Quantum-Resistant
Security

The Need for Post-Quantum Cryptography

The arrival of largescale, cryptographically relevant quantum computers is no longer a distant theoretical concept. The threat to today’s cryptographic systems is already active. Adversaries are believed to be harvesting encrypted data now with the intent to decrypt it later, once quantum computing capabilities mature. This Harvest‑Now, Decrypt‑Later threat has made the transition to Post‑Quantum Cryptography (PQC) an immediate national priority.

In June 2026, the White House issued Executive Order 14412, Securing the Nation Against Advanced Cryptographic Attacks, directing federal agencies and contractors to accelerate the transition to quantum‑resistant protections. With initial requirements due as early as July 2026, agencies must begin preparing now to avoid falling behind.

EO 14412 underscores a critical risk: adversaries may be harvesting sensitive data today—classified information, PII, medical records, trade secrets—with the intent to decrypt it later once large‑scale quantum computers are available.

The reality is clear:
• Classical encryption will break against future quantum computers.
• Public Key Infrastructure (PKI) will be vulnerable.
• Agencies must begin migrating to NIST‑approved, FIPS‑validated post‑quantum cryptography (PQC).

The time to prepare for the quantum threat is now.

Understanding Post-Quantum Cryptography (PQC)

crypto_agile

Post-Quantum Readiness Starts with Crypto-Agility

Crypto-agility is a strategy that enables you to future-proof your organization by:

  • Having the flexibility to quickly change protocols, keys, and algorithms
  • Using flexible, upgradeable technology
  • Reacting quickly to cryptographic threats, such as Quantum computing
  • Adding to your tech stack with minimal to no disruption

Thales TCT’s products have been purposely designed to help you be crypto-agile and quantum-safe.

Fast Facts: Securing The Nation Against Advanced Cryptographic Attacks Executive Order

Learn how to address requirements in the June 22, 2026 Executive Order, Securing The Nation Against Advanced Cryptographic Attacks.

Strategy for Migration to PQC

1. Inventory Cryptography

Identify where cryptography is used and prioritize high‑risk systems. Manual inventories quickly become outdated—agencies need accurate, automated visibility.

2. Automate Crypto Discovery

Cryptographic components change constantly. Automated discovery tools provide continuous, reliable updates across evolving systems.

3. Test PQC Algorithms

Set up a PQC test environment to evaluate NIST’s new algorithms. Larger keys and new performance patterns make controlled testing essential.

4. Practice Crypto Agility

Use technologies that support both classical and post‑quantum algorithms. Crypto‑agile systems ensure smooth updates as standards evolve.

5. Apply Quantum Key Generation 

Adopt quantum random number generators (QRNGs) to create high‑entropy, highly trusted cryptographic keys.

6. Implement Quantum‑Resistant Algorithms

Integrate standardized PQC algorithms—or ensure your systems can easily upgrade to them as federal requirements tighten.

Thales TCT’s Luna T-Series HSMs—the first PQC enabled HSMs manufactured in the U.S. to receive FIPS 140-3 Level 3 validation.

Thales TCT Quantum-Ready Solutions

Thales TCT  has integrated PQC into its high-assurance cryptographic solutions and incorporate crypto-agile frameworks to adapt to evolving PQC requirements. By aligning with NIST-standardized PQC algorithms, leveraging crypto-agility, and collaborating with NIST  and NSA, through a Cooperative Research and Development Agreement (CRADA), Thales TCT ensures quantum-resistant security for U.S. Government intelligence, defense, and civilian agencies.

Luna T-Series HSMs are the choice for government agencies when storing, protecting and managing cryptographic keys used to secure sensitive data and critical applications. Meeting government mandates for U.S. Supply Chain, the high-assurance, crypto-agile, tamper-resistant Luna T-Series HSMs are designed, developed, manufactured, sold, and supported in the United States.

Protect Encryption Keys with T-Series Luna Hardware Security Modules

Quantum Resistant Algorithms

Luna T-Series HSMs (v 7.13.0 forward) now include pre-standards implementations of NIST-selected PQC algorithms and stateful hashed-based signature algorithms.

The algorithms supported are:

  • CRYSTALS-Dilithium (ML-DSA)
  • CRYSTALS-KYBER (ML-KEM)
  • FALCON (FN-DSA)

Additionally, Thales TCT is introducing the Leighton-Micali Signature (LMS) stateful hash-based signature mechanism, along with its multi-tree variant, the Hierarchical Signature Scheme (HSS).  LMS/HSS enables customers to transition to quantum-resistant firmware/software signing.  The Luna T-Series HSM implementation of LMS is compliant with SP 800-208 and PKCS#11 v3.1.

Quantum Enhanced Keys

By embedding a quantum random number generator (QRNG) chip within the Luna HSM, Thales TCT is offering the industry’s first FIPS 140-2 compliant HSM capable of generating quantum enhanced keys. Using principles of quantum physics, the QRNG chip produces high quality entropy which is the basis for all random numbers and cryptographic keys generated by the HSM.  With a choice of operating the HSM in FIPS-approved mode using either the embedded, classic physical RNG or the embedded quantum RNG, customers can dynamically change between classical key generation and quantum enhanced keys as threats emerge over time.

LEARN MORE ABOUT QUANTUM ENHANCED KEYS

Quantum Random Number Generation

QRNG complements post quantum cryptography and is part of a crypto-agile strategy. Thales TCT’s Luna T-Series HSMs contain an embedded QRNG chip for high quality entropy based on quantum noise.

All keys and random numbers generated within the HSM are enhanced by the security of the quantum random numbers that are the foundation of the key generation process.

Secure Data in Transit with High Speed Encryptors (HSE)

Quantum Resistant Algorithms

Thales HSEs include a framework to support QRA via firmware upgrade. Thales HSE solutions support all four NIST Quantum Resistant Public Key algorithms (finalists) in all products (plus other non-finalist algorithms).

Quantum Key Distribution

Thales HSEs are quantum-ready and QKD compatible for more than a decade.

Quantum Random Number Generation

Quantum Random Number Generation is integrated into the HSE solution.

CN6100

Thales HSE network encryption solutions support Post-Quantum Cryptography with a crypto-agile, FPGA-based architecture.

Resources

ImageTitleLink
On Demand FedInsider Webinar: Looking Ahead – The Intersection of Quantum Computing, AI, and Security 
Fast Facts: Securing The Nation Against Advanced Cryptographic Attacks Executive Order
CTO Sessions On Demand: Zero Trust: Top 5 Best Practices
CTO Sessions On Demand: A Practical Guide to Quantum Resistant Security
Expert Edition eBook: Quantum-ready roadmap for securing federal cryptography
CTO Sessions On Demand: Word on the Street – 2026’s Top Tech Trends
CTO Sessions On Demand: Trusted Data in Motion – Securing Government Communications in the PQC Era
On Demand Webinar: Get Started with Post-Quantum PKI: A Tech Spotlight from Thales TCT & Keyfactor
Tech Spotlight: Keyfactor and Thales Deliver Post-Quantum PKI for Federal Agencies
CTO Sessions On Demand: When AI Learns to Breach and Quantum Learns to Decrypt – The Endgame
Washington Technology Commentary: Why federal agencies must act now on post-quantum cryptography
CTO Sessions Webcast On Demand: Intersection of Quantum, AI and Security
Solution Brief: Thales TCT Post-Quantum Cryptography Implementation
Washington Technology Commentary: Why post-quantum security planning must start today
GovLoop Blog Post: Quantum-Safe Encryption: What It Means, and Why Agencies Should Care
On Demand GovLoop Webinar: Taking a Realistic Look at Quantum Computing in Government
GovLoop Video: Quantum-Safe Encryption: Understanding the What, Why and How
Govloop Video Interview: Quantum-Safe Encryption: What It Means, and Why Agencies Should Care
CTO Sessions On Demand: Best Practices for Implementing Quantum-Resistant Security
Securing the Future: Navigation Post Quantum Cryptography Standards
FedNewsNetwork Video Interview: Preparing for the intersection of AI, quantum computing
FedNewsNetwork Commentary: Preparing for the intersection of AI, quantum computing
Blog Post: PQC Standards Released – Start Today
CTO Sessions: Quantum Resistant Security
The Dual Faces of Quantum Computing: Opportunities and Threats in National Security
CTO Sessions Webcast: Word on the Street – 2024’s Top Tech Trends
White Paper: Quantum Resistant Code Signing Secured by Hardware Security Modules
CTO Sessions On Demand: Are You Quantum Ready?
Quantum Enhanced Keys Solution Brief