The data your organisation encrypts today can be stolen today and decrypted later. It is an uncomfortable idea, and it is the reason post-quantum cryptography belongs on your plans now rather than later. Asymmetric cryptography, the RSA and elliptic curve (ECC) maths behind digital certificates, passkeys and the secure channels protecting your traffic, is safe against any classical computer. It is not safe forever against a quantum one.
Post-quantum cryptography (PQC) is a new generation of encryption and signing algorithms built to resist attacks from quantum computers. Most computers and servers can move to it through software updates, but hardware such as smart cards and security keys will need upgrading to quantum-resistant versions as they become available.
A quantum computer with enough stable qubits could break RSA and ECC keys outright. The machine capable of doing it at real key sizes does not exist yet, but the algorithms that would run on it are already known and proven against small keys. Every year the engineering gap narrows. No one can tell you the exact date, so the only sensible position is to assume it arrives and to have replacements deployed well before it does.
Why this matters now, not in 2035
Two threats stand out. The first, and the worst, is store now, decrypt later. Encrypted data captured in transit today can be held until quantum computers can crack the key that protected it. Anything with a long confidentiality life, intellectual property, customer records, sensitive personal data, is already exposed even though the attack itself is years away.
The second is sign now, deny later. A valid digital signature today proves the holder signed the data. Once the underlying RSA or ECC keys are breakable, that proof no longer holds for documents expected to stand for years. Authentication carries a lower risk, because the party checking a login decides in the moment whether it trusts the algorithm, but signing and encryption are built for the long term.
Symmetric encryption such as AES and hashing such as SHA-256 are not provably immune, but they are safe for the foreseeable future. The priority is clear: migrate the asymmetric keys, RSA and ECC, first.
The supply chain is the hard part
NIST has already standardised the first post-quantum algorithms: ML-DSA (FIPS 204) for digital signatures and authentication, and ML-KEM (FIPS 203) for key encapsulation and encryption. The maths is no longer the obstacle. Replacing the cryptography embedded across every operating system, library, device and certificate authority is, and no single vendor owns that chain. Support has to be added downstream before it can be added upstream.
This is why crypto agility matters more than any single algorithm. Software and protocols need to support multiple algorithms so they can move to new ones without a rewrite. Intercede has a track record here, having previously added RSA 3072 and 4096 and ECC P-256, P-384 and P-521 support across the product range. The same approach now applies to quantum-resistant algorithms, with hybrid combinations of classical and post-quantum keys to follow as those standards mature.
You also cannot migrate what you cannot see. MyID provides an inventory of the keys and algorithms in use, giving you the view you need to plan and manage the transition to stronger algorithms in a controlled way.
The regulatory timetable
This timetable reflects the NIST position as of May 2026. Other countries, sectors and regulators may set slightly different dates.
| Period | RSA | ECC | Post-quantum |
| 2026 to 2030 | RSA 2048 or higher | P-256 / P-384 / P-521 | ML-DSA, ML-KEM |
| 2031 to 2035 | RSA 3072+ allowed but deprecated | P-256 / P-384 / P-521 allowed but deprecated | ML-DSA, ML-KEM |
| 2036 onwards | RSA disallowed | ECC disallowed | ML-DSA, ML-KEM |
Source: NIST Post-Quantum Cryptography project, csrc.nist.gov/projects/post-quantum-cryptography
A credential issued in mid-2026 with a five-year life runs to mid-2031, the point at which RSA 2048 is no longer allowed. Factor in key lifetimes and multi-year upgrade cycles for large estates, and the planning window is now. We already see customers moving to larger RSA or ECC key sizes as an interim step to clear the 2031 cut-off.
The Intercede roadmap
Work is well underway, with post-quantum support rolling out incrementally across the MyID suite. Timings for future releases are indicative and may be affected by external factors.
| Year | MyID CMS | MyID MFA | MyID SecureVault |
| 2026 | Software certificates with ML-DSA / ML-KEM via EJBCA; initial CA support | ML-KEM encryption of data at rest; FIDO device support as it becomes available | Research into HSM integration for ML-KEM |
| 2027 | More certificate authorities; quantum-resistant FIDO, smart card and mobile support | Remaining RSA / ECC uses identified and upgraded | Support for ML-KEM archived keys |
| 2028 | Full release with no reliance on RSA or ECC | Full release with no reliance on RSA or ECC | Full release with no reliance on RSA or ECC |
Across all three products the outcome is the same: a full release with no reliance on RSA or ECC, reached well ahead of the regulatory deadlines.
What this means for you
Intercede has followed post-quantum standardisation for years and is integrating each part of the supply chain as it becomes available, working with technology partners to deliver complete credential and identity solutions. Any system you buy today should carry a credible quantum-readiness plan, and every existing system, key and device should be on a migration path. The crypto-agility built into MyID means you can adopt quantum-resistant algorithms as they arrive, without tearing out what you already run.
Chat with a MyID expert to discuss your PQC strategy.
Book a MyID demo to talk through your migration plan with our team.