Post Quantum Cryptography

What Is Post-Quantum Cryptography? A Beginner's Guide

Executive summary — Post-quantum cryptography, or PQC, is a new generation of encryption and digital-signature algorithms designed to stay secure even against a powerful quantum computer. It runs on the ordinary computers and phones we already use; no quantum hardware is needed. This guide explains, without assuming any background in cryptography, why the change is needed, what is actually changing, and what organisations can sensibly do first. Readers who want the detailed standards and migration phases can continue to eMudhra's enterprise PQC primer.

A quick refresher: public-key cryptography

Every time you see a padlock in a browser, sign a document digitally or log in to a banking app, public-key cryptography is at work. Each party has two mathematically linked keys: a public key that anyone may see, and a private key that is kept secret. Data locked with the public key can only be unlocked with the private key, and a signature made with the private key can be checked by anyone holding the public key.

The security of the most common schemes, RSA and elliptic-curve cryptography (ECC), rests on mathematical problems such as factoring very large numbers. Ordinary computers would need thousands or millions of years to solve them, so the private key stays safe.

Why quantum computers change the picture

Quantum computers process information in a fundamentally different way. In 1994 the mathematician Peter Shor showed that a sufficiently large quantum computer could solve the factoring and discrete-logarithm problems dramatically faster, which would break RSA and ECC outright. That would undermine the encryption protecting web traffic, the digital signatures that prove authenticity and vast amounts of stored data.

Not everything breaks equally. Symmetric encryption such as AES, used to encrypt the bulk of data once a connection is set up, is only weakened, and doubling the key length (for example, using AES-256) is generally considered sufficient. The urgent problem is public-key cryptography, which is exactly what PQC replaces.

Technology Used for Quantum impact
RSA, ECC (ECDH, ECDSA) Key exchange, digital signatures, certificates Broken by a large quantum computer — must be replaced
AES-128 Bulk data encryption Weakened — move to longer keys
AES-256, SHA-384/512 Bulk encryption, hashing Considered safe with today's guidance

How post-quantum cryptography responds

PQC algorithms are built on different mathematical problems — many of them on structures called lattices — that are believed to resist attacks from both classical and quantum computers. If you are curious how those work, eMudhra's explainer on lattice-based cryptography is a gentle next step.

In August 2024, the US National Institute of Standards and Technology (NIST) finalised its first three PQC standards: ML-KEM for establishing shared keys, and ML-DSA and SLH-DSA for digital signatures. These are concrete, vetted algorithms rather than research prototypes, and vendors are now building them into browsers, operating systems, hardware security modules and certificate authorities. A plain summary of each is in NIST's PQC standards explained.

Not sure where quantum-vulnerable cryptography sits in your estate? eMudhra's PQC readiness programme starts with discovery. Speak to an expert.

Why it matters now

The risk is not confined to the future. Encrypted data captured today can be stored and decrypted later, once quantum computers mature — a strategy known as harvest now, decrypt later. Health records, intellectual property, government files and financial data often need to stay confidential for ten years or more, so they are already exposed if they travel over quantum-vulnerable connections.

Regulators have set dates accordingly. NIST's transition guidance plans to deprecate RSA and ECC for many uses by 2030 and disallow them by 2035, and similar timelines are appearing worldwide. Nobody knows exactly when a cryptographically relevant quantum computer will arrive; eMudhra's quantum threat timeline explains why organisations plan against the regulatory dates instead.

Common myths about PQC

  • "PQC needs a quantum computer." It does not. PQC is ordinary software and firmware designed to withstand quantum attacks.
  • "PQC is the same as quantum cryptography." It is not. Quantum key distribution (QKD) uses physics and specialised hardware to share keys; PQC is mathematics that runs on existing networks.
  • "We can wait until quantum computers exist." Harvest-now-decrypt-later attacks mean long-lived data is already at risk, and large migrations take years.
  • "It is a one-time swap." Standards will keep evolving, so the lasting goal is crypto-agility — the ability to change algorithms without rebuilding systems.

What organisations can do first

The practical starting point is visibility: knowing where cryptography and digital certificates are used across the business, which algorithms they rely on and which systems protect long-lived or sensitive data. From there, organisations can prioritise, pilot the new standards in a controlled way — often using hybrid certificates that combine classical and post-quantum algorithms — and build the agility to change algorithms as guidance evolves. A step-by-step plan is set out in building a post-quantum migration roadmap.

Frequently Asked Questions

What is post-quantum cryptography?

It is a set of encryption and digital-signature algorithms designed to remain secure against quantum computers, while still running on the ordinary hardware in use today.

Does post-quantum cryptography need a quantum computer to run?

No. PQC algorithms run on today's computers; they are simply designed to withstand attacks from future quantum machines.

Why should organisations act before quantum computers exist?

Attackers can store encrypted data now and decrypt it later once quantum computers are capable, so long-lived sensitive data is already at risk today.

Is AES encryption broken by quantum computers?

Not in the same way. Quantum attacks weaken symmetric algorithms such as AES rather than breaking them, and using 256-bit keys is generally considered sufficient. The urgent replacement is public-key cryptography such as RSA and ECC.

Get ready for the quantum era

eMudhra helps organisations discover their cryptography, prioritise what matters and move to quantum-safe certificates at their own pace. Explore PQC readiness with eMudhra or contact eMudhra.

eMudhra Limited
About the Author

eMudhra Limited

eMudhra Editorial represents the collective voice of eMudhra, providing expert insights on the latest trends in digital security, cryptographic identities, and digital transformation. Our team of industry specialists curates and delivers thought-provoking content aimed at helping businesses navigate the evolving landscape of cybersecurity and trust services with confidence.

Ready to Try?

Talk to our team about how eMudhra can help secure your digital workflows with PKI, eSignatures and identity solutions.

Connect with sales