{"id":19,"date":"2026-08-12T12:04:03","date_gmt":"2026-08-12T12:04:03","guid":{"rendered":"https:\/\/blog.amitdhiman.com\/?p=19"},"modified":"2026-08-12T12:04:03","modified_gmt":"2026-08-12T19:04:20","slug":"tech-post-quantum-cryptography-nist-migration","status":"publish","type":"post","link":"https:\/\/blog.amitdhiman.com\/?p=19","title":{"rendered":"Post-Quantum Cryptography: Turn NIST Standards into a Practical Migration Plan"},"content":{"rendered":"<p>A post-quantum migration starts with a surprisingly ordinary question: where does your organization use public-key cryptography? The answer spans more than website certificates. It includes VPNs, software signatures, device identities, key management, and dependencies hidden inside purchased services. Finding those connections now is useful even before every supplier has a production migration path.<\/p>\n<p>This guide is for application owners, infrastructure teams, and security leads who need a defensible starting point. You will learn what the NIST standards cover, how to prioritize one pilot, and what evidence to request from vendors. No quantum computer or custom cryptographic implementation is required.<\/p>\n<h2>Three standards, two different jobs<\/h2>\n<p>NIST published its first three post-quantum cryptography standards on August 13, 2024. These are established standards, not speculative algorithm proposals. Their availability does not mean every protocol, hardware device, or certificate ecosystem has completed its transition.<\/p>\n<ul>\n<li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/203\/final\">FIPS 203 specifies ML-KEM<\/a>, a mechanism for establishing a shared secret. A protocol can use that secret with symmetric cryptography. ML-KEM is not a standalone file-encryption format and does not by itself authenticate the other party.<\/li>\n<li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/204\/final\">FIPS 204 specifies ML-DSA<\/a>, a digital signature scheme for verifying signed data and its origin.<\/li>\n<li><a href=\"https:\/\/csrc.nist.gov\/pubs\/fips\/205\/final\">FIPS 205 specifies SLH-DSA<\/a>, a stateless, hash-based signature scheme with a different underlying construction.<\/li>\n<\/ul>\n<p>The distinction matters operationally. Updating a connection&#8217;s key establishment does not automatically update its certificate signatures or your software release signing. Track confidentiality and authentication separately. Follow maintained product documentation and standard errata rather than translating mathematical specifications into application code.<\/p>\n<h2>Start with the lifetime of your data<\/h2>\n<p>A future attacker could retain encrypted traffic for later analysis. For information that must remain confidential for many years, waiting until a cryptographically relevant quantum computer exists may leave historical exposures unresolved. This is a planning risk, not a prediction of a particular arrival date.<\/p>\n<p>Consider a document portal holding long-lived research agreements. Its public endpoint is only one boundary. A load balancer may terminate TLS, another connection may reach the application, and an export service may send documents elsewhere. A successful browser handshake proves little about those remaining paths.<\/p>\n<h3>Prerequisites for a useful first assessment<\/h3>\n<ul>\n<li>An owner for the selected service and access to its architecture and dependency records.<\/li>\n<li>Read-only configuration visibility for certificates, transport libraries, gateways, and relevant key services.<\/li>\n<li>A data classification decision covering confidentiality duration and consequences of signature forgery.<\/li>\n<li>A staging environment, representative clients, supplier contacts, and an agreed rollback process.<\/li>\n<\/ul>\n<p>Do not put private keys or sensitive certificate-management credentials into the inventory. Record identifiers, owners, versions, and references to controlled systems.<\/p>\n<h2>A migration pilot in five steps<\/h2>\n<ol>\n<li>Map the selected transaction end to end. Include internal connections and outsourced components, then identify which cryptographic functions protect each boundary.<\/li>\n<li>Record current algorithms and implementations. Mark unknowns explicitly; a service described as encrypted is not sufficient evidence.<\/li>\n<li>Ask vendors which released versions support standardized algorithms, which protocol profiles they implement, and what interoperability and validation evidence applies.<\/li>\n<li>Enable a documented, supported configuration in staging. If a product offers hybrid key establishment, use its supported protocol construction rather than combining algorithms yourself.<\/li>\n<li>Exercise old and new clients, failed negotiations, certificate renewal, monitoring, and rollback. Record the negotiated protection rather than assuming a configuration switch took effect.<\/li>\n<\/ol>\n<p>A compact inventory entry might look like this. It is an assessment record, not a cryptographic configuration:<\/p>\n<pre><code>Service: research document portal\nBoundary: external client to gateway\nFunction: key establishment and peer authentication\nImplementation: record installed product and version\nData lifetime: determined by information owner\nPQC support: awaiting supplier evidence\nNext action: stage supported client compatibility tests<\/code><\/pre>\n<p>The <a href=\"https:\/\/www.nccoe.nist.gov\/applied-cryptography\/migration-to-pqc\">NCCoE migration project<\/a> separates cryptographic discovery from interoperability testing. That separation is practical: locating a dependency and proving its replacement works are different deliverables.<\/p>\n<h2>Budget for integration, not just algorithms<\/h2>\n<p>Some post-quantum choices increase key, ciphertext, or signature sizes relative to familiar deployments. Effects depend on the algorithm, parameter set, protocol, and implementation. Measure connection latency, bandwidth, memory, and failure behavior on your actual path. Do not apply a published microbenchmark as a capacity estimate for your service.<\/p>\n<p>Other costs include equipment replacement, vendor upgrades, staff training, and parallel operation. Standards compliance also differs from a cryptographic module&#8217;s validation status. Where validation is required, verify the exact module, version, operating mode, and applicable certificate.<\/p>\n<p>Keep current controls intact: patching, access control, secure key storage, and incident response still matter. Post-quantum algorithms do not repair a stolen private key or an exposed application.<\/p>\n<h2>Your next deliverable<\/h2>\n<p>Finish with an owned inventory, one measured pilot, and a supplier dependency list. Set a review date for unresolved support and standard updates. The emerging work is broad ecosystem integration; the immediate engineering task is making cryptography discoverable, replaceable, and testable without disrupting the service.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Understand ML-KEM, ML-DSA, and SLH-DSA, then build a cryptographic inventory and a controlled migration pilot without designing your own cryptography.<\/p>\n","protected":false},"author":1,"featured_media":39,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[10],"tags":[],"class_list":["post-19","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-quantum-computing"],"_links":{"self":[{"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/posts\/19","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=19"}],"version-history":[{"count":1,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/posts\/19\/revisions"}],"predecessor-version":[{"id":31,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/posts\/19\/revisions\/31"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=\/wp\/v2\/media\/39"}],"wp:attachment":[{"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=19"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=19"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.amitdhiman.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=19"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}