Governments Accelerate Post-Quantum Cryptography Shift as Deadlines Loom
Quantum computers capable of breaking widely used RSA and elliptic-curve cryptography remain under development, but the threat has already created a “harvest now, decrypt later” risk for sensitive data. The U.S. National Institute of Standards and Technology finalized its first three post-quantum cryptography standards on Aug. 13, 2024, giving governments and companies a technical foundation for replacing vulnerable algorithms across software, hardware, certificates and communications infrastructure.
A Taiwanese expert’s review of the global landscape in 2026 says governments, technology companies and semiconductor suppliers are accelerating migration plans as regulatory and procurement requirements take shape. U.S. agencies are working toward a 2035 federal transition target while inventorying cryptographic systems and incorporating quantum-resistant standards into technology refresh cycles. Organizations are being urged to build cryptographic agility now so algorithms can be replaced without disruptive redesigns across products, networks and supply chains.
All Coverage
1 original reportsThe Backstory
The history behind this eventF5 Urges Full Cryptographic Asset Inventory for PQC Shift
Quantum computers could eventually break widely used public-key encryption, pushing companies to prepare for post-quantum cryptography, or PQC. Cybersecurity provider F5 said the transition must extend beyond replacing TLS certificates. Organizations also need visibility into algorithms, keys, protocols and other cryptographic components embedded across applications, infrastructure and supply chains, where overlooked legacy technology could create security gaps.
F5 recommended that companies begin with a comprehensive inventory and adopt a machine-readable Cryptographic Bill of Materials, or CBOM, to document where cryptographic assets reside, how they are used and what systems depend on them. Because no single discovery method can cover every environment, businesses should combine network traffic analysis, source-code scanning and configuration reviews to reduce blind spots, assess exposure and prioritize upgrades according to risk and operational importance.
PQC Signatures Push Packets Beyond MTU Limits
The U.S. National Institute of Standards and Technology finalized its first post-quantum cryptography standards in August 2024, accelerating plans to replace RSA and elliptic-curve systems that could eventually be broken by quantum computers. The transition is not a simple software swap: PQC public keys and signatures are often far larger than their classical counterparts. Once protected traffic exceeds the common 1,500-byte Ethernet maximum transmission unit, cryptographic migration begins to affect packet handling, transport protocols and network architecture.
Recent deployment work has highlighted the operational risk. Adding PQC signatures to TLS handshakes or VPN traffic can push a single message beyond the 1,500-byte threshold, triggering IPv4 fragmentation or requiring endpoints to resize packets under IPv6. Some firewalls and middleboxes may treat a surge in fragmented traffic as a denial-of-service attack and discard it. Network operators must therefore reassess path-MTU discovery, maximum segment size settings, certificate-chain size and device compatibility before broad deployment.
Long-Lived Chips Drive Race to Embed Post-Quantum Security
Quantum computers could eventually break widely used public-key cryptography, creating an unusually long planning horizon for semiconductor makers. Chips deployed in vehicles, industrial systems and other infrastructure can remain in service for 10 to 20 years, meaning hardware designed today may still be operating when quantum attacks become practical. The industry is therefore moving post-quantum cryptography, or PQC, into the design phase.
The latest push is turning PQC migration into a contest over chip architecture and power, performance and area, known as PPA. Global semiconductor groups and Taiwanese IC designers are reworking cryptographic accelerators and open-source roots of trust to handle more complex algorithms efficiently. The central challenge is to add durable quantum-resistant protection without sharply increasing silicon area, energy use or cost over products’ extended operating lives.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →