# What is Quantum Computing Security?

> Quantum computing security is the practice of assessing and managing how quantum computing affects information security, cryptographic dependencies, and any quantum-enabled systems an organization uses.

- Canonical URL: https://yellowcube.eu/glossary/quantum-computing-security/
- Publisher: Yellow Cube
- Language: en
- Contact: hello@yellowcube.eu

## Content

For most organizations, the immediate focus is readiness for a future cryptographically relevant quantum computer: finding vulnerable public-key cryptography, estimating how long protected data must remain secret, and planning controlled migration before exposure becomes practical.

The discipline is broader than choosing a post-quantum cryptography (PQC) algorithm. It includes governance, data-retention horizons, cryptographic inventories, protocol and certificate dependencies, suppliers, replacement constraints, testing, crypto agility, incident planning, and the secure retirement of old keys and algorithms.

### Key points

- **Threat and time horizon:** Relate plausible quantum capabilities to the algorithms in use, the confidentiality life of stored or intercepted data, the authenticity life of signatures, and realistic migration lead times.
- **Dependency inventory:** Trace cryptography through applications, libraries, hardware security modules (HSMs), certificates, firmware, devices, archives, partner protocols, and managed services, including systems that cannot be upgraded easily.
- **Roadmap and agility:** Assign ownership, require supplier plans, test approved replacements, manage hybrid or transitional designs carefully, prevent downgrade, and preserve the ability to change algorithms and parameters again.
- **Important limitation:** The arrival date and capabilities of a cryptographically relevant quantum computer remain uncertain, and inventories or discovery tools will miss dependencies. PQC migration reduces particular cryptographic risks; it does not resolve weak implementations, endpoints, identities, access controls, or every threat to quantum systems.

### Related terms

[Post-quantum cryptography (PQC)](<https://yellowcube.eu/glossary/post-quantum-cryptography/>) · [Quantum key distribution (QKD)](<https://yellowcube.eu/glossary/quantum-key-distribution/>) · [Cryptography](<https://yellowcube.eu/glossary/cryptography/>) · [Public key infrastructure (PKI)](<https://yellowcube.eu/glossary/public-key-infrastructure/>) · [Data governance](<https://yellowcube.eu/glossary/data-governance/>)

### Sources

[NIST National Cybersecurity Center of Excellence, Migration to Post-Quantum Cryptography: Frequently Asked Questions](https://pages.nist.gov/nccoe-migration-post-quantum-cryptography/) · [NIST CSWP 39 Update 1, Considerations for Achieving Crypto Agility](https://csrc.nist.gov/pubs/cswp/39/upd1/considerations-for-achieving-crypto-agility/final) · [CISA, NSA, and NIST, Quantum-Readiness: Migration to Post-Quantum Cryptography](https://www.cisa.gov/sites/default/files/2023-08/Quantum-Readiness%20-%20Migration%20to%20Post-Quantum%20Cryptography_508c.pdf)

## Attribution and scope

This Markdown representation is generated from the same approved content records as the canonical HTML page. Cite the canonical URL above when referencing this material. Product and service descriptions are informational; confirm project-specific requirements with Yellow Cube.

