Skip to content
QubitWire
SECURITY · SECURITY

The Web Is Quietly Changing Its Locks Before Quantum Computers Arrive

Post-quantum cryptography is moving from standards into browsers, cloud services and migration plans. Most people will never see the change - which is exactly the idea.

Sources checked Published Sources checked
My reading list
Conceptual browser window and padlock beside the headline about changing the web’s locks.
A browser and stylized padlock represent the transition to post-quantum web security. Original conceptual illustration, not an actual browser interface or cryptographic design.Illustration: QubitWire · Original QubitWire work

The web's locks are being replaced while the doors remain open. NIST's first finalized post-quantum standards gave developers common building blocks for encryption and digital signatures. Now the slower work is underway: fitting those tools into browsers, cloud endpoints, private networks, certificates, devices and software that cannot all be upgraded at once.[1]

Post-quantum cryptography does not require a quantum computer. It is new mathematics designed to run on ordinary systems while resisting attacks from both classical machines and a future cryptographically relevant quantum computer. NIST's principal standards include ML-KEM for key establishment and ML-DSA and SLH-DSA for signatures.[1]

Timeline showing NIST standards in 2024 and NCSC planning, priority and completion milestones in 2028, 2031 and 2035.
NIST’s first three standards arrived in 2024. The U.K. NCSC targets planning by 2028, priority migration by 2031 and completion by 2035; these are migration goals, not predictions of a quantum attack.Illustration: QubitWire · Original QubitWire work

Deployment is already becoming visible in infrastructure rather than consumer settings. Google Cloud’s August roadmap says its API endpoints now offer hybrid quantum-safe key exchange, while other upgrades remain scheduled. Chrome and Cloudflare are experimenting with Merkle Tree Certificates, which use compact proofs to reduce the data sent when a browser checks a website’s identity.[2][5]

The urgency is not a claim that today's quantum machines can suddenly read your bank account. The concern is that encrypted information stolen now may retain value long enough to be decrypted later. Migration itself also takes years. The U.K. NCSC asks large organizations to complete discovery and planning by 2028, highest-priority moves by 2031 and broad migration by 2035. A September G7 call to action similarly pushed governments and organizations to begin.[2][3][4]

A browser and cloud service connected by arrows labeled classical exchange and post-quantum exchange; a conceptual overview, not a protocol trace.
Conceptual overview of combining classical and post-quantum key establishment. The arrows are not a literal protocol sequence and do not depict sending secret keys over the network.Illustration: QubitWire · Original QubitWire work

For ordinary users, the best outcome is boring: updated software, slightly different handshakes and no dramatic moment when the old internet switches off. For organizations, the first task is less glamorous and more urgent - find every place cryptography is hiding before it becomes the last lock no one remembered to change.[4]

READ NEXT

Continue exploring

All Security stories
  1. Related reading

    Your Encrypted Data Could Be Stolen Now—and Read Years Later

    The quantum security problem is not just when a powerful computer arrives. It is how long the information you send today needs to stay secret.

    Sources checked
  2. Related reading

    Can a Quantum Computer Solve a Problem It Cannot See?

    Blind quantum computing aims to hide your instructions and answer from the machine doing the work. A real experiment shows why that is more than a thought experiment.

    Sources checked
THE QUANTUM BRIEFING

A clearer signal.
Straight to your inbox.

A little perspective on a fast-moving field.

Read a briefing preview →

Selected quantum coverage, once a week. Read a preview before joining.