Editorial

How will identity security work in a post-quantum world?

Alan Radford, technology strategist at One Identity, examines how quantum computing will reshape digital trust – and why identity security, privileged access and cryptographic agility will be critical to preparing for a post-quantum world.

Posted 26 August 2026 by Christine Horton


Two years ago, Think Digital Partners reported on the threat that a working quantum computer would pose to traditional cryptographic methods that are used to secure public sector records and secrets. Why? Because quantum computing can reduce the time taken to calculate all possible permutations of a cryptograph from millennia to seconds.

Three months ago, Microsoft announced major advancements in its quantum computing chip and predicted that we are just three years away from seeing a working quantum computer.

 How much faster is quantum computing?

Google used 53 functional qubits to complete a specialised computational task in 200 seconds and estimated an equivalent classical computation would take 10,000 years.

These experiments do not show that today’s quantum systems can break deployed encryption, but they do demonstrate the potential of the technology.

 Harvest now, decrypt later

Some threat actors are caching stolen, encrypted communications, databases and archives in the hope of decrypting them once cryptographically-relevant quantum computing (CRQC) becomes available. The UK government’s National Cyber Security Centre advises, “This means that for organisations that need to provide long-term cryptographic protection of very high-value data, the possibility of a CRQC in the future is a relevant threat now.

 Replacing cryptography across complex enterprise environments will take many years. Organisations cannot afford to wait until the threat becomes practical.

 Why quantum threatens current security mechanisms

Financial transactions currently depend heavily on RSA public-key cryptography.

RSA encryption involves multiplying two large prime numbers to produce the modulus: a number with more than 600 digits for a 2048-bit key. Existing computers cannot work out the original prime numbers from the modulus, however, researchers have shown that Shor’s quantum algorithm can.

Public-key technologies such as RSA, Diffie–Hellman and elliptic-curve cryptography underpin digital signatures, secure communications and the trust mechanisms used to verify identities across networks.

 Preparing for the post-quantum era

Over the past decade, the US National Institute of Standards and Technology (NIST) has worked with cryptography experts from 25 countries to select 82 new algorithms capable of withstanding attacks using quantum computing. Following evaluations, 7 finalists and 8 alternatives were taken forward for standardisation.

Three principal standards were published in August 2024. NIST urges computer system administrators to apply these standards now to ensure their systems are migrated to quantum-resistant cryptography. 

Post-quantum key establishment:

Federal Information Processing Standard (FIPS) 203, specifies ML-KEM, the Module-Lattice-Based Key-Encapsulation Mechanism. Derived from CRYSTALS-Kyber, ML-KEM enables two parties to establish a shared secret securely over a public network.

Post-quantum digital signatures:

  • FIPS 204 is intended to serve as the principal general-purpose post-quantum digital-signature standard. It specifies ML-DSA, the Module-Lattice-Based Digital Signature Algorithm, derived from CRYSTALS-Dilithium.
  • NIST has also published a backup standard that uses a different mathematical approach, in case ML-DSA proves vulnerable to cracking. FIPS 205 specifies SLH-DSA, a stateless hash-based digital-signature algorithm derived from SPHINCS+.
  • The draft FIPS 206 standard for security digital signatures is based on the FALCON algorithm, which will be renamed FN-DSA when it is released. This is intended to be used for applications that need smaller signatures than FIPS 204 can provide.

 The UK’s National Cyber Security Centre (NCSC) advises that operational systems only use post-quantum algorithms that are based on robust implementations of the final standards. It views ML-KEM-768 and ML-DSA-65 as providing appropriate post-quantum security for most use cases.

Preparing identity security for the post-quantum era

Organisations need to identify everywhere cryptography is used, replace algorithms and certificates without redesigning entire systems, and adapt as standards and implementations mature. Strong key management, identity governance and control over privileged administration will be essential throughout this transition.

 PAM cannot make a vulnerable cryptographic algorithm quantum-resistant, but it can protect privileged accounts, systems and administrative processes used to manage certificate authorities, signing services, cryptographic keys, identity platforms and migration tooling.

 Even in a post-quantum world, attackers will still seek privileged access that enables them to move laterally and undetected inside organisations’ infrastructures. This puts PAM at the centre of post-quantum readiness. Organisations should expect identity security and PAM tools to provide:

  • Cryptographic agility:
    An architecture that allows algorithms, certificates and cryptographic libraries to be updated to support post-quantum standards without extensive platform redesign.
  • Protection of cryptographic infrastructure:
    Strong controls over privileged access to certificate authorities, hardware security modules, key-management platforms, signing services and identity infrastructure.
  • Quantum-level analytics of machine identities and credentials:
    Visibility and management for service accounts, SSH keys, certificates, API credentials and other non-human identities.
  • Least privilege and time-bound administration:
    Fine-grained elevation and automatic removal of access when each administrative task is complete.
  • Audit and session evidence: that demonstrates who and what accessed sensitive cryptographic and identity systems, what actions they performed and whether policy was followed.
  • Standards-based integrations:
    Support for established PKI, key-management, hardware security and identity standards as PQC implementations mature.

 Next Steps for CISOs

NCSC has published helpful guidance on adoption of post-quantum cryptography (PQC), including ensuring that devices and systems are updated to PQC as part of the replacement and upgrade cycle.

CISOs planning for a post-quantum enterprise environment need to take three clear steps:

  • Gain visibility of quantum vulnerabilities:

Create an inventory of the digital certificates and persistent credentials that depend on current public-key encryption.

  • Prioritise identity data, long-lived credentials, and biometrics:

To protect against historic cache-cracking and future attackers, focus on protecting high-value, sensitive, encrypted assets with post-quantum algorithms.

  • Choose frameworks that support seamless algorithm upgrades to minimise the risk of operational downtime

Key deadlines

On 22nd June 2026, the US president signed Executive Order 14412 setting new deadlines for federal agencies and contractors to adopt post-quantum cryptography for high-value assets and highly sensitive information. NIST-approved PQC must be used for key establishment by 31st December 2030, and post-quantum authentication for digital signatures by 31st December 2031.

In Europe, the EU’s NIS2 Directive requires relevant organisations to maintain risk-based policies and procedures governing the use of cryptography. The Digital Operational Resilience Act (DORA) technical standards go further for financial entities, requiring documented policies for encryption and cryptographic controls, lifecycle management of cryptographic keys and provisions for changing cryptographic technology in response to developments in cryptanalysis.

In the UK, the NCSC advises organisations to complete cryptographic discovery and produce an initial migration plan by 2028, complete their highest-priority migrations and establish a thorough roadmap by 2031 and work towards completing migration by 2035.

Identity security in a post-quantum world

The post-quantum transition will not happen through a single upgrade or product purchase. It will be a multi-year transformation touching certificates, cryptographic keys, machine identities, authentication and privileged administration.

The identity security challenge is to maintain control of privileged and machine identities while the underlying mechanisms of digital trust are transformed.

 Organisations must begin by discovering where vulnerable cryptography exists, identifying the identities and systems that control it, and ensuring their identity security architecture will evolve as standards mature.

Post-quantum cryptography does not eliminate the threat of credential theft, session hijacking, malware, insider risk or excessive privilege. Zero Trust remains a relevant approach. Verify identities and devices continuously, minimise standing privilege, limit access to what is required, and reassess trust as risk changes. Identity validation, least privilege and privileged-session oversight will remain integral to organisational security. 

Quantum computing is going to change the mechanisms of digital trust, but identity will remain at the centre of protecting it. The organisations that succeed will be those that modernise their cryptography without losing control of the identities, privileges and systems on which digital trust depends.

Event Logo

If you are interested in this article, why not register to attend our Think Digital Identity and Cybersecurity for Government conference, where digital leaders tackle the most pressing issues facing government today.


Register Now