Key Points
- The "Harvest Now, Decrypt Later" threat means data encrypted today could be intercepted and decrypted years from now, so PQC preparation can't wait for quantum computers to arrive.
- PQC migration is more than swapping RSA or ECC certificates — every part of the authentication chain, from RADIUS servers to EAP-TLS to client devices, must support the new algorithms first.
- The practical priority today is building crypto-agile PKI that can adopt new standards as they mature, not deploying post-quantum certificates everywhere now.
Quantum computing has moved from a long-term research project to an active planning priority for cybersecurity teams. While practical quantum computers capable of breaking today’s public key cryptography do not yet exist, organizations cannot afford to wait until that day arrives. Sensitive data encrypted today could be intercepted, stored, and decrypted years later once quantum computing becomes powerful enough.
This threat, commonly known as Harvest Now, Decrypt Later, is driving organizations to evaluate post-quantum cryptography (PQC) long before large-scale quantum computers become commercially available.
At the same time, the path toward post-quantum encryption is far from straightforward. Industry discussions, including those at the PKI Consortium’s 2025 PQC Conference, have highlighted a fragmented ecosystem with competing migration strategies, evolving standards, and inconsistent regulatory guidance.
More importantly, the challenge extends beyond replacing RSA or ECC certificates. Current authentication infrastructure, including RADIUS servers, EAP-TLS implementations, operating systems, and network devices, is still catching up.
The good news is that organizations do not need to deploy PQC certificates everywhere today. Instead, they should focus on building crypto-agile infrastructure that allows them to adopt new cryptographic standards as the ecosystem matures.
What Is Post-Quantum Cryptography (PQC)?
Post-quantum cryptography refers to cryptographic algorithms designed to remain secure against attacks from both classical and quantum computers.
Unlike RSA and elliptic curve cryptography (ECC), which rely on mathematical problems that quantum computers could eventually solve with algorithms such as Shor’s Algorithm, PQC uses entirely different mathematical foundations believed to resist quantum attacks.
To accelerate industry adoption, the National Institute of Standards and Technology (NIST) has standardized several post-quantum algorithms, including ML-KEM for key establishment and ML-DSA for digital signatures. These algorithms are expected to replace today’s public key cryptography over time.
It is important to understand that quantum computing primarily threatens asymmetric cryptography. Symmetric encryption such as AES-256 remains significantly more resistant to quantum attacks because Grover’s Algorithm provides only a quadratic speedup, making AES-256 a viable long-term encryption standard.
The biggest driver behind PQC adoption is the Harvest Now, Decrypt Later threat. Nation-state adversaries can collect encrypted traffic today and store it until quantum computers become capable of decrypting it.
Organizations handling sensitive information with long confidentiality requirements should begin preparing now rather than waiting for quantum computers to become practical.
Why Post-Quantum Cryptography Is Not Ready for Production Everywhere
Many organizations assume they can simply replace their existing certificates with PQC certificates. Unfortunately, certificate issuance is only one piece of the puzzle.
Successful deployment requires every component in the authentication chain to support the new algorithms:
- Certificate authorities
- RADIUS servers
- EAP-TLS implementations
- Operating systems and network infrastructure
- Client devices and certificate validation libraries
This is particularly challenging for enterprise Wi-Fi environments using certificate-based authentication. Current RADIUS ecosystems generally do not support the authentication of PQC-enabled client certificates in production. Deploying a PQC-enabled Root CA or issuing PQC client certificates without compatible authentication infrastructure could result in failed EAP-TLS authentication and widespread connectivity issues.
Industry efforts are underway to address these limitations. The Internet Engineering Task Force (IETF) is actively developing specifications for PQC support within EAP-TLS, but these standards remain under development and have not yet achieved broad vendor adoption. Until the surrounding ecosystem matures, production deployments will remain limited.
This does not mean organizations should postpone planning. Instead, it reinforces the importance of preparing infrastructure while monitoring evolving standards.
Prioritize Quantum-Resistant Encryption Before Certificate Replacement
One common misconception is that replacing certificates should be the first step in every PQC migration strategy.
In reality, many security experts believe organizations should first focus on protecting encrypted communications by adopting modern TLS versions, stronger cipher suites, and future quantum-resistant key establishment mechanisms.
The reason is simple. The Harvest Now, Decrypt Later threat targets encrypted network traffic. If attackers can capture confidential TLS sessions today, they may eventually decrypt them when quantum computing becomes viable. Protecting communication channels, therefore, provides immediate long-term value, even if certificate migration occurs later.
Certificates remain an important part of the long-term transition, particularly for public key infrastructure (PKI) hierarchies that protect digital identities. However, organizations should recognize that quantum readiness extends beyond certificate replacement. Transport encryption, authentication protocols, and cryptographic libraries all play equally important roles.
Hybrid vs. Composite Cryptography Explained
One of the most confusing topics in the PQC ecosystem is the distinction between hybrid and composite cryptography.
Hybrid PKI combines classical and post-quantum cryptographic algorithms while maintaining compatibility with existing systems. For example, a certificate or TLS session may rely on both RSA and ML-DSA during the transition period. This approach allows organizations to continue supporting legacy environments while gradually introducing PQC.
Composite cryptography takes a different approach by combining classical and post-quantum algorithms into a single cryptographic object. Rather than maintaining separate signatures or certificates, composite methods integrate both algorithms into one structure. Several composite certificate proposals are currently progressing through the IETF standardization process.
Unfortunately, the terminology surrounding hybrid cryptography has evolved rapidly. Terms such as Catalyst, Chimera, X.509 Alternatives, and hybrid certificates have been used differently across vendors and standards bodies, creating confusion even among experienced PKI practitioners. As standards mature, clearer terminology should improve interoperability across implementations.
Why Hybrid Cryptography Remains a Challenge
Although hybrid cryptography appears to offer an ideal migration path, industry consensus has not yet emerged.
- Government agencies have adopted different positions. The U.S. National Security Agency generally favors moving directly toward standardized post-quantum algorithms, while France’s ANSSI currently recommends hybrid approaches during the transition period. These differing recommendations create practical challenges for multinational organizations that must comply with multiple regulatory frameworks.
- Technical implementation proves complex. Competing hybrid certificate formats introduce compatibility concerns across software, networking equipment, and authentication systems. Some implementations rely on certificate extensions, while others concatenate keys and signatures. Supporting every variation increases complexity and slows adoption.
- Organizations face hardware limitations. Software-based PKI platforms and flexible cryptographic libraries can begin evaluating PQC algorithms and limited hybrid deployments today. In contrast, organizations relying on certified Hardware Security Modules (HSMs), smartcards, embedded devices, or firmware-based security often depend on lengthy FIPS and Common Criteria certification cycles before new algorithms become available.
This creates a growing crypto-agility gap. Organizations with modern, software-driven PKI environments can begin testing immediately, while hardware-dependent environments may require years before production deployment becomes possible.
Building a Practical PQC Migration Roadmap
Preparing for post-quantum cryptography starts with visibility rather than deployment. The following steps offer a practical roadmap for PQC migration:
- Create a complete inventory of certificates. Set up cryptographic algorithms, APIs, applications, devices, and network infrastructure that rely on public-key cryptography. Without this visibility, organizations cannot accurately assess migration complexity.
- Organizations should establish controlled testing environments. This allows you to evaluate interoperability between PQC algorithms, certificate authorities, clients, and authentication infrastructure. Lab testing helps identify compatibility issues before they impact production systems.
- Prioritize systems based on business risk and expected lifespan. Long-lived infrastructure such as IoT devices, industrial control systems, operational technology, and embedded hardware may require earlier planning because replacing cryptography after deployment can be expensive or impossible.
- Organizations should invest in crypto-agility. Rather than designing infrastructure around a single cryptographic algorithm, PKI architectures should support the replacement of algorithms with minimal operational disruption. Flexible certificate lifecycle management, automated certificate deployment, and centralized policy enforcement all reduce the complexity of future cryptographic migrations.
Prepare Today for a Post-Quantum Future With SecureW2
Post-quantum cryptography is not a technology organizations can simply switch on overnight. It represents a long-term transformation of PKI, authentication protocols, encryption standards, and enterprise infrastructure.
Although production deployment remains limited by evolving support across RADIUS, EAP-TLS, networking hardware, and software ecosystems, organizations should not interpret this as a reason to delay planning. Building cryptographic inventories, validating interoperability in test environments, and investing in crypto-agility today will significantly reduce migration risk tomorrow.
As PQC standards continue to mature, organizations with flexible PKI architectures will be positioned to adopt new algorithms with far less disruption than those relying on rigid, hardware-dependent environments.
SecureW2 JoinNow Dynamic PKI helps organizations build crypto-agile certificate infrastructure today through:
- Automated certificate lifecycle management
- Flexible PKI deployment
- Modern certificate-based authentication
By investing in a scalable PKI architecture now, organizations can simplify future adoption of Post-quantum cryptography as standards, authentication protocols, and enterprise ecosystems continue to evolve.