Post-quantum cryptography explained simply

What is post-quantum cryptography? ML-KEM, ML-DSA and hybrid key exchange explained simply, where you already use them, and the 2029 to 2035 migration timeline.

A capybara locksmith fits a new lock with an intricate lattice-grid pattern onto an old wooden door, right beside the old round lock it is replacing, with an open toolbox on the floor.
On this page

Post-quantum cryptography is a new set of encryption and signature algorithms that run on ordinary computers and phones but are designed to resist attacks from future quantum computers. It replaces the public-key cryptography (RSA and elliptic curves) that a large quantum computer could break. NIST published the first standards in August 2024, and if your browser is up to date, you are probably using one already.

Here is post-quantum cryptography explained without equations: what the new algorithms do, the idea behind the math, why they are deployed in "hybrid" pairs, where you already use them, and what still has to change.

What is post-quantum cryptography?

Most internet security rests on two kinds of cryptography. Symmetric cryptography, such as AES, locks and unlocks data with one shared secret key. Public-key cryptography, such as RSA and elliptic curves, uses a pair of keys: a public one you can hand to anyone and a private one you keep. Public-key methods let two strangers agree on a secret over an open network and let anyone check a digital signature.

A large quantum computer running Shor's algorithm would break today's public-key methods, while symmetric encryption would only need a big enough key. Can quantum computers crack passwords and encryption? explains why in detail. Post-quantum cryptography (often shortened to PQC, and also called quantum-safe or quantum-resistant cryptography) is the replacement for the public-key part.

Key encapsulation mechanism (KEM)
A way for two parties to end up with the same secret key. One side publishes a public key; the other uses it to "wrap" a fresh random secret and sends the wrapped version back; only the holder of the private key can unwrap it. ML-KEM works this way. Once both sides share the secret, fast symmetric encryption like AES takes over.

Post-quantum is not quantum cryptography

The names are easy to confuse. Quantum key distribution (QKD) uses physics, typically single particles of light sent over dedicated fiber or satellite links, to share keys. It needs special hardware and does not by itself prove who is on the other end. The U.S. NSA does not recommend QKD for national security systems and considers post-quantum cryptography more cost-effective and easier to maintain.

Post-quantum cryptography needs no quantum anything. It is software, and it runs on the phone or laptop you are reading this on.

How NIST chose the new standards

The U.S. National Institute of Standards and Technology (NIST) ran an open, worldwide selection process, much as it did for AES in the late 1990s. It called for proposals in late 2016 and in December 2017 accepted 69 complete submissions from teams around the world. Over the following years, cryptographers publicly attacked all of them.

Some fell, which is exactly what the process is for. In 2022 the signature scheme Rainbow was broken in about a weekend on a laptop, and the key exchange SIKE was broken on a single processor core, first in about an hour and, after refinements, in about ten minutes. Both attacks used ordinary computers, no quantum computer at all. Better to find that out before a standard ships than after.

On August 13, 2024, NIST published the first three standards:

StandardNameJobBuilt onStatus (September 2026)
FIPS 203ML-KEM (from CRYSTALS-Kyber)Agreeing on keysLatticesFinal, August 2024
FIPS 204ML-DSA (from CRYSTALS-Dilithium)General-purpose signaturesLatticesFinal, August 2024
FIPS 205SLH-DSA (from SPHINCS+)Conservative backup signaturesHash functions onlyFinal, August 2024
FIPS 206FN-DSA (from FALCON)Compact signaturesLatticesIn development
Not yet numberedHQCBackup for agreeing on keysError-correcting codesSelected March 11, 2025, final standard expected in 2027

The mix is deliberate. Two of the three final standards use lattices, a family of math problems studied for decades. SLH-DSA relies only on the security of hash functions, which are very well understood, as insurance if lattices ever turn out weaker than expected. HQC plays the same role for key agreement, built on different math from ML-KEM.

Lattices explained without math

Most post-quantum algorithms in use today, including ML-KEM, are built on lattices. Picture a city laid out on a perfect grid of streets, with a lamppost at every corner. Now imagine the same kind of grid, but in hundreds of dimensions instead of two, and with the streets drawn at odd, skewed angles.

Someone drops a pin near, but not exactly on, one of the lampposts: a grid point nudged by a little random "noise". The puzzle is to find the lamppost nearest to the pin.

With the secret shortcut

  • You know a neat description of the grid, with short, nearly square streets
  • Rounding the pin to the nearest lamppost is quick
  • This neat description is the private key

Without it

  • You only have a scrambled description, with long, skewed streets
  • In hundreds of dimensions, no known method, classical or quantum, finds the nearest lamppost in reasonable time
  • This scrambled description is the public key

The noise is what makes it hard. Without it, the problem would be ordinary algebra that computers solve instantly. With it, the best known attacks, including quantum ones, still take impossibly long at the key sizes the standards use. ML-KEM's version of this problem is called "module learning with errors"; the name describes solving equations where every answer has been blurred by a small random error.

Why hybrid: X25519 plus ML-KEM

When your browser connects to a site that supports it, it does not use ML-KEM alone. It runs the classic elliptic-curve key exchange X25519 and ML-KEM side by side and mixes both results into the session key. This combination is named X25519MLKEM768.

The logic is belt and suspenders. An attacker would have to break both: X25519, which a future quantum computer could break but which has held up against ordinary computers for years, and ML-KEM, which resists quantum computers but is younger. SIKE's collapse in 2022 showed that a promising post-quantum candidate can fail suddenly; hybrid means such a failure would not leave anyone unprotected. NIST accepts such hybrids as long as they include a NIST-approved algorithm.

The price: bigger keys and signatures

Post-quantum security comes with more bytes on the wire. The sizes below come from the FIPS documents and the RFCs for the classical algorithms.

JobClassical todayPost-quantum replacementStatus
Agreeing on keysX25519: 32-byte public keyML-KEM-768: 1,184-byte public key, 1,088-byte replyWidely deployed, usually hybrid
Everyday signaturesEd25519: 32-byte public key, 64-byte signatureML-DSA-44: 1,312-byte public key, 2,420-byte signatureStandardized, early deployment
Conservative signaturesRSA-2048: about 256-byte public key and signatureSLH-DSA-128s: 32-byte public key, 7,856-byte signatureStandardized, niche use
Compact signaturesECDSA P-256: about 64-byte signatureFN-DSA-512: about 897-byte public key, 666-byte signature (FALCON submission figures)Standard not final

For key agreement, an extra kilobyte per connection is a small price, which is why it spread quickly. Signatures are harder. A single website visit can involve several signatures and public keys in its certificate chain, and swapping each for a post-quantum one adds many kilobytes to every new connection. That is the main reason certificates are migrating later. Google's Chrome team is testing Merkle Tree Certificates, a design that batches many certificates under one signature, and plans broader phases in 2027.

You already use post-quantum cryptography

Most of this happened quietly, through ordinary updates.

  • Web browsers. Chrome turned hybrid post-quantum key agreement on by default in 2024 and moved to the standardized ML-KEM in November 2024. Firefox and Edge followed, and Apple's 26-series systems (iOS 26, macOS Tahoe 26) automatically offer X25519MLKEM768 for TLS connections.
  • Websites. Cloudflare, which sits in front of a large share of websites, supports hybrid key agreement for visitors by default. More than 65% of human traffic to Cloudflare was post-quantum encrypted as of April 2026. Connections from Cloudflare onward to the websites' own servers lag far behind: only 3.7% of those servers supported it in October 2025.
  • Messaging. Signal added post-quantum protection to starting a conversation with PQXDH in September 2023 and extended it to ongoing conversations with its Triple Ratchet in October 2025. Apple introduced PQ3 for iMessage in February 2024.
  • Remote servers. OpenSSH, the tool administrators use to log in to servers, has used a hybrid post-quantum key exchange by default since version 9.0 (April 2022), switched the default to ML-KEM in version 10.0 (April 2025) and since version 10.1 warns when a connection falls back to a non-post-quantum method.

What is not widely migrated yet: the certificates that prove a website's identity, code signing, most government ID and banking infrastructure, and a long tail of older servers and devices. These protect against impersonation rather than eavesdropping, and they only become urgent once a large quantum computer actually exists, but replacing them takes years.

PQC migration: the timeline so far

The switch started long before any threat was practical. Dates marked "planned" are published targets and may move.

  1. 1994

    Shor's algorithm

    Shows that a large quantum computer could break RSA and elliptic curves.

  2. 2016 to 2017

    NIST competition opens

    69 complete submissions accepted in December 2017.

  3. 2022

    First selections, first breaks

    NIST picks Kyber, Dilithium, FALCON and SPHINCS+. Rainbow and SIKE are broken with ordinary computers.

  4. 2023 to 2024

    Early adopters

    Signal PQXDH (2023), iMessage PQ3 and hybrid key agreement on by default in Chrome (2024).

  5. August 2024

    FIPS 203, 204 and 205 published

    ML-KEM, ML-DSA and SLH-DSA become final standards.

  6. 2025

    Backup and broad rollout

    HQC selected (March), OpenSSH 10.0 defaults to ML-KEM (April), EU roadmap (June), Signal Triple Ratchet (October).

  7. 2026

    Deadlines move closer

    Google and Cloudflare target 2029; the U.S. executive order of June sets 2030 and 2031 for federal systems.

  8. End of 2030planned

    High-risk systems

    EU target for high-risk uses; U.S. target for post-quantum key agreement in high-value federal systems.

  9. 2035planned

    Classical public keys retired

    NIST's draft plan would disallow RSA and elliptic curves; the EU aims to finish as far as feasible.

Selected milestones in the move to post-quantum cryptography, as of September 2026. Planned dates are targets published by the organizations named.

Some details behind those dates:

  • United States. NIST's draft transition plan, IR 8547 (initial public draft, November 2024, not final as of September 2026), proposes deprecating RSA and elliptic-curve algorithms at the 112-bit security level (such as RSA-2048) after 2030 and disallowing all of them after 2035. Executive Order 14412 of June 22, 2026 directs federal agencies to move their high-value and high-impact systems to post-quantum key establishment by December 31, 2030 and to post-quantum signatures by December 31, 2031.
  • European Union. The coordinated implementation roadmap of June 2025 asks member states to start by the end of 2026, move high-risk uses by the end of 2030 and complete as much as practically feasible by 2035.
  • Industry. Google set 2029 as its own deadline in March 2026, citing faster progress in hardware, error correction and attack estimates. Cloudflare followed in April 2026.

What post-quantum cryptography means for you

For most people, the honest answer is: keep your software updated and the rest happens for you. Browsers, operating systems, messengers and big websites are already switching, and you do not need to pick algorithms yourself.

A few practical points still help:

  • Be skeptical of "quantum-proof" marketing. A product that claims quantum safety should name what it uses (for example ML-KEM, ideally in a hybrid) and for which part. "Military-grade quantum encryption" says nothing.
  • Think about how long your secrets matter. If data must stay private for decades, prefer services that already use post-quantum key agreement, such as Signal and iMessage for messages. Our explainer on harvest now, decrypt later shows why that matters today.
  • Do not replace symmetric encryption. AES-256 is already on the right side of the line, and so are long random passwords.

What it means for Cappa

Cappa encrypts your notes with symmetric cryptography only. In your browser, a random 256-bit vault key encrypts every note with AES-256-GCM, and that vault key is itself encrypted with keys derived from your master password (Argon2id and HKDF-SHA-256) and from your recovery code. No public-key cryptography is involved in encrypting or unlocking your notes, so the stored notes have nothing to migrate: AES-256 already sits in NIST's highest post-quantum security category. AES-256 explained and end-to-end encrypted notes describe how that works.

The web connection is where post-quantum key agreement matters, as it does for every website. Cappa's traffic goes through Cloudflare, which terminates TLS. In our test in September 2026, the connection to cappa.page negotiated X25519MLKEM768 with a client that offered it, so current browsers get hybrid post-quantum key agreement between your device and Cloudflare. Inside that connection, your notes already travel as AES ciphertext.

If you are choosing a notes app with long-term privacy in mind, the question to ask is the same as always: who holds the key? Our comparison of notes apps asks it for each of them.

FAQ

Is post-quantum cryptography the same as quantum cryptography?

No. Post-quantum cryptography is ordinary software built on math problems believed to resist quantum computers, and it runs on today's devices. Quantum cryptography, such as quantum key distribution, uses physics and special hardware to share keys.

What is ML-KEM?

ML-KEM is the post-quantum algorithm NIST standardized in FIPS 203 in August 2024 for agreeing on secret keys over a network. It grew out of the CRYSTALS-Kyber submission and relies on a lattice problem called module learning with errors. Browsers currently use it in the hybrid X25519MLKEM768, together with the classic X25519.

Is post-quantum cryptography proven secure?

No cryptography used in practice is proven unbreakable, and that includes RSA and elliptic curves. Post-quantum algorithms have survived years of public analysis, but some candidates were broken during the competition. That is why deployments combine classical and post-quantum algorithms and why NIST keeps backups built on different math, like SLH-DSA and HQC.

Do I need to do anything to use post-quantum encryption?

Usually not. Keep your browser, operating system and apps updated, and they will use post-quantum key agreement where the other side supports it. You can check your browser on Cloudflare's test page.

Is AES-256 post-quantum?

AES-256 is not a new post-quantum algorithm, but it is already considered safe against quantum computers. Quantum attacks on symmetric ciphers only give a limited speedup, and NIST places AES-256 in its highest post-quantum security category. What needs replacing is the public-key cryptography used to agree on AES keys and to sign things.

Written by the Cappa team

We build Cappa, a private Markdown notes app that encrypts your notes on your device before they are synced. We write about the decisions behind it, including the limits, so you can judge them yourself.