{"id":21831,"date":"2026-07-10T11:00:00","date_gmt":"2026-07-10T11:00:00","guid":{"rendered":"https:\/\/www.securitytoday.de\/2026\/07\/10\/what-is-post-quantum-cryptography-definition-standards\/"},"modified":"2026-07-10T22:24:12","modified_gmt":"2026-07-10T22:24:12","slug":"what-is-post-quantum-cryptography-definition-standards","status":"publish","type":"post","link":"https:\/\/www.securitytoday.de\/en\/2026\/07\/10\/what-is-post-quantum-cryptography-definition-standards\/","title":{"rendered":"What Is Post-Quantum Cryptography? Definition and Standards"},"content":{"rendered":"<div class=\"st-definition\">\n<p><strong>What is Post-Quantum Cryptography?<\/strong> Post-Quantum Cryptography refers to encryption and signature schemes that are designed to withstand attacks by quantum computers. They rely on mathematical problems for which neither classical nor quantum algorithms have known efficient solutions. These schemes run on current hardware and are intended to eventually replace or supplement RSA and elliptic curve cryptography.<\/p>\n<\/div>\n<div style=\"background:#003340;color:#fff;padding:32px 36px;margin:32px 0;border-radius:8px;\">\n<p style=\"margin:0 0 18px 0;font-size:0.95em;font-weight:800;text-transform:uppercase;letter-spacing:0.2em;color:#69d8ed;border-bottom:2px solid rgba(105,216,237,0.25);padding-bottom:12px;\">Key Takeaways<\/p>\n<ul style=\"margin:0;padding-left:22px;color:rgba(255,255,255,0.92);line-height:1.6;\">\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Threat:<\/strong> The Shor algorithm breaks RSA and ECC on a sufficiently large quantum computer. Such a machine does not yet exist, the time horizon is open.<\/li>\n<li style=\"margin-bottom:10px;\"><strong style=\"color:#69d8ed;\">Standards:<\/strong> NIST published the first three final standards in August 2024: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for signatures.<\/li>\n<li style=\"margin-bottom:0;\"><strong style=\"color:#69d8ed;\">Pressure:<\/strong> Due to &#8216;harvest now, decrypt later&#8217; and long migration times, BSI (Federal Office for Information Security) recommends crypto\u2011agility, hybrid schemes and a cryptographic inventory as the first step.<\/li>\n<\/ul>\n<\/div>\n<h2>Why Quantum Computers Threaten Modern Encryption<\/h2>\n<p>Asymmetric cryptography that currently secures Transport Layer Security (TLS) connections, VPNs and digital signatures relies on factoring and discrete logarithms. Shor&#8217;s algorithm efficiently solves exactly these problems on a quantum computer. A sufficiently powerful machine would mathematically break RSA, Diffie\u2011Hellman and ECC, regardless of key length.<\/p>\n<p>A cryptographically relevant quantum computer does not exist today. Scaling, error correction and the number of stable logical qubits remain unresolved challenges. NIST and the Federal Office for Information Security (BSI) both stress that the timing cannot be predicted with any scientific rigor. Symmetric schemes such as AES\u2011256, by contrast, are considered far more robust and would only require longer keys.<\/p>\n<h2>Harvest now, decrypt later<\/h2>\n<p>The real risk emerges before the first functional quantum computer. Attackers can intercept, store, and later decrypt encrypted traffic today, once the technology becomes available. NIST explicitly cites this scenario as a reason to begin the transition now.<\/p>\n<p>Data with long confidentiality lifespans are especially vulnerable: health data, engineering documents, trade secrets, and government information. The BSI (Federal Office for Information Security) identifies key negotiation processes as particularly threatened by this scenario. Those who protect such data should weigh the migration period of their own systems against the remaining lifespan of the secrets.<\/p>\n<h2>The Standards and the Path Forward<\/h2>\n<div data-element=\"key_number\" style=\"background:#003340;border:1px solid rgba(105,216,237,0.28);border-radius:10px;padding:28px 24px;margin:32px 0;text-align:center;\">\n<div style=\"font-size:1.6em;font-weight:800;color:#69d8ed;line-height:1.05;word-break:keep-all;\">13. Aug. 2024<\/div>\n<p style=\"margin:10px 0 0;font-size:0.92em;color:#e6e3da;\">NIST publishes the first three finalized PQC standards<\/p>\n<p style=\"margin:6px 0 0;font-size:0.78em;color:#8fa3ab;\">FIPS (Federal Information Processing Standards) 203 (ML\u2011KEM (Machine Learning Key Encapsulation Mechanism)), FIPS (Federal Information Processing Standards) 204 (ML\u2011DSA (Machine Learning Digital Signature Algorithm)), FIPS (Federal Information Processing Standards) 205 (SLH\u2011DSA (Stateless Hash\u2011Based Signature Algorithm))<\/p>\n<\/div>\n<p>With the finalized FIPS (Federal Information Processing Standards) specifications, the fundamental question is answered. ML\u2011KEM (Machine Learning Key Encapsulation Mechanism) takes over quantum\u2011secure key encapsulation, while ML\u2011DSA (Machine Learning Digital Signature Algorithm) and SLH\u2011DSA (Stateless Hash\u2011Based Signature Algorithm) cover digital signatures. According to the current state of knowledge, these procedures are considered secure against known quantum attacks and are already being integrated into protocols, libraries and products.<\/p>\n<p>The BSI (Federal Office for Information Security) recommends hybrid combinations of classical and post\u2011quantum methods, as well as crypto\u2011agility, as a design principle for the transition. The technical guideline TR\u201102102\u20111, in its January\u202f2026 version, incorporates quantum\u2011secure mechanisms such as ML\u2011KEM and advises the sole use of classical asymmetric methods only for a transitional period. At the European level, the BSI and partner authorities have likewise highlighted the shift to post\u2011quantum cryptography in a joint declaration of priority.<\/p>\n<h2>What Companies Need to Check Now<\/h2>\n<p>The first step requires no new technology: an inventory of the cryptography in use. Without an overview of the methods, protocols and certificates, neither prioritization nor migration is possible. Next, the question is which data must remain confidential for the longest period.<\/p>\n<div data-element=\"checklist\" style=\"background:#23261f;border:1px solid rgba(105,216,237,0.22);border-radius:10px;padding:22px 24px;margin:32px 0;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 2px 10px rgba(0,0,0,0.22);\">\n<p style=\"margin:0 0 12px;font-family:'IBM Plex Mono',ui-monospace,SFMono-Regular,monospace;font-size:0.72em;letter-spacing:0.12em;text-transform:uppercase;color:#69d8ed;\">CHECK NOW<\/p>\n<ul style=\"margin:0;padding-left:0;list-style:none;\">\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Create a cryptographic inventory: catalog procedures, protocols, certificates and dependencies<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Prioritize data by confidentiality duration, longest lifespan first<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Embed crypto\u2011agility as a procurement and design criterion<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Ask vendors and service providers about their PQC roadmaps and ML\u2011KEM support<\/li>\n<li style=\"margin:0 0 10px;padding-left:26px;position:relative;color:#e6e3da;line-height:1.5;\"><span style=\"position:absolute;left:0;color:#69d8ed;\">&#10003;<\/span>Evaluate hybrid approaches for transition where full migration is not yet possible<\/li>\n<\/ul>\n<\/div>\n<h2>Distinguishing Related Concepts<\/h2>\n<p>Post-quantum cryptography (PQC) is often confused with quantum cryptography. Quantum cryptography, such as quantum key distribution, relies on physical quantum effects and requires specialized hardware. In contrast, post-quantum cryptography is based on classical mathematics that runs on existing computers and can be rolled out via software updates.<\/p>\n<p>Equally important is the distinction by method type. Directly affected is asymmetric cryptography, namely key exchange and signatures. Symmetric encryption and hash functions remain secure with appropriate parameters. A PQC migration therefore selectively replaces public\u2011key components and leaves proven symmetric procedures in use.<\/p>\n<h2 style=\"padding-top:64px;margin-bottom:20px;\">Frequently Asked Questions<\/h2>\n<p class=\"st-faq-hint\">Every question is locked. A tap unlocks the answer.<\/p>\n<details>\n<summary><strong>When will the quantum computer that breaks RSA come?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">No one can claim this seriously. A cryptographically relevant quantum computer does not currently exist, and both NIST and BSI explicitly consider the timeline to be open. Estimates vary widely.<\/p>\n<\/details>\n<details>\n<summary><strong>Do I need to take action now?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes, at least with inventory and planning. Data intercepted today can be decrypted later, and crypto migrations typically take years, according to experience. Both together create the pressure to act.<\/p>\n<\/details>\n<details>\n<summary><strong>What is ML-KEM?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">ML-KEM (Machine Learning Key Encapsulation Mechanism) is the mechanism standardized in FIPS 203 for quantum-safe key encapsulation based on lattice problems. It is expected to replace the classical key exchange, for example in TLS.<\/p>\n<\/details>\n<details>\n<summary><strong>What does the BSI recommend?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Cryptographic agility in new developments, hybrid combinations of classical and post-quantum methods, as well as the recommendations of TR-02102-1. A cryptographic inventory is regarded as the first practical step.<\/p>\n<\/details>\n<details>\n<summary><strong>Does this also apply to digital signatures?<\/strong><\/summary>\n<p style=\"margin:8px 0 4px 24px;color:#555;line-height:1.6;\">Yes. Signatures are supported by dedicated standards such as ML-DSA and SLH-DSA. It becomes critical especially for long validity periods, such as in document archiving or firmware signatures.<\/p>\n<\/details>\n<p><!--ST-LOWER-CARDS lang=en--><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">Editor&#8217;s Picks<\/h3>\n<p><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/06\/28\/post-quantum-becomes-mandatory-in-cloud-certification\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/06\/post-quantum-wird-pflicht-in-der-cloud-zertifizierung-cover-hero-250x141.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Post-Quantum becomes mandatory in cloud certification<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/03\/08\/post-quantum-cryptography-germany-prepares\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/03\/post-quantum-kryptografie-reboot-germany-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Post-Quantum Cryptography: Germany Prepares<\/span><\/span><\/a><a href=\"https:\/\/www.securitytoday.de\/en\/2026\/04\/05\/post-quantum-cryptography-enterprises-encryption-transition\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/04\/st-art2-pexels-5473960-250x167.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#69d8ed;margin-bottom:5px;\">Editor&#8217;s Pick<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Post-Quantum Cryptography: Enterprises Must Shift Encryption Now<\/span><\/span><\/a><\/p>\n<h3 style=\"margin:48px 0 18px;padding-left:12px;font-size:1.05em;font-weight:800;color:#e6e3da;border-left:3px solid #69d8ed;line-height:1.2;\">More from the MBF Media Network<\/h3>\n<p><a href=\"https:\/\/mybusinessfuture.com\/en\/post-quantum-cryptography-why-2026-is-the-starting-gun\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-post-quanten-kryptografie-bsi-deadline-p-24639000-250x250.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#aa8ac2;margin-bottom:5px;\">MyBusinessFuture<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Post-Quantum Cryptography: Why 2026 Is the Starting Gun<\/span><\/span><\/a><a href=\"https:\/\/www.digital-chiefs.de\/en\/post-quantum\/\" style=\"display:flex;align-items:center;gap:14px;padding:12px 14px;margin:0 0 10px;background:#23261f;border:1px solid rgba(105,216,237,0.18);border-radius:12px;box-shadow:inset 0 1px 0 rgba(230,227,218,0.06),0 6px 18px rgba(0,0,0,0.22);text-decoration:none;color:#e6e3da;box-sizing:border-box;width:100%;\"><span style=\"flex:0 0 116px;aspect-ratio:16\/9;overflow:hidden;border-radius:8px;background:#111210;border:1px solid rgba(230,227,218,0.08);display:block;\"><img decoding=\"async\" src=\"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/net-post-quantum-kryptographie-pqc-countdown-53354170-250x139.jpg\" alt=\"\" loading=\"lazy\" width=\"116\" height=\"65\" style=\"width:100%;height:100%;object-fit:cover;display:block;\"><\/span><span style=\"display:block;min-width:0;\"><span style=\"display:block;font-size:0.68em;font-weight:700;letter-spacing:0.1em;text-transform:uppercase;color:#e8828d;margin-bottom:5px;\">Digital Chiefs<\/span><span style=\"display:block;font-size:1.0em;font-weight:650;line-height:1.35;color:#e6e3da;overflow-wrap:anywhere;\">Post-Quantum Cryptography: The Countdown for Corporate IT Is Running<\/span><\/span><\/a><!--\/ST-LOWER-CARDS--><\/p>\n","protected":false},"excerpt":{"rendered":"Post-quantum cryptography explained: why quantum computers threaten RSA, what NIST standards cover, and how businesses can start now.","protected":false},"author":10,"featured_media":21805,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_yoast_wpseo_focuskw":"post-quantum cryptography","_yoast_wpseo_title":"What Is Post-Quantum Cryptography? Definition and Standards","_yoast_wpseo_metadesc":"Post-quantum cryptography explained: why quantum computers threaten RSA, NIST standards, and steps businesses should take today.","_yoast_wpseo_meta-robots-noindex":"","_yoast_wpseo_meta-robots-nofollow":"","_yoast_wpseo_meta-robots-adv":"","_yoast_wpseo_canonical":"","_yoast_wpseo_opengraph-title":"","_yoast_wpseo_opengraph-description":"","_yoast_wpseo_opengraph-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/was-ist-post-quantum-kryptografie-cover-hero.jpg","_yoast_wpseo_opengraph-image-id":0,"_yoast_wpseo_twitter-title":"","_yoast_wpseo_twitter-description":"","_yoast_wpseo_twitter-image":"https:\/\/www.securitytoday.de\/wp-content\/uploads\/2026\/07\/was-ist-post-quantum-kryptografie-cover-hero.jpg","_yoast_wpseo_twitter-image-id":0,"_evm_slot_owner":"","evm_cvss":0,"evm_risk":0,"evm_casefile":"","evm_primary_cve":"","evm_pin_until":0,"evm_external_preview_token":"","evm_external_preview_expires":"","_evm_translation_lang":"en","featured_post":0,"featured_post_sortierung":0,"_wp_old_slug":[],"footnotes":""},"categories":[263],"tags":[],"class_list":["post-21831","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sicherheitslexikon-en"],"evm_reading_time_minutes":6,"wpml_language":"en","wpml_translation_of":21792,"_links":{"self":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/21831","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/users\/10"}],"replies":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/comments?post=21831"}],"version-history":[{"count":1,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/21831\/revisions"}],"predecessor-version":[{"id":21841,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/posts\/21831\/revisions\/21841"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media\/21805"}],"wp:attachment":[{"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/media?parent=21831"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/categories?post=21831"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.securitytoday.de\/en\/wp-json\/wp\/v2\/tags?post=21831"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}