Robert Derby

Robert Derby

Senior Security Product Marketing Manager

Published
Last Updated

Post-Quantum Cryptography Explained

Post-Quantum Cryptography (PQC) refers to a new generation of cryptographic algorithms designed to withstand attacks from future quantum computers.

Today's digital world relies heavily on public-key cryptography to secure websites, applications, APIs, VPNs, software updates, digital signatures, and machine-to-machine communications. While these cryptographic systems remain secure today, advances in quantum computing could eventually make many of them vulnerable.

PQC is the industry's response to that challenge. It introduces quantum-resistant algorithms designed to protect sensitive data and trusted communications long before quantum attacks become practical.

Most discussions about PQC focus on cryptographic standards and migration timelines. Those are important topics. But they overlook a more immediate challenge.

Before organizations can migrate to quantum-resistant cryptography, they first need to understand where quantum-vulnerable cryptography exists today. That makes PQC readiness a visibility problem before it becomes a migration problem.

What Are the New PQC Standards?

The National Institute of Standards and Technology (NIST) finalized the first three post-quantum cryptography standards in 2024:

  • FIPS 203: ML-KEM for key establishment
  • FIPS 204: ML-DSA for digital signatures
  • FIPS 205: SLH-DSA as a stateless hash-based digital signature standard

These standards are designed to help organizations replace quantum-vulnerable public-key algorithms over time.

The important point for security and infrastructure teams is this: PQC will not arrive as one simple switch. Most organizations will move through a long transition period where classical cryptography, hybrid cryptography, and post-quantum algorithms may coexist.

That transition creates operational complexity.

Security teams will need to know which systems use which algorithms, which applications are dependent on older cryptographic libraries, which certificates need to be replaced, and which traffic paths still rely on quantum-vulnerable cryptography.

PQC readiness begins with that visibility.

Why Post-Quantum Cryptography Matters

The urgency around PQC is driven by a concept often called Harvest Now, Decrypt Later (HNDL).

In this scenario, attackers collect encrypted data today and store it for future use. While they may not be able to decrypt that information now, advances in quantum computing could eventually allow them to unlock data that was previously considered secure.

This creates risk for information that must remain confidential for years or even decades, including:

  • Financial records
  • Healthcare data
  • Intellectual property
  • Government communications
  • Legal documents
  • Critical infrastructure information
  • Customer and employee records

The threat is not that quantum computers will suddenly appear tomorrow.

The challenge is that organizations must begin preparing now for data that needs to remain protected long into the future.

Diagram of the Harvest Now, Decrypt Later Risk

PQC Readiness Starts with Visibility

Many organizations begin their PQC journey by evaluating cryptographic standards, vendor roadmaps, compliance requirements, and migration strategies.

Those efforts are necessary.

But they all depend on answering one foundational question:

Where are we currently using quantum-vulnerable cryptography?

That sounds straightforward. In reality, it is often one of the hardest questions to answer.

Modern enterprises operate thousands of applications, services, APIs, cloud workloads, certificates, and internal communication paths. Some are well documented. Others are not.

Before teams can prioritize migration efforts, they need visibility into:

  • Which cryptographic algorithms are currently being used
  • Which systems handle long-lived sensitive data
  • Which applications depend on older cryptographic implementations
  • Which internal communication paths may create hidden risk
  • Which systems should be prioritized first

Organizations cannot migrate what they cannot find. That is why cryptographic inventory is increasingly becoming the first step in every PQC readiness strategy.

PQC Readiness Is a Visibility Journey

Discover → Understand → Prioritize → Migrate → Validate

Inventory Tells You What Should Exist. Network Visibility Shows What Actually Exists.

Most organizations already have some form of inventory.

They maintain asset databases, certificate repositories, configuration management systems, vulnerability scanners, and architecture diagrams.

These sources provide valuable information.

But they often describe what should exist, not what is actually happening.

  • A documented application may have been upgraded, while live traffic still relies on older cryptographic dependencies.
  • A certificate inventory may identify known public-facing systems, while internal applications continue using outdated configurations.
  • A configuration database may reflect planned architecture, while real network communications reveal undocumented dependencies.

This is where network visibility becomes important. Observed network communications provide evidence of how systems are actually interacting, which cryptographic protocols are being negotiated, and where sensitive data is moving throughout the environment.

For PQC readiness, both perspectives matter.

  • Inventory provides the plan.
  • Observed network behavior provides the reality.
Declared Inventory vs Observed Network Reality

Not All Network Visibility Is Created Equal

Once organizations recognize the importance of network visibility for PQC readiness, the next question becomes: what kind of visibility is actually needed?

The answer depends on what you are trying to learn.

Some visibility tools can confirm that systems are communicating. Others can reveal how those communications are secured. A smaller group can provide the deeper evidence needed to investigate and validate what is happening across those connections.

Visibility ApproachWhat It RevealsPQC Readiness Value
Flow Data (NetFlow/IPFIX)Who communicated with whom, when, and how much data was transferred

Low Value

Useful for identifying communication patterns, but does not reveal cryptographic details

Handshake & Metadata AnalysisWhat Cryptography is being used; TLS versions, cipher suites, certificate information, and cryptographic parameters

Medium Value

Helps build cryptographic inventory and identify systems using older encryption standards, but limited context about application behavior, dependencies, and broader risk

Deep Packet Inspection (DPI)Packet-derived metadata, protocol behavior, and deeper communication context

Highest Value

Most complete view; Provides additional evidence for validating cryptographic usage, investigating dependencies, and understanding network behavior

For most organizations, cryptographic inventory begins with visibility into connection metadata and TLS handshakes. This provides the information needed to identify cryptographic algorithms, understand certificate usage, and prioritize migration efforts.

The challenge is that cryptographic inventory alone does not provide the full picture.

Security teams also need to understand where sensitive data moves, how applications communicate, which systems depend on one another, and whether migration efforts are reflected in real network behavior.

That requires visibility beyond simple connection records.

The goal is not just to know that cryptography has changed. The goal is to understand where cryptographic risk exists, how it affects the environment, and how progress can be validated over time.

The Hidden Challenge: East-West Traffic

When organizations think about cryptography, they often focus on internet-facing systems.

Websites. VPNs. External APIs. Public certificates.

These are important. But they are only part of the picture.

Some of the most sensitive communications happen inside the network.

  • Applications communicate with databases.
  • Identity systems communicate with workloads.
  • Cloud services communicate with internal infrastructure.

Business-critical data moves continuously between systems that never touch the public internet.

This internal communication, often called east-west traffic, is where many organizations discover undocumented dependencies, legacy cryptography, and sensitive data flows that were not fully understood.

A PQC strategy that only evaluates perimeter systems risks missing some of the most important cryptographic relationships inside the environment.

The East-West PQC Blind Spot

Common PQC Readiness Challenges

Most organizations are aware of PQC.

The challenge is operationalizing it.

ChallengeWhy It Matters
Unknown cryptographic usageTeams cannot migrate what they cannot identify
Internal traffic blind spotsCritical dependencies often exist inside the network
Inventory driftDocumentation rarely reflects real-world behavior
Shadow IT and unmanaged systemsUnknown assets often continue using older cryptography
Poor prioritizationNot every application carries the same level of risk
Lack of validationTeams need proof that migration efforts are working

PQC readiness is not just about selecting new algorithms. It is about building confidence in where cryptographic risk exists, how migration priorities should be established, and how progress can be measured over time.

7 Smart Questions to Ask About PQC Readiness

Most organizations understand that quantum-resistant cryptography is coming. The harder question is whether they have the visibility needed to prepare for it.

As organizations evaluate their readiness for the quantum transition, they should be able to answer the following questions:

  1. Which systems are actually using quantum-vulnerable cryptography in live communications?
  2. Can we identify cryptographic usage across east-west traffic, not just internet-facing systems?
  3. Which undocumented applications, services, or dependencies still rely on older cryptographic standards?
  4. If cryptographic standards change, what applications, systems, or communication paths could be affected?
  5. Can we validate that cryptographic changes are reflected in real network behavior?
  6. Where is sensitive data moving across the network, and what cryptography is protecting it?
  7. Are we relying on documented inventory, or observed network evidence?

These questions matter because PQC readiness is not simply a technology upgrade. It is an ongoing process of discovering, prioritizing, validating, and measuring cryptographic risk across the systems, applications, and communication paths that matter most.

How NETSCOUT Helps

PQC readiness begins with visibility.

NETSCOUT helps security teams move beyond inventories and assumptions by providing visibility into how systems actually communicate across the network, including the east-west traffic where undocumented dependencies and cryptographic risk often hide.

By combining deep packet inspection with packet-derived network intelligence, organizations can identify cryptographic usage, validate migration progress, and gain the evidence needed to make informed PQC decisions.

Before you can migrate to quantum-resistant cryptography, you need to understand what is happening across the network today.

The Bottom Line

Most conversations about Post-Quantum Cryptography focus on algorithms.

The more immediate challenge is visibility.

Organizations cannot prioritize what they cannot see. They cannot validate what they cannot observe. And they cannot measure progress based solely on documentation.

PQC readiness begins with understanding where quantum-vulnerable cryptography exists across real systems, real applications, and real communication paths.

Before organizations can migrate to the future, they need visibility into the present.

Frequently Asked Questions

What is Post-Quantum Cryptography?

Post-Quantum Cryptography (PQC) is a new class of cryptographic algorithms designed to resist attacks from future quantum computers.

Why is PQC important?

Future quantum computers could eventually break many of today's public-key cryptographic systems. Organizations need to begin preparing now, particularly for data that must remain confidential for many years.

What is Harvest Now, Decrypt Later?

Harvest Now, Decrypt Later refers to attackers collecting encrypted data today with the intention of decrypting it later as quantum computing capabilities mature.

What is the first step in PQC readiness?

The first step is understanding where quantum-vulnerable cryptography exists throughout the environment. Without visibility, organizations cannot effectively prioritize migration efforts.

Why does network visibility matter for PQC?

Network visibility helps organizations understand how systems actually communicate, which cryptographic protocols are being used, and where sensitive data flows throughout the environment. This provides important context for planning and validating PQC migration efforts.