惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Stack Overflow Blog
Stack Overflow Blog
D
Darknet – Hacking Tools, Hacker News & Cyber Security
爱范儿
爱范儿
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
有赞技术团队
有赞技术团队
罗磊的独立博客
博客园 - 三生石上(FineUI控件)
小众软件
小众软件
L
LINUX DO - 最新话题
T
Troy Hunt's Blog
博客园_首页
量子位
Jina AI
Jina AI
S
SegmentFault 最新的问题
IT之家
IT之家
Hacker News - Newest:
Hacker News - Newest: "LLM"
大猫的无限游戏
大猫的无限游戏
N
News | PayPal Newsroom
P
Proofpoint News Feed
Cyberwarzone
Cyberwarzone
S
Securelist
Google Online Security Blog
Google Online Security Blog
P
Privacy International News Feed
博客园 - Franky
美团技术团队
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
NISL@THU
NISL@THU
C
Cisco Blogs
V
Vulnerabilities – Threatpost
腾讯CDC
The Hacker News
The Hacker News
K
Kaspersky official blog
C
Cyber Attacks, Cyber Crime and Cyber Security
雷峰网
雷峰网
CTFtime.org: upcoming CTF events
CTFtime.org: upcoming CTF events
Security Archives - TechRepublic
Security Archives - TechRepublic
A
About on SuperTechFans
Webroot Blog
Webroot Blog
The Register - Security
The Register - Security
Scott Helme
Scott Helme
B
Blog
Security Latest
Security Latest
Last Week in AI
Last Week in AI
Google DeepMind News
Google DeepMind News
W
WeLiveSecurity
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
T
Tenable Blog
Blog — PlanetScale
Blog — PlanetScale
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
S
Schneier on Security

PostQuantum – Quantum Computing, Quantum Security, PQC

Lightning Network's Quantum Problem Ethereum's Five Quantum Vulnerabilities Bitcoin's Quantum Vulnerability — Anatomy How Close Is the Quantum Threat? Resource Estimates The Quantum Threat to Cryptocurrencies: What's Real Lattice-Based PQC "Limitations" Paper — A Reality Check China's Hanyuan-2 Dual-Core Quantum Computer Pick One Layer First for Your Post-Quantum Migration Cisco Quantum Switch: Room-Temperature Qubit Routing IonQ Claims Q-Day by 2029 — Here's What They Actually Said Project Eleven's 110-Page Quantum Blockchains Report QuantWare Raises $178M Series B Q-CTRL Claims Practical Quantum Advantage Quantum Computing Simulates 12,635-Atom Protein How Quantum Snake Oil Vendors Respond to Hard Questions Simulated Quantum Entanglement | PostQuantum.com Quantum Snake Oil: Guide to Misleading Quantum Terms Quantum AI Trading — Quantum Snake Oil Dictionary Quantum-Proof — Quantum Snake Oil Dictionary Quantum-Grade Encryption — Quantum Snake Oil Dictionary Quantum-Safe Certified — Quantum Snake Oil Dictionary Military-Grade Quantum Encryption | PostQuantum.com What Is a QBOM? Quantum Bill of Materials vs CBOM Explained Quantum-Inspired Encryption — Quantum Snake Oil Dictionary What Is Trust Now, Forge Later (TNFL)? Quantum Blockchain — Quantum Snake Oil Dictionary Quantum Financial System (QFS) | PostQuantum.com What Is QKD (Quantum Key Distribution)? What Is Quantum Error Correction (QEC)? Unhackable Quantum Encryption | PostQuantum.com Unconditionally Secure — Quantum Snake Oil Dictionary Perfect Secrecy — Quantum Snake Oil Dictionary Information-Theoretic Security | PostQuantum.com Quantum Encryption / Quantum Cryptography Quantum-Enhanced — Quantum Snake Oil Dictionary Quantum-Safe vs Quantum-Resistant vs Post-Quantum Anatomy of Quantum Denial: Bitcoin's Example What Is a Logical Qubit? The Metric That Actually Matters What Is a CRQC? Quantum Computer That Breaks Encryption What Is Q-Day? When Quantum Computers Break Encryption What Is Harvest Now, Decrypt Later (HNDL)? What Is Grover's Algorithm? What Is Shor's Algorithm? The Quantum Threat Explained What Is Quantum Safe? What the Label Means for CISOs What Is Quantum Computing Security? What Is Quantum Cyber Security? What Is Quantum Cryptography? QKD, PQC, and related? Quantum Security: A Complete Guide for Security Leaders What Is Post-Quantum Cryptography (PQC)? Crypto-Agility Is an Architecture Problem, Not a Library Swap IBM Quantum Advantage 2026: Heron + Fugaku Analyzed Aaronson Warns: CRQC by 2029 Is Plausible U.S. Quantum Policy: NQI Reauthorization and PQC Bills The Narrow Advantage: Why Quantum Computing Will Transform Five Industries and Disappoint Twenty The Error Correction Revolution Rewriting Quantum Timelines The Signature Supply Chain: How Deep Does Digital Trust Go? Quantum Chemistry's Honest Ledger: What the Resource Estimates Actually Say About Drug Discovery, Catalysis, and Materials Design Why Quantum Won't Save Wall Street (Yet): An Honest Assessment of Quantum Computing in Finance PQC Standards Fragmentation Quantum Sovereignty and the Utility Trap The Decoder Bottleneck: The CRQC Challenge Nobody Is Talking About IonQ Publishes Complete Fault-Tolerant Blueprint for Trapped Ions — The Walking Cat Architecture Quantum Computing by 2033: Which Industries Win, Which Wait, and Why Nature Reviews Publishes the Definitive CMOS–Spin Qubit Compatibility Assessment IonQ Photonic Interconnect: First Networked Commercial Quantum Computers QuEra Achieves 2:1 Physical-to-Logical Qubit Ratio With Ultra-High-Rate qLDPC Codes Grover's Algorithm vs AES - Why "Ignore It" Is Almost Right McKinsey Quantum Monitor 2026: Tipping Point? Meta PQC Migration Playbook: Lessons for CISOs NVIDIA Ising: Open AI Models for Quantum Calibration and Error Correction Harvard's Cascade Neural Decoder PQC Signature Migration Before Encryption Architecture Matters as Much as the Algorithm: Q-CTRL's Heterogeneous Quantum Computer Design Cuts RSA-2048 to 190k-381k Qubits China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Sensing Ecosystem: From Deep-Sea Diamonds to Drone-Mounted Submarine Hunters China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Anthropic's Mythos Preview and the End of a Twenty-Year Cybersecurity Equilibrium China's Quantum Networking and QKD — World's Most Ambitious Quantum Communication Program Cloudflare Joins Google: Two Internet Giants Now Say 2029 for Post-Quantum Migration China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging China's Quantum Computing Hardware: The Core Capability the West Keeps Misjudging QuiX Quantum Achieves First Below-Threshold Error Mitigation in Photonic Quantum Computing China's Quantum Talent Ecosystem: Building a Superpower's Workforce Quantum Threat Timeline Report 2025: Record Predictions, But Can the Survey Keep Up? China's Quantum Talent Ecosystem: Building a Superpower's Workforce China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower China's Hefei National Laboratory: The Nerve Center of a Quantum Superpower Gauge Theory Meets Quantum Computing China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority China's 15th Five-Year Plan Makes Quantum an Industrial Imperative — Not Just a Research Priority QuantumShield360 AI Achieves World's First Complete Post-Quantum Cryptography Migration — Full Quantum Resilience Across All Enterprise Systems 10,000 Qubits to Run Shor's Algorithm Google Quantum AI Achieves 10x Reduction in Resources to Break Bitcoin's Cryptography The U.S. Intelligence Community Just Put Quantum on Equal Footing with AI. And Expanded the Threat Definition Google Just Drew a Line in the Sand: PQC Migration by 2029 Silicon Crosses the Logical Threshold: First Universal Logical Operations Demonstrated in a Silicon Quantum Processor The 1,000-Qubit Ceiling That Probably Isn't Science Confirms What Large Corporate Survivors Already Knew - Organizational Bullshit Makes You Worse at Your Job A New Algorithm Shrinks the Quantum Attack Surface for ECC Quantinuum Squeezes 94 Logical Qubits from 98 Physical — But What Does It Actually Mean?
What Is PQC Migration? The Largest Cryptographic Overhaul
Marin Ivezic · 2026-05-05 · via PostQuantum – Quantum Computing, Quantum Security, PQC

This is part of the Quantum Security Reference Deep Dive series. For the full landscape overview, see the capstone article on quantum security.

Introduction

PQC migration is the process of replacing the classical public-key cryptographic algorithms (RSA, ECC, Diffie-Hellman) embedded throughout an organization’s infrastructure with the post-quantum cryptographic (PQC) standards finalized by NIST. It touches every system, protocol, certificate, key, and vendor relationship that relies on public-key cryptography. I have described it as the largest, most complex cryptographic overhaul in IT history, and the experience of organizations that have begun confirms that assessment.

Why It Takes Years

PQC migration is not a software patch. Replacing a cryptographic algorithm changes key sizes, signature sizes, handshake latencies, certificate chain structures, and protocol behaviors. These changes ripple through every layer of the technology stack.

A large enterprise program spans upwards of 120,000 discrete tasks across network infrastructure (TLS termination, VPN gateways, load balancers), application code (cryptographic library calls, key handling, signature verification), PKI hierarchies (root certificates, intermediates, leaf certificates, certificate revocation), key management systems, hardware security modules, embedded devices and IoT, operational technology, and vendor-supplied systems where you depend on someone else’s migration timeline.

The SHA-1 to SHA-2 migration offers a useful precedent. That transition involved replacing a single hash algorithm across the PKI ecosystem, and it took the industry over a decade to complete. PQC migration is broader in scope (multiple algorithm families, larger parameter changes, more severe performance impacts) and operates under harder deadlines.

NIST estimates that a large federal agency migration takes three to five years once fully resourced. Enterprise estates with legacy complexity, global operations, and diverse vendor dependencies should plan for the upper end of that range.

The Phases

Migration follows a structured progression. The Applied Quantum PQC Migration Framework formalizes this into a methodology; here is the essential sequence.

Discovery comes first. A cryptographic inventory identifies every instance of quantum-vulnerable cryptography across the organization. The output should be a Cryptographic Bill of Materials (CBOM) that maps algorithms to systems, protocols, vendors, and data flows. Without this inventory, prioritization is guesswork. If a comprehensive inventory is not immediately feasible, risk-driven strategies allow you to begin with the highest-exposure systems.

Risk assessment follows. Not all systems carry equal urgency. The HNDL threat makes systems handling long-lived confidential data the highest priority. The TNFL threat makes signature infrastructure (code signing, certificate issuance, legal document signing) a close second. Mosca’s inequality provides the mathematical framework for determining which systems are already past their safe migration window.

Planning translates the inventory and risk assessment into a sequenced migration roadmap. My first-year planning guide covers how to scope, resource, and govern the program. Key decisions at this stage include whether to deploy hybrid cryptography (running classical and PQC algorithms in parallel) or migrate directly to PQC-only configurations.

Execution is the longest phase. It involves deploying NIST-standardized algorithms across each system in the prioritized sequence, testing for performance impacts (PQC algorithms use larger keys and signatures that affect network protocols and bandwidth-constrained systems), updating vendor-supplied systems as PQC-ready versions become available, and validating that migrated systems interoperate correctly.

Ongoing management is permanent. Crypto-agility ensures you can adapt as PQC standards evolve, new algorithms are standardized, and potential vulnerabilities emerge. Migration is not a one-time event; it is the beginning of continuous cryptographic lifecycle management.

The Deadlines

The migration timeline is not optional for organizations in regulated sectors. NIST’s draft IR 8547 deprecates RSA, ECDSA, and Diffie-Hellman for federal systems by 2030 and disallows them by 2035. NSA’s CNSA 2.0 requires quantum-resistant algorithms for new National Security System acquisitions by January 2027. In Europe, NIS2 and DORA create parallel obligations.

As I have argued throughout PostQuantum.com, these deadlines are already set. Organizations starting in 2026 are on schedule. Organizations starting in 2028 will be compressed. Waiting until 2030 means missing the first hard deadlines entirely.

Where to Start

The Applied Quantum PQC Migration Framework provides the structured, open-source methodology. My practical steps guide maps the first concrete actions for cybersecurity teams. The PQC Readiness Self-Assessment Scorecard tells you where you stand today. And for a comprehensive treatment of organizational readiness strategy, my forthcoming book Quantum Ready covers the full picture.

Go Deeper

Infrastructure Challenges of PQC — what larger keys mean for real systems

Quantum Readiness / PQC Migration — why this is the largest cryptographic overhaul ever

120,000 Tasks: Why PQC Migration Is Enormous — full program plan breakdown

Planning the First Year — scoping and governance

Practical Steps to Quantum Readiness — where to start

Cryptographic Inventory — the foundation of migration

PQC Challenges — what makes migration difficult

Quantum Upside & Quantum Risk - Handled

My company - Applied Quantum - helps governments, enterprises, and investors prepare for both the upside and the risk of quantum technologies. We deliver concise board and investor briefings; demystify quantum computing, sensing, and communications; craft national and corporate strategies to capture advantage; and turn plans into delivery. We help you mitigate the quantum risk by executing crypto‑inventory, crypto‑agility implementation, PQC migration, and broader defenses against the quantum threat. We run vendor due diligence, proof‑of‑value pilots, standards and policy alignment, workforce training, and procurement support, then oversee implementation across your organization. Contact me if you want help.

Talk to me Contact Applied Quantum