Skip to main content
Home > How Will Post-Quantum Computers Affect Authentication As We Know It?

How Will Post-Quantum Computers Affect Authentication As We Know It?

Quantum computing is coming, and it will break the cryptography that protects your identity

▶ WATCH THE VIDEO

This blog post accompanies our video “PQC & Authentication,” where Intercede’s experts discuss the impact of quantum computing on the cryptographic foundations of modern authentication. The video covers the real-world timeline, what organisations need to worry about, and how to start preparing. Watch the full discussion for deeper insights.

The Quantum Threat to Authentication

Quantum computing promises extraordinary advances in science, medicine, and engineering. But as we explore in our accompanying video, it also poses a serious threat to the cryptographic foundations that underpin virtually all modern authentication. If your organisation relies on public key infrastructure, digital certificates, or encrypted credentials, the quantum era will demand fundamental changes to how you operate.

What Exactly Is at Risk?

Most authentication systems today rely on asymmetric cryptographic algorithms, particularly RSA and elliptic curve cryptography, that would be vulnerable to a sufficiently powerful quantum computer. These algorithms protect everything from TLS certificates and VPN connections to smart card authentication and digital signatures. A quantum computer running Shor’s algorithm could break these protections, potentially allowing attackers to forge identities, intercept communications, and decrypt previously captured data.

NIST’s Post-Quantum Standards

The good news is that the security community is not waiting for quantum computers to arrive before taking action. In August 2024, NIST released its first three finalised post-quantum cryptography standards: FIPS 203 (ML-KEM) for key encapsulation, FIPS 204 (ML-DSA) for digital signatures, and FIPS 205 (SLH-DSA) as a hash-based signature alternative. An additional algorithm, HQC, was selected for standardisation in March 2025. As discussed in our video, these quantum-resistant algorithms are designed to withstand attacks from both classical and quantum computers.

The “Harvest Now, Decrypt Later” Threat

Even though large-scale quantum computers are still years away, the threat is already real. Sophisticated adversaries are known to be collecting encrypted data now with the intention of decrypting it once quantum capability becomes available. For organisations handling sensitive data with a long shelf life, government, defence, healthcare, financial services, the time to start preparing is now. Our experts discuss this risk in detail in the video, including why it should be a concern today, not just in the future.

Impact on PKI and Certificate-Based Authentication

Organisations that rely on PKI for authentication will face a particularly complex migration. Certificate authorities will need to issue post-quantum certificates, and the entire chain of trust will need updating. This is not a simple software patch, it requires careful planning, testing, and potentially a complete refresh of cryptographic infrastructure. The US government has set a target of achieving widespread PQC adoption by 2035, but NIST guidance recommends organisations begin their transition planning now.

What Should Organisations Do Today?

Start by understanding your cryptographic inventory, where are you using vulnerable algorithms, and what would break if they were compromised? Develop a migration roadmap that aligns with NIST’s PQC standards. And partner with vendors who are actively preparing for the post-quantum world. Intercede is closely tracking PQC developments and is committed to ensuring that the MyID product suite evolves to support post-quantum algorithms as they mature, helping customers protect their digital identities against both current and future threats.

▶ WATCH THE FULL DISCUSSION

For the complete expert discussion on quantum threats to authentication, including the “harvest now, decrypt later” risk and what it means for PKI, watch our video: “How Will Post-Quantum Computers Affect Authentication As We Know It.”