Post quantum cryptography checklist for home users and small businesses [2026]

Started by GradientPiston, Today at 01:34 AM

Previous topic - Next topic

0 Members and 1 Guest are viewing this topic.

Topic: Post quantum cryptography checklist for home users and small businesses [2026]   Views(Read 41 times)
Active members in this topic:
GradientPiston(1)

GradientPiston

This forum is named after Q-Day, the point when a quantum computer could break the public key encryption that protects most of the internet. Nobody knows when that will happen, but the move to post quantum cryptography is already well under way. The good news is that most home users and many small businesses are already protected in more places than they realise. This checklist sets out what has changed, what you can do and what you can safely leave to your suppliers

First, a quick summary of where the standards stand. NIST published the first three post quantum standards on 13 August 2024: FIPS 203 (ML-KEM) for encryption and key exchange, and FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA) for digital signatures. HQC was chosen in March 2025 as a backup encryption algorithm, with a final standard expected in 2027. FN-DSA, due as FIPS 206, still had no published draft at the end of September 2026

For home users

1. Keep your browser and operating system updated. Chrome and Edge 131 or later, Firefox 132 or later and Safari 26 already use hybrid post quantum key exchange by default when the website supports it
2. Update Apple devices to iOS 26 or macOS 26 if you can. Apple says quantum secure TLS is on by default there for system services and many apps, when the server supports it
3. Use messaging apps with post quantum protection. Signal added it in 2023 and strengthened it in October 2025, and iMessage has used Apple's PQ3 protocol since iOS 17.4
4. Do not panic about passwords or files encrypted with AES-256. The main quantum threat is to public key cryptography such as RSA and elliptic curves, not to strong symmetric encryption
5. Be wary of products sold as quantum proof. Look for the NIST names, ML-KEM, ML-DSA and SLH-DSA, rather than marketing slogans

For small businesses

6. If you mainly use standard IT, keep it updated. The UK's NCSC says that for small firms using mainly commodity browsers, operating systems and devices, migration should happen seamlessly as vendors update their products
7. Ask your suppliers about their post quantum plans, and write it into contracts where you can. This is one of the three core steps in the 2023 quantum readiness factsheet from CISA, the NSA and NIST
8. Make a list of where you use encryption. The same factsheet recommends a cryptographic inventory, covering websites, VPNs, remote access, backups, signing keys and any custom software
9. Think about how long your data needs to stay secret. Harvest now, decrypt later means anything intercepted today could be read once a large enough quantum computer exists, so long lived secrets matter most
10. If you run your own servers, check what they support. OpenSSH 10.0, released in April 2025, uses a hybrid post quantum key exchange by default, and major web providers like Cloudflare already support it for websites
11. Plan for crypto agility. That means systems that can switch algorithms without a rebuild, and running traditional and post quantum methods side by side during the change, as the NCSC recommends
12. If you build custom software or handle sensitive data, follow the NCSC timeline. Discovery and planning by 2028, priority migration by 2031 and full migration by 2035

The scale of the change so far is impressive. Cloudflare reported in June 2026 that over two thirds of browser traffic to its network was protected with post quantum encryption, up from 29 percent at the start of 2025. Windows 11 added support for ML-KEM and ML-DSA in a November 2025 update. Signatures and certificates are moving more slowly, which is why the 2030s dates still matter

None of this is a reason to worry about your online banking tomorrow. It is a reason to keep things updated, ask the right questions and avoid being sold expensive fixes you do not need. If anything here goes out of date, reply below and the list will be corrected

Last updated: 4 October 2026

Sources:



Timelines for migration to post-quantum cryptography
https://www.nccoe.nist.gov/sites/default/files/2023-08/quantum-readiness-fact-sheet.pdf
PQC support
Quantum-secure cryptography in Apple operating systems
Signal Protocol and Post-Quantum Ratchets
https://www.openssh.org/txt/release-10.0
The White House's post-quantum executive order is an important milestone. It's time to get to work