What Is Post-Quantum Cryptography, and Why Federal Agencies Can't Wait
For more than two decades, public key cryptography has been the invisible backbone of federal identity. Every time a PIV card is tapped, a certificate is validated, or a document is digitally signed, algorithms like RSA and Elliptic Curve Cryptography (ECC) are quietly doing the work of proving who's who and keeping data safe in transit. That foundation has held up remarkably well - but it was never built to withstand a quantum computer.
The Threat Isn't Hypothetical Anymore
Quantum computing has moved from theoretical research to experimental hardware backed by serious public and private investment. Large-scale, fault-tolerant quantum machines capable of breaking RSA and ECC don't exist yet, but credible estimates put their arrival within the next 5 to 15 years - and possibly sooner.
That timeline matters less than what's already happening today. Adversaries are running "harvest-now, decrypt-later" attacks: collecting encrypted data right now, with the explicit plan of decrypting it once a sufficiently powerful quantum computer becomes available. For federal agencies, this means sensitive identity data, communications, and credentials encrypted today could be exposed retroactively the moment quantum computing catches up - regardless of how strong today's encryption looks.

What Post-Quantum Cryptography Actually Is
Post-quantum cryptography (PQC) refers to a new generation of cryptographic algorithms designed to resist attacks from quantum computers, while still running on the conventional hardware and software federal agencies already use. PQC isn't quantum cryptography - it doesn't require quantum hardware or quantum communication channels. Instead, it relies on mathematical problems that quantum algorithms aren't efficient at solving, such as lattice problems and hash-based functions, to deliver the same core functions cryptography has always provided: authentication, encryption, key exchange, and digital signatures.
In 2022, the National Institute of Standards and Technology (NIST) announced the first group of algorithms selected for standardization following its Post-Quantum Cryptography Standardization Project, launched in 2016:
- CRYSTALS-Kyber — a lattice-based key encapsulation mechanism for secure key exchange and encryption
- CRYSTALS-Dilithium — a lattice-based digital signature algorithm balancing strong security with efficiency
- FALCON — a compact, fast lattice-based signature algorithm suited to constrained environments
- SPHINCS+ — a stateless, hash-based signature scheme built for long-term quantum resilience
NIST has since translated these into formal federal standards: FIPS 203 (derived from Kyber), FIPS 204 (derived from Dilithium), and FIPS 205 (derived from SPHINCS+) — giving agencies a concrete, standardized path to adopt PQC rather than a moving target.
Why Agencies Specifically Can't Afford to Wait
Cryptographic transitions inside federal identity systems are not quick fixes. They touch interdependent systems - smart cards, firmware, middleware, certificate authorities, operating systems, and browsers - all of which need to evolve together. Layer in compliance mandates and the requirement for uninterrupted operations, and a full PQC migration realistically takes years, not months.
That timeline is exactly why early action matters. Federal directives are already pushing agencies in this direction: National Security Memorandum 10 (NSM-10) and OMB Memorandum M-23-02 both require agencies to inventory their cryptographic assets and build transition plans toward quantum-resistant algorithms. Waiting for quantum computers to arrive before starting this work means trying to migrate complex identity infrastructure under pressure, instead of through a deliberate, tested rollout.
Early adopters gain real advantages:
- Security resilience against both today's and tomorrow's adversaries
- Operational preparedness through phased implementation rather than a rushed cutover
- Interoperability leadership, shaping standards and best practices instead of just following them
-
Trust preservation for digital credentials and identity assurance over the long term
The Path Forward Is Already Being Tested
This isn't purely theoretical for federal identity systems anymore. GSA, in collaboration with industry partners, has already begun experimenting with PQC integration directly into the PIV credential ecosystem - issuing real credentials using post-quantum algorithms like Dilithium 2, 3, and 5 on production-grade smart card hardware, and validating digital signature workflows built on those algorithms. These experiments are surfacing exactly the kind of practical findings agencies need: where firmware and hardware are ready, where middleware and operating systems still have gaps, and what a realistic migration path looks like.
Post-quantum cryptography is no longer a distant research topic - it's an active, testable part of federal identity infrastructure today. Agencies that start inventorying systems, piloting hybrid credentials, and engaging with PQC-ready hardware now will be the ones positioned for a secure, orderly transition. Those that wait will be migrating under far more pressure, with far less runway.
ZTPass is actively engaged in advancing post-quantum readiness for federal identity systems, including direct participation in PQC credential issuance experiments on hardware supporting both ML-KEM and ML-DSA algorithms. To learn more about ZTPass's PQC-ready authentication solutions, visit www.ztpass.com.