What is quantum cryptography?
In everyday speech the term covers the whole intersection of quantum computers and encryption, but it spans two entirely different things, and the difference matters when you need to act:
- Post-quantum cryptography (PQC): New mathematical algorithms that run on completely ordinary computers but are designed to withstand attacks from quantum computers. These are the ones your business needs to migrate to.
- Quantum key distribution (QKD): Actual quantum cryptography, where keys are exchanged via quantum states (typically photons in fibre), and the laws of physics reveal any eavesdropping. Fascinating, but it requires special equipment and is in practice a niche technology for particular connections, not something SMBs should invest in.
The threat: Shor's algorithm
The background is mathematician Peter Shor's algorithm from 1994: On a sufficiently large quantum computer it can efficiently factor large numbers and solve the related problems that RSA and elliptic curves are built on. With that, the foundation under almost all asymmetric encryption falls: TLS, VPN, digital signatures and key exchange. No one knows when such a machine will exist, but the harvest now, decrypt later attack means data with a long confidentiality lifetime is at risk already today. Symmetric encryption such as AES-256 is far less affected and is still considered secure.
The NIST standards: PQC is ready to use
After a years-long open competition, NIST published the first finished standards in August 2024: ML-KEM (FIPS 203, formerly Kyber) for key exchange, and ML-DSA (FIPS 204) and SLH-DSA (FIPS 205) for signatures. In 2025, HQC was additionally selected as a backup algorithm for key exchange, built on different mathematics than ML-KEM. The rollout is in full swing: major browsers and cloud services already run hybrid key exchange, where classical ECDH is combined with ML-KEM, so the connection stays secure even if one of the methods later falls.
The EU roadmap: 2030 is the new deadline
The EU member states adopted a joint transition roadmap in 2025: national strategies and first steps by the end of 2026, critical infrastructure migrated to PQC by 2030, and all remaining systems by 2035. If you are covered by NIS2, a cryptographic inventory and a migration plan should therefore already be on the list: Which certificates, VPNs and integrations use vulnerable cryptography, which data lives longest, and which suppliers have a PQC plan?
How MI Support IT can help
We make the quantum question concrete: mapping your cryptography and certificates via PKI management, prioritising by risk and data lifetime, and a realistic migration plan as part of your IT security. Contact us if you want to know how far you are from the 2030 deadline.