2026-08-12

What Is PQC (Post-Quantum Cryptography)? Is Current Encryption Really Safe?

PQC (Post-Quantum Cryptography) is a new generation of encryption technology designed to withstand attacks from quantum computers. As "Harvest Now, Decrypt Later" makes this risk a present-day threat, NIST has already published its standards — how should enterprises respond?

What Is PQC (Post-Quantum Cryptography)? Is Current Encryption Really Safe?
background image

The security of current encryption technologies such as RSA and ECC is built on mathematical problems that are extremely difficult for classical computers to solve. However, once quantum computers mature, they will be able to break these algorithms effectively. Notably, the "Harvest Now, Decrypt Later" attack strategy allows hackers to steal encrypted data now and store it long-term, waiting to decrypt it once quantum computers become powerful enough — without needing to wait for that day to arrive. This means the quantum threat is no longer just a future concern, but a risk that is already unfolding today. Enterprises cannot afford to wait until Q-Day to begin evaluating and migrating to PQC.


Table of Contents

➤What Is PQC (Post-Quantum Cryptography)?
 ➤What Is a Quantum Computer? Computing Differences Between Classical and Quantum Computers
 ➤"Harvest Now, Decrypt Later"
 ➤PQC Standards
 ➤Common Challenges in Enterprise PQC Adoption
 ➤Frequently Asked Questions (FAQ)


What Is PQC (Post-Quantum Cryptography)?

"Post-Quantum Cryptography," abbreviated as PQC, is a branch of cryptography focused on developing encryption algorithms that can resist cryptanalytic attacks carried out by quantum computers.

However, even though quantum computers are still under development, data in existing systems could already be subject to "Harvest Now, Decrypt Later" attacks. In addition, upgrading the encryption algorithms across an entire network infrastructure — involving a complete overhaul of hardware, software, certificates, and communication protocols — can take several years, or even more than a decade. For these reasons, industry and governments worldwide agree that a new generation of quantum-resistant encryption algorithms must be deployed ahead of time. This is the reason PQC exists.


Current Encryption Technologies

Common public-key encryption methods used online today, such as RSA, are built on mathematical properties that are "easy to compute in one direction but extremely difficult to reverse."

Take RSA as an example: multiplying two large prime numbers together is easy. But given only the result, working backward to determine the original two prime factors requires computation time that grows explosively with key length — making it practically infeasible for classical computers today. This extreme difficulty of reverse computation is the security foundation of the entire public-key cryptography system, and it underpins the trust mechanisms the internet relies on today, including TLS certificates, VPN key exchange, and digital signatures.


What Is a Quantum Computer? Computing Differences Between Classical and Quantum Computers

A quantum computer is a type of computer that performs computation using quantum mechanical properties, such as superposition and entanglement, making its computing approach fundamentally different from the classical computers we use every day.

  • Classical Computers:
    The basic unit of computation in a classical computer is the "bit." At any given moment, each bit can only be in one of two states, 0 or 1, and all computations proceed step by step according to this binary logic.

  • Quantum Computers:
    The basic unit of a quantum computer is the "qubit." Due to the property of superposition, a single qubit can exist in a combined state of both 0 and 1 simultaneously, rather than being strictly either 0 or 1.

When multiple qubits become entangled and combined, they can simultaneously represent a vast number of state combinations. In theory, this allows certain types of computation to achieve exponential efficiency gains, processing enormous numbers of possibilities in parallel rather than testing them one by one as classical computers do.

It is precisely this potential for parallel processing that makes quantum computers particularly well-suited to solving certain mathematical problems that are extremely difficult for classical computers — a key example being "integer factorization" and the "discrete logarithm problem," which happen to form the security foundation of current encryption algorithms such as RSA and ECC. Shor's algorithm, proposed by mathematician Peter Shor in 1994, could theoretically allow a quantum computer to solve these problems within a reasonable amount of time. This is exactly why, once quantum computing technology matures, it will pose a direct threat to the encryption systems widely used across the internet today.


Shor's Algorithm: The Code-Breaking Power of Quantum Computers

In 1994, Peter Shor proposed Shor's algorithm, proving that a quantum computer could theoretically perform prime factorization in polynomial time, dramatically lowering the cost of breaking RSA and other public-key encryption. Factorization problems that would take a supercomputer millions of years to solve could theoretically be completed by a quantum computer in just a few hours.

Besides RSA, other widely used public-key encryption methods based on hard mathematical problems — such as Diffie-Hellman key exchange and Elliptic Curve Cryptography (ECC) — can also be effectively solved by Shor's algorithm, and therefore face the same risk from quantum computers. This means all three major families of public-key algorithms that today's network security relies on could eventually lose their effectiveness.

It's worth noting that symmetric encryption (such as AES) and hash functions (such as SHA-256) are not affected by Shor's algorithm. However, they are affected by another quantum algorithm, Grover's algorithm, which effectively reduces the computational effort required for brute-force attacks to its square root — roughly equivalent to cutting the key length in half. This is why the industry recommends upgrading symmetric encryption to AES-256, in order to maintain an adequate security margin.


Quantum Computers Are Still Under Development

Technology companies such as Google, IBM, and Microsoft, along with governments around the world, continue to invest heavily in quantum error correction technology. Google's Willow processor, unveiled in late 2024, demonstrated significant error-correction capabilities, prompting many researchers to reassess the timeline for achieving fault-tolerant quantum computing.

It's important to emphasize that quantum computing technology is still in its early stages. The number of qubits remains limited, and qubits are highly susceptible to environmental interference and errors. A large-scale, fault-tolerant quantum computer capable of genuinely threatening current public-key cryptography has not yet been built, and there is still no precise consensus on when such a "cryptographically relevant quantum computer" will emerge.

Precisely because all the encrypted data accumulated over the years could become instantly insecure the moment such a quantum computer arrives, forward-looking attack strategies and the early deployment of PQC are both seen as issues that demand attention now — not something to be dealt with only once quantum computers actually mature.


Which Encryption Algorithms Are Affected by Quantum Computers?

Taking into account the combined impact of Shor's algorithm and Grover's algorithm, the quantum risk levels of today's mainstream encryption methods can be summarized as follows:

Encryption MethodQuantum RiskRecommendation
RSAHighPlan migration to PQC
ECCHighPlan migration to PQC
Diffie-HellmanHighPlan migration to PQC
AESLowRecommend adopting AES-256
SHA-256MediumRisk can be reduced by increasing security parameters

"Harvest Now, Decrypt Later"

Every piece of encrypted data transmitted over the internet — whether it's a customer list, a financial report, or internal corporate secrets — may already have been intercepted and stored, simply awaiting the day it can be decrypted.

This quantum-computer-enabled attack strategy is known as "Harvest Now, Decrypt Later" (HNDL). Hackers take advantage of the fact that quantum computers have not yet matured to steal encrypted data with long-term value right now — such as classified government documents, financial transaction records, medical records, and authentication credentials or private keys. Because this data will still hold value and sensitivity ten or even twenty years from now, it's well worth the effort for hackers to act today.

Once they have stolen this encrypted data, hackers store it away long-term, waiting for quantum computing technology to mature and gain sufficient computing power before coming back to decrypt it. This approach is low-cost and requires no technological breakthrough on the attacker's part — hackers are simply betting that future quantum computers will be powerful enough to break encryption algorithms that appear secure today.

The point in time when quantum computers become powerful enough to break current public-key and key-exchange encryption standards is known as "Q-Day" (also called the "quantum apocalypse," or Y2Q, "Year to Quantum"). When Q-Day arrives, the global cybersecurity system could face a catastrophic collapse.

For organizations holding long-term sensitive data, the Q-Day risk deserves special attention, since such data often needs to remain confidential for ten years or more — far longer than the typical validity period of a TLS connection or authentication certificate. In other words, the risk clock doesn't start ticking on Q-Day itself; it starts the moment the data is intercepted and stored.


PQC Standards

The U.S. National Institute of Standards and Technology (NIST) began soliciting candidate algorithms from cryptographers worldwide in 2016. After multiple rounds of elimination and testing, NIST officially published its first set of PQC standards in 2024, comprising three main algorithms: ML-KEM, ML-DSA, and SLH-DSA.

  • ML-KEM:
    A key encapsulation mechanism (KEM) algorithm that replaces RSA or Diffie-Hellman for exchanging keys when establishing a secure channel. It is based on lattice-based cryptography.

  • ML-DSA:
    A digital signature algorithm, also based on lattice-based cryptography, that replaces RSA signatures or ECDSA for verifying data integrity and identity.

  • SLH-DSA:
    An alternative digital signature algorithm based on hash functions, serving as a backup option alongside ML-DSA. Its advantage is a more conservative security proof, though its signatures are larger and slower to compute.

  • FN-DSA:
    Another lattice-based signature algorithm, designed primarily for use cases that require smaller signature sizes, such as IoT devices and bandwidth-constrained environments. This algorithm has not yet been finalized and remains in the standardization process.


Standard NumberAlgorithm NamePrimary Use
FIPS 203ML-KEM (formerly CRYSTALS-Kyber)Key exchange and general encryption
FIPS 204ML-DSA (formerly CRYSTALS-Dilithium)Digital signatures
FIPS 205SLH-DSA (formerly SPHINCS+)Hash-based digital signatures, serving as a backup for ML-DSA
FIPS 206FN-DSA (derived from the FALCON algorithm)Use cases requiring smaller signature sizes

In practice, most current PQC adoption follows a "hybrid" transitional approach — using traditional encryption algorithms together with new PQC algorithms simultaneously. This way, even if one method is broken in the future, the data remains protected by the other, while also reducing the risk posed by any unknown weaknesses that might exist in the newer algorithms. This gradual deployment model has become the practical reference most enterprises use when evaluating their own migration paths.

Companies such as Google Chrome, Cloudflare, and Apple iMessage have already begun implementing hybrid PQC mechanisms in some of their services, primarily to guard against long-term data exposure risks like "Harvest Now, Decrypt Later."


Common Challenges in Enterprise PQC Adoption

Technical specifications are only a small part of PQC migration. In practice, enterprises more often get stuck on the following issues:

  • Larger key and signature sizes:
    The key and signature lengths of most PQC algorithms are noticeably larger than their traditional counterparts. This can affect network protocol packet sizes and certificate chain storage requirements, and requires extra evaluation particularly for devices with limited bandwidth or computing resources, such as embedded systems.

  • Difficulty inventorying cryptographic assets:
    Encryption algorithms are often scattered across network equipment, certificate systems, authentication mechanisms, application libraries, and third-party services. Many enterprises don't even know where they are using RSA or ECC until they conduct a full inventory.

  • Supply chain dependency:
    An enterprise's own PQC adoption progress is often constrained by the level of support provided by the cloud platforms, security appliances, and SaaS vendors it relies on. If a vendor has no clear PQC adoption timeline, the enterprise's migration plan can easily get stuck at this supply-chain bottleneck.

  • Hybrid mode is not the end goal:
    Hybrid encryption is currently the recommended transitional approach, not the final destination. Only after PQC standards have been battle-tested over a longer period, hardware acceleration has matured, and cross-system compatibility has stabilized will organizations gradually move toward pure PQC deployment.


How Can Enterprises Start Applying PQC Now?

Even though it may still be some time before quantum computers mature, organizations holding long-term sensitive data should start paying attention to this issue now. Enterprises are advised to begin planning in the following areas.

  1. Inventory current encryption mechanisms such as RSA, ECC, and TLS, and identify exactly which systems and data flows they are used in.

  2. Prioritize risk based on how long data must remain confidential and how sensitive it is, focusing first on data categories that require long-term confidentiality and would cause major impact if leaked.

  3. Assess whether existing equipment, systems, and vendors already support or plan to support PQC, and incorporate PQC compatibility into future procurement and contract requirements.

  4. Develop a phased migration timeline, starting with hybrid PQC trials on internal systems and non-critical applications before gradually expanding to external-facing services.

If your organization is planning a cloud infrastructure upgrade or evaluating a PQC adoption strategy, it's advisable to inventory existing encryption mechanisms early and choose a cloud platform that already supports post-quantum cryptography. SkyCloud already supports NIST-compliant post-quantum encryption technology and can help enterprises progressively complete their cryptographic asset inventory, migration planning, and deployment — reducing cybersecurity risk in the coming quantum era.


Frequently Asked Questions (FAQ)

Q: Can quantum computers break today's encryption systems? Is this risk already present now?▾A: Quantum computing technology is still in its early stages, and no large-scale, fault-tolerant quantum computer capable of breaking mainstream algorithms like RSA and ECC exists yet. However, the risk doesn't begin the day quantum computers mature — it begins the moment data is intercepted and stored by hackers. This is exactly why the "Harvest Now, Decrypt Later" strategy causes the risk to materialize ahead of time.
Q: When will Q-Day arrive? Is there a definite timeline?▾A: There is currently no precise, universally agreed-upon answer as to when Q-Day will arrive. Estimates from experts range from a few years to several decades, and the timeline will shift as breakthroughs in quantum error correction occur. Precisely because this timing is unpredictable, and because a full migration of encryption systems can easily take several years, enterprises are advised to deploy PQC ahead of time rather than waiting for a confirmed date to act.
Q: Do enterprises need to switch all their systems to PQC immediately?▾A: No, an immediate full replacement isn't necessary. The industry generally recommends a "hybrid" transitional approach — running traditional encryption algorithms alongside PQC algorithms — while prioritizing the inventory and migration of data and systems with long confidentiality requirements or severe consequences if leaked, then gradually expanding scope rather than migrating everything at once.
Q: Do encryption methods like AES and SHA-256 also need to be replaced?▾A: A full replacement isn't necessary, but upgrading security parameters is recommended. Symmetric encryption and hash functions like AES and SHA-256 aren't broken by Shor's algorithm, but they are affected by Grover's algorithm, which roughly halves the effective key length in terms of brute-force difficulty. This is why the industry recommends upgrading AES to AES-256 to maintain an adequate security margin.
Q: Will adopting PQC affect website or system performance?▾A: PQC algorithms typically have larger key and signature sizes than traditional algorithms, which can have some impact on bandwidth, packet size, or devices with limited computing resources, such as IoT devices. The actual impact varies depending on the algorithm and use case, so enterprises are advised to conduct compatibility and performance testing before adoption.
Q: Which of SkyCloud's services currently support PQC?▾A: SkyCloud has already implemented PQC protection on the origin-pull connections of its SkyEdge (CDN) platform, and continues to expand its PQC protection coverage to help customers get ahead of the cybersecurity challenges of the quantum era.

Previous:SkyCloud Invited to Join TPEx “Plus Startup Stars” Pavilion at InnoVEX 2026

Next:2025 DDoS Attack Statistics: 12 Months of Platform Data from Taiwan (Peak 2.4 Tbps)

SkyCloud Offers Free Trials

Activate When Ready!

check-black Experience fast, secure, and reliable service.

check-blackTest first, decide later. Zero risk.

We invite you to experience our superior performance firsthand. Discover SkyCloud's speed, reliability, and flexibility. Test it out, and activate only when you are satisfied.

background imagebackground image