The U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) has finalized its principal set of defensive post-quantum encryption algorithms, bringing some clarity to the process of preparing for the near future’s likely greatest cyber threat.
The three new algorithms are the first standards released as part of a research process that has now spanned almost a decade, as governments and security researchers around the world have scrambled to prepare for the looming reality of quantum computers that can potentially crack modern encryption in minutes or even seconds. These algorithms are far from the end of the preparatory process, but allow organizations to begin taking concrete action on post-quantum encryption strategies that may need to be operational by the early 2030s.
Shape of post-quantum encryption beginning to come into focus
Formally announced on August 14, the three NIST Federal Information Processing Standards (FIPS) were first introduced in 2017 along with a bundle of 66 others that were ultimately winnowed down through multiple evaluation rounds over the years. NIST ultimately selected CRYSTALS-KYBER as its public-key encapsulation mechanism and three digital signature schemes: CRYSTALS-Dilithium, FALCON, and SPHINCS+. These will be put to use as the US government’s post-quantum encryption standards for what is anticipated to be many years to come.
All have proven resilient to the theoretical level of attacks expected from quantum computers that might be developed in the next decade or two. FIPS 203 uses a form of cryptography called Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM), derived from the CRYSTALS-KYBER standard. FIPS 204 and 205 are digital signature schemes derived from CRYSTALS-Dilithium and SPHINCS+; NIST plans to develop one more of these schemes using the FALCON submission in the near future.
In addition to that third digital signature scheme, NIST continues to evaluate a number of general-purpose post-quantum encryption algorithms that are based on a different type of math problem. The agency expects to select one or two of these as backup methods by the end of 2024. It is also still evaluating a separate group of about 15 algorithms that might also someday serve as backups, with these having only been submitted in 2022 and still having some rounds of testing and narrowing down ahead of them.
But NIST is telling the public that these future selections are not necessarily going to be superior in any way to the three that have just been introduced, and that organizations should begin transitioning to these existing post-quantum encryption standards as soon as possible. It remains unclear when stable quantum computers capable of cracking modern encryption will emerge, but researchers have cautioned that it could be as early as eight to ten years from now. The US National Security Agency has set a deadline of 2035 for the country’s National Security Systems to complete their migration to post-quantum encryption standards.
Jon France, CISO of ISC2, elaborates on the technical workings of these new standards: “We welcome the announcement and the official release of crypto suites that are quantum resilient, especially as they come from more than one family of maths (lattices and hashes). Not only does this allow best use case selection but also diversifies the base of the cryptographic suite which in itself may prove useful for protection. Two of the three standards are based on a family of math problems called structured lattices and one is based on hash patterns. They’re hedging their bets that if lattice-based algorithms prove to be weak or inefficient, they’re going to need others that are efficient. So, the focus on quantum-resistant algorithms is strong in the research community, and I anticipate we’ll see more of that activity and search for improved algorithms from NIST, ETSI and others.”
“Steal now, decrypt later” approach threatens encrypted data taken today
Security researchers caution that the longer organizations wait to update to post-quantum encryption standards, the more they fall behind. A rash of “steal now, decrypt later” thefts are taking place, particularly by the most advanced nation-state APT hacking groups; these groups seek encrypted data that is virtually impossible to crack now, but will be trivial once quantum computers become available to them. Most at risk is “permanent” data that can still cause havoc 10 or more years from now, such as sensitive personal information that will not change.
The news with quantum computing is not all “doom and gloom” as the greatly increased power of these machines promises gigantic leaps in a variety of areas, from health care to general technology; they will also likely push AI to the level of capability that modern systems are only showing brief flashes of. But they will also make the math problems that underpin modern encryption (factoring large numbers into prime factors) trivial to solve, not just rendering individual files vulnerable but also breaking protocols such as the Secure Sockets Layer (SSL) and AES 256-bit that are foundational to the secure operation of the entire internet.
NIST is a global center for encryption and has drawn together the world’s foremost researchers for this project, and the EU and other nations have already signaled that they will either endorse or use whatever post-quantum encryption standards the agency settles on. The development of these standards appears to be running ahead of the development of quantum computers, the most advanced of which remain relatively small and hard to scale and have a variety of problems with stability and fragility. And even if these problems are sorted out along the most optimistic timeframe of inside a decade somewhere, it is extremely unlikely it will be available to home users or private threat actors in any way for a much longer time.
Still, organizations need to begin considering their changeover strategy now that the relevant tools are actually available. As Karl Holmqvist, Founder and CEO of Lastwall, notes: “We have been warned by the heads of the NSA, the FBI, and even the White House that there are active nation-state attacks stealing currently encrypted data and that we need to switch PQC algorithms. This announcement by NIST is fantastic and a positive progression for defense against a significant thread. In the last few years, the landscape of quantum computation has dramatically changed. The potential for a cryptographic class break is much more real than most people realize. Thirty years ago, in 1994, Peter Shor demonstrated that we would need approximately 4,100 qubits to factor 2048-bit RSA, which is the most broadly deployed asymmetric encryption algorithm. At that time, we had no quantum computers available, and people questioned if we would ever develop a functional quantum computer … Five years ago, KTH and Google researchers demonstrated that while we would need over 3,500 qubits to make each stable logical qubit, a 20-million-qubit system would crack 2048-bit RSA in less than eight hours. Time is not on our side to change to quantum-resistant ciphers. We need to address this now – it’s time to get to work and eliminate outdated cryptography.”
Murali Palanisamy, Chief Solutions Officer at AppViewX, elaborates on steps that organizations should be considering: “The standardization by NIST of three Quantum Resilient algorithms is an important first step toward preparing for Post-Quantum Cryptography (PQC). The journey to PQC readiness will be long, so we hope that organizations have already started down this path. The first step is to implement Crypto-Agility to gain visibility and an inventory of your crypto environment and be ready for crypto challenges which include PQC. Another important step is to begin testing the new Quantum Resilient algorithms and certificates to understand the impact they will have on critical systems and applications. While the threat of Quantum computers breaking today’s cryptographic algorithms may be a few years away at minimum, the time to start preparing is now with the release of the first set of Quantum Resilient algorithms by NIST.”
Jason Soroko, Senior Vice President of Product at Sectigo, adds: “NIST’s Post-Quantum Cryptography (PQC) standards mark a key step toward quantum-resistant systems, introducing algorithms to counter quantum threats. Organizations must take inventory of all of their cryptographic systems, identify where quantum-vulnerable algorithms like RSA or ECC are used, and plan a phased migration to PQC for both private and publicly trusted certificates and key generation. Working with security vendors will be critical in testing and understanding these algorithms in non-production environments. Identifying critical secrets that are transmitted along with legacy cryptographic algorithms will help to understand systems that need updating sooner than later due to the harvest and decrypt problem. Continuous monitoring of PQC developments and NIST standards is also crucial. Organizations should start planning for quantum-resistant solutions immediately. The dates of 2029 or 2030 have been discussed as being a date for organizations to assume that RSA and ECC could be deprecated due to advances in quantum computing. In the short term (1-2 years), they should assess current cryptographic systems, conduct audits, and initiate PQC pilots, ensuring vendor adoption of NIST standards. In the medium term (3-5 years), focus on deploying PQC in production environments and monitor QKD advancements for potential integration. In the long term (5-10 years), aim for full PQC implementation across critical systems, with QKD considered for highly sensitive sectors.”

