RSA
Widely used for signatures and key establishment. A sufficiently capable quantum computer would undermine the mathematical assumptions on which RSA security depends.
Quantum readiness is not a prediction exercise. It is the ability to understand exposure to quantum-vulnerable public-key cryptography and to prepare an orderly, risk-based transition to post-quantum cryptography.
The migration challenge connects every part of cryptographic resilience: discovery, dependency mapping, governance, crypto-agility, PKI, key management and third-party readiness.
Cryptographically relevant quantum computers do not exist today at the scale required to break widely deployed public-key cryptography. The exact future timeline remains uncertain. Risk management therefore should not treat a speculative date as the primary planning input.
The more actionable question is whether data, systems and business processes depend on public-key cryptography that will require replacement — and how long the organisation needs to discover, prioritise, test and migrate those dependencies.
Quantum risk is partly a future threat problem, but quantum readiness is a present-day dependency, governance and change-management problem.
The most urgent migration concern is current public-key cryptography based on mathematical problems that sufficiently capable quantum computers could solve efficiently.
Widely used for signatures and key establishment. A sufficiently capable quantum computer would undermine the mathematical assumptions on which RSA security depends.
ECC-based signatures and key-establishment mechanisms are also considered quantum-vulnerable and require transition planning.
Quantum impact is different from the effect on RSA and ECC. Symmetric algorithms are not replaced by PQC public-key standards in the same way; appropriate key strengths and current guidance still matter.
Hashing is affected differently from public-key cryptography. Organisations should follow applicable standards rather than treating every cryptographic mechanism as equally vulnerable.
A useful readiness programme can be organised around six connected activities rather than a single technology replacement project.
NIST published its first three final post-quantum cryptography standards in August 2024. FIPS 203 specifies ML-KEM for key establishment, while FIPS 204 and FIPS 205 specify the ML-DSA and SLH-DSA digital signature standards. NIST states that organisations should begin applying these standards and migrating systems to quantum-resistant cryptography.
A module-lattice-based key-encapsulation mechanism used to establish shared secret keying material.
A module-lattice-based digital signature standard for authentication and integrity use cases.
A stateless hash-based digital signature standard providing a different cryptographic foundation from ML-DSA.
NIST continues standardisation work on additional algorithms. Migration governance should distinguish final standards from algorithms or profiles still under development.
Governance principle
Do not build the programme around chasing every new algorithm announcement. Build governance that can adopt approved standards when the relevant products, protocols and use cases are ready.
A risk-based roadmap should combine the sensitivity and required protection lifetime of information with business criticality, quantum-vulnerable cryptographic use, external exposure, migration complexity and supplier readiness.
Do we know where RSA, ECC and other quantum-vulnerable public-key mechanisms are used across our critical services?
Which sensitive datasets require confidentiality for long enough that future decryption is relevant to today's risk?
Which critical systems would be hardest to migrate because cryptography is embedded in products, hardware or protocols?
Who owns the enterprise PQC transition risk and who owns remediation within individual services?
Which suppliers control our ability to migrate, and have we obtained credible roadmaps from them?
Are architecture and procurement decisions being made today that could create new long-lived quantum-vulnerable dependencies?
How will we test interoperability, performance and operational impact before production migration?
Are we using the PQC transition to improve long-term crypto-agility rather than creating the next hard-coded dependency?
An organisation that can discover its cryptography, understand dependencies, assign ownership, prioritise risk and execute controlled change is already building the capabilities required for PQC migration.
The goal is not simply to become “post-quantum compliant.” It is to become resilient enough to manage this transition — and the cryptographic transitions that follow it.
Quantum-computing timelines remain uncertain. This page intentionally focuses on risk-based preparedness and current public standards rather than predicting when a cryptographically relevant quantum computer will exist.