Why Post-Quantum Matters
Even before quantum computers exist, adversaries can record encrypted data today and decrypt it later, making the migration urgent now.
Harvest Now, Decrypt Later
The most important reason to adopt post-quantum cryptography before quantum computers are practical is the harvest-now-decrypt-later attack. An adversary intercepts and stores encrypted traffic today, unable to read it, and simply waits. When a capable quantum computer arrives, they decrypt the whole archive retroactively. Any secret that must stay confidential past the arrival of quantum computing is already at risk if it crosses the network protected only by classical public-key crypto.
The Time Horizons That Collide
- How long must this data stay secret? (the shelf life)
- How long will migration to new crypto take? (the transition time)
- How long until a cryptographically relevant quantum computer exists? (the threat time)
This is often called Mosca's inequality: if shelf life plus transition time exceeds threat time, you are already too late. Long-lived secrets force action now, regardless of the uncertain arrival date of quantum machines.
Migration Is Slow
Cryptography is embedded deep in protocols, hardware, certificates, and firmware. Replacing it across a large system takes years: inventorying where crypto lives, updating libraries, reissuing certificates, and testing interoperability. Organizations that start early avoid a rushed, error-prone scramble later. Crypto-agility, designing systems so algorithms can be swapped without redesign, is the practical goal.
Fusion Context
Firmware-signing keys and long-term design data for a fusion program have a shelf life measured in decades. Because the Hyperion breeder and burner designs are being fixed now, ahead of the Q2 2027 construction start, choosing crypto-agile signing and key exchange, with a path to post-quantum algorithms, is a design decision made at the right time rather than a costly retrofit.