For decades, organizations have relied on public-key cryptography algorithms such as RSA and Elliptic Curve Cryptography (ECC) to protect sensitive communications across networks. These technologies underpin VPNs, secure web sessions, encrypted data transfers, financial transactions, and government communications.
Today, however, CISOs and Data Protection Officers face a new challenge: the emergence of quantum computing.
While practical cryptographically relevant quantum computers have not yet arrived, security experts and government agencies agree that organizations must begin preparing now. The reason is simple. Adversaries can capture encrypted data today and store it, planning to decrypt it in the future when quantum computing capabilities mature. This growing threat is commonly known as “harvest now, decrypt later.” [whitehouse.gov], [quantum-infinite.com]
NIST Has Established the New Standard
In August 2024, the National Institute of Standards and Technology (NIST) finalized the first three Federal Information Processing Standards (FIPS) for post-quantum cryptography, marking a major milestone in cybersecurity modernization. These standards include:
- FIPS 203 (ML-KEM) for key establishment and key exchange
- FIPS 204 (ML-DSA) for digital signatures
- FIPS 205 (SLH-DSA) for hash-based digital signatures
These algorithms were specifically designed to resist attacks from both classical and future quantum computers. [csrc.nist.gov], [nist.gov]
Of particular importance for network encryption is FIPS 203, which standardizes the Module-Lattice-Based Key Encapsulation Mechanism (ML-KEM), derived from the CRYSTALS-Kyber algorithm. ML-KEM enables secure key exchange, a foundational requirement for encrypted communications across networks, VPNs, and other data-in-transit applications. [csrc.nist.gov], [nist.gov]
NIST’s guidance is clear: Organizations should begin migrating to quantum-resistant cryptography now rather than waiting for quantum computers to become operational threats. [csrc.nist.gov]
Government Guidance Is Driving Action
The push toward PQC is no longer just a technical discussion. In 2022, the Office of Management and Budget (OMB) issued Memorandum M-23-02 directing federal agencies to inventory vulnerable cryptographic systems and begin preparing migration plans for post-quantum cryptography. The memorandum specifically warns that future quantum computers could compromise currently deployed public-key cryptographic algorithms and notes that encrypted data collected today may remain vulnerable in the future. [whitehouse.gov], [quantum-infinite.com]
At the same time, the National Security Agency (NSA) has updated its Commercial National Security Algorithm Suite (CNSA 2.0) to define quantum-resistant cryptographic requirements for National Security Systems. The NSA explicitly states that RSA and ECC must ultimately be replaced with quantum-resistant alternatives. [media.defense.gov], [nsa.gov], [media.defense.gov]
Together, these initiatives signal a broader industry transition already underway.
The Challenge of Migration will Be Time and Materials
Although the standards now exist, many organizations face a practical challenge: replacing cryptographic infrastructure often requires substantial architectural changes.
Traditional encryption solutions were built around RSA and ECC. Migrating these systems can involve application modifications, infrastructure upgrades, interoperability testing, certification reviews, and lengthy deployment cycles.
For organizations handling sensitive financial, healthcare, government, defense, or intellectual property data, delaying migration may increase exposure to future quantum threats while also creating compliance concerns as industry and government requirements continue to evolve. [csrc.nist.gov], [whitehouse.gov]
A Practical Path Forward with the Librem PQC Encryptor from Santa Rosa Software
The Librem PQC Encryptor was designed to address this challenge by providing a deployable, network-level solution for protecting data-in-transit using NIST-standardized post-quantum cryptography.
Rather than requiring organizations to redesign existing applications, the platform offers a drop-in architecture that can be integrated into current network environments while supporting modern quantum-resistant encryption methods.
This approach enables organizations to:
- Protect critical network traffic against both current and future threats.
- Align with NIST’s finalized PQC standards, including FIPS 203 ML-KEM.
- Prepare for evolving federal guidance and regulatory expectations.
- Reduce the operational complexity often associated with large-scale cryptographic migrations.
- Establish a foundation for long-term cryptographic agility as additional PQC standards emerge.
Click here for more information about the PQC Encryptor from Santa Rosa Software.
Looking Ahead
The transition to post-quantum cryptography is increasingly viewed as inevitable. NIST has finalized its core standards and published migration guidance, including plans to deprecate quantum-vulnerable algorithms over time. NIST’s current roadmap envisions the eventual retirement of vulnerable public-key cryptography standards by 2035. [csrc.nist.gov]
Organizations that begin planning and deploying quantum-resistant protection today will be better positioned to manage risk, comply with future requirements, and safeguard sensitive information throughout its lifecycle.
The question is no longer whether enterprises should prepare for the quantum era. The question is how quickly they can begin.
With solutions such as the Librem PQC Encryptor, organizations can take a practical first step toward securing data-in-transit using the same post-quantum cryptographic standards now endorsed by NIST and supported by emerging government policy. [csrc.nist.gov], [csrc.nist.gov], [whitehouse.gov]
Suggested SEO Title: NIST Post-Quantum Cryptography Standards: Why Enterprises Must Secure Data-in-Transit Now
Suggested Meta Description: Learn how NIST’s new post-quantum cryptography standards are reshaping network security and how the Librem PQC Encryptor helps organizations protect data-in-transit against future quantum threats.

Recent Comments