Skip to content
All articles
Methodology

A field guide to post-quantum readiness, free and in the open

By quantakrypto Research3 min read

Also mentioned

TLSTLSTransport Layer SecurityTransport Layer Security, the protocol that encrypts and authenticates most internet traffic, including HTTPS. It uses key exchange, certificates, and symmetric encryption to protect a session.Read the full entry (new tab), FIPSFIPSFederal Information Processing StandardFederal Information Processing Standards, publicly announced standards developed by NIST for use in U.S. government computer systems, including cryptographic algorithms and modules.Read the full entry (new tab), NISTNISTNational Institute of Standards and TechnologyThe U.S. National Institute of Standards and Technology, the agency that develops and publishes cryptographic standards, including the FIPS series and post-quantum algorithms.Read the full entry (new tab), PQCPQCpost-quantum cryptographyCryptographic algorithms designed to run on today's classical computers while remaining secure against attacks by both classical and future quantum computers.Read the full entry (new tab), PKIPKIpublic key infrastructurePublic Key Infrastructure, the framework of certificate authorities, certificates, and policies that binds public keys to identities and enables trust in TLS, code signing, and email.Read the full entry (new tab), CBOMCBOMcryptographic bill of materialsA Cryptographic Bill of Materials, a structured, machine-readable inventory of the cryptographic assets used by a system or application, often expressed as an extension of a software bill of materials (SBOM).Read the full entry (new tab) are defined in the glossary.

TL;DR

Read this first

The quantakrypto knowledge base is a free, structured reference for the whole post-quantum transition: 11 collections and 49 topics running from cryptography basics and the quantum threat through the NIST standards, a full migration playbook, employee security awareness, governance, and hands-on tool guides, plus an 85-term plain-language glossary and a short FAQ. It is written for three readers at once, with a reading path for each: an employee who needs the basics, an engineer running the migration, and a leader funding it.

There is a strange gap in how post-quantum cryptography gets explained. On one side are vendor pages that tell you the sky is falling and to book a call. On the other are the primary standards, hundreds of pages written for people who already know the field. Between the panic and the doctorate there was very little: no plain, honest, well-organized place to actually learn this, understand what is true, what is urgent, and what to do, without paying for it or reverse-engineering a 200-page PDF. So we wrote one and put it in the open.

What is in it

The base is organized into 11 collections, ordered the way you would actually meet the material:

  • Orientation and Foundations: why post-quantum and why now, then the core concepts, symmetric versus asymmetric, hashing and key exchange, Shor versus Grover (what breaks and what only weakens), the PQC algorithm families, and crypto-agility.
  • Standards and references: the NIST PQC standards (FIPS 203 / 204 / 205) and what replaces what, NIST SP 800-63B on identity, CISA guidance, FIDO2 / WebAuthn / passkeys, and how the IETF, ETSI, BSI and ISO pieces fit, with a compliance mapping from standard to obligation.
  • The migration playbook: the full lifecycle, discover, assess, prioritize, plan, execute, validate, plus cryptographic inventory and CBOM, harvest-now-decrypt-later risk ordering, crypto-agile architecture, and migrating domain by domain (TLS, PKI, data-at-rest, code signing, secrets, identity).
  • Security awareness, IT and security playbooks, and Governance: the everyday security every employee needs, the deeper operational guidance for the people who run systems, and how to stand up, fund, measure, and lead a migration program.
  • Tools and how-tos, a glossary of 85 plain-language terms, a FAQ of straight answers, and a resources list of primary sources.

Built for three readers, not one

The hardest thing about this subject is that the people who need it are not one audience. An employee needs to know why a passkey beats a password and never needs to meet a lattice. An engineer needs the inventory method and the migration order. A leader needs the risk, the timeline, and the budget conversation. A single linear document serves none of them well, so the base has an explicit reading path for each, and every topic says plainly which reader it is for.

Why it is free, and in the open

Post-quantum migration is a literacy problem before it is a tooling problem. People do not act because they do not believe the threat is real, cannot see their own exposure, or have never been told the migration is tractable. A paywalled explainer helps none of that. A public, honest, well-structured one lowers the cost of understanding for a whole field, which is the point: the sooner more people can reason about this clearly, the sooner the migration stops being something only specialists can see. If a topic is wrong or missing, tell us, it is meant to be corrected. It is a reference rather than a curriculum; where a team needs the second, that is what training is for.

Start here

If you read one thing, read why post-quantum, why now. If you are running the migration, go to the cryptographic inventory topic and pair it with our CBOM how-to. If you are deciding whether to fund this, the governance collection is written for you.

References

Get started

Turn quantum risk into a credential.

Book a discovery call and get an indicative scope and pricing for your organisation.