Skip to main content
Skip to content
Reference Guides

Post-Quantum Cryptography Reference Guides

In-depth technical guides on NIST-standardized post-quantum algorithms, migration methodology, and cryptographic risk each with authoritative citations, direct quotes from NIST FIPS standards, and reference links to NSA, OMB, ETSI, and IETF publications.

Complete Guide to Post-Quantum Cryptography

A comprehensive reference covering why classical public-key cryptography is being replaced, the NIST-standardized algorithms (ML-KEM, ML-DSA, SLH-DSA), the harvest-now decrypt-later threat, and how to plan and execute a cryptographic migration program.

post-quantum cryptographyPQCML-KEM
22 min

What Is Harvest Now Decrypt Later?

Harvest-now, decrypt-later (HNDL) is the most immediate cryptographic risk requiring action before quantum computers exist at scale. This guide explains how HNDL attacks work, what data is most exposed, and why cryptographic migration cannot wait.

harvest now decrypt laterHNDLquantum risk
18 min

ML-KEM Explained

ML-KEM (NIST FIPS 203) is the primary post-quantum key encapsulation mechanism, replacing RSA and ECDH in TLS, VPNs, and SSH. This guide explains how it works, its parameter sets, hybrid deployment, and migration from ECDH.

ML-KEMFIPS 203CRYSTALS-Kyber
16 min

ML-DSA Explained

ML-DSA (NIST FIPS 204) is the primary post-quantum digital signature algorithm, replacing ECDSA and RSA signatures in PKI, code signing, and authentication. This guide explains how it works, its parameter sets, and migration from ECDSA.

ML-DSAFIPS 204CRYSTALS-Dilithium
16 min

SLH-DSA Explained

SLH-DSA (NIST FIPS 205) is a stateless hash-based post-quantum signature scheme providing algorithm diversity independent of lattice mathematics. This guide explains when to use SLH-DSA versus ML-DSA, its parameter sets, and its role in long-term trust infrastructure.

SLH-DSAFIPS 205SPHINCS+
14 min

Crypto-Agility Explained

Crypto-agility is the architectural property that allows cryptographic algorithms to be replaced without re-engineering dependent systems. This guide explains what crypto-agility means, why it matters for post-quantum migration, and how to build crypto-agile architecture.

crypto-agilitycryptographic agilityPQC migration
18 min

Cryptographic Discovery

Cryptographic discovery is the process of identifying every algorithm in use across an organization's systems, protocols, libraries, and supply chains. This guide explains discovery methods, how to build a CBOM, and how to translate findings into a migration roadmap.

cryptographic discoveryCBOMcryptographic inventory
17 min

Quantum Risk Assessment

A quantum risk assessment scores an organization's cryptographic exposure by data sensitivity, confidentiality lifetime, system criticality, and regulatory context. This guide explains the four risk dimensions and how to translate findings into a prioritized migration roadmap.

quantum risk assessmentcryptographic riskPQC migration
16 min

Cryptographic Bill of Materials (CBOM) Guide

A Cryptographic Bill of Materials (CBOM) is a structured inventory of every cryptographic asset in an organization's systems. This guide explains what a CBOM contains, how to build one, and how to use it as the foundation of a post-quantum migration program.

CBOMcryptographic bill of materialsSBOM
15 min

Hybrid Cryptography Guide

Hybrid cryptography combines classical and post-quantum algorithms so both must be broken simultaneously for security to be compromised. This guide explains how hybrid key establishment and hybrid signatures work, their security properties, and how to deploy them during PQC migration.

hybrid cryptographyhybrid KEMhybrid signatures
16 min