IETF Publishes Hybrid ML-KEM Key Agreement for TLS 1.3
RFC 10024 specifies three combinations of ML-KEM and elliptic-curve key agreement at Proposed Standard maturity.
The migration of today’s systems to quantum-resistant cryptography.
Post-quantum cryptography runs on conventional computers and is designed to resist both classical and quantum attacks. It is distinct from quantum key distribution, which uses physical quantum signals, and from quantum random-number generation.
Migration is a systems problem as well as an algorithm choice. Organizations need to identify where cryptography is used, check interoperability and update products as implementations and guidance evolve. Standards alignment does not automatically certify a particular product.
NIST post-quantum cryptography project ↗RFC 10024 specifies three combinations of ML-KEM and elliptic-curve key agreement at Proposed Standard maturity.
RFC 9980 adds composite encryption and signatures, plus standalone hash-based signatures, to the OpenPGP protocol.
High-value and high-impact federal systems receive 2030 key-establishment and 2031 digital-signature migration deadlines.
Supplies equipment for distributing cryptographic keys and components for generating randomness. ID Quantique operates as an IonQ subsidiary following the May 2025 controlling-stake acquisition.
Research & evidence →Provides cryptographic building blocks that developers integrate into applications and devices to prepare for quantum-computer attacks. PQC runs on conventional computing hardware and does not require a quantum network.
Research & evidence →QuProtect discovers the cryptography used by network connections, manages algorithm changes and produces a cryptographic inventory. It applies post-quantum algorithms in conventional software.
Research & evidence →post-quantum security; AI-driven simulation; quantum sensing
Research & evidence →Selected organizations relevant to this topic. Inclusion is not a ranking.
A computer scientist and a physicist unpack Shor’s factoring algorithm and why sufficiently capable quantum computers would threaten some public-key encryption.
Watch the original video →IBM Technology's Jeff Crume introduces Q-Day: the future threat powerful quantum computers could pose to today's encryption. His security briefing connects Shor's algorithm with the need to prepare for post-quantum cryptography, giving viewers a practical reason to care about quantum computing beyond the laboratory.
Watch the original video →In this 2018 Royal Institution discussion, Artur Ekert and Harry Buhrman join Philip Ball to unpack quantum computing, cryptography and the limits behind the promises.
Watch the original video →