What actually is post-quantum technology?
Every day, encryption protects the digital services we rely on. It keeps our bank transactions secure, safeguards medical records, enables confidential government communication and protects the critical infrastructure that keeps society running.
For decades, this encryption has been strong enough to withstand even the world's most powerful conventional computers. But that is beginning to change. As quantum computing continues to advance, organisations around the world are preparing for a future in which today's cryptography may no longer be sufficient.
That future may still be years away, but according to Thomas Attema, Researcher Cryptology at TNO and CWI the transition needs to start now.
"Post-quantum cryptography is cryptography that's capable of withstanding attackers that have quantum computers at their disposal." Thomas Attema
TNO, the Netherlands Organisation for Applied Scientific Research, works with governments, industry and research partners to translate scientific knowledge into practical innovation. In the field of post-quantum cryptography (PQC), that means helping organisations understand the risks, prepare for migration and implement new security standards.
Why organisations cannot afford to wait
One of the biggest misconceptions about post-quantum cryptography is that it will only become relevant once quantum computers are capable of breaking today's encryption. Attema explains that this is not the case.
Cybercriminals or hostile states could already be collecting encrypted information today, storing it until quantum computers become powerful enough to decrypt it in the future. This strategy, often described as harvest now, decrypt later, poses a particular risk for information that must remain confidential for many years, such as government data, intellectual property, defence information and medical records.
"In cryptography, you always have to look ahead for several decades. We're not only protecting against current threats but also threats of the future."
Not every organisation faces the same urgency. Systems protecting critical infrastructure or highly sensitive information should move sooner than systems where data quickly loses its value. Even so, Attema believes every organisation should begin preparing now rather than waiting for quantum computers to arrive.
The good news is that post-quantum cryptography is no longer just a research topic. International standards have already been developed, and many organisations have quietly started implementing them. Users of secure messaging apps such as Signal, for example, are already using post-quantum cryptography without even realising it. Updated internet protocols are also introducing quantum-resistant security for an increasing number of websites and online services.
From standards to implementation
Although international standards now exist, the next challenge is implementing them across existing digital infrastructure. Organisations need to understand where cryptography is used throughout their systems, determine which applications are most critical and gradually replace existing technology without disrupting day-to-day operations. This process will take time.
Previous cryptographic migrations lasted more than a decade, when digital systems were far less complex than they are today. Modern organisations rely on thousands of interconnected applications, devices and suppliers, all of which may depend on encryption in different ways. Helping organisations navigate that complexity is one of TNO's key roles.
Attema's work combines cryptographic research with practical advice for businesses and public organisations. Together with partners including CWI, and the General Intelligence and Security Service (AIVD), TNO also contributed to the PQC Migration Handbook, providing organisations with practical guidance on how to begin their transition.
The first step, Attema says, is often the simplest. Organisations need to understand which cryptography they currently use, where their most sensitive information is stored and which suppliers and technologies will need to support post-quantum security in the future. These actions improve cyber security regardless of when quantum computers become a reality.
Learning from one another
Preparing for post-quantum cryptography is not something organisations or countries should do alone. Across Europe, governments, researchers and industry are increasingly working together to share practical experiences, develop guidance and support organisations through the transition.
"It's not a topic that we should compete on."
The Netherlands plays an active role in this collaboration, working closely with countries such as France and Germany while contributing to international standards and European working groups.
Early adopters are already providing valuable lessons for others. Large technology companies have discovered that migrating cryptography can reveal unexpected challenges. Some software systems, for example, were designed with assumptions about encryption that no longer hold true when cryptographic keys become larger. Sharing these experiences helps other organisations avoid the same problems and speeds up adoption across the wider ecosystem. For start-ups, the opportunity is different. Rather than replacing older systems, they can design new products with post-quantum security built in from the beginning, making future transitions much easier.
Building resilience for the future
Quantum computing is expected to unlock major advances across science, healthcare and industry. Protecting society against the new cyber security risks that come with those advances will require just as much innovation.
For Attema, preparing for post-quantum cryptography is not simply about responding to a future threat. It is about improving cyber security today while building resilient digital infrastructure for decades to come. He hopes the Netherlands will continue to lead by example, not only by completing its own migration but also by sharing knowledge and helping other countries prepare for the same transition.
"I would hope that the Netherlands is a frontrunner in post-quantum cryptography migration, so that we can also advise and help other nations."
The quantum era is approaching gradually rather than arriving overnight. That gives organisations time to prepare, but only if they start now. Through applied research, international collaboration and a strong cyber security ecosystem, we are helping ensure that tomorrow's digital world remains as secure as the one we depend on today.