RETROSPECTIVE RECORD · PREPARED 16 SEPTEMBER 2026The incident desk · 100 retrospective records ↗

The incident desk / Defense

Defense / From the archive · 13 August 2024 event · prepared 16 September 2026

Three NIST standards turned post-quantum cryptography into a migration

FIPS 203, 204 and 205 give organizations concrete algorithms to plan a cryptographic migration around.

Visual published with the cited source for this record: Three NIST standards turned post-quantum cryptography into a migration
Visual published with the cited source, shown for identification of the record. Credit: nist.gov · source page ↗ Rights: owner-review-pending.

What the document says

On 13 August 2024, NIST finalized three post-quantum cryptography standards. FIPS 203 specifies ML-KEM, a module-lattice-based key-encapsulation mechanism intended for general encryption; the standard itself describes it as enabling two parties to establish a shared secret key over a public channel, secured by a mathematical problem believed to remain hard even for an adversary with a quantum computer, with three parameter sets, ML-KEM-512, 768 and 1024, offering increasing security strength. FIPS 204 specifies ML-DSA as the primary digital signature standard, and FIPS 205 specifies SLH-DSA as a structurally different, hash-based signature scheme intended as a backup should weaknesses later be found in lattice-based approaches.

NIST's release states that a device capable of breaking current public-key encryption methods could appear within a decade, and it encourages system administrators to begin integrating the new standards immediately because full integration across an organization's systems takes time. CISA's guidance, current as retrieved 16 September 2026, directs federal agencies to build and maintain a current inventory of information technology that would be vulnerable to future quantum decryption, framed around reducing what the field calls harvest-now-decrypt-later risk: the practice of collecting encrypted data now with the intention of decrypting it once a capable quantum computer exists.

Confidence and limits

The standards themselves and NIST's release are primary, authoritative sources for what each algorithm specifies and when it was finalized. What remains genuinely uncertain, and what these documents do not resolve, is the timeline for a cryptographically relevant quantum computer; NIST frames this as a possibility within a decade rather than a certainty, and organizations should treat any more specific timeline claim from a vendor with caution.

Why it mattered

Before these standards existed, organizations planning for a post-quantum future had algorithms to study but no finalized, government-standardized target to build toward, which made procurement, protocol design and compliance planning difficult to commit to. Finalizing FIPS 203 through 205 converts a research question into an engineering migration with defined targets, comparable to earlier transitions between cryptographic algorithm generations, though the scale of re-keying and re-certifying systems across an economy makes this a multi-year undertaking rather than a single patch cycle.

Defensive takeaway

Treat any data you must keep confidential for a decade or more, such as long-lived state or trade secrets, as the priority for early migration planning, since that is the data most exposed to collection today for decryption later.

  • Do we have an inventory of where RSA or elliptic-curve cryptography protects data with a long confidentiality requirement?
  • Have we asked our software and hardware vendors for their post-quantum migration timeline against FIPS 203 through 205 specifically?
  • Is responsibility for cryptographic inventory and migration assigned to a specific owner, or does it currently sit with no one?

The three finalized standards do not make any system quantum-safe by themselves; an organization becomes safer only once it has actually inventoried its cryptographic dependencies and begun migrating the ones that matter most, work the standards make possible but do not perform on an organization's behalf.

Defensive takeaway

Begin, or continue, an inventory of where your organization relies on RSA or elliptic-curve cryptography for data that must remain confidential for many years, since that data is most exposed to harvest-now-decrypt-later collection today.

NIST's own standards documents and release describe what each standard specifies and when it was finalized; statements about a future quantum computer capable of breaking current encryption describe an anticipated risk rather than a confirmed present capability, and this article does not assert a timeline beyond what NIST itself states.

Sources & reading trail

NIST Releases First 3 Finalized Post-Quantum Encryption Standards ↗

Announces finalization of FIPS 203, 204 and 205 on 13 August 2024 and urges immediate integration planning.

government-primary · Source published: 13 August 2024 · Retrieved: 16 September 2026

Module-Lattice-Based Key-Encapsulation Mechanism Standard (FIPS 203) ↗

Specifies ML-KEM as a key-encapsulation mechanism designed to remain secure against an adversary with a quantum computer, with three parameter sets.

standards-body · Source published: 13 August 2024 · Retrieved: 16 September 2026

Post-Quantum Cryptography ↗

As retrieved 16 September 2026, directs federal agencies to inventory cryptographic assets vulnerable to future quantum decryption to reduce harvest-now-decrypt-later risk.

government-primary · Source published: Not established · Retrieved: 16 September 2026

Official records establish the facts; confidence labels and defensive takeaways are Patch & Proof editorial analysis. This retrospective draft does not imply the site published on the event date.