NIST finalized post-quantum cryptography (PQC) standards in 2024. Two years later in 2026, most organizations are still not prepared.
The timeline concern:
- CRYSTALS-Kyber (FIPS 203) for general encryption
- CRYSTALS-Dilithium (FIPS 204) for digital signatures
- SPHINCS+ (FIPS 205) as stateless hash-based alternative
- "Store now, decrypt later" attacks are happening TODAY
What organizations should be doing in 2026:
- Inventory all crypto usage
- Prioritize long-lived data (certificates, backups, archives)
- Test hybrid classical+PQC deployments
- Update hardware security modules (HSMs)
Is your organization ready, or are you gambling with 10+ year data?