An official website of the United States government
A .gov website belongs to an official government organization in the United States.
A lock (lock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites.

Post-Quantum Cryptography Resource | Oct. 1, 2026

Post-Quantum Cryptography: Primer

Post quantum cryptography (PQC) is designed to be the safeguard against attacks targeting both standard and quantum computers. Using this system of cryptographic algorithms is critical for securing critical networks against the novel capabilities of quantum computers.

While traditional encryption protects networks from adversaries today, a powerful quantum computer could break through those defenses exponentially faster. As stable quantum computers get closer to reality, the transition to PQC is critical for public key infrastructure security.

So how exactly does it work?

Quantum vs. Classical Computing
Quantum vs. Classical Computing
Quantum vs. Classical Computing
Quantum vs. Classical Computing
Quantum vs. Classical Computing
Photo By: NSA
VIRIN: 260930-D-IM742-3333


Quantum Computing and Post-Quantum Cryptography

Quantum computers will operate at the atomic scale, which means they will be inherently delicate and difficult to build. It also means stable quantum computers will be able to leverage the rules of quantum mechanics to perform computations that standard computers cannot, including the ability to break cryptographic systems that rely on factoring large prime numbers (RSA) or solving discrete logarithms (ECC).

How PQC Works: Changing the Math of Security

Post-quantum cryptography algorithms are based on more intricate math problems than their classical counterparts. In 2024, the National Institute of Standards and Technology (NIST) finalized the first official standards for PQC. Let’s explore the main families of PQC algorithms:

  • Lattice-based Cryptography (ML-KEM and ML-DSA): Imagine an endless grid of dots that stretches across many dimensions. Lattice-based cryptography involves finding specific points in this complex geometric landscape, building security via geometric problems in high-dimensional lattices. Even for a quantum computer, finding the “closest” point in the maze would be incredibly difficult, making lattice-based cryptography a good option for long-term hardware root of trust. This is the basis for primary PQC standards, offering both key confidentiality (ML-KEM) and digital signatures (ML-DSA).

Lattice in Cryptography
Lattice in Cryptography
Lattice in Cryptography
Lattice in Cryptography
Lattice in Cryptography
Photo By: NSA
VIRIN: 260930-D-IM742-4444

  • Hash-based Signatures: These standards use the security of cryptographic hash functions — the same math that assures the foundational integrity of a blockchain  — to create digital signatures. They are one-way streets, easy to compute in one direction but nearly impossible to reverse. This makes them strong candidates for quantum-resistant signatures.
  • Leighton-Micali Signature (LMS): LMS is a hash-based signature scheme that generates a sequence of one-time unique signatures. LMS is particularly suited for environments where state management is feasible, making it a strong option for long-term hardware root of trust.
  • eXtended Merkle Signature Scheme (XMSS): XMSS is a hash-based signature scheme that extends the Merkle Signature Scheme to support multiple signatures, providing a flexible and scalable solution for securing digital communications.

To get started with post-quantum cryptography adoption today, explore the PQC Resource Hub.