Glossary
Post-Quantum Glossary
Plain-language definitions of the terms, algorithms, and concepts that shape post-quantum readiness.
- Crypto-Agility
- The ability of a system to swap cryptographic algorithms and parameters without major re-engineering. Crypto-agility lets organizations adopt new standards and respond to weaknesses in existing ones with less disruption.See how we plan migrations
- Cryptographic Bill of MaterialsCBOM
- An inventory of the cryptographic assets in use across an organization algorithms, key sizes, certificates, libraries, and where they are deployed. A CBOM is the foundation for prioritizing and planning a migration.Start with discovery
- Cryptographic Inventory
- A systematic map of every place cryptography is used in an organization: algorithms, protocols, libraries, certificates, keys, data flows, firmware, and supply-chain dependencies. A cryptographic inventory is the non-negotiable prerequisite for planning any migration.Start with discoveryExplore services
- FN-DSAFALCON
- A lattice-based signature scheme (FALCON) selected by NIST for standardization as FN-DSA. The FIPS 206 standard is not yet finalized, so it should be evaluated with that status in mind when planning.Compare algorithms
- Harvest Now, Decrypt LaterHNDL
- An attack strategy in which an adversary records encrypted data today and stores it to decrypt later, once quantum computers capable of breaking current public-key cryptography become available. It makes data with a long confidentiality lifetime an immediate concern.Understand the risk
- HQC
- A code-based key-encapsulation mechanism selected by NIST as a backup to ML-KEM. Because it relies on different mathematical assumptions, it provides diversity in case lattice-based schemes are later weakened.Compare algorithms
- Key-Encapsulation MechanismKEM
- A cryptographic construction used to securely establish a shared secret key between two parties. ML-KEM and HQC are the post-quantum KEMs referenced in the NIST standards.Compare algorithms
- ML-DSAFIPS 204
- Module-Lattice-Based Digital Signature Algorithm the NIST-standardized algorithm for digital signatures, based on the scheme formerly known as CRYSTALS-Dilithium. It is the primary general-purpose signature recommendation.Compare algorithms
- ML-KEMFIPS 203
- Module-Lattice-Based Key-Encapsulation Mechanism the NIST-standardized algorithm for establishing shared secrets, based on the scheme formerly known as CRYSTALS-Kyber. It is the primary recommendation for key exchange in post-quantum systems.Compare algorithms
- NIST PQC Standards
- The family of post-quantum cryptographic standards published by the National Institute of Standards and Technology. The first finalized standards are FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA), published in August 2024. Additional standards including FIPS 206 (FN-DSA) are in progress.Compare the algorithms
- Post-Quantum CryptographyPQC
- A family of cryptographic algorithms designed to resist attacks from both classical and quantum computers. PQC replaces the public-key algorithms (such as RSA and elliptic-curve cryptography) that a large-scale quantum computer could break.Explore the algorithmsSee the services
- PQC Migration
- The multi-year process of transitioning an organization's cryptographic systems from classical public-key algorithms (RSA, ECDH, ECDSA) to NIST-standardized post-quantum algorithms. A complete migration spans cryptographic inventory, risk prioritization, hybrid deployment, certificate replacement, protocol updates, and supply-chain coordination.See migration servicesRead the FAQ
- Quantum Readiness
- An organization's state of preparedness for the cryptographic transition demanded by quantum computing. A quantum-ready organization has completed a cryptographic inventory, risk-scored its exposure, developed a migration roadmap, and begun deploying post-quantum or hybrid cryptography for its highest-priority systems.Understand the riskRequest a strategy session
- SLH-DSAFIPS 205
- Stateless Hash-Based Digital Signature Algorithm a NIST-standardized signature scheme whose security rests only on hash functions. It offers a conservative alternative to lattice-based signatures, with larger signatures in exchange for different security assumptions.Compare algorithms

