PQC & Crypto-Agility
Not a product you buy. A programme you run.
Post-quantum cryptography is the set of algorithms designed to stay secure against quantum computers, now being standardised by NIST to replace the RSA and elliptic-curve cryptography behind most certificates today.
Crypto-agility is the durable capability underneath it — adapting cryptographic systems quickly as threats, standards and regulations move. PQC makes it urgent; it will not be the last transition.
The Threat
Two ways quantum breaks today's trust
Harvest Now, Decrypt Later
Adversaries collect encrypted data today to read once quantum capability matures. Anything with a long confidentiality life — health records, state secrets, IP — is exposed the moment it crosses the wire, not when quantum arrives.
Threat Now, Forge Later
The less-discussed counterpart: signatures made today could be forged in a quantum future. Long-lived code signing, legal instruments and device firmware lose their authenticity, not just their secrecy.
Standards
The NIST post-quantum standards
| Standard | Algorithm | Purpose | Replaces |
|---|---|---|---|
| FIPS 203 | ML-KEM | Key establishment | RSA / ECDH key exchange |
| FIPS 204 | ML-DSA | Digital signatures — the general-purpose choice | RSA / ECDSA signatures |
| FIPS 205 | SLH-DSA | Hash-based signatures — conservative, non-lattice | RSA / ECDSA signatures |
| Selected 2025 | HQC | Code-based key establishment, backup to ML-KEM | RSA / ECDH key exchange |
NIST has signalled that RSA-2048 and ECC P-256 will be deprecated around 2030 and disallowed by 2035. Those dates are NIST's, and they are what make the migration window finite.
You cannot migrate cryptography you cannot see. Every post-quantum programme is an inventory problem first.
The Roadmap
Five phases to quantum-safe
1. Discover
Inventory every key and certificate — a CBOM is the output.
2. Classify
Rank by what each asset protects and how long it must stay secret.
3. Prioritise
Long-lived secrets, then exposed systems, then anything slow to change.
4. Hybridise
Hybrid certificates stay interoperable with legacy peers while gaining resistance.
5. Migrate
Retire classical-only certificates in priority order, with agility built in.
The Platform
How CertiNext delivers PQC readiness
Centralised cryptographic visibility
"Where are we still quantum-vulnerable?" becomes a question with an answer, not a project to find out.
Policy-driven enforcement
Approve the algorithms and key strengths you accept; the platform holds issuance to them so the estate stops drifting backwards.
Hybrid coexistence
Approved PQC algorithms running alongside classical ones, for as long as the transition needs.
Bulk renewal and replacement
Migration means reissuing certificates in volume — an operation the platform runs, backed by automated lifecycle management.
What makes migration hard
The algorithms are settled. The difficulty is operational.
Finding what is vulnerable
Including cryptography embedded in systems nobody thinks of as cryptographic.
Managing coexistence
Classical and post-quantum run side by side for years — both governed at once.
Bigger keys, real cost
PQC key and signature sizes hit handshakes, bandwidth and constrained devices.
Replacement at scale
Sequencing a live estate so nothing goes down — why this is measured in years.
Who is migrating first
Government & Defence
Secrecy measured in decades
Financial Services
Long retention, heavy scrutiny
Telecom
Certificate populations at 5G scale
Manufacturing & IoT
Change cycles measured in years
Why eMudhra
A Migration Run From Inside the Trust Infrastructure
eMudhra is a globally trusted Certificate Authority and digital-trust provider, so post-quantum readiness in CertiNext is not an advisory exercise bolted onto someone else's platform — it runs in the same place your certificates are issued, your keys are managed, and your cryptographic inventory lives. Discovery, prioritisation and reissuance happen in one system rather than three.
Frequently Asked Questions
Crypto-agility is the ability of an organisation to rapidly adapt its cryptographic systems in response to evolving threats, standards or regulatory requirements. Post-quantum cryptography is the specific transition that makes that ability urgent right now. Organisations that build crypto-agility solve the PQC migration and every algorithm change after it; organisations that treat PQC as a one-off project will face the same problem again.
NIST finalised three standards in 2024: FIPS 203 (ML-KEM) for key establishment, FIPS 204 (ML-DSA) for general-purpose digital signatures, and FIPS 205 (SLH-DSA) as a hash-based signature alternative. A fourth algorithm, the code-based HQC, was selected in 2025 as a backup for key establishment so the world does not depend on a single family of mathematics.
It is the practice of collecting encrypted data today in order to decrypt it once quantum capability matures. It is why the quantum threat is already active: data with a long confidentiality lifetime is exposed at the moment it is transmitted, not at the moment quantum computers become practical. Its counterpart is "threat now, forge later" — the risk that signatures created today could be forged in a quantum-enabled future.
A hybrid certificate combines a classical algorithm with a post-quantum one, so a system stays interoperable with peers that have not migrated while gaining quantum resistance where the counterpart supports it. Hybridisation is a deliberate transition state rather than a destination — it buys time to update the long tail of systems that cannot move immediately.
It is a multi-year transition requiring visibility, planning and controlled execution rather than a single cutover. NIST has signalled that RSA-2048 and ECC P-256 will be deprecated around 2030 and disallowed by 2035, which sets a finite window. Systems with long change cycles — embedded, operational technology, anything protecting data that must stay confidential for a decade — should be starting discovery now.