
| Key Takeaways • NIST finalized its first three post-quantum cryptography standards, FIPS 203, FIPS 204, and FIPS 205, in August 2024, giving organizations concrete algorithms to begin migrating toward. • Security researchers warn of “harvest now, decrypt later” attacks, where adversaries capture and store encrypted traffic today so it can be decrypted once a powerful enough quantum computer exists. • The UK’s National Cyber Security Centre has published a three-phase migration roadmap running from 2025 through 2035, showing the transition to quantum-safe encryption is expected to take a decade or more. • Estimates for when a quantum computer capable of breaking today’s encryption could emerge vary widely, which is itself part of the argument for starting a phased migration early rather than waiting for certainty. |
What is post-quantum cryptography?
Post-quantum cryptography (PQC) is a set of encryption and digital-signature algorithms designed to stay secure even against an attacker armed with a large-scale quantum computer, unlike today’s widely used RSA and elliptic-curve (ECC) algorithms. In August 2024, the U.S. National Institute of Standards and Technology (NIST) finalized the first three federal standards built around this goal: FIPS 203 (a lattice-based key-encapsulation mechanism known as ML-KEM), FIPS 204 (a lattice-based signature scheme, ML-DSA), and FIPS 205 (a hash-based signature scheme, SLH-DSA). A fourth signature standard, FN-DSA, is still in progress, and in March 2025 NIST selected a fifth algorithm, Hamming Quasi-Cyclic (HQC), for further post-quantum encryption standardization. a broader explainer on quantum-safe encryption approaches for telecom networks walks through how these standards fit into a wider quantum-safe strategy for carrier networks.
Why does quantum computing threaten today’s encryption?
Quantum computing threatens today’s encryption because a sufficiently powerful quantum computer running Shor’s algorithm could, in theory, break widely deployed public-key algorithms like RSA-2048 or ECC far faster than any classical computer, undermining the key exchanges that secure most VPNs, TLS connections, and site-to-site links today. That risk isn’t tied to a single vendor or product; it applies to any network still relying solely on classical public-key cryptography for its long-term confidentiality. NIST’s own post-quantum migration guidance recommends that organizations start by taking a full cryptographic asset inventory, since most teams don’t have a clear picture of where classical public-key algorithms are actually used across their infrastructure.
What is “harvest now, decrypt later,” and why does it matter for today’s traffic?
“Harvest now, decrypt later” (HNDL) describes an attack where an adversary intercepts and stores encrypted network traffic today, with no way to read it yet, purely so it can be decrypted retroactively once a capable enough quantum computer becomes available. This matters even for traffic encrypted right now, because data with a long confidentiality shelf life, such as government records, health data, or years-long enterprise contracts sent over a site-to-site or site-to-cloud VPN, could still be exposed a decade from now if it was captured today under a classical-only algorithm. a telecom-focused partnership combining quantum-safe key generation with post-quantum algorithms was announced in March 2026 specifically to address this exposure for site-to-site VPN, site-to-cloud VPN, and data center interconnect traffic.
Is this being driven by government mandate, or is it optional?
For many organizations this is no longer purely optional: a series of U.S. government directives has steadily tightened requirements around post-quantum migration since 2022. National Security Memorandum 8 (NSM-8), issued in January 2022, set quantum-resistant protocol guidance for National Security Systems; NSM-10, issued in May 2022, extended cryptographic-inventory requirements to non-NSS federal assets and required reporting to the Cybersecurity and Infrastructure Security Agency (CISA); and OMB Memorandum M-23-02, issued in November 2022, further defined exactly which systems and assets that inventory must cover. More recently, a June 2026 executive order (EO-14412) mandated an accelerated federal migration timeline with binding deadlines specifically for high-value assets, signaling that the pace of migration is being pulled forward rather than left open-ended. Commercial carriers and enterprises aren’t directly bound by federal executive orders, but many serve government customers or operate infrastructure treated as critical, which is one reason vendor partnerships and standards work have accelerated alongside these mandates rather than independently of them. A telecom operator that carries government or critical-infrastructure traffic today may find itself contractually required to demonstrate quantum-safe readiness well before its own internal risk assessment would otherwise have prioritized the work, simply because a customer or regulator further up the compliance chain is already working against one of these deadlines.
How are organizations expected to migrate to quantum-safe encryption?
Organizations are expected to migrate in phases over roughly a decade rather than all at once, based on the clearest published timeline to date: the UK’s National Cyber Security Centre’s three-phase roadmap, released in March 2025. Phase one (2025–2028) covers identifying which cryptographic services need upgrading and building a migration plan; phase two (2028–2031) covers executing the highest-priority upgrades; phase three (2031–2035) covers completing migration across all remaining systems and products. The NCSC roadmap also notes that smaller organizations will largely receive quantum-safe upgrades automatically through routine vendor and service-provider updates, while larger organizations with more custom infrastructure will need dedicated planning and investment.

A three-phase national roadmap for migrating to quantum-safe encryption, based on the UK National Cyber Security Centre’s published guidance (announced March 2025).
What does a hybrid quantum-safe encryption approach look like in practice?
In practice, a hybrid approach combines a classical key-exchange method with a post-quantum one at the same time, so a network stays protected under the post-quantum algorithm even if a weakness is later found in the classical half, and stays interoperable with older equipment during the transition period. a carrier-grade 400G platform built with quantum-safe key exchange support is one example of this pattern applied to high-capacity Ethernet demarcation hardware, pairing programmable quantum-safe key exchange with AES-256-GCM for line-rate bulk encryption. AES-256-GCM itself is generally considered quantum-resistant at a 256-bit key length, which is one reason it continues to be recommended as the symmetric encryption layer even inside a broader post-quantum migration. Executives on the vendor side of one recent telecom-focused quantum-safe partnership described the goal in similar terms: one partner’s CEO called the need to fortify encryption against public-key weaknesses and harvest-now-decrypt-later attacks “beyond dispute,” while the networking vendor’s own VP of product and marketing framed the approach as hybridizing third-party quantum-safe key generation with post-quantum algorithms and existing high-speed wireline encryption, rather than replacing any one layer outright.
Is this just a theoretical, far-future concern?
No — the standardization work and vendor partnerships are already happening now, even though the exact date a quantum computer could break today’s encryption remains genuinely uncertain and debated among experts. independent trade coverage of that quantum-safe telecom partnership reported on the announcement as part of a broader wave of telecom-sector quantum-safe deals moving from research labs into commercially available network hardware. That pattern matters more than any single announcement: when standards bodies, national cyber agencies, and multiple vendors are independently converging on the same multi-year migration timeline, it’s a reasonable signal that the underlying risk is being treated as a planning problem to solve now, not a speculative one to revisit later.
Frequently Asked Questions
What does “post-quantum” mean in cryptography?
Post-quantum means an algorithm is designed to remain secure even against an attacker using a large-scale quantum computer, as opposed to classical algorithms like RSA and ECC that quantum computers could theoretically break.
Is post-quantum cryptography already in use today?
Yes. NIST finalized its first three post-quantum standards, FIPS 203, 204, and 205, in August 2024, and vendors have already begun building products and partnerships around them.
What is “harvest now, decrypt later”?
It is an attack strategy where an adversary captures and stores encrypted traffic today with the intention of decrypting it later, once a sufficiently powerful quantum computer exists, which makes long-lived confidential data risky to leave on classical-only encryption.
How long will migrating to quantum-safe encryption take?
Published national roadmaps, such as the UK NCSC’s, describe the migration as a multi-year, phased process running roughly from 2025 to 2035 rather than a single cutover.