Skip to main content
Post-quantum cryptography

The end of RSA and ECC is already on the calendar

NIST published the first post-quantum standards in August 2024. Its draft transition guidance deprecates today's quantum-vulnerable public-key algorithms after 2030, and the EU roadmap asks for high-risk systems to move by the end of 2030.

QuantumLock helps with the parts of the migration that can start now: knowing where vulnerable cryptography lives, and signing what must stay trustworthy for years.

Standards published
FIPS 203, 204 and 205 · Aug 2024
Deprecation proposed
After 2030 · NIST IR 8547 draft
EU high-risk systems
By the end of 2030

Why now

Two risks that start before a quantum computer exists

A quantum computer able to break RSA and ECC has not been demonstrated. The risk to your organisation starts earlier, because data and signatures outlive the systems that produce them.

  • Harvest now, decrypt later

    Encrypted traffic recorded today can be decrypted once the keys can be broken. Data that must stay confidential for ten years is exposed now.

  • Trust now, forge later

    Firmware, releases, contracts and licences are verified for years. Once a signature scheme falls, forged signatures look as valid as real ones.

  • Inventory comes first

    Every roadmap starts with the same step: find where quantum-vulnerable cryptography is used, then decide what moves first.

Fig. 02 · Long-lived data: Shots · H on 240 qubits, simulated

The timeline

The dates regulators have set

The milestones that shape migration plans in Europe and for organisations that sell to US agencies. Draft documents are marked as drafts.

  1. Aug 2024

    NIST publishes the first post-quantum standards

    FIPS 203 (ML-KEM) for key establishment, FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures.

    Source · NIST FIPS 203, 204, 205

  2. Nov 2024

    NIST proposes end dates for RSA and ECC

    The initial public draft of NIST IR 8547 deprecates quantum-vulnerable public-key algorithms at 112-bit security after 2030 and disallows them after 2035.

    Source · NIST IR 8547, initial public draft

  3. Jan 2025

    DORA applies to EU financial entities

    The ICT risk standards under DORA require financial entities to keep their cryptographic controls up to date with developments in cryptanalysis.

    Source · Commission Delegated Regulation (EU) 2024/1774, Art. 6

  4. Jun 2025

    The EU sets a coordinated roadmap

    The NIS Cooperation Group publishes a coordinated implementation roadmap for the transition to post-quantum cryptography across Member States.

    Source · EU Coordinated Implementation Roadmap

  5. End of 2026

    First steps under way

    Member States are expected to have started the transition, including national plans and the first inventories of cryptographic assets.

    Source · EU Coordinated Implementation Roadmap

  6. 2030

    High-risk systems and signing move

    The EU roadmap targets high-risk use cases by the end of 2030. NSA CNSA 2.0 expects software and firmware signing for US national security systems to use quantum-resistant algorithms exclusively by 2030.

    Source · EU roadmap; NSA CNSA 2.0

  7. 2035

    Quantum-vulnerable algorithms disallowed

    The NIST draft disallows quantum-vulnerable public-key algorithms, and the EU roadmap aims to migrate as many systems as feasible.

    Source · NIST IR 8547 draft; EU roadmap

What QuantumLock does

The parts of the migration you can start this quarter

In production

Cryptographic inventory

Import a CycloneDX 1.6 CBOM and evaluate it against a versioned policy pack. QuantumLock does not scan your systems; it evaluates the inventory your tools produce.

Cryptographic inventory
In production

Post-quantum signing

Sign artifacts with ML-DSA (FIPS 204). The implementation comes from liboqs and is not CAVP-validated.

Quantum-safe signatures
In production

Hybrid signing

A classical signature and an ML-DSA signature over the same digest. QuantumLock accepts the pair only when both verify.

In production

Hybrid licence validation

Software licences that validate under classical and post-quantum rules, so licensing can move with the rest of the estate.

Available

Evidence verification

Check that a QCOS evidence record is unchanged against its SHA-256 Merkle root, using the RFC 9162 tree format.

Verifiable computation
In development

AI agent access

A QuantumLock MCP server is in development. Today, agents can reach QuantumLock through the REST API and Python SDK.

How the migration runs

Four steps, in the order regulators expect

  1. 01

    Inventory

    Export a CBOM from the discovery tools you already run and import it into QuantumLock.

  2. 02

    Evaluate

    Run it against the softquantus-pqc-baseline policy pack. Each finding has a severity, and the result is a pass, review or fail decision with a reproducible id.

  3. 03

    Sign hybrid

    Keep the classical signature your verifiers know and add an ML-DSA signature beside it.

  4. 04

    Move to post-quantum only

    When your verifiers and your policy allow it, sign with ML-DSA alone.

Questions

Post-quantum cryptography, answered plainly

What is post-quantum cryptography?

Public-key algorithms designed to resist attacks from quantum computers as well as classical ones. NIST standardised the first set in August 2024: ML-KEM for key establishment and ML-DSA and SLH-DSA for digital signatures.

When do RSA and ECC have to be replaced?

It depends on your regulator. The NIST draft IR 8547 deprecates them after 2030 and disallows them after 2035. The EU roadmap targets high-risk use cases by the end of 2030. Signatures that must be verified for many years are usually moved first.

What does hybrid mean?

Two signatures over the same data, one classical and one post-quantum, both required to verify. A forger would have to break both schemes, so the pair holds as long as either scheme holds.

Does QuantumLock encrypt traffic or replace TLS?

No. QuantumLock signs, validates licences and evaluates cryptographic inventories. Key establishment, such as ML-KEM in your TLS stack, is outside its scope.

Is the ML-DSA implementation validated?

QuantumLock uses ML-DSA from liboqs. It implements the FIPS 204 algorithm but is not CAVP-validated. If your policy requires a validated module, tell us before procurement.

Can AI agents use QuantumLock?

A QuantumLock MCP server is in development. Until it ships, agents can call the REST API through the Python SDK. QCOS already has an MCP server, see MCP integration.

Start with what you have

Send us a CBOM, or the list of what you sign today. We will show you what QuantumLock evaluates and signs, and what it does not.