Post-quantum cryptography: why prepare now
The public-key algorithms widely deployed today (RSA, elliptic curves) rely on mathematical problems that sufficiently powerful quantum computers could solve efficiently. In 2024, NIST finalized its first post-quantum cryptography standards (ML-KEM, derived from CRYSTALS-Kyber, for key exchange, and ML-DSA, derived from CRYSTALS-Dilithium, for digital signatures), marking a decisive step toward widespread adoption.
The risk isn't limited to a theoretical future scenario: encrypted traffic intercepted today can be stored and decrypted retroactively once sufficient quantum computing power exists — the so-called "harvest now, decrypt later" strategy. Data that must remain confidential over the long term (trade secrets, health records, sensitive government data) is directly at risk, which is why preparation should start now rather than after the threat materializes.
Preparing doesn't mean migrating in a rush, but rather adopting a crypto-agility approach: mapping existing cryptographic usage, identifying data with long confidentiality horizons, and designing architectures able to integrate new algorithms without a complete overhaul.
Our PDF courses cover the practical implementation of a crypto-agility approach in detail.
View PDF Courses