up:: For Press
For a security or technology audience
For readers who already know TLS, PKI, certificates, and how a migration program behaves, and who need the quantum specifics rather than the security basics. The standards are settled. What’s contested sits below them, in parameter selection, deployment strategy, and whether published timelines survive contact with real estates.
What’s the story in one paragraph?
Shor’s algorithm solves integer factorization and the discrete logarithm efficiently on a quantum computer, which recovers a private key directly from its public key and takes RSA, Diffie-Hellman, and every elliptic-curve construction with it. Symmetric primitives and hashes survive, because Grover’s algorithm only halves effective strength and larger sizes absorb it. That splits the threat into 2 clocks: confidentiality fails retroactively, since ciphertext recorded today opens once the key exchange is broken, while signature forgery waits on the machine because the public key was already published and nothing can be staged in advance. NIST finalized ML-KEM, ML-DSA, and SLH-DSA on August 13, 2024, and the hard part now is discovery, vendor-controlled surfaces, and handshake sizes that break middleboxes.
What are the 5 most important things?
- The break is specific: factoring and discrete logarithms. RSA, finite-field Diffie-Hellman, ECDH, and ECDSA all fall to the same algorithm. Elliptic curve falls to a smaller machine than RSA at comparable classical strength, because it needs fewer error-corrected qubits, so migrating RSA to ECC to buy time runs backward.
- Symmetric and hashing survive, and the NSA’s own suite proves it. The same CNSA 2.0 advisory that retires RSA and ECC keeps AES-256 as the required symmetric cipher. AES-128 drops to roughly 64 bits under Grover and is worth retiring on its own schedule.
- Two clocks, and conflating them produces the wrong migration order. Harvest-now-decrypt-later is live today and prioritizes by data confidentiality lifetime. Forge-later waits on the machine and prioritizes by trust lifetime: root and intermediate CAs, identity-provider signing keys, and firmware-signing keys.
- Discovery is the actual bottleneck. Standard asset inventories record installed software rather than which algorithms it uses, and a large share of the estate sits in vendor-controlled surfaces no internal scan sees. Every published mandate names algorithm-level inventory as the first deliverable.
- What to do about it, in the order that works. Inventory at the algorithm level before anything else, since nothing can be sequenced without it. Sort by confidentiality lifetime and by trust lifetime separately, because they produce different lists. Deploy hybrid where the size budget allows and where a regulator requires it. Get dated vendor commitments into contracts at renewal rather than accepting roadmaps. And build agility so the next algorithm change is configuration rather than another multi-year program.
How exactly do RSA and Diffie-Hellman break?
Both rest on a one-way relationship: a calculation that’s cheap forward and infeasible to reverse at real key sizes.
RSA rests on integer factorization. The public key contains a modulus that’s the product of 2 large primes, and recovering those primes yields the private key. Diffie-Hellman and its elliptic-curve variants rest on the discrete logarithm: given a generator and a public value, recovering the exponent yields the shared secret. Classically, both are infeasible at deployed parameters, and that infeasibility is the security.
Shor’s algorithm solves both in polynomial time on a quantum computer. The consequence is direct: given a public key, it computes the corresponding private key. No captured traffic is required for the signature case, and no interaction with the victim is required at all.
Source: Peter W. Shor, “Polynomial-Time Algorithms for Prime Factorization and Discrete Logarithms on a Quantum Computer,” SIAM J. Computing 26(5), 1997, arxiv.org.
For key establishment specifically, the attack against recorded traffic works because the handshake is in the recording. An adversary captures the full session, including the key exchange that produced the session key. Recovering that exchange yields the session key, and the session key decrypts the rest of the capture. Forward secrecy doesn’t help, which is the point most often missed: ephemeral key exchange protects against later compromise of a long-term key, and Shor breaks the ephemeral exchange itself.
The starting position looks worse than assumed, with the caveats attached. A 2026 analysis of Nginx TLS configurations published to public GitHub repositories found 28.9% specifying an RSA key exchange with no forward secrecy at all, meaning any recorded session can be reopened once that server’s long-term key is recovered. It’s a corpus of 8,443 configuration files rather than a scan of live servers, the paper doesn’t state which subset the 28.9% is drawn from, and the authors include a commercial post-quantum vendor and the bank that funded the work, so it’s evidence of a persistent pattern rather than a measurement of the internet.
Source: Balaji et al., “Operationalising Post-Quantum TLS,” 2026, arxiv.org.
What survives, and how much margin is left?
Grover’s algorithm gives a quadratic speedup on unstructured search, which halves effective key strength. NIST’s assessment is that this “does not render cryptographic technologies obsolete,” and that “doubling the key size will be sufficient to preserve security.” NIST further notes the primitives “provide substantially more quantum security than a naïve analysis might suggest,” because Grover parallelizes poorly and demands very deep circuits.
Source: NIST, “Report on Post-Quantum Cryptography,” NISTIR 8105, April 2016, csrc.nist.gov.
| Primitive | Classical strength | Post-quantum position |
|---|---|---|
| AES-256 | 256-bit | ~128-bit under Grover, comfortably safe, and required by CNSA 2.0 |
| AES-128 | 128-bit | ~64-bit under Grover, worth retiring |
| SHA-256 | 128-bit collision resistance | ~128-bit preimage resistance retained, stays strong |
| SHA-384 | Higher | Covers highest-assurance use |
| RSA, DH, ECDH, ECDSA | Varies | Broken completely by Shor |
What’s genuinely contested?
The standards are settled. These 6 have credible people on both sides.
| The question | The positions | Where it stands |
|---|---|---|
| Hybrid or standalone? | The U.S. accepts standalone deployment on a schedule. France and Germany require pairing with a proven classical algorithm so the composite is never weaker than the classical one alone. | Unresolved. France applies it to signatures as well as key establishment. Hybrid also compounds the size problem, since both handshakes travel together. |
| Which parameter set? | CNSA 2.0 requires the strongest set per function. The NCSC recommends a middle set for general use. | Both defensible. Systems built to the 2 recommendations don’t automatically negotiate a common configuration. |
| Do the retirement dates hold? | IR 8547 sets deprecation after 2030 and disallowance after 2035. | Initial public draft, so the years could shift. Procurement language and vendor roadmaps are already being written against it. |
| Are the new algorithms durable? | Lattice constructions carry years of scrutiny. | SIKE, a fourth-round candidate, fell to a classical key-recovery attack in 2022. That’s the field’s own cautionary case and the strongest argument for hybrid. |
| Does QKD have a role? | Vendors position it as a quantum-native alternative. | Several national authorities decline to recommend it as a general replacement. It addresses key exchange over a dedicated physical link and addresses none of the signature and authentication half. |
| Are the timelines achievable? | Governments have published dated schedules. | Against a baseline where 28.9% of sampled published configurations still specify RSA key exchange with no forward secrecy. |
Source: NIST IR 8547 initial public draft, csrc.nist.gov; ANSSI, cyber.gouv.fr; BSI TR-02102-1, bsi.bund.de; NSA CNSA 2.0 FAQ, media.defense.gov; NCSC, ncsc.gov.uk; Castryck and Decru, “An efficient key recovery attack on SIDH,” EUROCRYPT 2023, eprint.iacr.org.
What actually breaks in deployment?
Size, and it surprises teams in testing rather than in design.
The replacement algorithms produce substantially larger keys, ciphertexts, and signatures. Three consequences show up in real estates: middleboxes, load balancers, and inspection appliances that assumed a certain handshake size drop connections rather than passing them, and the failure presents as intermittent connectivity rather than a crypto error, which makes it slow to diagnose. Constrained links and embedded devices hit real memory and message-size limits. And larger signatures across a big certificate hierarchy add up in storage and validation cost.
Beyond size, the recurring blockers are the ones no library upgrade reaches: cryptography fixed in firmware with no update path, certificate hierarchies that need rebuilding rather than reissuing, stored data whose key-protection chain contains a public-key operation, and vendor-controlled surfaces on release schedules the operator doesn’t set.
What are practitioners actually being told to do?
Three structural prescriptions from the standards side, stated publicly at Quantum USA 2026 in June by the cybersecurity engineer leading the post-quantum migration project at NIST’s National Cybersecurity Center of Excellence.
- Run 3 migration programs by technology area, covering TLS, code and firmware signing, and public key infrastructure. Splitting the estate by technology rather than by business unit is what keeps the work sequenceable.
- Transport comes first. “You can’t get to PQC without getting to TLS 1.3.” The protocol floor has to be in place before the new algorithms can ride on it.
- Compliance is widely misunderstood. “Just because it’s in the product doesn’t mean you’ve turned it on.” Shipping support and having it enabled are different states, and audits routinely conflate them.
The same session set out acquisition as the near-term lever: stop buying equipment that can’t be updated, and require vendor and supply-chain readiness at purchase.
Source: Forum Global, “The Report: Quantum USA 2026,” Washington D.C., June 18, 2026, recording remarks by Bill Newhouse of the NIST National Cybersecurity Center of Excellence. Statements are attributed to the speakers who made them.
A useful counterweight from the same panel: a vendor chief technology officer argued for a Q-Day window of 2029 to 2030 and a 10-to-15-year migration, which is a vendor estimate from a company selling post-quantum products and sits well inside the published expert-survey range rather than replacing it. Treat it as an attributed position. The vendor-claim tiering for this whole field is at Every figure and where it comes from.
Where’s the technical layer?
Written for practitioners, with parameter sets, primary sources, and the open disputes intact.
Section indexes: Foundations MOC · The Threat MOC · The New Standards MOC · Quantum Computing MOC · The Mandates MOC · Migration Architecture MOC · In the Protocols MOC · Breaking Today’s Cryptography MOC
Which errors draw corrections?
- “Quantum breaks all encryption.” It breaks public-key. Symmetric and hashing survive with larger sizes.
- “An N-qubit machine means Q-Day is closer.” Headline counts are noisy physical qubits. The threshold is error-corrected logical qubits, each requiring many physical ones.
- “Move from RSA to ECC to buy time.” ECC falls to a smaller machine than RSA at comparable classical strength.
- “Forward secrecy protects against this.” It protects against later compromise of a long-term key, and Shor breaks the ephemeral exchange itself.
- “QKD is the post-quantum solution.” It addresses key exchange over a dedicated link and none of the signature and authentication half.
Where to go deeper
- Every figure and where it comes from carries every number with accurate phrasing and its qualifier.
- The primary documents behind every claim is the annotated source index.
- What gets reported wrong carries every recurring error.
- What is technically happening to our systems is the estate-level version for a business audience.
- For Press is the full index.
Last verified 2026-08-02 · Maintained by Addie LaMarr, LaMarr Labs.