What is post-quantum cryptography?
A large quantum computer would break the encryption that guards banking and the web. Here is what replaces it, why the change started early, and what to check first.
Post-quantum cryptography means encryption designed to stay safe even against a large quantum computer. Today's public-key schemes rely on factoring and related sums that a quantum machine could solve quickly. The replacements use different hard problems, such as finding the nearest point in a huge grid, for which no fast quantum method is known.
Picture a suggestion box in a market. Anyone walking past can drop a note through the slot. Only the person with the key can open the box and read what is inside.
Public-key encryption works like that box, and it is what keeps your bank app and your messages private. The slot is a public key that anybody may use. The key to the door is a private key that only one side holds.
Post-quantum cryptography is a new set of locks for that box. The old locks rest on sums that ordinary computers cannot do quickly. A large quantum computer could do those sums, so the locks have to change.
What today’s encryption rests on
Two hard sums do most of the work.
The first is factoring. Take two very large prime numbers and multiply them together, then hand someone the answer and ask them for the two primes. So far as anyone knows, that is very slow on a normal computer. This is the basis of RSA, one of the oldest schemes still in wide use.
The second sum is called the discrete logarithm, and it is used in elliptic curve cryptography, which protects most web traffic today. The details differ and the shape is the same. One direction is easy and the other is slow.
Both sums are easy to check and hard to reverse, and that gap is where all the safety lives.
What would a quantum computer break?
Shor’s algorithm, named after Peter Shor, solves both of those sums quickly on a large enough quantum machine. Such a machine would need many steady qubits and a long, error-free run. Given one, RSA and elliptic curve cryptography would both fall.
That covers a lot. It covers the certificate that proves a website really belongs to your bank. It covers the key exchange that starts every secure connection, and it covers most digital signatures.
However, the damage stops there. Symmetric encryption, the kind that scrambles the message once both sides share a key, holds up far better. So do hash functions, which turn a file into a short fingerprint. The best known quantum attack on those roughly halves the strength of a key. The standard answer is simple, and it is to use a longer key. Moving from a 128-bit key to a 256-bit key restores the margin, and that is why 256-bit keys are the common advice now.
Why act now, when no such machine exists?
No public quantum computer can break RSA as of 2026. So why hurry?
Because of an attack with a plain name. Harvest now, decrypt later. Someone records your encrypted traffic today and stores it. They cannot read it yet, so they wait. When a capable machine appears, they go back and read every file they kept.
Therefore the date the machine arrives is only half the question. Ask two more. How long must your data stay secret? How long will it take you to change every system that uses the old locks? Add those two numbers together, and if the total is longer than the time until a capable machine exists, you are already late.
What does the new maths look like?
Different hard problems, picked because no fast quantum method is known for them.
- Lattice problems. Picture a huge grid of points in many dimensions, and a target point sitting off the grid. Finding the nearest grid point is hard. Most of the new standards are built on this idea.
- Hash-based signatures. These lean only on hash functions, which are already well trusted. They are cautious by design, and the signatures are large.
- Code-based encryption. This uses error-correcting codes and deliberate noise. It has been studied for decades, and the keys are big.
- Other families exist, and some were broken during public review. That is the process working as intended.
Notice the pattern. Nobody has proved that these are safe forever. They are safe as far as anyone has managed to test them, which is the same honest footing the old locks always stood on.
Where do the standards stand?
A public contest sorted this out, and teams from around the world submitted designs. Everybody spent years trying to break everybody else’s work.
In 2024 the United States standards body, known as NIST, published the first finished post-quantum standards. The main one for key exchange is a lattice design called ML-KEM. There are signature standards too, one from the same lattice family and one built on hash functions. Other countries and standards bodies have since lined up behind the same designs.
That agreement matters, because encryption only works when both sides support the same scheme. Therefore a private design that nobody else has adopted protects nothing.
What is a hybrid handshake?
Moving to new maths carries a risk of its own, because the new schemes are younger and a flaw could still turn up.
The common answer is to run both at once. A hybrid handshake does the old key exchange and the new one together, then blends the two results into a single key. An attacker has to break both to get in.
This is already in use, and many browsers and large servers now agree a hybrid key by default. You may well be using one while you read this page.
Why is the move so slow?
Encryption is buried everywhere, and much of it is hard to reach.
Keys and certificates sit inside payment terminals, routers, meters, cars and medical devices. Some of that hardware cannot be updated at all, and some of it was installed by a company that no longer exists.
The new keys are also larger, so handshakes carry more data. On a fast link nobody notices. However, on a weak mobile link, or on a small sensor running off a battery, those extra bytes are a real cost.
There is a third problem, and it is the most common one. Many organisations do not know where their own encryption is, and you cannot replace what you cannot find.
What to do this year
Start with a list, and buying comes later.
Write down every place your organisation uses public-key encryption. Websites, virtual private networks, code signing, backups, internal services, and any device out in the field. Then mark the ones that protect data which must stay secret for ten years or more, and those come first.
After that, ask each supplier one question in writing. When will your product support the published post-quantum standards? Keep the replies, and the gap between the confident answers and the vague ones shows you where the real work is.
For background, read our explainers on quantum computing and on quantum error correction. The second one sets the timeline, because a machine that can run Shor’s algorithm against real keys needs working error correction first.
Just Out Tech explains new research in plain language. This article was drafted with AI assistance and checked by a human against the original source.
- Post-quantum cryptography replaces public-key schemes such as RSA and elliptic curve cryptography, which a large quantum computer could break.
- Symmetric encryption and hash functions survive the change, and doubling the key length restores their safety margin.
- Attackers can record encrypted traffic today and open it years later, which is why organisations are moving to post-quantum schemes before any capable machine exists.
Questions people ask
is my data at risk right now?
Not from decryption today, because no public quantum computer can break current encryption as of 2026. The risk is storage. Anyone who records your encrypted traffic now could read it later once a capable machine exists. That only matters for data that must stay secret for many years.
does a quantum computer break all encryption?
No. It threatens public-key schemes such as RSA and elliptic curve cryptography, which handle key exchange and digital signatures. Symmetric encryption and hash functions are far less affected. Using a longer symmetric key, such as 256 bits instead of 128, restores the safety margin.
what does a hybrid handshake mean?
It means running an old key exchange and a post-quantum one side by side, then blending both results into one key. An attacker would have to break both schemes to succeed. It guards against a hidden flaw in the newer maths, and many browsers and servers already use it.
when should an organisation migrate?
Start the inventory now and migrate the long-lived secrets first. Add the years your data must stay secret to the years your migration will take. If that total runs past the point where a capable quantum machine could exist, you are already behind and should begin.