QNSI

PQC concepts

What is PQC?

Also known as Post-Quantum Cryptography.

Cryptography designed to resist attack by both classical and quantum computers. Distinct from quantum cryptography (which uses quantum mechanics to transmit keys, e.g. QKD). All four NIST standards (FIPS 203/204/205/206) are PQC - they run on classical hardware and resist quantum attack.

Decision context

Why PQC matters

Post-quantum cryptography changes key establishment and signature primitives so cryptographic decisions can resist known quantum attacks while still running on conventional computers. It addresses neither every security problem nor every external dependency; authentication, implementation quality, custody, protocols and operations remain essential.

How to evaluate PQC

Ask which real primitive executes at each confidentiality and authenticity boundary, with which parameter set, provider and evidence. Map classical third-party legs explicitly, test downgrade and failure behaviour, and reject labels that merely rename random bytes, hashes or conventional cryptography as post-quantum operations.

PQC concepts

PQC concepts evidence boundary

Post-quantum programmes combine cryptography, architecture, data lifetime, operational ownership, and migration governance. A concept is useful only when it changes a concrete inventory, policy, design, test, or evidence decision. Treat terminology as a decision aid rather than proof that a control exists.

FAQ

Common questions

What is PQC?

Cryptography designed to resist attack by both classical and quantum computers. Distinct from quantum cryptography (which uses quantum mechanics to transmit keys, e.g. QKD). All four NIST standards (FIPS 203/204/205/206) are PQC - they run on classical hardware and resist quantum attack.

Why does PQC matter?

Post-quantum cryptography changes key establishment and signature primitives so cryptographic decisions can resist known quantum attacks while still running on conventional computers. It addresses neither every security problem nor every external dependency; authentication, implementation quality, custody, protocols and operations remain essential.

How should PQC be evaluated?

Ask which real primitive executes at each confidentiality and authenticity boundary, with which parameter set, provider and evidence. Map classical third-party legs explicitly, test downgrade and failure behaviour, and reject labels that merely rename random bytes, hashes or conventional cryptography as post-quantum operations.

What is PQC also known as?

PQC is also known as Post-Quantum Cryptography. Cryptography designed to resist attack by both classical and quantum computers. Distinct from quantum cryptography (which uses quantum mechanics to transmit keys, e.g. QKD). All four NIST standards (FIPS 203/204/205/206) are PQC - they run on classical hardware and resist quantum attack.

More

Keep exploring