking, enterprise portals, and machine-to-machine communication.
VPNs and enterprise networks
VPNs, zero-trust access systems, SD-WAN, private 5G networks, and enterprise connectivity rely on secure key exchange and authentication. These systems are important PQC migration targets.
Public Key Infrastructure and certificates
PKI is one of the most important migration areas. Certificates are used for websites, servers, users, organizations, devices, and software. PQC affects certificate authorities, certificate formats, hardware security modules, smart cards, and certificate lifecycle management.
Digital signatures
PQC signatures protect software updates, firmware updates, documents, contracts, identity systems, secure boot, code signing, and audit logs. This is where algorithms such as ML-DSA, SLH-DSA, and eventually FN-DSA become important.
Email and messaging
Secure email systems such as S/MIME and OpenPGP, as well as enterprise messaging platforms, need quantum-safe encryption and signatures to protect long-lived communications.
Critical infrastructure
Energy, telecommunications, transport, healthcare, water, finance, public administration, and defense systems often have long lifecycles and high security requirements. These sectors are therefore priority areas in the EU roadmap [4].
IoT, embedded systems, and firmware
Many connected devices remain in operation for 10 to 20 years. PQC is relevant for secure firmware updates, device authentication, connected vehicles, industrial sensors, routers, smart meters, and medical devices.
Telecom networks
Telecom networks use cryptography across core networks, access networks, subscriber identity systems, management interfaces, cloud-native network functions, roaming, APIs, and operational support systems. PQC migration is particularly important because telecom networks are long-lived, distributed, and part of critical infrastructure.
Key message
Post-Quantum Cryptography is not a future topic. It is a migration program that needs to start before large-scale quantum computers become available.
The algorithms are now standardized, the EU roadmap is in place, and Germany’s BSI guidance already supports the transition toward quantum-safe cryptography.
The practical goal is simple:
Identify where vulnerable cryptography is used, prioritize the highest-risk systems, introduce standardized PQC algorithms, and make systems crypto-agile enough to adapt over time.
Quellenangaben
[1] NIST, “NIST Releases First 3 Finalized Post-Quantum Encryption Standards,” August 2024.
https://www.nist.gov/news-events/news/2024/08/nist-releases-first-3-finalized-post-quantum-encryption-standards
[2] NIST, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption,” March 2025.
https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption
[3] European Commission, “Recommendation on a Coordinated Implementation Roadmap for the transition to Post-Quantum Cryptography,” April 2024.
https://digital-strategy.ec.europa.eu/en/library/recommendation-coordinated-implementation-roadmap-transition-post-quantum-cryptography
[4] European Commission, “A Coordinated Implementation Roadmap for the Transition to Post-Quantum Cryptography,” June 2025.
https://digital-strategy.ec.europa.eu/en/library/coordinated-implementation-roadmap-transition-post-quantum-cryptography
[5] Bundesamt für Sicherheit in der Informationstechnik, “EU-Roadmap zur Quantenkryptografie,” July 2025.
https://www.bsi.bund.de/DE/Service-Navi/Presse/Alle-Meldungen-News/Meldungen/EU-Roadmap_Quantenkryptografie_250711.html