Post-Quantum Cryptography Is Ready. The Hard Part Is Moving
Most warnings about quantum computers breaking encryption come from companies selling the fix. The latest one comes from the very body that wrote the rules. NIST spent eight years running an open contest to find encryption a quantum computer can’t break, and its cryptographers are now saying the same thing in plainer terms. Start moving your systems to post-quantum cryptography today, because for a lot of sensitive data, the risk already began. Andrew Regenscheid, a NIST mathematician who worked on the standards, laid out why in a recent interview.
Why NIST says the quantum risk starts today
The intuitive plan is to upgrade once a quantum computer can actually break today’s encryption. Regenscheid’s point, and the reason NIST keeps pushing, is that this plan fails for anything that has to stay secret for years. An attacker doesn’t need the machine yet. As Regenscheid said in an interview published on July 30:
“An adversary doesn’t need a quantum computer today to put your data at risk. They can intercept and store encrypted information now and simply hold onto it until they have a quantum computer capable of breaking that encryption.”
That’s the harvest-now-decrypt-later problem, which flips the timeline. Health records, financial data, trade secrets, and government material need to stay confidential for a decade or more. Information sent or stored today is exposed to a machine that doesn’t exist yet, because a patient adversary can hold the ciphertext until it does exist. Q-Day was never a single morning, and the mechanics of harvest now decrypt later are why the exposure is now.
Regenscheid is careful about the timeline itself. Current quantum computers, he says, are much too small and unstable to threaten cryptography, and nobody knows when a “cryptographically relevant” one arrives. The uncertainty is a reason to begin early, because migration is slow and you can’t compress it into the final months before a deadline you can’t see.
What NIST finished
The standards exist now, which is the part that changed. In August 2024, after an eight-year public competition that began in 2016, NIST finalized three post-quantum algorithms. One handles key establishment, ML-KEM (FIPS 203). Two handle digital signatures, ML-DSA (FIPS 204) and SLH-DSA (FIPS 205). They rest on math problems studied for more than three decades, which is where the confidence comes from.
The process is worth understanding, because it’s the source of the trust. NIST solicited algorithms from researchers worldwide, then let the global cryptographic community attack them in public for seven years. That scrutiny broke some candidates and hardened others. Both outcomes were expected, and both are how confidence gets built. It’s the same open vetting that carried algorithms like Classic McEliece into international standards.
Why deploying post-quantum cryptography will take years
The finished standards are just the beginning. Regenscheid calls the coming migration the most complex cryptographic transition yet, and he means it structurally. Cryptography sits in laptops, phones, credit cards, chips, and the web services all of them talk to. Updating that base means software developers, chip vendors, web-service providers, and standards bodies all moving in sequence, and that sequence takes years.
His advice to organizations is to inventory where and how you use cryptography: find your most sensitive, longest-lived data, because that’s what harvest now decrypt later targets first. Build a migration roadmap, then press vendors on when they’ll support the new standards and buy accordingly. The enterprises already building migration paths are the ones that will hold a stronger position when the rest scramble.
As for individual crypto holders, the answer is to keep their devices set to auto-update, and expect browsers and apps to adopt post-quantum cryptography over the next decade. When you pick a new product, you should ask whether it supports the new standards. The more people expect it, the faster it ships.
Why the standards body is the one saying it
Strip away the vendors and the preprints, and the case for urgency reads the same coming from NIST, which has no product to sell you. Washington has put weight behind it too, through a 2026 White House action on cryptographic attacks that pushes agencies to prepare. Regenscheid frames the entire effort as a chance to modernize security broadly, beyond just the quantum threat.
The machine that breaks today’s encryption isn’t here yet, but the data that machine could someday read is being sent right now. That distance is why the people who built the standards are telling everyone else to stop waiting.