Glossary · Reference
Post-quantum cryptography glossary
Each entry has its own link (the # next to the term) so you can point colleagues to a single definition. Where we have a deeper guide, it is linked under the definition.
A
- AES#
- The Advanced Encryption Standard (FIPS 197), the most widely deployed symmetric block cipher. Quantum computers do not break it: Grover’s algorithm gives at most a quadratic speed-up, so AES-256 is generally considered to remain secure, and some guidance asks for 256-bit keys for long-term protection.
- ANSSI#
- France’s national cybersecurity agency (Agence nationale de la sécurité des systèmes d’information). Its post-quantum position favours hybrid cryptography during the transition and sets expectations for qualified products.Read more: ANSSI and hybridisation (in French)
- Asymmetric (public-key) cryptography#
- Cryptography that uses a key pair: a public key that can be shared and a private key that must not. It underpins key exchange, digital signatures and certificates. Today’s widely deployed public-key algorithms (RSA, elliptic-curve and finite-field Diffie-Hellman) are the ones a quantum computer would break.
B
- BSI#
- Germany’s Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik). Its technical guideline TR-02102 sets recommended algorithms and key lengths, and recommends using post-quantum algorithms in combination with classical ones.
C
- CBOM (cryptographic bill of materials)#
- A machine-readable inventory of the cryptographic assets a system uses: algorithms, certificates, protocols and key material, with their parameters and where they were found. CycloneDX 1.6 defines a standard format for it.Read more: What is a CBOM?
- Certificate (X.509)#
- A signed document that binds a public key to an identity, such as a server name or an organisation. Certificates are issued by a certificate authority within a PKI and carry a signature algorithm, a key and a validity period, all of which belong in a cryptographic inventory.
- Cipher suite#
- The combination of algorithms a TLS connection uses for key exchange, authentication, encryption and integrity. What a server actually negotiates can differ from what its configuration file suggests, which is why live endpoint inspection matters.
- CNSA 2.0#
- The US National Security Agency’s Commercial National Security Algorithm Suite 2.0 (2022). It sets the quantum-resistant algorithms for US national security systems, including ML-KEM and ML-DSA at their highest parameter sets, and a transition timeline running to 2035. Often used as a reference outside the US.
- CRA (Cyber Resilience Act)#
- EU Regulation 2024/2847, which sets cybersecurity requirements for products with digital elements, including an SBOM and state-of-the-art protection of data. Reporting obligations apply from 11 September 2026 and most other obligations from 11 December 2027.Read more: CBOM vs SBOM and the CRA
- CRQC (cryptographically relevant quantum computer)#
- A quantum computer large and reliable enough to run Shor’s algorithm against real key sizes, such as RSA-2048. None exists today and estimates of when one might vary widely, which is why guidance focuses on data lifetime and migration time rather than a single date.Read more: HNDL assessment
- Crypto-agility#
- The ability to change cryptographic algorithms, parameters or implementations quickly and safely, without rewriting the systems that use them. Post-quantum will not be the last migration; agility determines what each future one costs.Read more: Crypto-agility explained
- Cryptographic inventory#
- A current, evidence-based list of where cryptography is used across code, certificates, endpoints and key stores. The first milestone of the EU post-quantum roadmap expects organisations to have started one by the end of 2026. A CBOM is its standard machine-readable form.Read more: Cryptographic inventory
- CycloneDX#
- An open bill-of-materials standard from the OWASP community. Version 1.6 added cryptographic assets, so the same format carries both an SBOM and a CBOM.Read more: CBOM generator
D
- DORA#
- The EU Digital Operational Resilience Act (Regulation 2022/2554), applicable to financial entities since 17 January 2025. Article 9 and the ICT risk management RTS (Delegated Regulation 2024/1774) include requirements on encryption and cryptographic controls.Read more: DORA Article 9
E
- ECC, ECDH and ECDSA#
- Elliptic-curve cryptography and its two most common uses: ECDH for key exchange and ECDSA for signatures (EdDSA and X25519 are close relatives). They are efficient and widely deployed, and they are broken by Shor’s algorithm just like RSA.
- ENISA#
- The European Union Agency for Cybersecurity. It supports the implementation of NIS2 and other EU cybersecurity law and publishes guidance, including on post-quantum cryptography.
- EU post-quantum roadmap#
- The Coordinated Implementation Roadmap published by the NIS Cooperation Group in June 2025, following Commission Recommendation 2024/1101. It expects first steps, including inventories, by the end of 2026, high-risk use cases migrated by the end of 2030, and as many systems as feasible by 2035.Read more: EU roadmap: 2026, 2030, 2035
F
- FIPS 203, 204 and 205#
- The first three NIST post-quantum standards, published in August 2024: FIPS 203 (ML-KEM), FIPS 204 (ML-DSA) and FIPS 205 (SLH-DSA).Read more: PQC migration roadmap
- FN-DSA#
- A lattice-based signature scheme derived from Falcon, being standardised by NIST as FIPS 206. Its signatures are smaller than ML-DSA’s, at the cost of a more delicate implementation.
G
- Grover’s algorithm#
- A quantum search algorithm that speeds up brute-force attacks quadratically. It weakens symmetric keys and hash functions rather than breaking them, which is why the usual response is larger keys and outputs, not new algorithms.
H
- Hash function (SHA-1, SHA-2, SHA-3)#
- A function that maps data to a fixed-size digest, used for integrity, signatures and passwords. SHA-1 is broken (practical collisions were shown in 2017) and should be retired regardless of quantum risk; SHA-2 and SHA-3 remain recommended.
- HNDL (harvest now, decrypt later)#
- Recording encrypted traffic or data today in order to decrypt it once a quantum computer exists. It makes quantum risk a present concern for any data that must stay confidential for years.Read more: Assess your HNDL exposure
- HQC#
- A code-based key encapsulation mechanism selected by NIST in March 2025 as a backup to ML-KEM, so that a second KEM rests on different mathematics.
- HSM (hardware security module)#
- A tamper-resistant device that generates, stores and uses keys without exposing them. HSM firmware and certification often set the pace of a post-quantum migration, because new algorithms must be supported in hardware first.
- Hybrid cryptography#
- Combining a classical and a post-quantum algorithm so that the result stays secure as long as either one holds. In TLS 1.3 the common example is X25519MLKEM768 key exchange. ANSSI and BSI recommend hybrid use during the transition.Read more: ANSSI on hybridisation (in French)
K
- KEM (key encapsulation mechanism)#
- A public-key method for establishing a shared secret: one party encapsulates a random secret under the other’s public key. Post-quantum key establishment, such as ML-KEM, uses KEMs rather than Diffie-Hellman-style key agreement.
L
- LMS and XMSS#
- Stateful hash-based signature schemes specified in NIST SP 800-208. They are conservative and already standardised, but the signer must never reuse a one-time key, which suits firmware and code signing better than general use.Read more: PQC for energy & utilities
M
- Migration wave#
- A group of systems migrated together, ordered by risk and dependencies. Planning in waves turns “migrate everything” into a sequence that teams can execute and budget.Read more: Estimate the blast radius
- ML-DSA#
- Module-Lattice-Based Digital Signature Algorithm, standardised in FIPS 204 (derived from CRYSTALS-Dilithium). The main general-purpose post-quantum signature, with three parameter sets: ML-DSA-44, -65 and -87. Keys and signatures are much larger than ECDSA’s.Read more: FIPS 203/204/205
- ML-KEM#
- Module-Lattice-Based Key-Encapsulation Mechanism, standardised in FIPS 203 (derived from CRYSTALS-Kyber). The main post-quantum replacement for RSA and elliptic-curve key exchange, with three parameter sets: ML-KEM-512, -768 and -1024.Read more: FIPS 203/204/205
- Mosca’s inequality#
- A rule of thumb from Michele Mosca: if the time your data must stay secret (x) plus the time it takes to migrate (y) is greater than the time until a CRQC exists (z), you are already late. It is why data lifetime drives priority.Read more: HNDL assessment
N
- NCSC#
- The UK National Cyber Security Centre. Its 2025 migration timeline asks organisations to complete discovery and planning by 2028, migrate priority systems by 2031 and complete migration by 2035.
- NIS2#
- EU Directive 2022/2555 on a high common level of cybersecurity. Article 21(2)(h) requires policies on cryptography and, where appropriate, encryption; Implementing Regulation 2024/2690 details what that means for many digital service providers.Read more: NIS2 Article 21 and cryptography
- NIST IR 8547#
- A NIST draft (November 2024) on the transition to post-quantum standards. It proposes deprecating quantum-vulnerable public-key algorithms after 2030 and disallowing them after 2035.
P
- PKI (public key infrastructure)#
- The certificate authorities, policies and processes that issue, renew and revoke certificates. Root certificate lifetimes, HSM support and relying-party compatibility make PKI one of the longest-lead items in a post-quantum migration.
- Post-quantum cryptography (PQC)#
- Classical algorithms, running on today’s computers, designed to resist attacks by quantum computers. Not to be confused with quantum cryptography: PQC is a software and protocol change, not new hardware.Read more: PQC migration roadmap
Q
- QKD (quantum key distribution)#
- Using quantum physics to distribute keys over dedicated links. It needs special hardware and does not provide authentication on its own; European agencies including ANSSI and BSI favour post-quantum cryptography as the main migration path.
R
- RSA#
- The most widely deployed public-key algorithm, used for encryption, key transport and signatures. Its security rests on factoring large numbers, which Shor’s algorithm would make practical on a CRQC; larger keys do not fix this.
S
- SARIF#
- Static Analysis Results Interchange Format, an OASIS standard for the output of code-analysis tools. Code-scanning platforms read it to show findings at the right file and line.Read more: Cryptography in CI/CD
- SBOM (software bill of materials)#
- A machine-readable list of the components a product is built from: libraries, versions, package identifiers, licences and dependencies. Required for manufacturers under the CRA. It does not show how cryptography is used.Read more: CBOM vs SBOM
- Shor’s algorithm#
- A quantum algorithm (1994) that factors integers and computes discrete logarithms efficiently. On a CRQC it would break RSA, Diffie-Hellman and elliptic-curve cryptography, which is the core of the quantum threat.
- SLH-DSA#
- Stateless Hash-Based Digital Signature Algorithm, standardised in FIPS 205 (derived from SPHINCS+). Its security rests only on hash functions, which makes it a conservative choice for long-lived roots and firmware, at the cost of large signatures and slower signing.Read more: FIPS 203/204/205
T
- TLS 1.3#
- The current version of the Transport Layer Security protocol that protects most network traffic. Hybrid post-quantum key exchange is already deployed in TLS 1.3 by major browsers and providers; post-quantum certificates are further behind.
See these terms on real code
In a 30-minute demo we run CRYPTAGION live on a public repository that matches your stack: the inventory, the CBOM and the risk scores behind these definitions. No access to your code needed.
Request a free demo →