The short version
Much of the internet’s security relies on public-key cryptography, such as RSA and elliptic curves. A large enough quantum computer could break it. Nobody has built one yet, and estimates of when (or whether) that will happen vary widely.
The replacements, though, are ready. In August 2024 the US National Institute of Standards and Technology (NIST) published the first post-quantum standards, including ML-KEM for exchanging keys and ML-DSA for digital signatures. These are designed to resist attacks from both ordinary and quantum computers.
Why act before quantum computers exist?
- Harvest now, decrypt later. Data intercepted today could be stored and decrypted in future. If your information needs to stay confidential for years, that matters now.
- Migration takes time. Cryptography is buried in websites, VPNs, email, devices, software and suppliers. Finding and replacing it is a multi-year job for most organisations.
- Trust lasts a long time. Signatures on software, documents and devices may need to remain trustworthy for a decade or more.
The UK timeline
In 2025 the UK’s National Cyber Security Centre (NCSC) set out milestones for moving to post-quantum cryptography:
- By 2028: define your migration goals, understand where you depend on cryptography, and build an initial plan.
- By 2031: complete your highest-priority migration activities.
- By 2035: complete the migration of all systems, services and products.
These dates are aimed at larger organisations, but the order of work is good advice for everyone: understand first, then prioritise, then migrate.
What’s already happening
The good news is that a lot of the work arrives through updates. Modern browsers and networks such as Cloudflare already use hybrid post-quantum key agreement for many connections, combining a classical algorithm with ML-KEM, so traffic is protected even if one of them is broken. Visits to this website, for example, use it with supported browsers.
Operating systems, programming languages, VPNs and messaging apps are following. Keeping software current is quietly one of the most effective post-quantum steps you can take.
Practical first steps
- Make an inventory. List where you use cryptography: websites, VPNs, email, file transfers, code signing, backups and third-party services.
- Ask your suppliers. What are their post-quantum plans and timelines? Good suppliers will have an answer.
- Prioritise long-lived secrets. Data that must stay confidential for many years should move first.
- Keep everything up to date. Much of the migration will arrive in routine updates.
- Build in crypto-agility. Prefer systems where algorithms can be swapped without a rebuild.
- Ignore “quantum-proof” sales pitches. Look for the standard names (ML-KEM, ML-DSA, SLH-DSA) and recognised guidance, not marketing.
Where to start
For most small and medium organisations, the right first step is a short review: where cryptography is used, which suppliers matter, and what to do first. It doesn’t need to be expensive or dramatic.
That’s exactly the kind of practical, plain-English work we do in AI and emerging tech and technical advice.