What is Post Quantum Cryptography?

by Zoya Cochran, Managing Editor, AT&T

What is post quantum cryptography? It’s a new generation of encryption and digital signature methods designed to protect data from future quantum computers that could weaken today’s public-key systems. The risk is already active: Attackers can steal encrypted data now and save it for later decryption.

New federal standards give security teams a place to start: find exposed cryptography, protect long-lived sensitive data, and plan upgrades across the technology estate before quantum capabilities become a practical threat to enterprise security.

  • NIST standards give companies a clearer starting point for migration.
  • “Harvest now, decrypt later” attacks create risk for long-lived sensitive data.
  • Public-key encryption faces the greatest future quantum exposure.
  • Crypto inventories help leaders see where vulnerable systems exist.
  • Network modernization can support a staged migration plan.

For executives, the issue is no longer theoretical. Post-quantum cryptography can’t sit outside normal security planning. Large companies may need years to update their technology estate and supplier ecosystem. The work starts with a basic question: Which systems use cryptography that future quantum computers could weaken?

Advances in post-quantum cryptography

Post-quantum cryptography has moved from research into standards. The National Institute of Standards and Technology (NIST) finalized its first three post-quantum cryptography standards in 2024. They cover key establishment, the process two systems use to create a shared secret, and digital signatures, which verify that software, messages, or certificates haven’t been changed.1 2 3

Those standards identify the first algorithms many enterprises will need to evaluate.

  • Module-Lattice-Based Key-Encapsulation Mechanism (ML-KEM) became the main standard for creating shared secrets between systems.
  • Module-Lattice-Based Digital Signature Algorithm (ML-DSA) became a key standard for digital signatures.
  • Stateless Hash-Based Digital Signature Algorithm (SLH-DSA) became another approved signature method.

NIST also selected Hamming Quasi-Cyclic (HQC) in 2025 for future standardization as another key-establishment algorithm.4 That decision reinforces the need for crypto agility, or the ability to change algorithms without a full rebuild.

The business risk has already started. In a “harvest now, decrypt later” attack, attackers steal encrypted data now and wait for future tools to decrypt it. That creates the greatest concern for sensitive information that keeps value for years, including business, legal, financial services, healthcare, regulated, and government-related data.

Post-quantum planning now belongs in enterprise risk management. Standards give companies a starting point, but migration depends on knowing which algorithms protect which systems.

Post quantum cryptography algorithms

Post quantum cryptography algorithms use math problems that aren’t known to be easy for either classical or quantum computers to solve. They run on today’s enterprise infrastructure, which makes them practical for planning as vendor support grows.

The main post-quantum algorithm families include:

  • Lattice-based cryptography: Uses hard problems tied to high-dimensional grids. ML-KEM and ML-DSA are lattice-based NIST standards.
  • Code-based cryptography: Has a long research history and strong security traits, though some methods require large keys.
  • Hash-based cryptography: Uses well-studied hash functions and is mainly used for digital signatures.
  • Multivariate cryptography: Uses systems of equations, though some candidates haven’t held up in public review.

These algorithms don’t all serve the same purpose. Key-establishment algorithms help two systems create a shared secret. Digital signature algorithms help prove that software, devices, certificates, messages, or transactions came from a trusted source and weren’t changed.

Adoption will take time. Post-quantum algorithms can affect network and system performance, certificate handling, and compatibility. Large enterprises may also have older infrastructure and third-party dependencies that are difficult to update.

Discovery is the first practical move. Security teams need to know where encryption runs, which algorithms are active, who owns each system, and which vendors control upgrades. That inventory helps leaders decide which risks need attention first as quantum computing develops.

Will quantum computers break encryption?

Quantum computers won’t break all encryption. The greatest concern is public-key encryption, which uses a pair of mathematically linked keys to secure data and verify trust. These methods support secure access, certificates, key exchange, and digital signatures.

A powerful enough quantum computer running Shor’s algorithm, which can attack the math behind some public-key encryption, could solve those problems much faster than a classical computer.

Current quantum computers don’t yet have the scale or reliability, including error correction, needed to break modern enterprise encryption in real use. The timeline remains unclear, but the migration work is too large for many companies to delay.

Symmetric encryption, which uses the same secret key to encrypt and decrypt data, has a different risk profile. Algorithms such as the Advanced Encryption Standard (AES) can use larger keys to help address quantum search attacks, which could make brute-force guessing more efficient. Public-key systems need deeper changes because the math faces a more direct quantum threat.

The takeaway is measured urgency. Quantum computers aren’t breaking enterprise encryption today. But long-lived data and slow-moving systems still need earlier planning, especially where public-key cryptography protects access, identity, and trust.

Quantum resistant cryptography

Quantum resistant cryptography refers to security methods designed to resist attacks from both classical and quantum computers. For most companies, it’s the practical path to post-quantum migration because it works with conventional computing systems.

This isn’t only a security team issue. It affects how companies buy, build, audit, and operate technology. Leaders should expect cryptography questions to show up in audits, vendor reviews, and technology planning.

A strong migration plan starts with a cryptographic inventory. That inventory should cover:

  • Public key infrastructure (PKI), which manages digital certificates and trust
  • Certificate authorities, which issue and validate digital certificates
  • Hardware security modules, which store and protect cryptographic keys
  • Remote access systems
  • Secure Shell (SSH) used for secure administrative access
  • Transport Layer Security (TLS) used to secure web and application traffic
  • Application programming interfaces
  • Code signing
  • Cloud gateways
  • Branch connections
  • Embedded devices

After discovery, teams should rank data and systems by risk. Data that must stay private for years should move higher on the list. Systems that establish trust across the business also deserve early review.

Business network design can reduce exposure during the transition. Modern network controls can help teams limit access, monitor traffic, and test new algorithms in stages.

Quantum resistant cryptography helps companies reduce future risk without waiting for a crisis. The work becomes more manageable when teams connect data protection, network modernization, and implementation planning early.

How does quantum resistant cryptography work?

Quantum resistant cryptography works by replacing vulnerable public-key math with algorithms designed to resist known quantum attacks. These methods still need careful testing because they can affect:

  • Performance
  • Certificate size
  • Bandwidth
  • Processing demands on older devices
  • Compatibility with existing systems
  • Hybrid modes that combine current and post-quantum algorithms during the transition

Network modernization can help companies phase in these changes. A secure software-defined wide area networking (SD-WAN) approach, which is used to protect traffic across branch, cloud, and data center connections, can centralize policy, improve visibility, and support segmentation.

Quantum resistant cryptography works best when teams build it into architecture, operations, and vendor planning. That discipline helps clarify a broader phrase often used in business discussions: quantum proof encryption.

[Read: What is SD-WAN?]

Quantum proof encryption

Quantum proof encryption is a common business phrase for security designed to withstand future quantum attacks. Technical teams usually use more precise terms, including post-quantum cryptography and quantum resistant cryptography, because no encryption method can guarantee permanent protection.

The better business goal is readiness. Enterprises need cryptographic and network controls that can move to standards-based algorithms without an emergency rebuild. That requires crypto agility, testing, and supplier coordination.

Is quantum proof encryption possible?

Yes, in a practical sense. Quantum proof encryption is possible when organizations use standards-based algorithms designed to resist known quantum attack models. For most companies, post-quantum cryptography is the practical path because it works on conventional systems and can be adopted through enterprise technology updates as vendor support matures.

The goal isn’t permanent certainty. It’s to reduce known quantum-era risks and make future cryptographic changes easier to manage.

How does quantum proof encryption work?

Quantum proof encryption works by replacing vulnerable public-key methods with algorithms designed around problems that resist known quantum attacks. Key-establishment algorithms help systems create shared secrets, while digital signature algorithms help verify software, certificates, and other trusted interactions.

The work extends beyond one product or protocol. Enterprises need policies that cover the full cryptographic lifecycle, from certificates and software signing to remote access, cloud gateways, and vendor contracts. The next step is to turn that goal into practical planning questions.

Post Quantum Cryptography FAQs

As post-quantum standards make their way into products and roadmaps, planning is becoming more practical. Teams need to know where cryptography is already in use across applications, infrastructure, and network security, which systems carry the most risk, and where to start.

What is post quantum cryptography?

Post quantum cryptography is a new generation of encryption and digital signature methods designed to resist attacks from future quantum computers. It focuses on replacing public-key algorithms that could become vulnerable as quantum computing advances.

Is post quantum cryptography the same as quantum proof encryption?

Not exactly. “Quantum proof encryption” is a common business phrase. Technical teams usually use more precise terms such as post-quantum cryptography or quantum resistant cryptography.

Is post quantum cryptography available now?

Yes. NIST-standardized post-quantum algorithms now exist, and companies can begin planning and testing. ML-KEM, ML-DSA, and SLH-DSA are among the first finalized standards, and HQC has been selected for future standardization.

How does post quantum cryptography work?

Post-quantum cryptography uses algorithms built on math problems that are not known to be easy for either classical or quantum computers to solve. Some algorithms help systems establish shared secrets, while others verify software, certificates, and trusted communications.

What should procurement teams ask vendors about post-quantum readiness?

Procurement teams should ask vendors:

  • Which NIST post-quantum standards do your products support?
  • Do you support hybrid deployment with both current and post-quantum algorithms?
  • How quickly can your products switch algorithms?
  • Which products or services are included in your post-quantum roadmap?

These questions help make vendors accountable for post-quantum readiness and show whether they can support a staged migration as standards, products, and risks evolve.

Is quantum cryptography the same as post quantum cryptography?

No. Quantum cryptography and post quantum cryptography are different approaches. Quantum cryptography, including quantum key distribution, which uses quantum physics to help exchange encryption keys, usually requires specialized infrastructure.

Post quantum cryptography uses algorithms designed to run on today’s conventional computers, networks, and software. Most enterprises need protections that work across existing systems and managed services, which makes the distinction important.

Broad adoption will still take time. Enterprises need to test performance, certificate size, compatibility, hybrid deployment, vendor readiness, and broader cybersecurity impact.

The first step is to understand where cryptography is used, which data needs long-term protection, and which systems may need upgrades.

Getting started with post quantum cryptography

Businesses should start with a cryptographic inventory. They should identify where encryption runs, which algorithms are active, which data needs long-term protection, and which vendors control upgrades.

From there, teams can test standards-based algorithms, build crypto agility into architecture, and align network modernization with security planning. A planned migration gives teams time to budget, update vendors, and protect high-value data without disrupting daily operations.

Prepare your network for the post-quantum era with AT&T Business. AT&T Dynamic Defense with Palo Alto Networks delivers enterprise-grade security.

To connect with an expert who knows business, contact your AT&T Business representative.

Why AT&T Business

See how ultra-fast, reliable fiber, protected by built-in security, and 5G connectivity give you a new level of confidence in the possibilities of your network. Let our experts work with you to solve your challenges and accelerate outcomes. Your business deserves the AT&T Business difference—a new standard for networking.


1 National Institute of Standards and Technology, “FIPS 203: Module-Lattice-Based Key-Encapsulation Mechanism Standard,” August 13, 2024, https://csrc.nist.gov/pubs/fips/203/final.

2National Institute of Standards and Technology, “FIPS 204: Module-Lattice-Based Digital Signature Standard,” August 13, 2024, https://csrc.nist.gov/pubs/fips/204/final.

3National Institute of Standards and Technology, “FIPS 205: Stateless Hash-Based Digital Signature Standard,” August 13, 2024, https://csrc.nist.gov/pubs/fips/205/final.

4National Institute of Standards and Technology, “NIST Selects HQC as Fifth Algorithm for Post-Quantum Encryption,” March 11, 2025, https://www.nist.gov/news-events/news/2025/03/nist-selects-hqc-fifth-algorithm-post-quantum-encryption.