The Quantum Threat That Is Making Today's Encryption Obsolete
The encryption systems that protect the majority of internet communications, financial transactions, and government communications rely on mathematical problems whose computational difficulty on classical computers provides the security that these applications require. RSA encryption and elliptic curve cryptography, the dominant public key encryption systems in commercial use, derive their security from the difficulty of factoring large integers and computing discrete logarithms respectively on classical computers, where these computations require time proportional to exponential functions of the key size. A sufficiently powerful quantum computer running Shor's algorithm could solve these mathematical problems in polynomial time, rendering RSA and elliptic curve cryptography insecure without the need to brute-force the key space. The threat is not theoretical: IBM, Google, and a growing number of quantum computing companies have demonstrated quantum processors of increasing capability, and while the fault-tolerant quantum computer of sufficient scale to run Shor's algorithm against practical RSA key sizes does not yet exist, the cryptographic community's consensus is that the transition timeline to post-quantum cryptography must be measured in years rather than decades given the uncertainty about when such a computer will be achieved.
The harvest now, decrypt later attack strategy adds urgency to post-quantum cryptography deployment that the future arrival of capable quantum computers alone would not create. Adversaries with access to encrypted internet traffic can record and store encrypted data today, with the intention of decrypting it retrospectively once a capable quantum computer becomes available. The data whose confidentiality must extend beyond the estimated decade-scale timeline to capable quantum computers, including classified government communications, long-term commercial contracts, personal health records, and financial transaction histories, is already at risk from harvest-now-decrypt-later if it is currently protected by RSA or elliptic curve cryptography. The commercial and government imperative to deploy post-quantum encryption before the quantum threat materialises rather than after is the market driver that is accelerating post-quantum cryptography adoption.
NIST Standardisation and the ML-KEM Benchmark
The National Institute of Standards and Technology completed its post-quantum cryptography standardisation process in 2024, publishing three post-quantum cryptographic standards whose underlying mathematical security rests on problems in structured lattice mathematics. The CRYSTALS-Kyber algorithm, standardised as ML-KEM under FIPS 203, is the primary post-quantum key encapsulation mechanism whose lattice-based hardness problem provides security against both classical and quantum computers. The learning with errors problem that ML-KEM's security relies on, whose hardness derives from the difficulty of distinguishing a vector of approximate inner products from a random vector in high-dimensional lattice space, has no known efficient quantum algorithm, providing the post-quantum security that RSA and elliptic curve cryptography cannot offer. The NIST standardisation provides the technical benchmark and the regulatory authority that government agencies and commercial organisations need to begin mandatory post-quantum cryptography migration, and the US federal government's directive requiring post-quantum cryptography adoption across federal information systems has created the compliance deadline that is accelerating migration planning.
Apple's deployment of post-quantum cryptography in iMessage through its PQ3 protocol, which incorporates Kyber lattice-based key exchange into the iMessage encrypted messaging protocol, represents the highest-profile consumer technology deployment of lattice-based cryptography and has demonstrated that post-quantum cryptography can be deployed in production at scale in a consumer application without meaningful performance degradation. Apple's PQ3 implementation, which combines the new lattice-based key exchange with continued use of elliptic curve cryptography for a hybrid security approach, achieves quantum resistance for iMessage communications while maintaining the operational performance that users expect. Google's announced intention to include lattice-based cryptography in Android alongside elliptic curve cryptography creates the mobile platform deployment that follows Apple's iOS lead, suggesting that post-quantum cryptography will be standard infrastructure across the major mobile platforms within a few years.
Enterprise Migration and the Commercial Market
The commercial market for post-quantum cryptography infrastructure is emerging from the government compliance mandate and extending into the enterprise market whose own data protection obligations create the adoption pressure that follows the government sector. Financial services organisations whose transaction data and customer financial records require long-term confidentiality protection are among the most commercially motivated early adopters of post-quantum cryptography beyond the government sector. Hardware security module manufacturers, virtual private network providers, certificate authorities, and the public key infrastructure software vendors whose products implement the cryptographic algorithms that enterprise security infrastructure depends on are the commercial beneficiaries of the post-quantum migration whose technology replacement cycle creates the enterprise IT spending that the cryptography infrastructure market captures.
Top 10 Companies in Post-Quantum and Lattice-Based Cryptography Globally
- IBM: US technology company whose IBM Quantum Safe cryptography portfolio implements NIST post-quantum standards including ML-KEM and whose quantum computing research creates the dual position as both quantum threat developer and post-quantum solution provider; its z16 mainframe with quantum-safe cryptography accelerators and its consulting services for post-quantum migration create the enterprise post-quantum infrastructure that financial services and government organisations are adopting.
- PQShield: UK post-quantum cryptography company whose hardware and software implementations of ML-KEM and other post-quantum standards are deployed in semiconductor chips, hardware security modules, and enterprise security software; its NIST standardisation process contribution and its semiconductor customer integrations create the IP licensing and product business that post-quantum algorithm deployment in hardware requires.
- Quantinuum: UK-US quantum computing and quantum security company whose Quantum Origin quantum random number generation and its post-quantum cryptography tools create the quantum security product portfolio; its unique position as both a quantum computer developer and a quantum security provider creates the insider knowledge of quantum threat capabilities that its security product development leverages.
- DigiCert: US certificate authority and PKI company with post-quantum certificate and digital signature infrastructure; its role as the CA issuing the digital certificates that TLS encryption depends on creates the central position in the PKI migration to post-quantum algorithms that the entire internet's encrypted communications infrastructure must complete.
- Thales: French defence and technology company with hardware security modules and encryption products incorporating post-quantum algorithms; its Luna HSM with post-quantum support and its government cryptography relationships create the post-quantum infrastructure for the classified and sensitive government communications that are highest priority for post-quantum migration.
- Cisco: US networking company with post-quantum VPN and network security products incorporating ML-KEM; its enterprise network infrastructure position and its post-quantum upgrade path for its existing VPN and firewall customer base create the commercial post-quantum migration pathway for the enterprise network security market.
- SandboxAQ: US AI and quantum technology company spun out of Alphabet with post-quantum cryptography discovery and migration tools; its AQtive Guard platform that identifies RSA and elliptic curve cryptography usage across enterprise systems and generates migration roadmaps creates the post-quantum readiness assessment and migration management capability that large enterprises use to plan their cryptographic infrastructure transition.
- Cloudflare: US internet infrastructure company that has implemented post-quantum key exchange in its CDN and zero-trust security products; its deployment of post-quantum cryptography at internet scale across its network of data centres and its open-source post-quantum library contributions create the practical infrastructure deployment experience that informs the enterprise post-quantum migration guidance that the industry needs.
- ISARA Corporation: Canadian post-quantum cryptography company with quantum-safe security solutions for enterprise and government; its post-quantum certificate authority and its embedded device cryptography update capability for IoT and industrial control systems create the post-quantum migration pathway for the long-lived device categories whose ten to twenty year operational lifetimes require quantum-safe cryptography protection today.
- Post-Quantum: UK post-quantum security company with hybrid post-quantum VPN and identity solutions; its NATO secure communications deployment and its government customer relationships create the highest-security-clearance post-quantum deployment reference that enterprise security procurement uses to validate post-quantum technology maturity.