A look at the competition to develop new encryption standards to guard against quantum-computing attacks and replace public-key cryptography methods like RSA
Sara Castellanos / Wall Street Journal : Tweets: @chrispeikert , @mchui , and @scastellwsj Tweets: Chris Peikert / @chrispeikert : The Wall Street Journal has a good overview of the ongoing #NISTPQC post-quantum cryptography process. https://www.wsj.com/... Michael Chui / @mchui : Via @ChrisPeikert via @SCastellWSJ Experts are trying to design cryptographic systems that will be secure against quantum computers, which they don't know how to build and can only assume will exist https://www.wsj.com/... Sara Castellanos / @scastellwsj : My latest for @WSJ 's Future of Everything section: Hundreds of cryptographers are taking part in a competition to develop new encryption standards to safeguard online data >>> https://www.wsj.com/...
Context & Ripple Effects
This story sits mid-arc in a decade-long standards effort. The alarm was sounded back in 2015, when physicists argued modern encryption techniques must adapt to resist quantum attacks, and NIST responded by opening its PQC process — the #NISTPQC competition this WSJ overview covers — drawing hundreds of cryptographers into a multi-round bake-off to succeed RSA.
What makes the timing matter is the asymmetry the coverage keeps returning to: adversaries can record encrypted traffic today and decrypt it once a quantum computer exists, which is why US agencies were already retooling for harvest-now-decrypt-later threats before any standard was final. The competition Peikert and Castellanos describe is the front end of that migration.
First-order effects
- Hundreds of competing cryptographers and their candidate algorithms now face successive rounds of public cryptanalysis inside NISTPQC, with weak submissions eliminated and survivors moving toward standardization.
- Organizations whose security rests on RSA and other public-key methods gain an early mandate to inventory where those algorithms live, since data encrypted today remains exposed to future quantum decryption.
Second-order effects
- Once NIST settles on winners — as it did with its selection of four quantum-resistant algorithms two years later — software vendors, hardware makers, and certificate authorities must rebuild their crypto stacks around the chosen primitives.
- Security budgets shift toward crypto-agility: buyers start demanding products whose encryption can be swapped without redesign, pressuring vendors still hard-coding RSA.
Third-order effects
- If the pattern holds, the industry moves from a single dominant public-key family to standardized post-quantum suites rolled out over years — a global migration NIST formalized when it moved from selection toward publishing final algorithms in 2024.
- Standards bodies, not individual vendors, become the choke point for cryptographic trust worldwide, since every government and enterprise ultimately adopts whatever NIST certifies.
The trend: Post-quantum cryptography is moving from an open research competition into mandated global standards, with NIST's multi-year process deciding what replaces RSA across the internet's security infrastructure.