Summary
Post-quantum cryptography, or PQC, is moving from a long-term research topic into an active cybersecurity migration priority. Governments, technology companies, financial institutions and blockchain networks are preparing for a future in which sufficiently capable quantum computers could break widely used public-key cryptography. The urgency is not based on the assumption that a cryptographically relevant quantum computer already exists. Instead, organizations are preparing because sensitive information encrypted today may still have value years or decades from now. This creates the so-called “harvest now, decrypt later” risk, in which attackers collect encrypted information today and attempt to decrypt it when quantum technology becomes powerful enough. NIST has already finalized its first major PQC standards and says organizations should begin applying them now. These include ML-KEM for key establishment, ML-DSA for digital signatures and SLH-DSA as a hash-based signature standard.
The hardware race is adding urgency to that migration. IBM’s current roadmap targets a fault-tolerant system with 200 logical qubits and 100 million quantum gates by 2029, although IBM explicitly describes these milestones as goals that are subject to change. DARPA is separately evaluating whether utility-scale quantum computing can be achieved by 2033. These timelines do not mean that quantum computers will automatically break today’s cryptography by 2029. They do show why governments and enterprises are unwilling to wait for a definitive “Q-Day” announcement before beginning migration.
Web3 networks face an especially important challenge because blockchain security relies heavily on digital signatures and public-key cryptography. Algorand is one of the clearest examples of a blockchain ecosystem actively building a post-quantum transition strategy. The Algorand Foundation announced in June 2026 a roadmap targeting broad quantum resilience by the end of 2027, with native post-quantum accounts beginning in Q3 2026, post-quantum multisignatures later in 2026 and additional research covering consensus and verifiable random functions.
Key Takeaways
- PQC is becoming an immediate migration issue, rather than a purely future-facing research project.
- NIST finalized ML-KEM, ML-DSA and SLH-DSA as its first principal PQC standards in 2024.
- The “harvest now, decrypt later” threat means organizations may need to protect long-lived data before large-scale quantum computers arrive.
- IBM’s roadmap targets 200 logical qubits and 100 million gates by 2029, but this remains a corporate technology goal rather than a guaranteed industry milestone.
- DARPA is evaluating multiple approaches to determine whether utility-scale quantum computing can be achieved by 2033.
- Algorand executed a post-quantum transaction using Falcon signatures on mainnet in 2025.
- Algorand’s 2026 roadmap targets broad quantum resilience by the end of 2027.
- Hybrid cryptography can allow organizations to combine classical and post-quantum protections during migration.
- Procurement, hardware security modules, identity systems, cloud infrastructure and software libraries will all play important roles in PQC adoption.
Why is post-quantum cryptography becoming urgent before large-scale quantum computers arrive?
Because cryptographic migration can take years, while sensitive data may need protection for decades. NIST has already established PQC standards, and organizations are being encouraged to begin migration now. At the same time, quantum-computing roadmaps are targeting increasingly capable fault-tolerant systems later this decade. The exact date when quantum computers could threaten RSA or elliptic-curve cryptography remains uncertain, but the combination of long data lifetimes, complex technology migrations and accelerating quantum research makes early preparation a strategic necessity.
What is post-quantum cryptography and why does it matter?
Post-quantum cryptography refers to cryptographic algorithms designed to remain secure against attacks from both classical and future quantum computers. It is different from quantum cryptography because PQC does not require a quantum communication channel or quantum hardware. Instead, it uses mathematical techniques that can run on conventional computers and networks. The objective is to replace or supplement public-key algorithms that could eventually become vulnerable to quantum algorithms such as Shor’s algorithm. This matters because public-key cryptography protects some of the most important functions of modern digital infrastructure, including secure communications, authentication, digital signatures, certificates, software updates, cloud services and blockchain transactions.
The migration is difficult because cryptography is embedded throughout technology stacks. A company may know which algorithms its applications use but still struggle to identify cryptographic dependencies inside operating systems, firmware, hardware security modules, third-party software and supplier systems. Government agencies face an even larger challenge because national-security information can have exceptionally long confidentiality requirements. NIST’s transition work is therefore focused not only on choosing algorithms but also on helping agencies and industry manage the migration from vulnerable standards to quantum-resistant alternatives.
Why is the “harvest now, decrypt later” threat important?
The harvest-now, decrypt-later model changes the traditional cybersecurity timeline. An attacker does not necessarily need a quantum computer today. Instead, they can collect encrypted communications or other valuable information and store it. If a future quantum computer becomes capable of breaking the underlying public-key protection, previously captured information could potentially become readable. This is especially relevant for government intelligence, military information, intellectual property, financial records, healthcare data and other information with a long useful life.
NIST has specifically highlighted this issue in its transition planning. Its guidance notes that application-specific requirements may call for migration to quantum-resistant key-establishment techniques before classical algorithms are generally disallowed because of the risk associated with harvest-now, decrypt-later attacks. The practical implication is simple: organizations cannot measure the threat only by asking when the first cryptographically relevant quantum computer will appear. They also need to ask how long their sensitive information must remain confidential and how long their own technology migration will take.
What PQC standards has NIST approved?
NIST approved three major post-quantum cryptography standards in August 2024. FIPS 203 specifies ML-KEM, a key-encapsulation mechanism used for establishing shared secrets. Moreover, FIPS 204 specifies ML-DSA, a digital-signature standard. FIPS 205 specifies SLH-DSA, another digital-signature standard based on hash functions. NIST describes these standards as its principal PQC standards and encourages organizations to begin applying them as part of migration planning.
| NIST Standard | Algorithm | Primary Function | Strategic Importance |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key establishment | Helps protect encrypted communications and secure key exchange |
| FIPS 204 | ML-DSA | Digital signatures | Supports authentication, integrity and signing |
| FIPS 205 | SLH-DSA | Digital signatures | Provides a hash-based signature alternative |
| Falcon / FN-DSA family | Lattice-based signatures | Digital signatures | Important for compact signatures and specialized applications |
The significance of these standards goes beyond the algorithms themselves. Standardization gives governments and companies a stable foundation for product development, procurement and compliance. It also allows software vendors, hardware manufacturers and cloud providers to build compatible implementations rather than waiting for every organization to make its own cryptographic decision.
How advanced are quantum computers heading into 2027–2029?
Quantum hardware is advancing rapidly, but the number of physical qubits alone does not determine whether a quantum computer can threaten modern cryptography. The more important concept is the logical qubit. Physical qubits are noisy and error-prone. Logical qubits use quantum error correction to create more reliable computational units from multiple physical qubits. Building useful numbers of high-quality logical qubits is therefore one of the central challenges in the industry.
IBM currently states that it aims to deliver its Starling fault-tolerant quantum computer in 2029, with 200 logical qubits capable of running 100 million quantum gates. Its roadmap also describes intermediate milestones in 2027 and 2028 involving larger processors, modularity, error correction and fault-tolerant computing components. These are ambitious company targets, not independent predictions that guarantee a cryptographically relevant quantum computer by 2029.
DARPA’s approach highlights the uncertainty. Its Quantum Benchmarking Initiative is evaluating multiple architectures and seeks to determine whether an industrially useful quantum computer can be built by 2033. In March 2026, DARPA said it had evaluated approaches from 20 commercial companies, with 11 organizations advancing to Stage B and two performers progressing to the final verification-and-validation stage from the earlier US2QC program.
| Quantum Milestone | Current Outlook | Why It Matters for PQC |
|---|---|---|
| 2026 | Error correction and modular-system development continue | Migration planning is already underway |
| 2027 | IBM targets larger quantum systems and modular fault-tolerant development | Organizations face increasing pressure to test PQC |
| 2028 | Fault-tolerant architecture and magic-state technologies are targeted | PQC implementations should be moving beyond experiments |
| 2029 | IBM targets 200 logical qubits and 100 million gates | A major technology milestone, but not proof of cryptographic breaking capability |
| 2033 | DARPA targets verification of utility-scale quantum computing feasibility | Illustrates the broader industry uncertainty and longer-term risk |
The important distinction is that a 200-logical-qubit system is not automatically a machine capable of breaking RSA-2048 or elliptic-curve cryptography. Cryptographic attacks require specific algorithms, error rates, gate counts, circuit depth and enormous computational resources. The hardware roadmap should therefore be viewed as a reason to accelerate preparedness, not as a prediction of a specific “Q-Day.”
Why are government networks moving toward PQC?
Government systems have some of the strongest reasons to begin migration early. Sensitive information may need to remain confidential for decades, and government networks often contain enormous technology estates that are difficult to upgrade quickly. Identity systems, secure communications, certificates, VPNs, databases, cloud platforms and embedded devices may all depend on public-key cryptography.
NIST is actively updating government identity standards to accommodate PQC. In June 2026, NIST released working drafts addressing the use of ML-DSA and ML-KEM within Personal Identity Verification standards. The proposed approach uses a dual-stack model that retains classical credentials while adding PQC credentials, allowing incremental deployment and backward compatibility. This is an important example of how migration is likely to work in practice. Organizations will not replace every cryptographic system overnight. They will gradually introduce cryptographic agility, hybrid methods and new credentials while legacy systems remain operational.
Why is cryptographic agility becoming essential?
Cryptographic agility means designing systems so that cryptographic algorithms can be replaced without rebuilding the entire application or infrastructure stack. This concept is becoming central to PQC migration because standards and implementation practices will continue evolving. A system that hard-codes one cryptographic algorithm into hardware or software can become extremely expensive to upgrade.
The lesson extends beyond quantum security. Cybersecurity history has repeatedly shown that algorithms, protocols and key sizes eventually need to change. Organizations that build algorithm flexibility into their architecture can respond more quickly when vulnerabilities emerge. PQC is therefore not simply an algorithm replacement project. It is an opportunity to modernize the way organizations manage cryptography across their technology environments.
What does quantum computing mean for Web3 and blockchain networks?
Blockchain systems have a particularly visible exposure because digital assets depend on cryptographic signatures. Many blockchain networks use elliptic-curve cryptography to authenticate transactions. A sufficiently capable quantum computer using Shor’s algorithm could theoretically undermine the mathematical assumptions behind these systems. The risk is not limited to transactions. Consensus messages, validator identities, wallets, bridges and other infrastructure can also depend on public-key cryptography.
This creates a difficult migration challenge for Web3 ecosystems. Blockchain networks are decentralized, so changing cryptographic assumptions requires coordination among protocol developers, wallet providers, exchanges, validators, infrastructure operators and users. A network cannot simply update a single government-owned server and declare the migration complete. It must establish new standards while maintaining compatibility and protecting assets during the transition.
How is Algorand preparing for post-quantum security?
Algorand provides one of the clearest examples of an active blockchain PQC strategy. The network began preparing for quantum resilience with State Proofs in 2022. These use Falcon signatures to provide quantum-resistant attestations of blockchain state. In 2025, Algorand executed a post-quantum transaction on mainnet using Falcon signatures, demonstrating that quantum-resistant signatures could protect real digital assets rather than remaining confined to research environments.
In June 2026, the Algorand Foundation announced a broader roadmap targeting quantum resilience by the end of 2027. The plan begins with native post-quantum accounts in Q3 2026, including SDK and developer-tooling support. Later milestones include post-quantum multisignature capabilities, treasury migration and research into post-quantum consensus messaging and VRFs.
This approach is significant because it recognizes that blockchain security involves several layers. Protecting historical ledger data is one challenge. Protecting current accounts and transactions is another. Consensus mechanisms and validator communications create additional requirements. Algorand’s roadmap addresses these components progressively rather than treating PQC as a single software update.
Why are hybrid cryptographic systems important?
Hybrid cryptography can provide a practical bridge between existing classical algorithms and newer post-quantum algorithms. Instead of immediately abandoning classical cryptography, an organization can use both a traditional and a PQC mechanism during the migration period. This can reduce transition risk while allowing systems to gain quantum-resistant protection.
Algorand’s roadmap explicitly discusses hybrid accounts that combine elliptic-curve and lattice-based signatures. NIST’s current work on PIV standards also describes a dual-stack approach that preserves classical credentials while adding PQC credentials. The wider lesson is that migration should be treated as a controlled transformation rather than a one-time replacement.
What challenges could slow PQC adoption?
PQC migration will not be easy. New algorithms can have larger keys and signatures than traditional cryptography. That can increase bandwidth, storage and processing requirements. These issues are especially important in constrained devices, high-throughput networks and blockchain systems. Algorand, for example, notes that larger PQC keys and signatures can create challenges for block size, throughput and node accessibility.
Hardware is another challenge. Cryptographic operations are often performed inside hardware security modules, smart cards, secure elements and hardware wallets. Those devices may have long replacement cycles. Algorand’s research into Falcon signing on the Trezor Safe 5 illustrates the type of engineering work required for PQC on constrained hardware. Its reported proof-of-concept showed roughly 0.7 seconds for Falcon-1024 signing and median key-generation times around 2.2 seconds using an integer-only approach, although optimization remains ongoing.
What should companies do now to prepare for PQC?
The first step is cryptographic discovery. Organizations need to identify where RSA, ECC and other vulnerable public-key systems are used. This includes applications, certificates, VPNs, APIs, databases, cloud environments, firmware, hardware security modules and third-party software. The next step is to classify information according to how long it must remain confidential. Data with a 20-year confidentiality requirement deserves much more urgent attention than information that becomes obsolete within months.
Companies should then create a migration roadmap around NIST standards, test PQC implementations and evaluate hybrid approaches. Procurement teams should also ask suppliers about their PQC readiness. A company may upgrade its own applications but remain exposed through a supplier, cloud platform or embedded device that continues using vulnerable cryptography.
How will PQC affect procurement and supply chains?
Post-quantum security is becoming a procurement issue as much as a cybersecurity issue. Organizations will increasingly need suppliers to demonstrate cryptographic inventories, upgrade roadmaps and support for standardized PQC algorithms. Hardware manufacturers may need to redesign secure elements and HSMs. Software vendors may need to update libraries and certificate systems. Cloud providers will need to provide migration tools and hybrid cryptographic options.
This creates an opportunity for procurement leaders to build PQC requirements into contracts before migration becomes urgent. Supplier questionnaires can ask whether vendors support ML-KEM, ML-DSA or other approved standards, whether their products provide cryptographic agility and how quickly vulnerable algorithms can be replaced. Long-term contracts should also address future cryptographic upgrades rather than locking organizations into fixed algorithms.
Could PQC create a new cybersecurity investment cycle?
Yes. The migration will likely create demand across several layers of the technology ecosystem. Cybersecurity vendors will need to provide discovery and migration tools. Cloud providers will need quantum-resistant networking and identity services. Hardware manufacturers will need PQC-capable secure elements and HSMs. Enterprises will need new certificates, software libraries and security architectures.
The investment cycle could also extend into consulting, testing, compliance and managed security services. The biggest opportunity may not come from a single algorithm. It may come from the infrastructure required to move billions of devices, applications and digital identities from classical cryptography toward cryptographic systems designed for the quantum era.
Why should businesses start before quantum computers become a threat?
The strongest argument is migration time. Large enterprises rarely replace their entire cryptographic infrastructure in a single year. They have legacy applications, global suppliers, embedded systems and regulatory requirements. Some hardware may remain in operation for ten or fifteen years. Government and financial data can have even longer confidentiality requirements.
That means waiting for a fully capable quantum computer could create an unnecessary strategic disadvantage. By the time the threat becomes obvious, organizations may discover that their migration will take several years. Starting early allows businesses to test standards, identify compatibility problems and replace vulnerable systems according to normal technology-refresh cycles rather than through emergency programs.
What does the future of PQC look like through 2029?
The next several years are likely to be defined by migration rather than by a single dramatic quantum breakthrough. NIST standards will increasingly move into enterprise software, government identity systems, cloud infrastructure and hardware. Quantum hardware companies will continue pursuing better error correction, larger logical-qubit systems and fault-tolerant architectures. Blockchain networks will experiment with quantum-resistant wallets, signatures and consensus mechanisms.
The most important development may therefore be cryptographic readiness. Organizations do not need to know the exact year a quantum computer becomes capable of breaking today’s cryptography. They need to know whether their systems can be upgraded before that happens. This is why cryptographic agility, asset discovery and supplier readiness are becoming as important as the underlying algorithms.
FAQs
What is post-quantum cryptography?
PQC uses cryptographic algorithms designed to remain secure against attacks from future quantum computers. It can run on conventional computing infrastructure and does not require a quantum communication network.
Why is PQC needed now?
Sensitive information collected today could potentially be decrypted in the future. This “harvest now, decrypt later” risk makes early migration important for data that requires long-term confidentiality.
What are NIST’s main PQC standards?
NIST has standardized ML-KEM, ML-DSA and SLH-DSA. They cover key establishment and digital signatures and form the foundation of the current U.S. PQC migration strategy.
Will quantum computers break Bitcoin and other blockchains?
A sufficiently powerful quantum computer could threaten some public-key cryptography used by blockchain networks. The timing and practical feasibility remain uncertain, but blockchain ecosystems are already researching and deploying quantum-resistant alternatives.
Is Algorand quantum resistant?
Algorand has already implemented several post-quantum protections and executed a Falcon-based quantum-resistant transaction on mainnet in 2025. Its current roadmap targets broad quantum resilience by the end of 2027.
Will 200 logical qubits break modern encryption?
Not necessarily. A logical-qubit milestone does not directly translate into the ability to break RSA or elliptic-curve cryptography. Attack requirements depend on algorithms, error rates, circuit depth and other technical factors.
When should companies start PQC migration?
Organizations should begin with cryptographic discovery and risk assessment now, especially when protecting information with long confidentiality periods. NIST explicitly encourages organizations to begin applying its PQC standards.
What is cryptographic agility?
Cryptographic agility means designing systems so algorithms can be replaced without rebuilding the entire technology stack. It is an important strategy for managing both quantum and future cryptographic threats.
Will PQC increase cybersecurity costs?
Initially, migration can increase costs because organizations need new software, hardware, testing and expertise. Over time, cryptographic agility can reduce the cost and disruption of future security upgrades.
What role will procurement teams play?
Procurement teams can assess supplier PQC readiness, include quantum-security requirements in contracts and ensure that new technology purchases support standardized algorithms and future cryptographic upgrades.
Conclusion
Post-quantum cryptography is moving from a long-term cybersecurity concern to an important strategic priority. NIST has already established major PQC standards, while quantum hardware companies continue to pursue increasingly capable fault-tolerant systems. The exact timing of a quantum computer capable of threatening current encryption remains uncertain, but the “harvest now, decrypt later” risk means organizations cannot afford to wait. Governments, enterprises and Web3 networks are increasingly focusing on cryptographic discovery, hybrid protection, algorithm agility and long-term migration planning. Algorand’s ongoing work toward broader quantum resilience by 2027 also shows how blockchain ecosystems are preparing before the quantum threat becomes immediate.
From a strategic procurement and business-development perspective, Mattias Knutsson, a Strategic Leader in Global Procurement and Business Development, highlights the importance of looking beyond technology itself and considering suppliers, contracts, hardware lifecycles and long-term resilience. PQC adoption will affect the entire technology supply chain, from cloud infrastructure and cybersecurity software to hardware security modules and digital identity systems. Organizations that begin preparing now can reduce future disruption, strengthen supplier readiness and build a more flexible security architecture. The quantum era may not arrive on a predictable timeline, but businesses that prepare early will be better positioned to protect their data, infrastructure and digital assets when it does.


