Why Post-Quantum Cryptography Starts With Credentials
Quantum computers will soon break public-key cryptography, making encrypted data vulnerable. Organizations should start migrating to quantum-resistant cryptography, prioritizing credentials.
Intelligence analysis by Llama 3.3 70B

The advent of quantum computers poses a significant threat to public-key cryptography, making it essential for organizations to transition to quantum-resistant cryptography, starting with credentials.
Imagine you have a safe with a special lock that only you and your friend know how to open. But one day, someone invents a super powerful tool that can break that lock. That's kind of what's happening with quantum computers and the locks we use to keep data safe on the internet. We need to start using new, stronger locks, especially for important things like passwords and secret keys.
Analysis
The Quantum Threat to Public-Key Cryptography
The emergence of quantum computers has significant implications for public-key cryptography, which is used to establish trust and secure data between systems. According to the Global Risk Institute's 2025 Quantum Threat Timeline report, security specialists believe a cryptographically relevant quantum computer is likely to be available within 15 years. This threat is not new, dating back to 1994 when Peter Shor proved that a powerful quantum computer could efficiently factor large numbers and compute discrete logarithms, posing a threat to public-key cryptography.
The Risk of Harvest Now, Decrypt Later
The tactic of Harvest Now, Decrypt Later, where an attacker captures encrypted traffic today and decrypts it when a quantum computer is available, makes the quantum threat relevant today. With a capable quantum computer plausibly available within 15 years, any data intercepted and harvested today should be treated as data already exposed. This underscores the urgency of migrating to quantum-resistant cryptography, particularly for credentials, which have a long confidentiality lifetime and are thus more vulnerable to this tactic.
Prioritizing Credentials in Quantum Migration
Given that credentials carry major risk in a post-quantum future due to their long lifespan and the growing population of Non-Human Identities (NHIs) like service accounts and API keys, organizations should take a credentials-first approach to quantum migration. This involves inventorying existing cryptography, prioritizing risk over size, migrating to hybrid cryptography, and building for crypto-agility. By focusing on credentials and adopting hybrid cryptography, organizations can ensure that their most vulnerable data is protected against both traditional and quantum attackers.
Key points
- Quantum computers will soon break public-key cryptography
- Credentials are particularly vulnerable due to their long lifespan
- Organizations should take a credentials-first approach to quantum migration
- Hybrid cryptography can protect against both traditional and quantum attackers
By migrating to quantum-resistant cryptography, organizations can protect their data and credentials from the potential threats posed by quantum computers, ensuring the confidentiality and integrity of their information. This proactive approach can also foster trust among customers and partners, demonstrating a commitment to security and privacy.
The transition to quantum-resistant cryptography is complex and time-consuming, requiring significant resources and investment. If organizations fail to prioritize this migration, they risk exposing their data and credentials to quantum attacks, potentially leading to significant financial and reputational losses.



