Skip to main content
Skip to content
Glossary

Post-Quantum Glossary

Plain-language definitions of the terms, algorithms, and concepts that shape post-quantum readiness.

Crypto-Agility
The ability of a system to swap cryptographic algorithms and parameters without major re-engineering. Crypto-agility lets organizations adopt new standards and respond to weaknesses in existing ones with less disruption.See how we plan migrations
Cryptographic Bill of MaterialsCBOM
An inventory of the cryptographic assets in use across an organization algorithms, key sizes, certificates, libraries, and where they are deployed. A CBOM is the foundation for prioritizing and planning a migration.Start with discovery
Cryptographic Inventory
A systematic map of every place cryptography is used in an organization: algorithms, protocols, libraries, certificates, keys, data flows, firmware, and supply-chain dependencies. A cryptographic inventory is the non-negotiable prerequisite for planning any migration.Start with discoveryExplore services
FN-DSAFALCON
A lattice-based signature scheme (FALCON) selected by NIST for standardization as FN-DSA. The FIPS 206 standard is not yet finalized, so it should be evaluated with that status in mind when planning.Compare algorithms
Harvest Now, Decrypt LaterHNDL
An attack strategy in which an adversary records encrypted data today and stores it to decrypt later, once quantum computers capable of breaking current public-key cryptography become available. It makes data with a long confidentiality lifetime an immediate concern.Understand the risk
HQC
A code-based key-encapsulation mechanism selected by NIST as a backup to ML-KEM. Because it relies on different mathematical assumptions, it provides diversity in case lattice-based schemes are later weakened.Compare algorithms
Key-Encapsulation MechanismKEM
A cryptographic construction used to securely establish a shared secret key between two parties. ML-KEM and HQC are the post-quantum KEMs referenced in the NIST standards.Compare algorithms
ML-DSAFIPS 204
Module-Lattice-Based Digital Signature Algorithm the NIST-standardized algorithm for digital signatures, based on the scheme formerly known as CRYSTALS-Dilithium. It is the primary general-purpose signature recommendation.Compare algorithms
ML-KEMFIPS 203
Module-Lattice-Based Key-Encapsulation Mechanism the NIST-standardized algorithm for establishing shared secrets, based on the scheme formerly known as CRYSTALS-Kyber. It is the primary recommendation for key exchange in post-quantum systems.Compare algorithms
NIST PQC Standards
The family of post-quantum cryptographic standards published by the National Institute of Standards and Technology. The first finalized standards are FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), published in August 2024. Additional standards including FIPS 206 (FN-DSA) are in progress.Compare the algorithms
Post-Quantum CryptographyPQC
A family of cryptographic algorithms designed to resist attacks from both classical and quantum computers. PQC replaces the public-key algorithms (such as RSA and elliptic-curve cryptography) that a large-scale quantum computer could break.Explore the algorithmsSee the services
PQC Migration
The multi-year process of transitioning an organization's cryptographic systems from classical public-key algorithms (RSA, ECDH, ECDSA) to NIST-standardized post-quantum algorithms. A complete migration spans cryptographic inventory, risk prioritization, hybrid deployment, certificate replacement, protocol updates, and supply-chain coordination.See migration servicesRead the FAQ
Quantum Readiness
An organization's state of preparedness for the cryptographic transition demanded by quantum computing. A quantum-ready organization has completed a cryptographic inventory, risk-scored its exposure, developed a migration roadmap, and begun deploying post-quantum or hybrid cryptography for its highest-priority systems.Understand the riskRequest a strategy session
SLH-DSAFIPS 205
Stateless Hash-Based Digital Signature Algorithm a NIST-standardized signature scheme whose security rests only on hash functions. It offers a conservative alternative to lattice-based signatures, with larger signatures in exchange for different security assumptions.Compare algorithms
Put the terms to work

Build Your Post-Quantum Roadmap

Turn these concepts into a prioritized plan for your own systems.