Technology

Quantum computing and post-quantum cryptography

Quantum computing uses quantum-mechanical systems for computation; post-quantum cryptography uses classical algorithms designed to resist known quantum attacks. Present hardware capability, algorithmic theory, cryptographic risk, standards, migration and export control are separate questions.

Capability and risk

Shor's algorithm creates a theoretical threat to widely used public-key systems if a sufficiently capable fault-tolerant quantum computer is built. Current devices have limited scale, noise and error-correction capability. No reviewed official source establishes that a cryptographically relevant quantum computer exists as at 30 July 2026.

Forecasts for such a system vary and must be attributed. A qubit count does not directly measure logical qubits, error correction, gate quality or time to break a cryptographic key. Editors should not state a break date as fact.

The harvest-now-decrypt-later risk arises when an adversary collects encrypted data today for possible future decryption. Its importance depends on data sensitivity, protection period, capture opportunity and later capability. Panopticon effect is an analytical consequence of perceived observation, not proof that stored traffic will be decrypted.

Standards and migration

NIST finalised FIPS 203, 204 and 205 for post-quantum key establishment and digital signatures. A published standard is not a validated implementation or completed migration. Systems need inventory, protocol changes, testing, cryptographic agility and replacement of vulnerable dependencies.

Real-time gross settlement (RTGS) systems and other long-lived infrastructure may require coordinated migration across operators, vendors and participants. Bitcoin and permissionless cryptoasset networks use cryptographic components with different governance and upgrade constraints.

NIST and CISA advise agencies and operators to plan transition without asserting a known arrival date for a threatening machine. Implementation errors, side channels and legacy interfaces can remain risks after an algorithm changes.

Statecraft and controls

Quantum hardware, enabling equipment, software and technical knowledge may face export controls under specific classifications. Encryption technology, export controls and lawful-access policy is a separate legal layer. A research announcement or export restriction does not demonstrate operational cryptanalytic capability.

Assessment should distinguish physical qubits, logical performance, algorithm, standard, validated module, deployed protocol and protected data. Strategic claims require a dated capability measure and a stated counterfactual, while publication-day review must refresh standards and migration guidance.

Migration controls

Organisations should first inventory cryptographic assets, protocols, certificates, hardware modules, libraries and data-retention needs. Discovery can be incomplete where vendors embed cryptography inside appliances or cloud services. Priority should reflect sensitivity, replacement difficulty and how long confidentiality must last.

Interoperability is a transition risk. A server, client, certificate authority and hardware module may support different algorithms or parameter sets. Hybrid approaches can reduce some uncertainty while adding complexity and implementation burden.

Standards adoption should distinguish algorithm approval from module validation and production deployment. Performance testing, key size, bandwidth, storage and failure handling affect real systems. A mathematically secure algorithm can still be undermined by implementation errors or compromised endpoints.

Quantum policy also requires avoiding double counting. Public research funding, patent filings, qubit announcements and export controls are not comparable capability metrics. Editors should use reproducible benchmarks and identify whether a result demonstrates computation, error correction, networking or cryptographic relevance.

Sources

  1. National Institute of Standards and Technology, post-quantum cryptography project (accessed 30 July 2026).
  2. National Institute of Standards and Technology, FIPS 203.
  3. National Institute of Standards and Technology, IR 8547 transition report, initial public draft.
  4. US Cybersecurity and Infrastructure Security Agency, post-quantum cryptography initiative (accessed 30 July 2026).

Recommended citation

Cite this entry

Tennant, James J., ed. 'Quantum computing and post-quantum cryptography.' The Encyclopedia of Economic Statecraft, version 2.0, last reviewed 30 July 2026. https://jamesjtennant.com/entries/quantum-computing-and-post-quantum-cryptography/.

Suggest an edit