NIST, ODNI Urge Agencies to Prepare for Post-Quantum Cryptography
Protecting data from future threats could see benefits from implementing post-quantum cryptography into agency frameworks.

The National Institute of Standards and Technology (NIST) is advising agencies to incorporate post-quantum cryptography into their security frameworks in order to protect against next-gen cyberattacks.
Over the past six years, NIST has been working to develop quantum-resistant algorithms that are more resilient against attempts to break complex passwords or otherwise erode network security. In 2016, NIST held an international competition to select new cryptosystems that would be quantum-resistant and standardized for later use.
After evaluating over 80 submissions in July, NIST had selected four algorithms that will be standardized and implemented once published.
โThree algorithms are lattice-based cryptography,โ said NIST Computer Security Division Mathematician Dustin Moody. โTheyโre very efficient and a little larger than weโre used to, but we expect that most organizations and applications will be able to use these algorithms in their processes.โ
Moody said it is important to have more than one algorithm to base cryptography on in case a new attack discovers vulnerabilities in an existing algorithm.
โYou want to be able to easily and rapidly switch out the cryptographic algorithms that youโre using today for future cryptographic algorithms,โ Moody said. โThis will be useful for post-quantum, but itโs also useful in general because at any time you can have an algorithm that is attacked, and you need to replace it with a different algorithm that is secure.โ
The agency has also launched the Migration to Post-Quantum Cryptography project, which provides technical guidance and details known risks.
โKnowing your data, being able to look into your systems and understand what you have so that you can make risk decisions about which areas to focus on first to protect with the new algorithms should be a foremost priority,โ said NIST Cybersecurity Engineer Bill Newhouse.
Though itโs projected that current-gen quantum computers wonโt be outdated for another 10 to 20 years, organizations need to start preparing now for the transition to post-quantum cryptography.
โKnow whatโs on your systems, know what crypto systems you currently have, do an inventory,โ said Sue Gordon, former principal deputy director of national intelligence at ODNI. โSecondly, what do you have thatโs important to protect? With these two things in place you will be off and running when the standards get set and the products become available.โ
Gordon added that having these frameworks already in place will be essential for a streamlined transition to post-quantum cryptography.
โYou need to have a budget aligned and have talent in place. You also need policy and regulations established to be able to move to this as quickly as it becomes available,โ Gordon said.
Moody said NIST is currently writing the standards for CRYSTALS-Kyber, Dilithium, Falcon and Sphincs. The first draft will be released for public comment in early 2023.
โBesides the four that weโre standardizing, we also selected four algorithms to continue to evaluate and we will also be calling for new digital signature algorithms in the future to get more diversity,โ Moody said. โThere will continue to be future standardization work, but the first main standards with the primary algorithms Kyber and Dilithium should be finalized for people to use in 2024.โ
This is a carousel with manually rotating slides. Use Next and Previous buttons to navigate or jump to a slide with the slide dots
-
How NASAโs AI Plan Boosts Government Efficiency
NASA Chief Data and AI Officer David Salvagnini shares how the agency is integrating AI with data to drive innovation and efficiency across government.
9m watch -
Modernizing IT Systems for AI Adoption
USPS, NIH and Lumen discuss how modernization, data strategies and security are shaping AIโs future role in government.
20m watch -
NSF Wants Industry Driving Quantum Innovation
The agency is pushing for partnerships to enhance the research community as Congress weighs additional legislation.
3m read -
Modernizing Critical Infrastructure in the Face of Global Threats
Officials are expanding the latest strategies in boosting defense infrastructure, including securing satellite communications, upgrading enterprise-wide technology, optimizing data management.
20m watch