What is post-quantum cryptography?

Post-quantum cryptography (PQC) is cryptography designed to resist attacks by both classical computers and future quantum computers, replacing the vulnerable public-key algorithms RSA, Diffie-Hellman and elliptic-curve cryptography (ECC). PQC runs on existing hardware and software; it requires no quantum technology at all. For OT the transition is urgent because installations stay in service for fifteen to thirty years: a PLC, RTU or gateway commissioned today will still be running when a cryptographically relevant quantum computer becomes a realistic prospect.


🧠 Why does a quantum computer threaten today’s cryptography?

Almost every secure connection relies on two building blocks: public-key cryptography for key exchange and digital signatures, and symmetric encryption for the data itself. A sufficiently large quantum computer affects both, but not to the same degree:

  • Shor’s algorithm (1994) — solves integer factorisation and the discrete logarithm problem efficiently. That breaks RSA, (EC)DH and ECDSA completely, whatever the key length. It hits TLS, VPNs, SSH, certificates and code signing.
  • Grover’s algorithm (1996) — gives a quadratic speed-up for brute-force search, effectively halving the strength of symmetric keys. AES-128 drops to roughly 64 bits; AES-256 and SHA-384 or stronger remain comfortably sufficient.

The real migration challenge therefore lies on the public-key side, which has to be replaced entirely, while symmetric cryptography usually just needs longer keys.


⏳ What does ‘harvest now, decrypt later’ mean?

In a harvest now, decrypt later attack, an adversary intercepts encrypted traffic today and stores it until a quantum computer can decrypt it. Sensitive process recipes, network designs or key material sent over a VPN today could still be exposed ten years from now.

Signatures carry a second risk: forge later. Once RSA or ECDSA can be broken, an attacker can create fake firmware or certificates that are accepted as genuine. For OT this is the bigger problem, because devices use the same trusted public key for years to verify firmware signatures.

The Dutch PQC Migration Handbook uses Mosca’s rule of thumb here: if the shelf life of your data plus your migration time exceeds the time until a quantum computer arrives, you are already too late. In OT, both of the first two terms are large.


🔧 Which PQC standards exist?

The US standards body NIST launched an open selection process in 2016 and published the first three final standards in August 2024. In March 2025 it selected HQC as a backup key-establishment algorithm built on a different mathematical foundation. FN-DSA, based on Falcon, is being prepared as FIPS 206; NIST submitted the draft for approval in August 2025.

Current algorithm Function PQC replacement Use in OT
RSA / (EC)DH key exchange Agree a session key ML-KEM (FIPS 203, lattice-based) TLS to historian and cloud, VPN for remote access
RSA / ECDSA signature Authentication, certificates ML-DSA (FIPS 204, lattice-based) Certificates for OPC UA, MQTT brokers and web interfaces
RSA / ECDSA for firmware Long-lived signature SLH-DSA (FIPS 205, hash-based) or LMS/XMSS Firmware signing and secure boot
— Compact signature FN-DSA (FIPS 206, in preparation) Bandwidth-constrained devices
— Backup KEM HQC (code-based, standard expected 2027) Diversification alongside ML-KEM
AES-128 Symmetric encryption AES-256 Existing hardware acceleration remains usable

PQC keys and signatures are considerably larger. An ECDSA P-256 signature is 64 bytes, an ML-DSA-65 signature 3,309 bytes and an SLH-DSA-128s signature 7,856 bytes. An ML-KEM-768 public key is 1,184 bytes. For a field device with little memory or a narrowband radio link, that is far from a detail.


🗓️ Which deadlines apply in Europe and the Netherlands?

Date Milestone
March 2023 First PQC Migration Handbook from AIVD, CWI and TNO
August 2024 NIST publishes FIPS 203, 204 and 205
November 2024 NIST IR 8547 (initial draft): RSA/ECC at 112-bit security strength deprecated after 2030, all quantum-vulnerable algorithms disallowed after 2035
December 2024 Second, extended edition of the PQC Migration Handbook
June 2025 EU Coordinated Implementation Roadmap from the NIS Cooperation Group
End of 2026 Member states and organisations start: strategy, awareness, cryptographic inventory
End of 2030 High-risk systems, including critical infrastructure, quantum-safe
2035 As many systems as feasible migrated

The EU roadmap recommends hybrid solutions: a classical and a PQC algorithm used together, so the connection stays secure as long as either one holds. For Dutch essential and important entities under the Dutch Cybersecurity Act (Cbw), 2030 is therefore the practical horizon.


🏭 Why is PQC particularly hard in OT?

  • Long lifecycles — controllers stay in service for 15 to 30 years; legacy systems often no longer receive cryptographic updates
  • Constrained devices — microcontrollers in sensors and IIoT nodes have little RAM, flash or computing power for large keys
  • Hard-coded cryptography — algorithms and root keys live in bootloaders, ROM or secure elements and cannot be replaced by an update
  • Firmware signing — the trusted key inside the device decides which firmware is accepted until the end of its life
  • Protocol support — OPC UA security policies use RSA or ECC; no standardised PQC policy exists yet
  • Availability first — larger handshakes cost time and bandwidth, and every change has to be tested within scarce maintenance windows

The key concept is crypto agility: the ability to swap algorithms without replacing the hardware.


🛠️ How do you migrate an OT environment to PQC?

  1. Build a cryptographic inventory — extend your asset inventory into a cryptographic bill of materials (CBOM): which algorithms, key lengths, certificates and libraries does each system use, and where are the root keys stored?
  2. Classify by shelf life — which data and which trust anchors must still be secure after 2030? Firmware signing, PKI roots and long-lived process data come first.
  3. Take the no-regret steps — move to AES-256 and SHA-384, shorten certificate lifetimes and automate certificate management.
  4. Set vendor requirements — include a PQC roadmap, crypto agility and updatable trust anchors in your procurement requirements and supplier assessment, in line with IEC 62443-4-2.
  5. Start at the edges — IT/OT connections, VPN gateways and cloud links can already use hybrid TLS (such as X25519MLKEM768).
  6. Isolate what cannot migrate — keep non-upgradable equipment behind segmentation and gateways that terminate the PQC connection on the device’s behalf.
  7. Build PQC into the replacement cycle — make it part of lifecycle management, so that every new system from 2027 onwards is quantum-safe or demonstrably crypto-agile.

🔐 How does PQC relate to the Cyber Resilience Act?

The Cyber Resilience Act requires products with digital elements to protect data using state-of-the-art mechanisms and obliges manufacturers to supply security updates throughout the support period. These obligations apply in full from 11 December 2027. A controller placed on the market then and supported until well beyond 2035 must therefore be able to keep pace with the shift to PQC. For operators, NIS2 requires appropriate cryptographic measures; the EU roadmap makes clear what “appropriate” will mean in the years ahead.


❓ Frequently asked questions

When will a quantum computer be able to break RSA?

Nobody knows exactly when a cryptographically relevant quantum computer will exist, but governments are planning for the 2030–2035 window. Post-quantum cryptography has to be in place before then, because encrypted data can already be harvested today. That is why the EU roadmap sets 2030 as the deadline for high-risk systems.

Is AES still secure against quantum computers?

AES-256 remains secure, because Grover’s algorithm only halves its effective key strength to 128 bits. AES-128 would then offer roughly 64 bits and is less suitable for data that must stay confidential for a long time. Post-quantum cryptography therefore focuses mainly on replacing RSA and ECC.

What is the difference between ML-KEM and ML-DSA?

ML-KEM (FIPS 203) is the post-quantum algorithm for securely agreeing a session key and replaces RSA and Diffie-Hellman key exchange. ML-DSA (FIPS 204) is a post-quantum algorithm for digital signatures and replaces RSA and ECDSA signatures. Both are based on lattice problems.

What is hybrid post-quantum cryptography?

In hybrid post-quantum cryptography, a connection combines a classical algorithm such as X25519 with a PQC algorithm such as ML-KEM. The connection stays secure as long as either one remains unbroken. The EU roadmap recommends this approach during the transition period.

Do I need to replace my PLCs for post-quantum cryptography?

Not immediately: post-quantum cryptography is software, but older PLCs often lack the memory, processing power or an updatable root of trust. Assess per device whether a firmware update is possible, or whether segmentation and a PQC gateway will suffice until the planned replacement. Make quantum safety a requirement in every new purchase.

What is the PQC Migration Handbook?

The PQC Migration Handbook is a Dutch guide from AIVD, CWI and TNO for organisations moving to post-quantum cryptography. The second edition of December 2024 covers cryptographic asset management, quantum risk assessment and crypto agility, among other topics. It is freely available in Dutch and English.


📌 In summary

Post-quantum cryptography replaces RSA and ECC with NIST algorithms such as ML-KEM and ML-DSA, and OT organisations need to start now because their installations outlive today’s cryptography. Begin with a cryptographic inventory, prioritise firmware signing and long-lived data, demand crypto agility from your vendors and aim for 2030 for critical systems.