avalw news
Noah MitchellNoah MitchellVIEW PROFILE →

The race to quantum-proof the internet accelerates in 2026 as post-quantum encryption goes mainstream

tech2026-08-22 · 4 min read · 29 reads

As quantum computers edge closer to breaking the encryption that protects the internet, 2026 has become a pivotal year for post-quantum cryptography. With NIST standards finalized, browsers and operating systems adopting quantum-resistant algorithms, and a hard 2035 migration deadline looming, the g

One of the most consequential and least visible races in technology is accelerating sharply in 2026. As quantum computers steadily advance toward the point where they could break the encryption that secures nearly all digital communications, governments, standards bodies and technology companies are scrambling to quantum-proof the internet before it is too late. This effort, known as post-quantum cryptography, is rapidly moving from the laboratory into the mainstream.

New standards for a new threat

The foundation of this global effort was laid when the United States National Institute of Standards and Technology, known as NIST, finalized its first post-quantum cryptography standards in August 2024. These standards provide the core quantum-resistant algorithms that organisations around the world are now beginning to adopt to protect their most sensitive data against future attacks.

Three standards form the backbone of the new framework. FIPS 203, known as ML-KEM, is a module-lattice-based key-encapsulation mechanism used for general encryption. FIPS 204, or ML-DSA, provides a lattice-based digital signature algorithm for identity verification, while FIPS 205, or SLH-DSA, offers a stateless, hash-based signature scheme as an alternative approach.

The framework has continued to expand. A secondary code-based key-encapsulation mechanism known as HQC was adopted in 2025 to provide diversity in the underlying mathematics. In addition, a further standard, FIPS 206 or FN-DSA, is under development for bandwidth-constrained applications, with its finalization expected between 2026 and 2027 as the toolkit of approved algorithms grows.

The harvest now decrypt later threat

The world is racing to secure digital communications against future quantum computers. (Illustrative image)
The world is racing to secure digital communications against future quantum computers. (Illustrative image)

The urgency behind this work stems from a threat model known as harvest now, decrypt later. The concern is that adversaries can capture and store encrypted data today, then simply wait until a sufficiently powerful quantum computer becomes available to decrypt it in the future, potentially years down the line, exposing secrets that were assumed to be safe.

This makes the threat uniquely pressing. Every encrypted message captured today by an adversary patient enough to hold it for many years is, in effect, a candidate for retroactive decryption once quantum capabilities mature. Industries that hold long-lived secrets, such as defence, banking and government archives, are therefore under particular pressure to migrate to quantum-resistant systems well ahead of the general timeline.

A rigorous selection process

The algorithms now being deployed were not chosen lightly. They emerged from an eight-year global review process in which a total of 82 algorithms were evaluated, with submissions arriving from 25 different countries. This exhaustive and international scrutiny was designed to ensure that the chosen standards could withstand attacks from both classical and quantum computers for decades to come.

The scale of this collaboration reflects the gravity of the challenge. Because the security of the entire digital economy depends on getting the underlying mathematics right, the process deliberately favoured caution and thoroughness over speed, drawing on the expertise of cryptographers worldwide to stress-test each candidate algorithm before it could be enshrined as a formal standard.

Adoption reaches everyday devices

The new standards are already finding their way into the technology that people use every day. Chrome version 131 and above, along with Firefox version 135 and above, have integrated ML-KEM into the TLS 1.3 protocol that secures web browsing. Meanwhile, Windows 11 version 24H2 has incorporated ML-KEM into its Cryptography Next Generation programming interface.

Crucially, these deployments use a hybrid mode that combines traditional encryption with the new quantum-resistant algorithms. This approach ensures that systems remain secure against today's threats while adding protection against future quantum attacks, providing a safety net during the long transition period as the world moves away from vulnerable legacy cryptography.

The pace of real-world adoption has been striking. By late October 2025, more than half of all human-initiated web traffic passing through the network of the infrastructure company Cloudflare was already using post-quantum key agreement. Both Cloudflare and Google have publicly committed to completing significant parts of their migration by 2029, ahead of official deadlines.

A roadmap with hard deadlines

For government systems, the transition follows a clear and demanding timeline. An initial deadline for post-quantum integration by federal civilian agencies falls in 2026, followed by compliance gates for high-value assets in 2030 and full system migration for high-impact and defence systems in 2031. The final infrastructure cutover for all federal systems is set for 2035.

This roadmap is backed by formal policy. The migration effort is underpinned by the Quantum Computing Cybersecurity Preparedness Act, while a directive known as OMB M-26-15 outlines a detailed five-phase migration plan. By 2035, NIST expects organisations to have retired the public-key algorithms that currently secure most of the internet, marking the end of an era in digital security.

A quiet but vital transformation

For most people, this vast undertaking will remain almost entirely invisible, happening silently within the protocols and devices they use without a second thought. Yet its importance is difficult to overstate, as it aims to protect everything from private messages and financial transactions to state secrets against a threat that, while not yet fully realised, is widely regarded as inevitable.

In conclusion, 2026 stands as a defining year in the long effort to secure the digital world against the coming age of quantum computing. With standards finalized, everyday software adopting them, and firm deadlines driving action across government and industry, the race to quantum-proof the internet has moved decisively from theory into practice, shaping the security of communications for decades to come.

Noah Mitchell
WRITTEN BY THE AUTHOR
Noah Mitchell
2026-08-22 · 4 min read · 29 reads
View profile →
VERIFY THIS STORY
ASK AI
MORE FROM Noah Mitchell
Report this articlesupport@avalw.com