Skip to content
NEWSROOM

Reading the CCPP Post-Quantum Cryptography stripe from the outside

08 May 2026·3 min read·post-quantum · curriculum

Post-quantum cryptography stopped being a research topic when NIST published FIPS 203, 204, and 205 in August 2024. ML-KEM, ML-DSA, and SLH-DSA are federal standards; agencies are on the clock to migrate; industry follows about eighteen months behind. The question your CISO will be asked in the next board pack is not whether you have a plan, but how far into it you are.

What the stripe covers

Five chapters. The first sets the ground: what a quantum computer of the size described in the NIST call breaks (Shor against RSA-2048 and P-256), what it does not (AES-256 remains meaningful, symmetric primitives lose about half their security margin under Grover). The second walks FIPS 203 (ML-KEM), 204 (ML-DSA), and 205 (SLH-DSA) with the actual parameters and their implications for message sizes, signature sizes, and code footprint.

Chapter three is the hybrid-TLS chapter — the one your platform team will care about most. It covers the current IETF drafts for hybrid key exchange in TLS 1.3, the reasoning for hybrid over pure-PQC in the transition years, and the operational cost of longer key material inside a TLS handshake. Chapter four is the harvest-now-decrypt-later chapter — the risk model, the assets that qualify as high-value, and the migration prioritisation that survives contact with a hostile CFO.

Chapter five is the migration project chapter. Cryptographic agility as a concept, an inventory of the places long-lived symmetric keys already exist in your estate, the vendor-management conversations that have to happen, and the memo that justifies the budget line to the audit committee.

Who it is for

A cryptography engineer, a platform lead, or a security architect at an organisation with a ten-year data-sensitivity horizon: finance, defence, health, critical infrastructure. If your organisation stores nothing an adversary would want to decrypt in 2033, the stripe is over-specified. If you do — and the definition catches a wider net than the average CIO expects — the stripe is the fastest way to reach a defensible migration position.

What it does not cover

  • The mathematics of lattices, ring-LWE, or hash-based signatures at graduate level. The stripe explains why the primitives are believed hard; it does not derive the proofs.
  • Hardware implementations. FPGA and ASIC integration is a separate discipline.
  • Quantum key distribution. QKD is a different product with a different threat model and is not covered here.
The board question next quarter will be operational: "How far are we along?" The right answer is not a promise; it is an inventory, a plan, and a first row already migrated.

Enrolment and bundle pricing at /stripe/post-quantum-cryptography. Requires CCPP as a prerequisite.