Home Solutions Services About Us Discovery Contact Us

Strawinskylaan 411 1077XX,
Amsterdam, Netherlands

Wilhelmina van Pruisenweg 35,
2595 AN Den Haag

+31 6 11 10 62 26

[email protected]

Thales

Post-Quantum Cryptography: A Strategic Roadmap for Cybersecurity

The rise of quantum computing introduces significant challenges to existing cryptographic systems.

Estimated reading time: 5 minutes
By G.D. - Netsmart
 - 10 June 2025, Tuesday

Understanding Post-Quantum Cryptography

The rise of quantum computing introduces significant challenges to existing cryptographic systems. Quantum algorithms, such as Shor’s and Grover’s, have the potential to compromise widely used asymmetric and symmetric cryptographic methods, including RSA, DSA, Diffie-Hellman, and Elliptic Curve Cryptography (ECC). These vulnerabilities demand a proactive response to safeguard sensitive data and infrastructure.

Post-Quantum Cryptography (PQC) encompasses a suite of cryptographic algorithms engineered to withstand quantum-based attacks while operating efficiently on classical computing platforms. These algorithms leverage mathematical foundations designed to resist quantum threats, including:

  • Lattice-based cryptography: Examples include CRYSTALS-Kyber and CRYSTALS-Dilithium.
  • Code-based cryptography: Such as Classic McEliece.
  • Multivariate polynomial cryptography: For instance, Rainbow.
  • Hash-based cryptography: Including SPHINCS+.

Assessing Readiness for the Post-Quantum Era

Current State of Preparedness

Many organizations remain in the preliminary stages of preparing for the post-quantum transition. Critical systems, such as digital certificates, VPN tunnels, digital signatures, and key management frameworks, predominantly rely on RSA and ECC, which are vulnerable to quantum attacks. In 2022, the National Institute of Standards and Technology (NIST) initiated standardization of PQC algorithms, endorsing CRYSTALS-Kyber for key exchange and encryption, and CRYSTALS-Dilithium for digital signatures. By 2024, some organizations have started testing these algorithms and crafting transition strategies, but the process remains complex, resource-intensive, and long-term.

Regulatory and Policy Landscape

  • The U.S. National Security Agency (NSA) has outlined timelines for adopting PQC standards.
  • The European Union has allocated funding to advance PQC research, particularly for critical infrastructure.
  • In Turkey, the Information and Communication Technologies Authority (BTK) is encouraged to develop national roadmaps to address this transition.

Strategic Actions for Enterprises

To navigate the shift to a post-quantum cryptographic framework, organizations must adopt a comprehensive strategy that includes:

  1. Cryptographic Inventory Assessment
    Enterprises should conduct a thorough audit of cryptographic algorithms across all systems, encompassing software, hardware, data flows, third-party services, and API integrations.
  2. Risk-Based Prioritization
    Systems handling sensitive data—such as payment platforms, authentication servers, and Hardware Security Modules (HSMs)—should be prioritized for PQC adoption. The “harvest now, decrypt later” threat, where encrypted data collected today could be decrypted by quantum computers in the future, underscores the urgency of this step.
  3. Hybrid Cryptography Implementation
    During the transition, hybrid approaches combining classical and PQC algorithms will gain traction. For example, TLS 1.3 can support key exchanges using both ECC and Kyber, ensuring compatibility and security.
  4. Certificate and Key Management Overhaul
    Next-generation certificate authorities must provide PQC-compatible certificates. Corporate Public Key Infrastructure (PKI) systems will require updates to accommodate these new algorithms.

Building a Forward-Looking Strategy

Effective planning for the post-quantum era hinges on several key considerations:

  • Data Retention Periods: Long-term data storage, such as in healthcare, military, or financial sectors, necessitates swift adoption of PQC to protect sensitive records.
  • Supply Chain Dependencies: Organizations must evaluate the PQC readiness of their suppliers and partners.
  • Regulatory Compliance: Adherence to regional and industry-specific regulations will shape transition priorities.
  • Workforce Development: Cybersecurity teams must receive training to build expertise in PQC implementation and management.

Hardware Implications of the PQC Transition

The shift to PQC extends beyond software to hardware infrastructure:

  • Firewalls and VPN Devices
    Hardware-based VPNs using IPSec may face performance challenges with PQC algorithms. Manufacturers must develop firmware updates and testing protocols to ensure compatibility.
  • Smart Cards, Hardware Tokens, and TPMs
    ECC-optimized devices may lack the memory capacity for algorithms like Dilithium, necessitating new PQC-compatible hardware to maintain security and performance.

The Role of Hardware Security Modules (HSMs)

HSMs, critical for secure key generation and storage, will undergo significant changes:

  • Firmware and SDK Updates: HSM vendors must provide updates to support PQC algorithms.
  • Performance Demands: PQC algorithms, particularly for signature verification and key generation, require greater computational resources than traditional algorithms.
  • Hardware Upgrades: Existing HSMs may lack the capacity to support PQC, driving demand for next-generation hardware.
  • Key Lifecycle Management: Policies for managing hybrid key sets must be restructured to accommodate PQC requirements.

Microsoft has unveiled its Majorana 1 quantum chip. © John Brecher for Microsoft

Microsoft’s Quantum Chip Initiative and Its Impact

In 2024, Microsoft announced its entry into quantum hardware development through the “Azure Quantum Elements” program, introducing a prototype quantum chip based on topological qubit architecture. This approach prioritizes stability, error tolerance, and scalability, offering a robust foundation for quantum computing. Integrated with Microsoft’s software and cloud infrastructure, the “Quantum-as-a-Service” model aims to deliver hybrid classical-quantum computing via Azure, enabling enterprises to leverage quantum technology.

Comparing Quantum Hardware Initiatives

Company Technology Base Approach Notes
Microsoft Topological Qubit Scalable, error-tolerant design Long-term focus, high security
IBM Superconducting Qubit 1000+ qubits, supported by Qiskit Strong software ecosystem
Google Superconducting Qubit Quantum supremacy (Sycamore) High-density hardware, rapid testing
IonQ Trapped Ion Stable, high-precision operations Commercialization-focused
PsiQuantum Photonic Qubit Scalable quantum computing Laboratory-stage development

Microsoft’s investment signals that quantum computing is no longer a distant threat but a present reality, urging organizations to accelerate their PQC adoption across both software and hardware. If companies like Microsoft are starting to produce hardware, it signals a transformative turning point in the world of cryptography.

Conclusion: Netsmart’s Commitment to a Post-Quantum Future

The impact of quantum technologies on cryptography is not just a theoretical threat—it is a rapidly materializing reality. This new era requires organizations not only to adapt to technology but also to reposition themselves in terms of strategic resilience.

At Netsmart, we closely follow global developments in post-quantum cryptography and implement a comprehensive strategy to ensure our clients are prepared for this transformation through our solution partners and product portfolio.

With our advanced key management solutions, HSM integrations, certificate lifecycle management platforms, and product sets ready for hybrid encryption infrastructures, we analyze our clients’ cryptographic inventories, plan transition scenarios together, and ensure maximum security with minimal disruption at the application layer.

Additionally, through continuous training programs, PoC studies, and product compatibility tests conducted with our partners, we enable organizations to manage this technological transformation in a healthy and sustainable manner.

Netsmart acts with a vision that builds not only today’s but also tomorrow’s security. As your companion in the transition to the post-quantum era, we are ready to build a more resilient, more secure, and better-prepared digital future together.

Resources
  1. NIST Post-Quantum Cryptography Project
    https://csrc.nist.gov/projects/post-quantum-cryptography
  2. Microsoft Azure Quantum and Topological Qubit Studies
    https://www.microsoft.com/en-us/quantum/azure-quantum
    https://www.microsoft.com/en-us/research/project/stationq/
  3. IBM, Google and Other Global Quantum Players
    https://research.ibm.com/quantum
    https://quantumai.google/
    https://ionq.com/
    https://psiquantum.com/
  4. Google and Cloudflare Experiment with Hybrid PQC (TLS/IPSec)
    https://security.googleblog.com/2016/07/experimenting-with-post-quantum.html
    https://blog.cloudflare.com/post-quantum-for-all/
  5. Thales & Utimaco – PQC Support in HSMs
    https://cpl.thalesgroup.com/blog/encryption/post-quantum-cryptography-and-hsm
    https://utimaco.com/blog/post-quantum-cryptography-transition
  6. NSA & CISA – US Official PQC Transition Guides
    https://media.defense.gov/2022/Sep/12/2003074984/-1/-1/0/CSI-CNSA-2-EN.PDF
    https://www.cisa.gov/news-events/news/2023/08/21/cisa-nsa-nist-release-post-quantum-cryptography-roadmap
  7. TÜBİTAK BİLGEM – PQC Research in Türkiye
    https://bilgem.tubitak.gov.tr/tr/haber/post-kuantum-kriptografi

Post-Quantum Cryptography: A Strategic Roadmap for Cybersecurity

Thales

The rise of quantum computing introduces significant challenges to existing cryptographic systems.

More
In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization's security posture.

Simulation of Active Directory Attacks with Splunk

Splunk

In today’s post we’ll explain how to simulate Active Directory attacks using Splunk and various tools to improve an organization’s security posture.

More
In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

SIEM vs. SOAR

Versus

In this blog post, we will cut through the confusion and explain the core differences between SIEM and SOAR, two essential security tools used to protect your organization.

More
In this blog post, we will explore how to strengthen the security of CyberArk by leveraging Hardware Security Modules (HSMs).

Integration of CyberArk with HSM

CyberArk

The privileged accounts of organizations play an important role in today’s cybersecurity ecosystem. Protecting these accounts and the critical resources they access has become crucial for organizations to manage, control, and audit all privileged account activities.

More