Where things stand
The public-key cryptography protecting nearly all internet traffic — RSA, elliptic-curve, and Diffie–Hellman — is broken by a sufficiently capable quantum computer running Shor's algorithm. The threat is not purely future: under harvest-now-decrypt-later, adversaries are already recording encrypted traffic to decrypt once the hardware matures. Any data that must stay confidential into the 2030s is exposed today.
The response is no longer waiting on research. NIST finalized its post-quantum standards in 2024, and government mandates now attach hard deadlines to the transition. The work left is organizational: inventory, prioritize, migrate, and prove it.
The deadlines that already apply
| 2024 | NIST finalizes FIPS 203 / 204 / 205 (ML-KEM, ML-DSA, SLH-DSA). The algorithms are standardized and available. |
| 2030 | RSA, DSA & ECC deprecated for most U.S. federal use. Critical systems should be actively migrating. |
| 2033 | Broad categories expected on exclusive CNSA 2.0 / quantum-safe algorithms. |
| 2035 | Target for National Security Systems to be fully quantum-resistant. |
Dates reflect published NIST and NSA guidance; confirm specifics against the current official publications.
A 10-point readiness self-assessment
Give yourself one point for each "yes." Be honest — an aspirational answer hides the risk.
- 01You have a complete, current inventory of where RSA, ECC, and Diffie–Hellman are used (a CBOM).
- 02You know which data must remain confidential past 2030.
- 03You've identified third-party and vendor cryptographic dependencies you don't directly control.
- 04You've applied Mosca's Inequality (X + Y > Q) to prioritize systems.
- 05TLS 1.3 is deployed on your internet-facing and high-sensitivity services.
- 06You've piloted hybrid key exchange (e.g., X25519 + ML-KEM) somewhere.
- 07You have a plan for signature and PKI migration (ML-DSA / SLH-DSA).
- 08Software and firmware signing is on a path to quantum-safe schemes (LMS/XMSS or PQC).
- 09You have crypto-agility — algorithms can change by configuration, not re-architecture.
- 10Your board understands the risk in business terms, with an owner assigned.
The four-phase path
- Discover. Build a machine-readable CBOM across code, traffic, certificates, and dependencies.
- Prioritize. Rank systems by quantum severity, data lifetime, and migration effort — highest X + Y over Q first.
- Migrate. Deploy hybrid key exchange first (it defeats harvest-now-decrypt-later), then signatures and PKI.
- Validate. Verify the quantum-safe algorithms are actually negotiated, and baseline for continuous crypto-agility.
The one-minute Mosca check
X + Y > Q? Add the years your data must stay secret (X) to the years it takes you to migrate (Y). If that total exceeds the years until a quantum computer arrives (Q, roughly a decade), your data is already exposed — and the only variable you fully control is Y.
Turn this brief into a plan
A scoped discovery engagement converts these questions into a CBOM, a Mosca-based risk score, and a prioritized roadmap.
Request an assessment