Blog


Exploring the future of security — From Hardware Root of Trust to End-to-End Quantum-Safe Protection.


[FAQ]Quantum Security Explained โ€• Beginner's FAQ 0n PQC

ICTK
30 Jun 2026

Quantum Computing and PQC โ€” Not as Distant or Difficult as You Think

Post-Quantum Cryptography (PQC) Basics โ€” 11 Questions Answered

"Once quantum computers are powerful enough, today's encryption will be cracked" โ€” it's a statement most people have heard at least once. But few can explain precisely what is at risk, why, and when. Post-Quantum Cryptography (PQC) is the industry's standardized answer to that question. Here are 11 questions that cover the essentials.

Q1. Why would a quantum computer be able to break today's encryption?

The encryption standards underpinning today's internet security โ€” RSA and ECC (Elliptic Curve Cryptography) โ€” rely on the fact that factoring large numbers or solving discrete logarithm problems takes an impractical amount of time. A classical computer would need decades. A sufficiently powerful quantum computer, however, could apply Shor's Algorithm to solve these problems in what amounts to no time at all. The mathematical assumptions that encryption security rests on would simply collapse.

Q2. So what exactly is PQC?

PQC is a new family of cryptographic algorithms built on mathematical problems that are hard for quantum computers to solve โ€” problems such as lattice-based problems and code-based problems. Like existing encryption, PQC runs on classical computers. What sets it apart is that it is designed to remain secure even against quantum computing attacks.

Q3. How far along are NIST's PQC standards?

In August 2024, NIST finalized three algorithms as PQC standards: ML-KEM (CRYSTALS-Kyber), ML-DSA (CRYSTALS-Dilithium), and SLH-DSA (SPHINCS+), published as FIPS 203, 204, and 205 respectively. In March 2025, HQC was selected as a backup algorithm for ML-KEM, and FALCON-based FIPS 206 is currently under development. The core standards are already finalized and ready for immediate implementation.

Q4. What are ML-KEM and ML-DSA each used for?

ML-KEM (formerly Kyber) is used for key exchange and general encryption โ€” in protocols like TLS, VPN, and 5G core networks, where two systems need to open a secure communication channel. ML-DSA (formerly Dilithium) is used for digital signatures โ€” in code signing, certificates, and firmware authentication, where the question is "did this data really come from who it claims to come from?"

Q5. Do we need to migrate to PQC right now?

NIST recommends starting migration now, for two reasons. First, cryptographic transitions take years to complete. Second, there is the threat of "Harvest Now, Decrypt Later" attacks โ€” where adversaries collect encrypted data today and decrypt it once quantum computers become capable enough. Any data currently in transit that needs to remain confidential for years is already at risk.

The United States has moved beyond recommendations to mandates. On June 22, 2026, President Trump signed Executive Order 14412, "Securing the Nation Against Advanced Cryptographic Attacks." The order requires federal agencies to transition high-value assets and high-impact systems to PQC for key establishment by December 31, 2030, and for digital signatures by December 31, 2031. Federal contractors face the same FIPS compliance deadline of December 31, 2030, and each agency must designate a PQC migration lead within 30 days of the order.

The significance of this executive order lies less in the deadlines themselves and more in what they signal: PQC migration has moved from a research-stage recommendation to a mandated operational task with defined timelines and assigned accountability. For companies operating within global supply chains, PQC readiness may become a practical business requirement at the point of transacting with U.S. federal agencies or contractors.

Q6. When will quantum computers actually become practical?

Expert predictions vary, but most fall within a ten-year window. Pinpointing an exact date is difficult โ€” but the critical point is that migration itself takes years. Waiting for quantum computers to arrive before beginning the transition is already too late, and that is the consensus across the industry.

Q7. What is a hybrid approach?

In the early stages of transition, a hybrid key exchange โ€” combining a classical algorithm (RSA or ECC) with a PQC algorithm (e.g., Kyber + X25519) โ€” is the recommended approach. The rationale is insurance: in the event PQC algorithms prove to have unforeseen vulnerabilities, the classical layer still provides a baseline level of protection.

Q8. What is the most challenging part of implementing PQC?

Key and signature sizes are significantly larger than those of classical algorithms. ML-DSA signatures are several times the size of ECDSA signatures, which affects TLS handshake size and certificate chain length. Additionally, algorithms like FALCON require floating-point arithmetic, which introduces potential side-channel attack exposure โ€” making constant-time implementation a critical requirement at the development stage.

Q9. Can PQC be applied to IoT and embedded devices?

ML-KEM and ML-DSA do not require floating-point operations, which means they run reasonably efficiently on ARM microcontrollers and embedded SoCs. That said, devices with constrained memory and processing resources will feel the impact of larger key and signature sizes more acutely, making hardware acceleration or lightweight implementation an important consideration.

Q10. How should an organization start its PQC migration?

The first step is a cryptographic asset inventory โ€” a complete map of which cryptographic algorithms are in use across every system, application, API, and database in the organization. From there, migration should begin with the highest-priority areas (databases, API gateways, authentication servers) using a hybrid approach, with transition timelines and compliance requirements managed in parallel.

Q11. Does South Korea have its own post-quantum cryptography standards?

South Korea is developing its own independent standards. The National Intelligence Service and the Ministry of Science and ICT launched the Korean Post-Quantum Cryptography competition (KpqC) in November 2021. Starting with 16 candidate algorithms, 8 advanced to the first round in December 2023. In January 2025, four algorithms were finalized: AIMer (developed by Samsung SDS and KAIST), and SMAUG-T and HAETAE (developed by CryptoLab). Standardization is now proceeding under the government's National Post-Quantum Cryptography Transition Master Plan.

As of 2026, the Ministry of Science and ICT has included nationwide PQC transition as a new initiative in its R&D implementation plan, with cryptographic module development and cryptographic agility identified as core priorities. The government's target is to migrate all critical national information and communications infrastructure to PQC by 2035.

NIST standards and KpqC standards are not alternatives โ€” they are parallel tracks. Organizations running global services should prioritize NIST standards, while those expanding into South Korea's public sector or defense market will also need to assess KpqC compliance.


๐Ÿ“Œ Go deeper on PQC with the PAZI Series
PQC is one of the four core pillars of ICTK's PAZI Architecture.
To see how post-quantum cryptography is implemented within a real security architecture, explore the PAZI Executive Insight Series.

โ†’ View the complete PAZI Insight Series


Key Takeaways

PQC standards are finalized, and migration is no longer a question of whether โ€” only when. With the U.S. executive order setting hard deadlines and South Korea's KpqC standardization underway, the gap between organizations that start now and those that wait will ultimately come down to one question: when did they begin?


๐Ÿ” See how ICTK implements PQC
ICTK builds PQC into hardware security chips from the ground up โ€” delivering quantum resistance at the physical layer that software-only transitions cannot reach.

โ†’ Explore ICTK Security Solutions
โ†’ Contact Usย 







Copyright โ“’ 2025 ICTK.com. All Rights Reserved.

16, Gangnam-daero 84-gil, Gangnam-gu, Seoul, Republic of Korea (06241)

+82.2.569.0010