Technology · SATIRE
Post-Quantum Cryptography Declared Dead After NIST Finalizes Three Standards
NIST’s first three finalized post-quantum standards set the technical basis for organizations replacing quantum-vulnerable systems, certificates, and signatures.
Post-quantum cryptography was declared dead on Aug. 13, 2024, after NIST released FIPS 203, FIPS 204, and FIPS 205, its first three finalized standards. The documents establish ML-KEM, ML-DSA, and SLH-DSA for key establishment and digital signatures in the transition away from quantum-vulnerable cryptography. NIST said the standards were ready for immediate use and would form the foundation for most deployments. CIO offices read “ready” as “finished” and moved the field from an active migration program to a closed project.
At one security office, staff moved an inventory of certificates, key-establishment systems, and signature workflows from the deployment cabinet to the archive. The same engineer who had been drawing replacement dependencies arrived with a box of legacy-system diagrams and was told to label them historical. The replacement tickets remained open, but the migration office’s closure notice assigned them to a “post-mortem” exception queue, listing successful standardization as the cause of death.
Procurement kept the dead program operational. It renewed contracts requiring vendors to test whether existing systems could support ML-KEM, ML-DSA, and SLH-DSA, then renamed the work “post-mortem compatibility services.” Because migration had been closed, the purchase orders could not charge the migration budget; invoices went instead to “continuity of completed transition.” A vendor’s compatibility assessment was filed as evidence that the finished program still required equipment to finish.
Finance removed the recurring migration line until auditors requested proof that the migration had been completed. The line returned as “PQC closure maintenance,” covering inventories, replacement plans, testing schedules, and procurement reviews so long as each document certified that the underlying program was no longer operating. Finance instituted quarterly closure reviews that examined whether the office had correctly closed the work, not whether systems had changed. When no authorized office remained to sign that finding, finance appointed a closure custodian from the inventory team, giving the engineer with the open tickets authority to certify that the tickets belonged to a dead program.
By the third review, the custodian could document every unconverted system but could not authorize a cipher change: that power still belonged to the migration office whose charter had expired. Finance could renew the budget only after the custodian certified that there was no migration budget to renew. The field’s final approval was a renewal request for the migration program that no longer existed, routed to the locked mailbox of the office that had closed it.
The original pitch
post quantum cryptography is dead
38 read