How close are quantum computers to breaking today’s encryption?
“We don’t know.”
That was the answer from Andrew Regenscheid, a mathematician at the National Institute of Standards and Technology (NIST), in an interview earlier this year. The thought that it could become a reality at any given moment is scary, but the timeline doesn’t actually matter.
As Regenscheid reminds us, adversaries can collect encrypted data now and decrypt it once the hardware catches up, so some information has already been exposed.
Change is already underway; U.S. federal agencies have been directed to move to NIST-approved Post-Quantum Cryptography (PQC) standards, with vendors, contractors, and infrastructure operators to follow.
Three PQC algorithms serve as the initial foundation of this transition, and the first step in migration planning is to know what each one does.
Today’s Public-Key Cryptography is Running Out of Time
RSA and elliptic curve cryptography protect the most secure connections today. They use complex math problems like integer factorization and discrete logarithms, which today’s computers can’t reliably solve.
A quantum computer that could solve them, on the other hand, would break the key exchange that protects data and digital signatures and proves that software, certificates and documents are authentic.
The timing makes it tricky.
Algorithm migrations can take years, and this is one of the most challenging the industry has ever seen. Organizations that wait for a working quantum machine will be instantly vulnerable. There is also some understandable confusion since the current standards have been renamed; Kyber, Dilithium, and SPHINCS+ are now known as ML-KEM, ML-DSA, and SLH-DSA, respectively, and it’s a challenge for teams to remember which one replaces what.
One Standard for Key Encapsulation, Two for Signatures
NIST finalized its first three post-quantum standards in August 2024, with each targeting a specific vulnerable function. They’re based around two types of math, lattices and hash functions, the thinking being that if a weakness emerges in one, the other will still hold up.
Let’s take a deeper look:
ML-KEM (FIPS 203) is designed to handle key establishment. A derivation of CRYSTALS-Kyber, it lets two parties agree on a shared secret over a public channel; that secret is then used with fast symmetric encryption to reveal the actual data. The security is based around the Module Learning with Errors problem, with three sets of parameters: ML-KEM-512, ML-KEM-768 and ML-KEM-1024. This algorithm is meant to replace RSA key transport and elliptic-curve key exchange.
ML-DSA (FIPS 204) is the primary standard for signatures. It’s derived from CRYSTALS-Dilithium and generates/verifies signatures for authentication, integrity, and non-repudiation. It uses the same family of module-lattice math as ML-KEM, which may simplify implementation. The size of a signature may present an implementation trade-off: an ML-DSA-65 signature is about 3.3 kilobytes, compared to just 64 bytes for ECDSA P-256.
SLH-DSA (FIPS 205) is an alternative digital signature standard. This one is derived from SPHINCS+ and uses hash functions for security. Experts say there are two main trade-offs compared to classic digital signature algorithms: larger signatures (roughly 8-50 kilobytes depending on the parameter set) and slower signing. It’s generally a good option for long-lived roots of trust such as firmware and code signing.
There are two other algorithms in the pipeline:
- FN-DSA (FIPS 206): A lattice-based algorithm formerly known as FALCON that produces the smallest signature and public key sizes of the PQC standards selected by NIST.
- HQC (FIPS 207): A code-based algorithm for key encapsulation that serves as an insurance policy if lattice-based options falter.
Choose Standards Based on Your Inventory
Organizations making the PQC transition should start with visibility. Inventory all of your systems, applications and data, and identify the most sensitive information—that’s what’s most at risk of a harvest-now, decrypt-later attack.
Then, create a roadmap and hold your vendors accountable when it comes to PQC readiness.
Fortanix Data Security Manager (DSM) supports the full PQC transition, starting with a discovery toolset that locates cryptographic assets and key metadata analysis to determine which keys depend on vulnerable algorithms. Its REST API-based architecture helps teams automate key lifecycle management.
Fortanix implements the NIST-standardized algorithms (ML-KEM, ML-DSA and SLH-DSA), and DSM integrates with databases, PKIs and data signing workflows both on-premises and across cloud and neocloud services.
The ultimate goal is crypto-agility: the ability to quickly switch between cryptographic algorithms without disruption or rebuilding infrastructure. When a standard changes or a new one is implemented, teams can change algorithms without redesigning applications.
Start With What You Can Measure
NIST has settled on the first three PQC algorithms: ML-KEM to secure key exchange, ML-DSA to sign at scale, and SLH-DSA as a hash-based alternative. Where does your organization stand?
Many enterprises can’t list every place RSA and elliptic-curve keys are used across their systems, and they won’t be able to migrate until they can. Start with that detailed inventory, and Fortanix can help you plan your work and work your plan.

