singtel logo

Article

Post-quantum cryptography: what does it mean for your tech stack?

Post-quantum cryptography is moving from research into implementation. With the first global standards now established, enterprises can start preparing for a post-quantum future. But readiness is not simply about choosing the right algorithm. Discover where post-quantum cryptography fits into your tech stack and why crypto agility matters.

Categories: Quantum-safe network

13 Aug 2026

10 Mins

/business/insights/post-quantum-cryptography-what-does-it-mean-for-your-tech-stack.html

Key takeaways

  • NIST has finalised three foundational Post-Quantum Cryptography (PQC) standards, covering two critical functions: establishing secure connections and verifying identities and data through digital signatures.¹
  • Enterprises do not need to wait for every post-quantum standard to be finalised. PQC is already moving into areas such as secure network connections, certificates and software signing.¹ ⁴
  • The bigger priority is crypto agility: ensuring networks, applications and security infrastructure can adopt or replace cryptographic algorithms as standards and threats evolve.
  • PQC and Quantum Key Distribution (QKD) can play complementary roles, enabling enterprises to apply quantum-resistant protection across different environments according to their security and connectivity requirements.

     

 

From future risk to today's infrastructure decision

For years, the threat quantum computing poses to encryption could be treated as a future problem. That position is becoming harder to sustain. The reason is not simply how quickly quantum computing develops. It is how long the data enterprises hold today needs to remain protected. In a "harvest now, decrypt later" attack, an adversary can collect encrypted information today and retain it in the hope of decrypting it in future, when sufficiently powerful quantum computers become available.

For organisations protecting information that must remain confidential for many years — from financial and healthcare records to intellectual property and government communications — post-quantum security is therefore becoming a present-day planning consideration. That shift is already reflected in global standards. The US National Institute of Standards and Technology (NIST) published its first three final post-quantum cryptography standards in 2024 and has encouraged organisations to begin transitioning towards quantum-resistant cryptography.¹ The question for enterprises is increasingly moving from "When should we think about this?" to "Where do we start?"

What do the new algorithms actually do?

The good news is that enterprise leaders do not need to become cryptographers to understand the implications. At a high level, the public-key cryptography threatened by sufficiently capable quantum computers performs two important jobs. The first is establishing shared secrets for secure communications. This happens behind the scenes when systems establish encrypted connections. The second is digital signing — verifying that a user, device, application, software update or piece of data is genuinely what it claims to be.
 

NIST's first three standards address these functions:¹
 

• L-KEM establishes shared secrets that can be used to secure communications, making it relevant to areas such as secure network connections.
 

• ML-DSA provides digital signatures that can help authenticate identities, software and data.
 

• SLH-DSA provides another approach to digital signatures, based on different security assumptions, giving organisations and technology providers greater cryptographic diversity.

Other algorithms are progressing through NIST's standardisation process, including alternatives for both key establishment and digital signatures.² ³ That continuing evolution is important. Enterprises should not think of post-quantum migration as replacing today's algorithm with a single new one and considering the job finished.

Cryptographic standards will continue to develop, and vulnerabilities or new requirements may emerge over time. That makes the ability to change cryptography increasingly important.

Crypto agility may matter more than picking the "right" algorithm

Consider how deeply cryptography is embedded across a modern enterprise. It can sit inside applications, network connections, VPNs, certificates, cloud services, security appliances, hardware, APIs, software updates and connected devices. Now consider what happens if an algorithm used across thousands of those systems needs to be replaced. For many organisations, that could be a much bigger challenge than selecting the algorithm itself. This is where crypto agility becomes important: the ability to discover where cryptography is being used and update, replace or combine cryptographic approaches without redesigning the entire technology environment. It changes the post-quantum conversation.

Instead of asking only:

Which post-quantum algorithm should we adopt?

Enterprises should also ask:


How quickly could we change it if we needed to?

That is particularly relevant because post-quantum standardisation is still progressing. In May 2026, NIST advanced nine additional digital-signature candidates into a third round of evaluation, which is expected to run for approximately two years.² For enterprises, the lesson is straightforward: build for change rather than hard-coding today's choices into tomorrow's infrastructure.

Where should enterprises look first?

A post-quantum migration does not have to begin with a wholesale infrastructure replacement. A more practical starting point is understanding where cryptography exists today, which data and systems have the longest security lifespans, and where future quantum threats would create the greatest business risk.

Several areas are likely to demand early attention.

• Network connections.
Post-quantum cryptography can protect how shared secrets are established for secure communications, including connections across enterprise networks.¹

• VPNs and remote connectivity.
Organisations with distributed operations need to consider how cryptographic changes will affect secure connections between offices, data centres, clouds and remote environments.

• Certificates and identity infrastructure.
Digital certificates underpin trust across a vast range of enterprise systems. The IETF has standardised conventions for using ML-DSA in X.509 certificates and certificate revocation lists.⁴

• Software and firmware signing.
Long-lived systems need to continue verifying that updates come from trusted sources. This is particularly important for infrastructure and devices expected to remain operational for many years.

• Long-lived sensitive data.
Organisations should identify information that must remain confidential well into the future and assess whether "harvest now, decrypt later" presents a meaningful risk.

These assessments can help enterprises decide where migration should begin rather than attempting to change everything at once.

PQC and QKD: different approaches, complementary roles

Post-Quantum Cryptography (PQC) is not the only technology being developed to address quantum-era security. Quantum Key Distribution (QKD) uses principles of quantum physics to distribute cryptographic keying material. Unlike PQC, it requires specialised infrastructure, which influences where and how it can be deployed. That means the enterprise conversation does not necessarily need to be framed as PQC versus QKD. The two can play different roles:
 

  • PQC can provide scalable quantum-resistant protection using conventional computing and networking infrastructure, making it applicable across distributed enterprise environments.

  • QKD can be applied to selected high-value connections where specialised infrastructure is practical and the sensitivity of the communications warrants it.


A hybrid approach can therefore enable enterprises to match different security technologies to different levels of risk and different parts of their network.

Turning post-quantum standards into operational security

This is where the challenge moves beyond cryptography. An organisation may understand the emerging standards and still face a much harder question: how does it apply quantum-resistant protection consistently across data centres, branch offices, cloud environments, remote locations and international operations?

Singtel's Hybrid Quantum-Safe Network (QSN) is designed to address this infrastructure challenge. Launched as Southeast Asia's first Hybrid Quantum-Safe Network, it brings PQC and QKD together within a managed network architecture.⁵ ⁶

The hybrid approach enables enterprises to apply PQC across distributed and cloud environments while using QKD for selected communications where specialised quantum infrastructure is appropriate.⁵ ⁶ Rather than requiring organisations to approach quantum-safe security as an isolated infrastructure project, Hybrid QSN is designed to integrate quantum-safe capabilities into existing enterprise network and cybersecurity environments.⁵

Singtel's QSN also supports encryption across OSI Layers 1, 2 and 3, as well as MPLS, giving organisations flexibility in how quantum-safe protection is introduced according to their existing architecture and security requirements.⁵ For organisations that want to understand how these technologies would operate in their own environments before moving towards wider deployment,

Singtel also provides a three-phase pilot programme covering exploration workshops, integration testbeds and operational trials.⁵

Five questions to start asking now

Preparing for the post-quantum era does not mean replacing every cryptographic system tomorrow. It means understanding where the risks are and ensuring today's architecture does not limit tomorrow's choices.

Enterprise technology and security leaders can start with five questions:
 

  1. Where is public-key cryptography used across our organisation today?

  2. Which data needs to remain confidential for the longest period?

  3. Which systems, devices and network connections would be hardest to migrate?

  4. Can our existing security infrastructure support new or hybrid cryptographic approaches?

  5. How quickly could we replace an algorithm if standards or threats changed?
     

The first post-quantum standards are already here. More will follow. For enterprises, the objective should not be to predict exactly which cryptographic algorithm will dominate ten years from now. It should be to build an infrastructure capable of adapting whichever way the standards evolve. That is what turns post-quantum readiness from a cryptography project into a resilience strategy.

Explore how Singtel's Hybrid Quantum-Safe Network can help your organisation build a practical path towards post-quantum readiness.

References

1. National Institute of Standards and Technology (NIST), Post-Quantum Cryptography.

2. National Institute of Standards and Technology (NIST), Nine Candidates Advance to the Third Round of the Additional Digital Signatures for the PQC Standardization Process, 2026.

3. National Institute of Standards and Technology (NIST), Status Report on the Fourth Round of the NIST Post-Quantum Cryptography Standardization Process, 2025.

4. Internet Engineering Task Force (IETF), RFC 9881: Internet X.509 Public Key Infrastructure — Algorithm Identifiers for the Module-Lattice-Based Digital Signature Algorithm (ML-DSA), 2025.

5. Singtel, Quantum-Safe Network.

6. Singtel, Singtel launches Southeast Asia's first Hybrid Quantum-Safe Network to deliver flexible, scalable security for enterprises, 2025.

Discover more insights

  1. The four technologies reshaping how cities keep citizens safe — Across Asia Pacific, governments are investing in smarter, safer cities, and public safety is becoming an infrastructure question. Robotics, quantum-safe security, modern data architecture, and AI-driven decision systems are changing how agencies patrol, respond, and protect. Each one depends on the same underlying network conditions. See how the four capabilities come together, and the Singtel stack built to carry them. /business/insights/the-four-technologies-reshaping-how-cities-keep-citizens-safe
  2. Why the future of security is written in your data’s DNA — Security is moving beyond the perimeter towards the core cryptographic layer that defines trust across every transaction, device, and data flow. As quantum computing reshapes the threat environment, the durability of this data “DNA” becomes a true measure of resilience. /business/insights/why-the-future-of-security-is-written-in-your-datas-dna
  3. Singtel named Frost & Sullivan’s 2025 Singapore Cybersecurity Services Company of the Year — As cyber security becomes an infrastructure priority, Singtel’s integrated model gives businesses a more reliable way to secure and scale their digital operations. Frost & Sullivan’s 2025 report details why this approach earned Singtel the Singapore Cybersecurity Services Company of the Year recognition. Read the full report to learn more. /business/insights/frost-and-sullivan-2025-sg-cybersecurity-services-company-of-the-year-report
  4. From connected enterprises to connected intelligence — At GovWare, Singtel showcased a complete suite of future-ready enterprise solutions, showing connected intelligence in action, where networks, data, and AI come together to transform what’s possible. Dive into the highlights in this snapshot. /business/insights/from-connected-enterprises-to-connected-intelligence
  5. Singtel wins the Frost & Sullivan 2025 Singapore QSN Service Provider COTY award — With the emergence of quantum computing, existing encryption systems face a significant threat to data confidentiality. Singtel is proactively mitigating these threats by deploying advanced quantum-resistant cryptographic solutions across its expansive network in Singapore. With its strong overall performance, Singtel earns Frost & Sullivan’s 2025 Singapore Company of the Year Recognition in the quantum-safe network service provider industry. /business/insights/2025-singapore-quantum-safe-network-service-provider-coty-award

View all

View all

Stay ahead

Get the latest digest on business and technology trends straight to your inbox.

  1. Business /
  2. Business Insights

© Singtel (CRN: 199201624D) All Rights Reserved