NIST finalized its first post-quantum cryptography standards in August 2024 and added HQC as a fifth algorithm in March 2025. The US federal government set a 2030 deadline to deprecate RSA and elliptic-curve cryptography, with an outright ban in 2035. The NSA's CNSA 2.0 suite becomes a procurement gate for new national security systems on January 1, 2027. The cybersecurity industry is still treating post-quantum as a software problem: update your algorithms, recompile your code, ship the patch. The fiber industry knows something the cybersecurity industry hasn't fully processed: running quantum-resistant protocols across networks at line rate also requires hardware upgrades, and by October 2026 the first wave of that spending is visible in vendor order books.

Post-quantum cryptographic algorithms, ML-KEM, ML-DSA and SLH-DSA among the NIST standards, are computationally heavier than RSA and ECC and carry much larger keys and signatures. Encrypting and decrypting traffic at line rate requires processing headroom that older network hardware wasn't designed to provide. Optical transport equipment deployed in the 2015-2022 window generally lacks the ASIC capacity to run post-quantum key exchange alongside AES-256 at 400G and above without adding external encryption appliances or replacing the line cards outright. The newest coherent generation is a different story, and that distinction now defines the upgrade cycle.

Members Only

Keep reading — it's free

Futures analysis is exclusive to FiberPulse readers. Drop your email to unlock every article.

No spam — unsubscribe anytime.