Start with an inventory of every place your systems use RSA, Diffie-Hellman or elliptic-curve cryptography. Rank each by how long the protected data must stay secret. Make your code crypto-agile, pilot hybrid key exchange (classical + ML-KEM), then roll out the NIST standards finalized in August 2024: ML-KEM (FIPS 203), ML-DSA (FIPS 204) and SLH-DSA (FIPS 205).
Why this matters before quantum computers exist
A large, fault-tolerant quantum computer running Shor's algorithm would break RSA and elliptic-curve cryptography. Nobody can say exactly when that arrives, but attackers can record encrypted traffic today and decrypt it later — the 'harvest now, decrypt later' threat.
So the question is not 'when will quantum computers arrive?' It is 'how long must this data stay secret, and how long will our migration take?' If the sum of those two numbers is longer than the time until a capable quantum computer exists, you are already late.
The standards you are migrating to
| Standard | Algorithm | Replaces | Use |
|---|---|---|---|
| FIPS 203 | ML-KEM (Kyber) | RSA / ECDH key exchange | Establishing shared keys, TLS |
| FIPS 204 | ML-DSA (Dilithium) | RSA / ECDSA signatures | General-purpose digital signatures |
| FIPS 205 | SLH-DSA (SPHINCS+) | RSA / ECDSA signatures | Conservative, hash-based backup signatures |
| Selected 2025 | HQC | — | Backup key-establishment algorithm, standard in progress |
A five-step migration plan
- 1. Inventory — Build a cryptographic bill of materials: libraries, protocols, certificates, hardware security modules, and vendor services. Most teams find cryptography in places nobody documented.
- 2. Prioritize — Rank systems by data lifetime and exposure. Long-lived sensitive data sent over public networks goes first.
- 3. Crypto-agility — Wrap cryptographic calls behind interfaces so an algorithm change is a configuration change, not a rewrite.
- 4. Hybrid pilot — Run classical and post-quantum key exchange together (e.g. X25519 + ML-KEM) in one service. Measure handshake size, latency and compatibility.
- 5. Roll out and monitor — Expand service by service, update certificates and signing, and add PQC requirements to vendor contracts.
Common mistakes
- Treating it as a certificate swap. Key exchange, signatures, firmware signing and stored data all need separate plans.
- Ignoring larger key and signature sizes. Post-quantum artifacts are bigger and can break packet limits, databases and embedded devices.
- Skipping vendors. Your exposure includes every SaaS and API that handles your data.
- Waiting for a deadline. Government timelines (such as NSA's CNSA 2.0) already point to the early 2030s for full transition.
Common questions
When will quantum computers break RSA?
No one knows precisely. Estimates vary widely, which is why security agencies recommend migrating now rather than waiting for a specific date.
Is AES broken by quantum computers?
Symmetric encryption like AES is much less affected. Using 256-bit keys is generally considered sufficient. The urgent problem is public-key cryptography.
What is hybrid post-quantum cryptography?
Combining a classical algorithm and a post-quantum one so the connection stays secure as long as either remains unbroken. It is the recommended transition approach for key exchange.
How long does a migration take?
It depends on the size of the estate. Inventory and a pilot can happen in weeks; full rollout across a large organization typically takes years, which is why starting early matters.
Have a specific situation? Talk to an engineer at NextGen — we do free 30-minute scoping calls with a senior developer, not a salesperson.

