Post-quantum cryptography: why you should start now
Future quantum computers could break today's encryption. What is post-quantum cryptography, what does the EU expect, and how does a business get started?
Almost everything you secure online, from websites and VPNs to email and payments, relies on encryption such as RSA and elliptic curves. It is safe today. But a sufficiently powerful quantum computer could break these forms of encryption in the future. That is why the world has started moving to post-quantum cryptography: encryption that also withstands quantum computers.
"But those quantum computers don't exist yet?"
True, a quantum computer that can break RSA does not exist yet. Still, there is a risk today, known as "harvest now, decrypt later". Attackers intercept encrypted data now and store it, expecting to decrypt it a number of years from now.
For data that must stay confidential for a long time, such as medical records, contracts, trade secrets and personal data, that is a real problem. What you send today must still be secret in ten or fifteen years.
On top of that, the migration itself takes a long time. In large organisations it takes years to replace or update every system, integration and device.
The new standards are already here
The US National Institute of Standards and Technology (NIST) published the first three post-quantum standards in August 2024:
- ML-KEM (FIPS 203) for secure key exchange, for example when setting up an HTTPS connection;
- ML-DSA (FIPS 204) for digital signatures;
- SLH-DSA (FIPS 205) as an alternative signature scheme based on different mathematics.
Browsers and operating systems already support the first steps. Recent versions of Chrome, Firefox and OpenSSL, among others, can set up connections with a hybrid key exchange, classical and post-quantum at the same time.
What does the EU expect?
In June 2025, the European Commission and the member states published a coordinated roadmap for the transition:
- End of 2026: all member states have started moving to post-quantum cryptography.
- By the end of 2030 at the latest: high-risk systems, such as critical infrastructure, have migrated.
- 2035: the transition is complete for as many systems as practically feasible.
The roadmap targets governments and critical sectors, but the effects are broader. Suppliers to those organisations will sooner or later face the same requirements, and NIS2 already requires appropriate encryption and risk management.
How to get started
1. Build a crypto inventory. Where do you use encryption? Think of websites, VPNs, email, API integrations, databases, backups, certificates and devices on your network. Most organisations are surprised by how long this list is.
2. Decide what must stay secret for long. Which data must still be confidential in ten years? That is your biggest risk, and where you start.
3. Ask your suppliers about their plans. Much of your encryption lives in other people's software and services. Ask when they will support post-quantum algorithms.
4. Build crypto agility. Set up systems so you can swap algorithms without rebuilding everything. That makes this migration, and future changes, much easier.
5. Migrate in phases. Start with the hybrid approach where the risk is highest, test thoroughly, then expand.
How we help
Nuraghi Cloud builds a crypto inventory of your systems, works with you to identify where the risk is highest, and drafts a phased migration plan to the NIST standards. A first quick scan is included in our readiness scan.
Sources
- European Commission: EU reinforces its cybersecurity with post-quantum cryptography
- NIST: Post-Quantum Cryptography standardization