Quantum computers will eventually break RSA and ECC encryption. Post-quantum cryptography (PQC) provides quantum-resistant alternatives. The migration has already begun.
Why Act Now?
The threat model is "harvest now, decrypt later" — adversaries collect encrypted data today, planning to decrypt it once quantum computers are powerful enough. If your data has a long shelf life, you need PQC now.
NIST finalized its first PQC standards in 2024:
- ML-KEM (Kyber) — key encapsulation
- ML-DSA (Dilithium) — digital signatures
- SLH-DSA (SPHINCS+) — stateless hash-based signatures
Hybrid PQC/TLS Deployment
The safest migration path uses hybrid mode — combining classical and post-quantum algorithms:
# Nginx configuration for hybrid TLS
ssl_protocols TLSv1.3;
ssl_ecdh_curve X25519Kyber768Draft00:X25519:P-256;
ssl_prefer_server_ciphers on;This ensures security even if one algorithm is compromised.
Master this topic with hands-on labs
Go beyond reading — build real projects in sandboxed environments with expert video guidance.
Browse Courses →Infrastructure Migration Checklist
- Inventory all cryptographic usage — TLS certificates, SSH keys, API tokens, database encryption, secrets management
- Classify data by sensitivity and lifespan — Healthcare records, financial data, and government secrets need PQC first
- Update TLS libraries — OpenSSL 3.x and BoringSSL support PQC algorithms
- Test performance impact — PQC key sizes are larger, affecting handshake times
- Migrate certificates — Start with internal services, then external-facing
- Update key management — KMS and HSM systems need PQC support
- Audit CI/CD pipelines — Ensure build and deploy processes use PQC-safe crypto
Performance Considerations
PQC algorithms have different performance characteristics:
| Algorithm | Key Size | Signature Size | Speed |
|---|---|---|---|
| RSA-2048 | 256 B | 256 B | Baseline |
| ML-KEM-768 | 1,184 B | 1,088 B | ~2x faster keygen |
| ML-DSA-65 | 1,952 B | 3,293 B | ~5x faster signing |
| SLH-DSA-128s | 32 B | 7,856 B | Slower, conservative |
Larger key and signature sizes increase bandwidth and storage requirements. Plan for 2-5x larger TLS handshakes.
Kubernetes and PQC
For Kubernetes clusters, focus on:
- etcd encryption: Rotate encryption keys to PQC-safe algorithms
- Service mesh TLS: Update Istio/Linkerd CA certificates
- Secrets management: Ensure Vault or KMS supports PQC
- Container image signing: Update Sigstore/cosign to PQC signatures
Get weekly IT automation tips
Docker, Ansible, Terraform, MLOps — curated insights delivered to your inbox. No spam.
Subscribe Free →Cloud Provider PQC Support (2026)
- AWS: KMS supports ML-KEM, S3 hybrid encryption available
- GCP: Cloud KMS PQC preview, Certificate Authority Service with hybrid certs
- Azure: Key Vault PQC preview, hybrid TLS on Application Gateway
FAQ
When will quantum computers break current encryption? Estimates range from 2030 to 2040+. The exact timeline is uncertain, which is why migration should start now.
Can I just switch to PQC overnight? No. PQC migration is a multi-year process. Start with inventory and hybrid deployments.
Does PQC affect application performance? Slightly. Larger keys increase TLS handshake time by 10-30ms. For most applications, this is negligible.
---
Ready to go deeper?
This article is part of a hands-on learning path. Continue building your skills with our course catalog on CopyPasteLearn.
Ready to learn by doing?
Stop reading tutorials — start building. Expert video courses with hands-on labs in real sandboxed environments.
Related Articles
Cert Manager Kubernetes TLS Guide
Cert-manager automates TLS certificate management in Kubernetes with Let's Encrypt. Learn how to install cert-manager, configure issuers, and secure your.
Ubuntu 26.04 Makes sudo-rs Default
Ubuntu 26.04 LTS replaces the 44-year-old C sudo with sudo-rs, a Rust rewrite. Learn what changes, why it matters for security, and what else ships.
Quality vs Safety in Engineering
Quality and safety are not the same thing in software engineering. Learn when to prioritize safety over quality, how to build guardrails without slowing.
Postgres Operator for Kubernetes
Run production PostgreSQL on Kubernetes with CloudNativePG or Zalando Postgres Operator. Learn automated failover, backup, and high availability for stateful.
PostgreSQL for DevOps Engineers
PostgreSQL for DevOps teams. Backup and restore, streaming replication, performance monitoring, PgBouncer, and Ansible automation.
Preemptive Cybersecurity Strategy
Shift from reactive to preemptive cybersecurity with automated threat detection, predictive vulnerability management, and proactive defense strategies.
Explore topics
Browse more articles on the topics covered here.