Passkeys are considered today's gold standard against phishing, but they rely on cryptography that quantum computers could eventually break. Security key manufacturers are therefore already experimenting with quantum-resistant signatures. Before this technology reaches everyday use, though, quite a bit of standardization work still lies ahead.
An expiration date for today's cryptography
Even though quantum computers are still at an early stage of development, their technological potential is already becoming clear: the cryptography underlying digital identity has an expiration date. Given that algorithms may soon solve complex mathematical problems in seconds, and cybercriminals are already busily collecting encrypted data streams (harvest-now-decrypt-later), asymmetric encryption standards like RSA and ECC are under threat. That means sensitive data is already practically unprotected today. To keep securing authentication and data integrity going forward, the shift to post-quantum cryptography (PQC) is no longer a distant vision but an immediate strategic necessity.
Looking at how authentication has evolved makes clear that security shouldn't be viewed as a static state but as an evolutionary process. Traditional authentication, based on passwords and conventional multi-factor authentication, has critical weaknesses, especially once phishing and human error come into play. Passkeys mark a significant technological breakthrough: they eliminate many of these typical risks, since they simplify password management and rely on robust asymmetric cryptography. But while passkeys still count as the gold standard for usability and phishing resistance, the classical public-key algorithms currently in use aren't fully resistant to attacks from quantum computers. PQC is therefore the next necessary step in the evolution of digital identity, needed to preserve the security passkeys have achieved so far into the age of quantum computing.
Two protective dimensions for authentication
PQC refers to mathematically highly complex algorithms, such as the methods standardized by NIST, designed to withstand both classical and quantum-based computation. This upgrade is critically important because the harvest-now-decrypt-later scenario means attackers are already storing sensitive identity data en masse today, to decrypt it later once more powerful computers become available. In the context of modern authentication, PQC provides protection across two key dimensions: quantum-resistant digital signatures secure the long-term verifiability of identities and verifiable credentials, while new key exchange methods guarantee the confidentiality of communication channels like TLS. Without appropriate adjustments, encrypted connections considered secure today could be retroactively exposed within a few years, which makes a comprehensive modernization of infrastructure, from hardware security modules to end devices, essential by now.
First prototypes on hardware tokens
The practical implementation of these security standards already shows up in concrete proof-of-concept studies, such as PQC prototypes on hardware tokens. Yubico has demonstrated that post-quantum-resistant signatures are possible directly on physical security keys without disrupting the familiar user experience, the complex cryptographic protection happens in the background while the user triggers the process as usual with a simple touch. These demonstrations already yield some early insights for future infrastructure. Accompanying standards in areas like the PIN protocol, attestation, and general user experience still need to mature further to ensure seamless integration. Storage space is also a central challenge: since today's security keys often have too little capacity for the more extensive PQC algorithms, introducing new, more capable hardware becomes unavoidable. The goal is deep integration across the entire identity stack, extending passkeys beyond the simple login process into comprehensive digital identities and signatures within complex workflows.
Standardization as a shared task
The future viability of digital security depends heavily on PQC not existing as an isolated collection of algorithms but being deeply anchored in the global protocol infrastructure. Successful implementation requires integrating PQC at the protocol level into established standards like FIDO, WebAuthn/CTAP, PKI, PIV, and OpenPGP. This transformation can only happen through intensive industry cooperation that goes beyond individual companies and involves bodies like the IETF and the FIDO Alliance. Central challenges here include so-called crypto-agility, meaning the ability to flexibly swap out cryptographic methods, compatibility between current passkeys and new PQC methods, and the complex requirements around certificate lifecycles and existing hardware constraints.
How you can prepare now
To successfully manage the transition to quantum-resistant security, your organization should act proactively and develop a clear roadmap. The first step is creating a cryptographic bill of materials (CBOM) to gain full transparency into the crypto assets deployed across the company and where they're located. On that basis, you can systematically assess the specific PQC readiness of critical infrastructure components like passkeys, smart cards, hardware tokens, as well as TLS connections and IAM stacks.
Since an immediate, complete replacement of all systems is barely feasible technically, planning hybrid strategies is gaining importance, combining classical and PQC algorithms to ensure a secure transition. Companies should use this phase to gather valuable experience as early adopters through tests and pilot projects in PKI labs or with beta hardware. The transition to post-quantum cryptography should be understood not as a radical break but as a gradual evolutionary process spanning several years. Usability remains a central success factor throughout, since modern security solutions only get accepted if the increased protection doesn't come at the expense of user experience. Hardware-based identities form the technological core of this development: physical security components like security keys and secure elements serve as the load-bearing pillar that protects digital identities against future threats from quantum computers.