SOUTH+BRIDGE
Tech AI-translated

The Year of Changing Locks That Haven't Been Broken Yet

PQC standards have been finalized. Yet the threat has not arrived. We examine the new industries created by this time gap and South Korea's public procurement timeline.

Ampersand · June 6, 2026 · 6 min read

AI Summary

With NIST finalizing its post-quantum cryptography (PQC) standards in August 2024, the field has shifted from a research question to a procurement and migration challenge. The 'Harvest Now, Decrypt Later' threat model means that long-lived data — medical records, state secrets, financial ledgers — is already at risk long before any quantum computer arrives, making early migration a matter of insurance logic rather than reactive response. For South Korea, the strategic opening lies not in algorithm development itself, but in building the migration tooling, certification infrastructure, and lightweight PQC applications for IoT and mobility, with cities like Busan uniquely positioned to build PQC-ready from the ground up.

The Year of Changing Locks That Haven't Been Broken Yet

The question people most commonly ask about post-quantum cryptography (PQC) is: when will quantum computers break RSA? It is the wrong question. This is not a technology you wait for the breaking point to arrive — it is a technology you migrate to before the breaking point comes. The threat lies in the future, but the cost is incurred today. That asymmetry is what PQC is really about.

In August 2024, NIST finalized its PQC standards as FIPS 203, 204, and 205 — covering ML-KEM (key encapsulation), ML-DSA, and SLH-DSA (digital signatures). What matters more than the publication of these documents is what they signal: finalized standards mean the question has shifted from research to procurement and migration.

The Threat Is in the Future; the Cost Is Now

Viewed as a single tool, PQC reads simply as one more secure encryption algorithm. But the security industry approaches it very differently. The key concept is 'Harvest Now, Decrypt Later' — a scenario in which encrypted traffic is bulk-collected and stored today, then decrypted once a sufficiently powerful quantum computer becomes available. Under this scenario, data with protection periods of 10 or 20 years — medical records, state secrets, financial transaction ledgers — is already at risk long before a quantum computer ever arrives.

This is where it becomes clear that PQC is not a matter of swapping one algorithm for another. It is the work of replacing cryptography everywhere it is embedded: TLS handshakes, code signing, VPNs, firmware update verification, public key infrastructure, and blockchain signature schemes. Cryptography is the invisible plumbing of infrastructure, and PQC migration is the work of replacing that entire plumbing system while the city keeps running.

Convergence Has Always Happened in the Plumbing

Historically, the technology convergences that transformed industries happened not at the dazzling surface layer but in invisible standards. When container specifications were unified, shipping, rail, and trucking linked into a single logistics system — and on top of that, a new industry called global supply chains was built. When HTTPS became the default, e-commerce and fintech became possible. Both were agreements made at a layer users never notice. PQC occupies the same position. Crypto-agility — the capacity to swap out algorithms when needed — is not visible in itself, but it becomes the prerequisite for every digital service built on top of it.

Let us reframe the question: what other technologies does this one converge with? First, PQC meets AI. The work of building a Cryptographic Bill of Materials (CBOM) — automatically locating every instance of cryptography in a codebase — is nearly impossible by hand and only becomes feasible with code-analysis AI. PQC also meets IoT and robotics. Lattice-based signatures such as ML-DSA carry larger key and signature sizes than their predecessors. On sensors, vehicle ECUs, and industrial robots where compute and memory are constrained, that added weight immediately becomes a design constraint. The security of mobility systems and over-the-air (OTA) firmware updates is directly tied to PQC performance.

Who Profits from This Time Gap?

Convergence creates new economic actors. The gap itself — standards finalized, threat not yet arrived — is a market. One category of player is the 'PQC consulting and inventory' vendor that scans cryptographic assets and sells migration roadmaps. Another is the PKI infrastructure supplier replacing hardware security modules (HSMs) and certificates with PQC-ready versions. A third is the open-source community and cloud providers supplying hybrid-mode transition libraries that run existing encryption and PQC simultaneously. The fact that Google and Cloudflare have already enabled hybrid key exchange on portions of their traffic is evidence that this layer is quietly becoming infrastructure.

The counterargument is legitimate. A quantum computer capable of breaking RSA-2048 is still far off — and may never arrive. Spending enormous sums now on replacement costs for an unproven threat sounds like overkill. It is a fair point. But the answer lies in the logic of insurance. Migration does not happen overnight. For a large financial institution or a public-sector system, replacing its cryptographic infrastructure typically takes years. Starting after the threat arrives is too late. The decision only makes sense when cost is measured not in 'probability of a break' but in 'time required to migrate.'

Is South Korea's Clock Running Fast?

Shifting the frame to South Korea, the picture sharpens. The National Intelligence Service and the National Security Research Institute have run a domestic post-quantum cryptography competition called KpqC, selecting homegrown algorithms. This brings both opportunity and risk. The opportunity is that South Korea can stand in the position of shaping standards rather than merely following them. The risk is that when the international NIST-based standards and the domestic KpqC family diverge, Korean companies face the cost of simultaneously managing two tracks: global compatibility and domestic procurement requirements.

The real test is the speed of public procurement. The Government Public Key Infrastructure (GPKI), the common certificate framework, and the government cloud all need to be redesigned with crypto-agility as a premise. For regions like Busan that are currently laying new data center and digital administrative infrastructure, designing for PQC from the outset is overwhelmingly cheaper than retrofitting later. This is one of those rare fields where new construction beats renovation. South Korea's opening is not in the algorithms themselves, but in the migration tooling, the certification infrastructure, and the application layer that brings lightweight PQC to IoT and mobility.

The future will not come from quantum computing alone. New industries will emerge at the intersection where PQC meets AI code analysis, the design constraints of robots and vehicles, and public authentication systems. The cost of changing locks that have not yet been broken — who pays it first, and in what structure, will determine who supplies digital trust for the next decade.

This article was automatically translated from the Korean original by AI. For the authoritative version, read it in Korean.

한국어 원문 읽기 →