The one quantum application with a deadline
Everything else on this site is "someday." Security is "already." A large fault-tolerant quantum computer running Shor's algorithm would break RSA and elliptic-curve cryptography: the locks on most internet traffic, banking and signatures. That machine does not exist and is likely years-to-decades away. But the defense cannot wait, for one reason with a name: harvest now, decrypt later. Encrypted data stolen today can be stored cheaply and unlocked by a future machine. Anything that must stay secret for a decade is already at risk.
That logic, not panic, is why the migration started while quantum computers remain small.
The new locks are already standardized
After an eight-year open competition, NIST published the first post-quantum cryptography standards on August 13, 2024: FIPS 203 (ML-KEM, key encapsulation), FIPS 204 (ML-DSA, signatures) and FIPS 205 (SLH-DSA, hash-based signatures), with a further algorithm, HQC, selected in 2025 as a backup. These run on ordinary computers: no quantum hardware required to be protected.
Deployment is not theoretical. Signal added post-quantum protection to its key exchange in 2023; Apple shipped its PQ3 protocol in iMessage in 2024; Chrome and major infrastructure providers rolled out hybrid post-quantum key exchange for TLS across 2023-2024. Chances are good some of your traffic is already quantum-resistant.
The physics-based defense
Separately from the new math, quantum physics offers its own security primitive: quantum key distribution, where any eavesdropper on a quantum link unavoidably disturbs it and reveals themselves. China's Micius satellite demonstrated space-to-ground QKD in peer-reviewed experiments, and a Beijing-Shanghai fiber backbone carries quantum-secured government and banking traffic. QKD is real but niche. It needs special infrastructure, and most security agencies recommend post-quantum cryptography as the practical defense, with QKD as a specialized complement.
The full story (Shor, the standards table, the migration timeline) lives on the Quantum Security page.
التحفظ الصادق: Post-quantum cryptography runs on classical computers. This is actionable today and independent of quantum hardware timelines.
The full security story (Shor, harvest-now-decrypt-later, the NIST standards table and the migration) lives on الأمان الكمي.