PLAIN QUANTUM
← All articles
Security

Post-quantum cryptography for non-engineers

On this page
  1. First, what it isn't
  2. Why the old locks fail
  3. How the new algorithms were chosen
  4. The new algorithms, one sentence each
  5. The maths, in pictures
  6. What's different in practice: size
  7. Hybrid: belt and braces
  8. A hybrid handshake, step by step
  9. Signatures: the slower half
  10. What changes for an organisation
  11. Deadlines to know
  12. Common questions
  13. Sources and further reading

Post-quantum cryptography is the replacement for the encryption that quantum computers are expected to break. It's already in your browser, it's being built into banking and government systems, and it will quietly protect most of the internet within a decade. This guide explains what it is, how it works at a high level, and what changes for organisations, without any maths you'd need to write down.

First, what it isn't

The name confuses people, so let's clear that up. Post-quantum cryptography doesn't use quantum computers or quantum physics. It's ordinary software that runs on the phones, laptops and servers we already have. The "post-quantum" part means it's designed to stay secure even after large quantum computers exist.

It's also different from quantum key distribution (QKD), which uses special hardware to send quantum signals, usually single photons, down dedicated fibre links or via satellite. QKD is interesting, but it needs new physical infrastructure and only covers part of what cryptography does. Security agencies including the US NSA and the UK's National Cyber Security Centre currently recommend post-quantum cryptography as the main defence.

Why the old locks fail

Today's public-key cryptography rests on two maths problems: factoring huge numbers (RSA) and a related problem on elliptic curves (ECC). Both are effectively impossible for ordinary computers at the sizes we use. But both have a hidden repeating structure, and Shor's quantum algorithm finds that structure efficiently. Once a large enough quantum computer exists, the problems stop being hard.

So the job is to find different maths problems: ones that are hard for ordinary computers and that have no known shortcut for quantum computers either.

How the new algorithms were chosen

In 2016 the US National Institute of Standards and Technology (NIST) launched an open, international competition. Researchers around the world submitted 82 candidate algorithms. Over the next six years, cryptographers attacked them publicly, round after round.

That process worked exactly as intended, sometimes dramatically. In 2022 one promising finalist, Rainbow, was broken by a researcher using an ordinary laptop over a weekend. A few months later another, SIKE, was broken in about an hour on a single computer core. Neither attack needed a quantum computer. It was the strongest possible argument for testing algorithms in public for years before trusting them, and for designing systems that can switch algorithms if one fails.

In August 2024 NIST published the first three standards. In 2025 it selected a backup algorithm for key agreement, and more are in progress.

The new algorithms, one sentence each

ML-KEMFIPS 203. Agrees a shared secret key between two parties. The main replacement for RSA and elliptic-curve key exchange.
ML-DSAFIPS 204. Creates and checks digital signatures. The main general-purpose replacement for RSA and ECDSA signatures.
SLH-DSAFIPS 205. A slower, larger signature scheme based only on hash functions, kept as a conservative backup.
FN-DSAExpected as FIPS 206. A signature scheme with smaller signatures, for places where size matters.
HQCSelected in 2025, with a standard expected around 2027. A backup for ML-KEM, built on different maths in case lattices ever fall.
The "ML" stands for module lattice, the family of maths the two main algorithms are built on.

You'll still see the competition names in older articles: Kyber became ML-KEM, Dilithium became ML-DSA, SPHINCS+ became SLH-DSA and Falcon is becoming FN-DSA. If a vendor's material only uses the old names, it's a hint their information predates the final standards.

Each algorithm also comes in several strengths. ML-KEM, for example, has 512, 768 and 1024 versions, with the higher numbers more secure and slightly larger. Most commercial deployments today use ML-KEM-768. US national security systems, under the NSA's CNSA 2.0 rules, must use only the strongest versions, ML-KEM-1024 and ML-DSA-87, so "post-quantum" doesn't automatically mean "meets every requirement".

The maths, in pictures

The new algorithms come from a few families of hard problems.

Lattices. Picture a regular grid of points, like the corners of squares on graph paper. Now imagine that grid in hundreds of dimensions instead of two, with its axes skewed at awkward angles. If someone picks a grid point, nudges it by a small random amount and tells you only the nudged position, finding the original point is extraordinarily hard. That "nudge" idea is known as learning with errors. With the right secret information, the problem becomes easy, which is what makes it usable as a lock. ML-KEM, ML-DSA and FN-DSA are all built on lattices.

Hash functions. A hash function turns any input into a short fingerprint that's practically impossible to reverse. Hash functions are among the most studied tools in cryptography, and quantum computers only weaken them modestly. SLH-DSA builds signatures entirely out of them, which is why it's the conservative backup: slow and bulky, but resting on very well-understood ground.

Error-correcting codes. Codes are used everywhere to fix transmission errors, from phone calls to QR codes. Some code-based problems are hard to reverse without a secret, and cryptographers have studied them since the 1970s. HQC comes from this family. Using a different family as a backup means one mathematical breakthrough can't knock out everything at once.

What's different in practice: size

The main practical change is that keys and signatures get bigger, sometimes a lot bigger.

WhatTodayPost-quantum
Key-exchange public key32 bytes1,184 bytes (ML-KEM-768)
Signatureabout 64 bytes3,309 bytes (ML-DSA-65)
Hash-based signaturen/aabout 8–50 KB (SLH-DSA)
Typical sizes compared with today's elliptic-curve algorithms. Speed is generally fine; size is the main adjustment.

For a web page that already downloads megabytes of images, an extra kilobyte or two barely matters. But some systems have tight limits: payment card chips with little memory, network protocols with fixed message sizes, small devices on slow links, and certificate chains that carry several signatures each. Those are where testing and engineering effort go.

Hybrid: belt and braces

Because the new algorithms are younger than the old ones, many systems use them in hybrid mode during the transition. A connection performs both a traditional key exchange and a post-quantum one, then combines the results. An attacker would need to break both. If a flaw is found in the new algorithm, the old one still protects you against today's attackers; if a quantum computer arrives, the new one protects you against it.

This is already how most post-quantum protection on the web works today. Major browsers and large networks switched hybrid key agreement on by default during 2024 and 2025, most commonly pairing the elliptic-curve method X25519 with ML-KEM-768.

One detail that surprises people: the hybrid combination itself isn't part of the NIST standards. The individual algorithms are standardised; how to combine them is covered by transition guidance and internet standards still being finalised. That's normal for a transition period, but it's worth knowing if someone asks whether hybrid is "a NIST standard".

A hybrid handshake, step by step

Here's roughly what happens when your browser opens a hybrid post-quantum connection, in plain terms:

  1. Your browser sends a hello message containing two public values: one for a traditional elliptic-curve exchange and one for ML-KEM.
  2. The server does its half of both exchanges and replies with its two values.
  3. Each side now has two shared secrets, one from each method. They feed both into a function that mixes them into a single session key.
  4. Everything after that is encrypted with the session key using fast symmetric encryption, exactly as before.

The whole thing adds about a kilobyte to the start of the connection and takes a fraction of a millisecond longer. You'd never notice.

Signatures: the slower half

Key agreement has moved quickly because it only involves the two ends of a connection, and it defends against harvesting. Signatures are moving more slowly, for good reasons.

A signature only matters if someone checks it, and the checking side is often spread across huge numbers of devices and organisations. Website certificates, for instance, form chains of trust that every browser and operating system has to understand. Payment cards, car software, medical devices and industrial controllers all verify signatures, and many can't be updated easily. Switching signature algorithms therefore needs agreement across whole ecosystems: standards bodies, certificate authorities, device makers and regulators. Expect key agreement to be largely done well before signatures are.

What changes for an organisation

For most organisations, post-quantum migration is less a cryptography project than an inventory, vendor and change-management project. The typical steps:

  1. Find your cryptography. Build an inventory of where public-key cryptography is used. A newer approach is a cryptographic bill of materials, or CBOM: a structured list of every cryptographic asset, now supported by the CycloneDX standard, so it can be shared and checked like a software parts list.
  2. Rank by risk. Prioritise systems that protect long-lived secrets or that take years to replace.
  3. Talk to vendors. Much of your cryptography lives inside products you buy. Ask suppliers for their post-quantum roadmaps and put requirements into contracts.
  4. Test, then migrate in waves. Pilot hybrid modes, measure the effect of bigger keys, and move system by system.
  5. Build crypto-agility. Make algorithms swappable through configuration rather than rebuilds. The broken finalists show why you'll want that.

There's an important human point here. Automated scanners find a lot, but cryptography is often set in configuration files, middleware and integrations that tools don't see. The people who know how your systems actually connect, such as architects, analysts and operations teams, are as important to the inventory as the security specialists.

Deadlines to know

NIST's draft transition plan proposes deprecating RSA and elliptic-curve cryptography from 2030 and disallowing them by 2035. The NSA's CNSA 2.0 guidance requires post-quantum algorithms for new US national security systems from 2027. The EU's roadmap asks for cryptographic inventories by the end of 2026, high-risk systems by 2030 and the rest by 2035. Canada's federal roadmap targets high-priority government systems by the end of 2031 and the rest by the end of 2035.

Most of these rules apply to governments, not private companies. But they set the expectations of customers, regulators and vendors, and they all agree on the first step: know where your cryptography is, by roughly now.

Common questions

Is post-quantum cryptography proven secure? No cryptography is proven secure in an absolute sense; RSA isn't either. The new standards have survived years of intense public analysis, which is the same basis on which we trust today's algorithms.

Do I need new hardware? Usually not for software and servers. Some specialised devices, like older hardware security modules, smart cards and embedded equipment, may need replacing or upgrading.

Will it slow things down? Mostly no. The new algorithms are generally fast; the main cost is extra data, which matters only in constrained systems.

Three things to remember
  • Post-quantum cryptography is ordinary software built on maths problems quantum computers can't shortcut.
  • ML-KEM replaces key exchange, ML-DSA replaces signatures, and hybrid mode eases the transition.
  • For organisations, the hard part is inventory and vendors, not the algorithms themselves.

Built from public standards and published research. Educational only; not security advice for any specific organisation.

Sources and further reading

Tags show what kind of source each one is. A standard or government guidance is an official document; a peer-reviewed paper has been checked by other experts; a preprint has not been peer-reviewed yet; an experiment reports a real-world demonstration; a company announcement is the company's own account. Dates and figures were checked against these sources on 11 October 2026. Spotted an error? Email hello@plainquantum.com and it will be corrected, with a note.

  1. StandardFIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard (ML-KEM)NIST, 2024
  2. StandardFIPS 204: Module-Lattice-Based Digital Signature Standard (ML-DSA)NIST, 2024
  3. StandardFIPS 205: Stateless Hash-Based Digital Signature Standard (SLH-DSA)NIST, 2024
  4. StandardNIST selects HQC as fifth algorithm for post-quantum encryptionNIST, 2025
  5. StandardPost-Quantum Cryptography project (status of FN-DSA and other work)NIST Computer Security Resource Center
  6. Government guidanceNIST IR 8547 (Initial Public Draft): Transition to Post-Quantum Cryptography StandardsNIST, 2024
  7. Government guidanceNSA releases future quantum-resistant algorithm requirements for national security systems (CNSA 2.0)US National Security Agency, 2022
  8. Peer-reviewed paperBreaking Rainbow takes a weekend on a laptopWard Beullens, CRYPTO, 2022
  9. Peer-reviewed paperAn efficient key recovery attack on SIDH (the SIKE break)Wouter Castryck and Thomas Decru, EUROCRYPT, 2023
  10. Company announcementProtecting Chrome traffic with hybrid Kyber KEMChromium blog, 2023
  11. StandardCryptography Bill of Materials (CBOM)CycloneDX / OWASP