Learn about post-quantum cryptography, including how it works and why organizations are moving toward new cryptography methods for the growing quantum computing field.
![[Featured Image] A cybersecurity expert uses post-quantum cryptography strategies to help their organization plan for future cyber threats.](https://d3njjcbhbojbot.cloudfront.net/api/utilities/v1/imageproxy/https://images.ctfassets.net/wp1lcwdav1p1/4Rg41EM7rlrq6uqiCIiXrq/943821955a705dc4a285dab80aff7786/GettyImages-2268594927-converted-from-jpg.webp?w=1500&h=680&q=60&fit=fill&f=faces&fm=jpg&fl=progressive&auto=format%2Ccompress&dpr=1&w=1000)
Post-quantum cryptography (PQC) focuses on addressing cybersecurity challenges posed by advances in quantum computing.
PQC uses algorithms based on lattice, hash, and code-based math that are too complex for quantum computers to break.
Recent developments in post‑quantum cryptography from the National Institute of Standards and Technology (NIST), the National Cyber Security Centre (NCSC), and Google highlight how new standards and migration plans are shaping organizations’ preparations for quantum‑era threats to security.
Understanding the purpose of post‑quantum cryptography can guide your migration strategy, especially as organizations adopt new standards to prepare for quantum‑era threats. Learn how getting an early start in PQC can help keep your organization’s information safe in this evolving threat landscape. If you’re ready to build your cybersecurity skills, consider earning a Google Cybersecurity Professional Certificate, which gives you in-demand skills in incident response, intrusion detection, and threat modeling, plus experience with programming languages like Python and SQL.
Post-quantum cryptography is a form of cryptography designed to address the unique challenges posed by quantum computing. As the prevalence of quantum computing grows and the technology advances, so does the need for new approaches to cryptography. Current cryptography methods are vulnerable to defending against cyberattacks from a quantum computer, as these high-powered devices would have the ability to break standard encryption algorithms with minimal resistance. The massive increase in processing power between classical computers and quantum computers makes the ease of decryption a real problem, one that post-quantum cryptography is working to solve in preparation for the future quantum computing landscape.
Advanced Encryption Standard (AES-256) is considered the strongest cryptography method in existence against potential quantum attacks and sets the standard for PQC. A popular choice in industries such as finance and health care, AES-256 uses a 256-bit key, the longest in use today, making it the highest attainable level of security currently.
Current expectations for the future of quantum computing will disrupt cryptography, as the methods organizations are using today will eventually fail to keep up with the level of threats they will face in the future. This foresight is leading to efforts in PQC to develop methods capable of securing sensitive data and protecting valuable infrastructure. The motivation for adequate cryptography in a post-quantum world isn’t exclusively internal, as the National Institute of Standards and Technology (NIST) released its initial Federal Information Processing Standards (FIPS) in August of 2024, stating its PQC standards [1].
Post-quantum cryptography works by basing the encryption algorithms on mathematical concepts that are too complex for quantum computers to solve. This is where PQC can differentiate from standard cryptography methods. Generally speaking, cryptography algorithms follow formulas such as logistic regression and factoring large numbers, both of which are challenging for modern computers to solve but simple for a quantum computer to break. Instead, PQC utilizes lattice-based, hash-based, and code-based algorithmic approaches. NIST-approved algorithms following these approaches include:
ML-KEM: The general encryption method for PQC, ML-KEM enables parties to share a key securely over a public channel, which is crucial for securing web traffic.
HQC: Serving as the backup for ML-KEM, HQC uses a different mathematical formula, which could prove valuable for general encryption if quantum computers one day solve ML-KEM.
FrodoKEM: A lattice-based algorithm, FrodoKEM uses unstructured lattices, which gives it an advantage over structured lattice algorithms by avoiding certain algebraic properties that may present vulnerabilities with future quantum developments.
The NIST standardization is well underway, with three post-quantum cryptography standards already being released. These standards are part of an effort that NIST spent eight years developing and are now mandated for federal systems. Organizations around the world are actively adopting them to prepare for the transition to post-quantum cryptography. The three PQC standards include:
FIPS 203: Focusing primarily on general encryption, FIPS 203 uses a Module-Lattice-Based Key-Encapsulation mechanism, specifying how parties can share a secret key over a shared channel.
FIPS 204: Using the module-lattice-based digital signature algorithm, FIPS 204 details the PQC standard for securing and verifying digital signatures.
FIPS 205: Also for securing digital signatures, FIPS 205 uses the Stateless Hash-Based Digital Signature Algorithm, essentially serving as a safeguard if the FIPS 204 approach fails.
NIST has led PQC standardization since 2016, with Google, Microsoft Research, and the UK's NCSC also playing significant roles in development and migration. However, the NIST hasn’t been working alone, as it requested help directly from the public to assist in gathering algorithms for testing in order to identify viable cryptography strategies.
In the United Kingdom, the National Cyber Security Centre (NCSC) is also preparing for a future with quantum computing, as the organization works on developing algorithms and migration protocols for organizations to follow, establishing key milestones over the next decade to ultimately reach full migration.
As for the private sector, Google is looking to set the standard for PQC, with the goal of migrating by 2029. As an early innovator in this space, Google has been experimenting with PQC since 2016, recognizing the need to acquire real-world experience in developing cryptographic methods for future post-quantum algorithms. Industry professionals from Google were directly involved in supporting NIST’s early efforts to develop PQC standards, as well as team members from Microsoft Research.
Although post-quantum solutions are already in effect, it doesn’t mean PQC is necessarily solved, as the future impact of quantum computing itself is not yet fully understood. Considering this, continuous algorithm development is necessary to adequately prepare in case current standards fall short.
Although quantum computing is still in development, it’s important to start your migration process now due to a type of cyberattack called Harvest Now, Decrypt Later (HNDL). This involves capturing data now with the intention of using quantum computing in the future to break the encryption when the technology advances.
To begin your migration, start by taking a close look at your current encryption protocols throughout your infrastructure and cloud environments, and determine their potential vulnerabilities, particularly those susceptible to HNDL attacks. This includes data such as financial and medical records and other personal information, legal communication, and intellectual property.
From there, you can start to prioritize your systems and begin testing and implementing PQC algorithms, following NIST standards. However, you’ll need to take a hybrid approach to your PQC migration, implementing both post-quantum algorithms and those designed for standard cryptography. This way, you can ensure your systems remain secure according to their present needs, in addition to future threats. As time goes on, you will need to continue monitoring recent developments so you can stay up to date and remain compliant with the latest standards and regulations.
Read more: What Is Quantum Safe Encryption?
Subscribe to our weekly LinkedIn newsletter, Career Chat, for updates on popular skills, tools, certifications, and more. Then check out some of our other free resources to keep learning more about cybersecurity:
Watch on YouTube: How to Launch a Cybersecurity Career Without a College Degree
Read an insider story: Meet the IT Support Tech Advancing Toward a Cybersecurity Career
Whether you want to develop a new skill, get comfortable with an in-demand technology, or advance your abilities, keep growing with a Coursera Plus subscription. You’ll get access to over 10,000 flexible courses.
NIST. “Post-Quantum Cryptography PQC, https://csrc.nist.gov/projects/post-quantum-cryptography.” Accessed July 6, 2026.
Editorial Team
Coursera’s editorial team is comprised of highly experienced professional editors, writers, and fact...
This content has been made available for informational purposes only. Learners are advised to conduct additional research to ensure that courses and other credentials pursued meet their personal, professional, and financial goals.