Technology

Post-Quantum Encryption: What the New NIST Standards Mean for You

Quantum computers could one day break the encryption that protects online banking and messages. Here is what NIST's new post-quantum standards do, and what ordinary users can actually do now.

Illustration of a padlock with a gold keyhole beside a red diamond shape

The encryption that protects online banking, private messages and medical records was designed for a world without large quantum computers. The US National Institute of Standards and Technology (NIST) has already published replacement standards, and the slow, behind-the-scenes switch to them is underway.

This guide explains what the threat is, what NIST has standardized, why the timing matters even though no one knows when the risk arrives, and what everyday users can reasonably do.

What exactly is the quantum threat to encryption?

Most of the encryption that secures the internet depends on math problems that ordinary computers find far too hard to solve in any useful time. A website proves its identity, and two devices agree on a secret key, using those problems as a lock.

According to NIST, a sufficiently capable quantum computer would be able to work through a vast number of potential solutions far faster than today’s machines. That could undermine the protection behind, in NIST’s words, “just about everything we do online.” NIST’s own explainer is careful on one point: current quantum computers are too small and unstable to pose this threat today.

The concern, then, is about a future machine, not a present one. A “cryptographically relevant” quantum computer would need many thousands of qubits, the fragile units of quantum information that are prone to errors.

When could it actually happen?

Nobody knows, and NIST says so directly. In its “What Is Post-Quantum Cryptography?” page, the agency notes that estimates range from “a few years to a few decades,” and that some people think it could happen in under 10 years. It also says it is not possible to predict exactly when, or even if, such a machine will break present-day encryption.

That uncertainty is the reason the work is happening now rather than later. If the date were known, organizations could schedule a migration. Because it is not, the sensible approach is to prepare before it is needed.

What are the three NIST standards?

On August 13, 2024, NIST released its first three finalized post-quantum encryption standards. They came out of an eight-year effort that began in 2015, in which NIST assessed 82 candidate algorithms submitted from 25 countries.

Standard Algorithm What it is for
FIPS 203 ML-KEM (formerly CRYSTALS-Kyber) Primary standard for general encryption
FIPS 204 ML-DSA (formerly CRYSTALS-Dilithium) Primary standard for digital signatures
FIPS 205 SLH-DSA (formerly SPHINCS+) Backup digital signature standard, built on a different mathematical approach

The two jobs matter. General encryption protects information exchanged across a public network, such as the connection between a browser and a bank. Digital signatures verify identity and show that software or documents have not been tampered with.

NIST’s initial algorithms are based on structured lattices and hash functions. The agency’s stated aim is to offer more than one algorithm for each application, in case one proves vulnerable.

Why does the backup signature standard use different math?

SLH-DSA exists as insurance. If a weakness were found in the lattice math behind ML-DSA, a signature scheme built on a different foundation would still stand. The same logic applies to encryption, which leads to the next development.

Why did NIST add a fifth algorithm?

On March 11, 2025, NIST announced it had selected a fifth algorithm, HQC, to serve as a backup for general encryption. HQC uses error-correcting codes, which have been used in information security for decades, rather than the structured lattices behind ML-KEM. Reviewers judged its operation clean and secure. Its main drawback, according to NIST, is that it is a longer algorithm that requires more computing resources.

HQC is a fallback, not a replacement. NIST said ML-KEM remains the recommended choice for general encryption. At that time the agency planned a draft standard for public comment in about a year, with finalization expected in 2027. It also said a draft of a fourth standard, FIPS 206, based on the FALCON signature algorithm, was expected shortly. Readers following the topic should rely on NIST’s own updates, since marketing around “quantum-safe” products can run ahead of the actual standards.

What does “harvest now, decrypt later” mean?

This phrase explains the urgency. An adversary can intercept and store encrypted data today and simply hold onto it until a quantum computer capable of breaking the encryption exists. The data does not have to be readable now to be valuable later.

NIST’s guidance on this point is that information which must stay secret for years or decades is already exposed to this approach, and that waiting for a quantum computer to appear means waiting too long. A tax record, a medical history, or a government secret loses little value with age. A one-time login code loses almost all of it within minutes.

That distinction is useful in practice:

  • Long shelf life: health records, legal documents, identity details, trade secrets.
  • Short shelf life: session tokens, one-time codes, routine traffic of no lasting interest.

Organizations are therefore asked to identify their most sensitive, longest-lived data first.

Why is this migration so hard?

Swapping encryption algorithms sounds like a software update. In reality, cryptography is buried in browsers, servers, apps, payment systems, embedded devices, certificates and hardware. NIST describes the move to new algorithms as a yearslong process for companies and expects this transition to be the most challenging one yet, because of how many systems it touches and how complex the change is.

Many steps also have to happen in sequence. Vendors need to ship support, organizations need to find out where they use cryptography at all, and systems that are difficult to update, such as industrial equipment, take longest.

For organizations, NIST recommends a short list of first steps:

  1. Inventory systems, applications and data to see where cryptography is used.
  2. Identify the most sensitive data, which is most exposed to harvest-now, decrypt-later collection.
  3. Build a migration roadmap and ask technology vendors when and how they will support post-quantum cryptography.
  4. Build post-quantum support into purchasing and IT modernization decisions, and ask partners and suppliers about their plans.

What should everyday users do?

Far less than organizations, and almost none of it is technical. NIST’s guidance for individuals is short:

  • Turn on automatic updates. Devices will receive post-quantum protections as vendors roll them out.
  • Expect gradual change. NIST expects apps, browsers and other tools to adopt post-quantum cryptography over the next decade.
  • Ask when choosing products. When picking a new product or service, ask whether it supports the new standards.

Nothing here requires changing a password or buying special software today. Moving to passkeys instead of passwords is a practical example of a security upgrade that is available now.

How does this connect to AI tools and cloud services?

Many of the tools people use at work, including generative AI assistants and AI agents that act on a user’s behalf, send sensitive data across networks to cloud services. Their post-quantum readiness is therefore part of the same vendor conversation NIST suggests having: ask providers how and when they plan to adopt the new standards.

Illustrative arithmetic: how long is long enough?

A simple worked example shows why timing matters. Suppose an organization holds records that must stay confidential for 15 years, and its migration to new encryption would take 5 years to complete. Suppose also, purely for illustration, that a capable quantum computer arrived 15 years from now.

  • Start the migration today and it finishes in year 5, ten years before the hypothetical machine arrives. Data protected with the new algorithms from year 5 onward has a 10-year cushion.
  • Start in year 10 and it finishes in year 15, exactly when the machine arrives, with no cushion at all. Anything captured in the meantime under the old encryption, and still sensitive after year 15, is exposed.
  • Delay to year 12 and the migration finishes in year 17, two years after the machine arrives. Everything sent under old encryption through those years is open to decryption.

The numbers are hypothetical, but the structure is not: the time needed to migrate has to fit inside the time before the threat arrives. When the arrival date is unknowable, starting early is the only way to keep a margin.

A slow transition, with a clear starting point

Post-quantum encryption is a long-running infrastructure project rather than an emergency for individuals. The standards exist, the guidance is consistent, and the main burden falls on the organizations that build and run the systems. For everyone else, the most useful actions are the unglamorous ones: keep devices updated, use modern sign-in methods, and ask the companies holding your most sensitive data how they plan to adapt.

This article is general information about technology and security and is not professional security advice.

Sources: National Institute of Standards and Technology