Skip to content
ContentLora

    Tip: press / anywhere to search.

    Explainer

    Post-quantum cryptography and security in 2026: a crash course

    A large enough quantum computer could break RSA and elliptic-curve cryptography, the public-key systems that protect most internet traffic, so governments and companies are switching to new "post-quantum" algorithms that NIST standardized in 2024.[1][2] As of October 2026 most browser traffic to large networks already uses post-quantum key exchange, the US has set 2030-2031 deadlines for its most sensitive systems, and AI has become a major new factor on both sides of cybersecurity.[3][4][5]

    Editor reviewedUpdated Post-quantum cryptography and securityComputingTech policy

    Why this field matters

    Every time you open a secure website, send a private message or install a software update, public-key cryptography is working in the background. Two families do most of that work: RSA, and elliptic-curve cryptography (ECC). In 1994 the mathematician Peter Shor showed that a quantum computer could solve the math problems both families rely on.[6][1]

    Nobody has built that machine yet. NIST, the US standards agency, says no one knows when one will appear; expert guesses range from a few years to a few decades.[7] The problem is that attackers can record encrypted traffic today and wait. Once a capable quantum computer exists, they could decrypt it. This is called “harvest now, decrypt later”.[8] Changing the world’s cryptography has historically taken 10 to 20 years, which is why the work has already started.[9]

    Shor’s algorithm solves integer factorization and discrete logarithms in polynomial time. That breaks RSA, finite-field Diffie-Hellman and elliptic-curve schemes alike. Grover’s algorithm only gives a quadratic speed-up against symmetric ciphers and hashes, which larger keys can absorb.[1][10] The estimated cost of an attack keeps falling. A 2025 estimate put RSA-2048 at under a million noisy qubits for under a week, and a March 2026 Google estimate put 256-bit ECC at fewer than 1,200 logical qubits.[11][12] Confidentiality is exposed to harvest-now-decrypt-later attacks today. Authentication is only at risk once a cryptographically relevant quantum computer (CRQC) actually exists.[13]

    A map of the field

    The field has five overlapping parts:

    Key ideas

    Post-quantum algorithms do two jobs. They agree on secret keys over the internet, and they sign data so you know who sent it.[19] They run on ordinary computers. You do not need a quantum computer to use them. The catch is size: an ML-KEM public key is 1,184 bytes, far larger than the elliptic-curve keys it replaces.[20]

    Most deployments today are “hybrid”. They combine a classic algorithm with a post-quantum one, so an attacker has to break both.[21]

    ML-KEM is a key-encapsulation mechanism whose security rests on Module Learning With Errors (MLWE). ML-DSA is an MLWE-based signature scheme. SLH-DSA relies only on hash functions.[22][23][24] NIST deliberately keeps backups based on different math. HQC uses error-correcting codes in case a weakness turns up in lattices.[25] That caution comes from experience. SIKE, an isogeny-based candidate, was broken classically in 2022 on a single core.[26] NIST treats hybrids as temporary because they add complexity.[27]

    Who the main players are

    • Standards bodies and governments. NIST runs the standardization process. The IETF published RFC 10024 in August 2026, defining hybrid ML-KEM key exchange for TLS 1.3.[28] The UK NCSC, the EU and the US government have set migration deadlines.[29][30][4]
    • Platforms. Google moved Chrome to hybrid ML-KEM and set a 2029 migration target. Apple ships hybrid TLS in iOS 26 and PQ3 in iMessage. Cloudflare reports most human traffic to its network as post-quantum encrypted. Signal added post-quantum protection to its protocol in 2023 and 2025.[31][32][33][34][3][35]
    • Open source. OpenSSL 3.5 added ML-KEM, ML-DSA and SLH-DSA in April 2025.[36]
    • Quantum hardware builders. Their progress sets the clock. See quantum computing crash course. A March 2026 preprint by researchers at Oratomic, Caltech and UC Berkeley argued that about 10,000 neutral-atom qubits could be enough to run Shor’s algorithm at cryptographically relevant scale, a theoretical estimate that still faces large engineering hurdles.[37][38]
    • Security agencies. NSA’s CNSA 2.0 suite and the EU roadmap both target 2035 for completing the transition, with earlier dates for the most sensitive systems.[39][40]
    • AI labs and security teams. DARPA, Google and anthropic have all shown AI systems finding real vulnerabilities.[41][42][5]

    Where the frontier is (October 2026)

    Encrypting web traffic against future quantum attacks is going well. Cloudflare saw client support rise from under 3% of traffic in early 2024 to over 60% by February 2026.[43] The harder part is authentication, meaning certificates and signatures. Google and Cloudflare both now put authentication first and aim to finish by 2029.[44][45] Governments are setting deadlines. A June 2026 US executive order gives the most sensitive federal systems until the end of 2030 for encryption and the end of 2031 for signatures.[4]

    Open items as of October 2026 include the HQC draft standard and FIPS 206 (FN-DSA), neither yet finalized.[15] NIST is also running a third round of additional signature schemes, and IR 8547’s 2030/2035 deprecation schedule is still a draft.[46][47][48] Post-quantum signatures are much larger than today’s: ML-DSA-44 signatures are 2,420 bytes.[49] That makes the Web PKI the hardest migration target.[50] On the AI side, Anthropic reported a largely AI-executed espionage campaign in 2025. In April 2026 it said its Mythos Preview model had found thousands of high-severity vulnerabilities.[51][5]

    Two debates remain open: how fast to migrate, given expert estimates that range from a few years to a few decades, and whether AI helps attackers or defenders more.[7][52] See the migration timeline debate and the AI and cybersecurity debate. Dated milestones are in the post-quantum and security tracker.

    Questions readers ask

    Can quantum computers break encryption today?

    No. Breaking current encryption needs quantum computers with many thousands of high-quality qubits, and NIST says no one knows when one will exist; expert estimates range from a few years to a few decades.[53][7]

    What are the new post-quantum standards?

    NIST published FIPS 203 (ML-KEM, for establishing keys), FIPS 204 (ML-DSA, for signatures) and FIPS 205 (SLH-DSA, a backup signature scheme) on 13 August 2024, and picked HQC as a backup key-establishment algorithm in March 2025.[2][25]

    Am I already using post-quantum encryption?

    Quite possibly. Cloudflare said in April 2026 that over 65% of human traffic to its network was post-quantum encrypted, and current Chrome and Apple operating systems offer hybrid ML-KEM key exchange by default.[3][31][33]

    Why move now if quantum computers are years away?

    Because attackers can record encrypted data now and decrypt it later, and because past cryptographic migrations have taken 10 to 20 years.[8][9]

    Sources

    Each numbered claim is a statement we checked against the sources listed with it. Status shows how well established it is.

    1. [1]

      A large-scale quantum computer would make insecure the public-key systems based on integer factorization, such as RSA, and those based on the discrete logarithm problem, which includes elliptic-curve cryptography. confirmedas of 2026-10-10

    2. [2]

      On 13 August 2024 NIST published its first three finalized post-quantum standards, FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA). confirmedas of 2024-08-13

    3. [3]

      As of April 2026, Cloudflare said over 65% of human traffic to its network was post-quantum encrypted. confirmedas of 2026-04-07

    4. [4]

      The order requires agencies to move all high value assets and high-impact systems to PQC for key establishment by 31 December 2030 and for digital signatures by 31 December 2031. confirmedas of 2026-06-25

    5. [5]

      Anthropic said Claude Mythos Preview had found thousands of high-severity vulnerabilities, including some in every major operating system and web browser. confirmedas of 2026-04-07

    6. [6]

      In 1994 Peter Shor of Bell Laboratories showed that quantum computers can efficiently solve the mathematical problems that public-key cryptosystems rely on, such as factoring and discrete logarithms. confirmedas of 2026-10-10

    7. [7]

      NIST says no one knows when a quantum computer able to threaten current encryption will appear, with expert estimates ranging from a few years to a few decades. confirmedas of 2026-10-10

    8. [8]

      In a "harvest now, decrypt later" attack, an adversary captures encrypted data today and stores it, hoping a future quantum computer will break the encryption. confirmedas of 2026-10-10

    9. [9]

      NIST says it has historically taken 10 to 20 years from the standardization of a new algorithm until it is fully integrated into information systems. confirmedas of 2026-10-10

    10. [10]

      Grover's algorithm gives only a quadratic speed-up against symmetric-key systems, and NIST judged that doubling the key size would be enough to preserve their security. confirmedas of 2026-10-10

    11. [11]

      A May 2025 Google preprint estimated that 2048-bit RSA could be factored in less than a week by a quantum computer with fewer than a million noisy qubits, down from a 2019 estimate of 20 million noisy qubits. confirmedas of 2026-10-10

    12. [12]

      In March 2026 Google researchers estimated that breaking 256-bit elliptic-curve cryptography would need fewer than 1,200 logical qubits and 90 million Toffoli gates, or under 500,000 physical superconducting qubits running for a few minutes. confirmedas of 2026-03-31

    13. [13]

      Unlike encryption, authentication is not exposed to harvest-now-decrypt-later attacks; it stays secure as long as the algorithms and keys are secure at the moment authentication is performed. confirmedas of 2026-10-10

    14. [14]

      Of the four algorithms NIST first selected, three are based on structured lattices and one on hash functions, math problems experts believe are hard for both classical and quantum computers. confirmedas of 2026-10-10

    15. [15]

      As of its August 2026 update, NIST's project page said Falcon and HQC had been selected for standardization and that the process was still underway. confirmedas of 2026-08-05

    16. [16]

      NIST defines cryptographic agility as the capabilities needed to replace and adapt cryptographic algorithms in protocols, applications, software, hardware, firmware and infrastructure while preserving security and ongoing operations. confirmedas of 2025-12-19

    17. [17]

      On 8 August 2025 DARPA named Team Atlanta, with members from Georgia Tech, Samsung Research, KAIST and POSTECH, the winner of its two-year AI Cyber Challenge, with Trail of Bits second and Theori third. confirmedas of 2025-08-08

    18. [18]

      Anthropic reported in November 2025 that a group it assessed with high confidence to be Chinese state-sponsored used its Claude Code tool to attempt intrusions into roughly thirty organizations in September 2025, succeeding in a small number of cases. confirmedas of 2025-11-13

    19. [19]

      Post-quantum algorithms are designed for two main tasks, general encryption (establishing keys) and digital signatures used for authentication. confirmedas of 2026-10-10

    20. [20]

      In ML-KEM-768 the encapsulation (public) key is 1,184 bytes and the ciphertext 1,088 bytes, and every parameter set produces a 32-byte shared secret. confirmedas of 2024-08-13

    21. [21]

      Hybrid schemes combine a quantum-resistant and a classical algorithm and are typically designed to stay secure if at least one of the two components is secure. confirmedas of 2024-11-12

    22. [22]

      ML-KEM's security rests on the difficulty of solving certain systems of noisy linear equations, the Module Learning With Errors (MLWE) problem, and it is believed to be secure even against quantum adversaries. confirmedas of 2024-08-13

    23. [23]

      ML-DSA is based on the Module Learning With Errors problem and is believed to be secure, and strongly unforgeable, even against an adversary with a large-scale fault-tolerant quantum computer. confirmedas of 2024-08-13

    24. [24]

      SLH-DSA is a stateless hash-based digital signature algorithm based on SPHINCS+. confirmedas of 2024-08-13

    25. [25]

      On 11 March 2025 NIST selected HQC as a backup to ML-KEM for general encryption, built on error-correcting codes rather than structured lattices. confirmedas of 2025-03-11

    26. [26]

      In 2022 researchers at KU Leuven published a classical attack that broke SIKEp434, an instance of the isogeny-based SIKE scheme then in NIST's fourth round, in about ten minutes on a single core. confirmedas of 2022-07-30

    27. [27]

      NIST notes that hybrid solutions add complexity, which can raise security risks and costs, and expects them to be temporary steps toward a second transition to PQC-only tools. confirmedas of 2024-11-12

    28. [28]

      In August 2026 the IETF published RFC 10024, a Proposed Standard defining three hybrid key agreement mechanisms for TLS 1.3, X25519MLKEM768, SecP256r1MLKEM768 and SecP384r1MLKEM1024, which combine ML-KEM with elliptic-curve Diffie-Hellman. confirmedas of 2026-08-10

    29. [29]

      The UK NCSC's March 2025 guidance sets three milestones, define goals and complete discovery by 2028, carry out the highest-priority migration by 2031, and complete migration of all systems by 2035. confirmedas of 2025-03-20

    30. [30]

      Under the EU coordinated roadmap adopted in June 2025, all member states should start transitioning to PQC by the end of 2026, and high-risk use cases should move to PQC no later than the end of 2030. confirmedas of 2025-06-23

    31. [31]

      Google announced that Chrome 131 would switch from Kyber to ML-KEM, changing the TLS codepoint for hybrid post-quantum key exchange from 0x6399 (Kyber768+X25519) to 0x11EC (ML-KEM768+X25519), because minor changes in the final ML-KEM standard made it incompatible with the Kyber version deployed earlier. confirmedas of 2024-09-13

    32. [32]

      On 25 March 2026 Google set 2029 as its timeline for post-quantum cryptography migration, citing progress in quantum hardware, quantum error correction and factoring resource estimates. confirmedas of 2026-03-25

    33. [33]

      In iOS 26, iPadOS 26, macOS Tahoe 26 and visionOS 26, TLS connections automatically advertise hybrid quantum-secure key exchange, including X25519MLKEM768 in the ClientHello. confirmedas of 2026-10-10

    34. [34]

      In February 2024 Apple announced PQ3 for iMessage, which uses post-quantum cryptography for both initial key establishment and ongoing message exchange, rolling out with iOS 17.4. confirmedas of 2024-02-21

    35. [35]

      On 2 October 2025 Signal announced the Sparse Post Quantum Ratchet (SPQR), which runs alongside its Double Ratchet and mixes both keys in a "Triple Ratchet", rolling out without any user action. confirmedas of 2025-10-02

    36. [36]

      OpenSSL 3.5, released on 8 April 2025, added support for ML-KEM, ML-DSA and SLH-DSA. confirmedas of 2025-04-08

    37. [37]

      A preprint posted on 30 March 2026 by researchers at Oratomic, Caltech and UC Berkeley argued that Shor's algorithm could run at cryptographically relevant scales on as few as 10,000 reconfigurable neutral-atom qubits, with P-256 discrete logarithms taking just a few days on a 26,000-qubit system and RSA-2048 factoring one to two orders of magnitude longer. confirmedas of 2026-03-30

    38. [38]

      The Oratomic authors acknowledged that substantial engineering challenges remain, noting that neutral-atom experiments had so far shown computation on arrays of hundreds of qubits and trapping arrays of more than 6,000 qubits. confirmedas of 2026-03-30

    39. [39]

      NSA's CNSA 2.0 advisory expects US national security systems to complete the move to quantum-resistant algorithms by 2035, in line with NSM-10, and sets earlier dates for using CNSA 2.0 algorithms exclusively, such as 2030 for software and firmware signing and networking equipment and 2033 for operating systems. confirmedas of 2022-09-07

    40. [40]

      The EU's coordinated PQC roadmap says the transition should be completed for as many systems as practically feasible by 2035, and that quantum-vulnerable public-key mechanisms should not be used on their own after the end of 2030 for high-risk use cases or after the end of 2035 for medium-risk ones. confirmedas of 2025-06-11

    41. [41]

      In the AIxCC final, competing systems found 54 of the synthetic vulnerabilities across 63 challenges, patched 43 of them, and also discovered 18 real, non-synthetic vulnerabilities. confirmedas of 2025-08-08

    42. [42]

      In November 2024 Google's Big Sleep AI agent was reported to have found a previously unknown exploitable memory-safety bug in SQLite, which Google called the first public example of an AI agent doing so in widely used real-world software. confirmedas of 2024-11-01

    43. [43]

      Cloudflare Radar measured client support for post-quantum encryption growing from under 3% of traffic at the start of 2024 to over 60% in February 2026. confirmedas of 2026-02-27

    44. [44]

      Google said it had adjusted its threat model to prioritize post-quantum migration of authentication services and digital signatures, and recommended other engineering teams do the same. confirmedas of 2026-03-25

    45. [45]

      On 7 April 2026 Cloudflare said it was targeting full post-quantum security, including authentication, across its entire product suite by 2029. confirmedas of 2026-04-07

    46. [46]

      On 14 May 2026 NIST announced that nine candidates advanced to the third round of its additional digital signature schemes process (NIST IR 8610). confirmedas of 2026-05-14

    47. [47]

      NIST's draft transition plan (IR 8547, November 2024) proposes deprecating RSA and elliptic-curve algorithms at 112-bit security after 2030 and disallowing quantum-vulnerable public-key algorithms after 2035. confirmedas of 2024-11-12

    48. [48]

      As of October 2026 NIST IR 8547 remained an initial public draft dated 12 November 2024. confirmedas of 2026-10-10

    49. [49]

      ML-DSA's three parameter sets, ML-DSA-44, ML-DSA-65 and ML-DSA-87, have public keys of 1,312, 1,952 and 2,592 bytes and signatures of 2,420, 3,309 and 4,627 bytes. confirmedas of 2024-08-13

    50. [50]

      The NCSC singles out the Web PKI, the system of certificate authorities and transparency logs, as an area where post-quantum migration will be harder than a simple algorithm swap. confirmedas of 2025-03-20

    51. [51]

      Anthropic said the AI performed 80-90% of that campaign, with humans intervening at perhaps 4-6 critical decision points, and called it the first documented large-scale cyberattack executed without substantial human intervention. confirmedas of 2025-11-13

    52. [52]

      Anthropic said AI models had reached a level of coding capability at which they can surpass all but the most skilled humans at finding and exploiting software vulnerabilities, and warned that such capabilities may soon proliferate. confirmedas of 2026-04-07

    53. [53]

      NIST notes that breaking present-day encryption will need quantum computers with many thousands of qubits, and that qubits are fragile and easily corrupted by disturbances. confirmedas of 2026-10-10

    Revision history (2)
    1. Page created.
    2. Linked the Anthropic entity page.

    Created Oct 10, 2026. Last reviewed by an editor on Oct 10, 2026. Next scheduled review: Jan 10, 2027.

    Cite this page

    "Post-quantum cryptography and security in 2026: a crash course." ContentLora, updated Oct 10, 2026. https://contentlora.com/explain/cryptography-security

    Spotted an error? Suggest a correction or emailcorrections@contentlora.com.