Post-quantum cryptography at Alanata TALKS

The March edition of Alanata TALKS examined quantum risk, post-quantum cryptography, migration planning and the tools available for examining existing cryptographic systems.

Four speakers seated during a panel at Alanata TALKS
The Alanata TALKS panel on quantum risk and post-quantum cryptography. Source image.

The March 2025 edition of Alanata TALKS examined how quantum computing may affect the cryptographic algorithms used to protect data and IT systems. The programme included Michal Křelina from Sympulse and Miloš Soukup from IBM. Their presentations covered emerging standards, migration questions and technical tools associated with post-quantum cryptography (PQC).

The discussion focused on four subjects:

  • How quantum computing changes the risk profile of symmetric and asymmetric cryptography and hash functions
  • How organizations can identify the cryptographic algorithms already used across their systems
  • Which post-quantum standards, algorithms and tools are currently available
  • How cryptographic agility can support a gradual transition between existing and post-quantum algorithms

Migration planning and long-lived data

Michal Křelina discussed how organizations can assess the urgency of post-quantum migration. His presentation distinguished between the risks to asymmetric cryptography, symmetric cryptography and hashing, and referred to guidance from NÚKIB and NBÚ.

The proposed planning sequence covered an assessment of the current environment, a gap analysis, pilot projects and the selection of suitable algorithms. Křelina also discussed cryptographic agility and controls associated with ISO/IEC 27001:2022 and CIS Controls v8.1.

Michal Křelina speaking at Alanata TALKS
Michal Křelina speaking about post-quantum migration planning. Source image.

One issue raised during the session was the long lifespan of sensitive data. Encrypted information collected today could become readable later if sufficiently capable quantum computers and suitable decryption methods become available. Křelina argued that organizations with long-lived sensitive data should examine that exposure before migration becomes urgent.

IBM’s quantum-safe tools and standards

Miloš Soukup, Business Technology Leader and Quantum Ambassador at IBM, presented IBM’s view of the current PQC landscape. His talk covered:

  • NIST standards and algorithms including ML-KEM, ML-DSA and SLH-DSA
  • PQC support in IBM Cloud and IBM z16
  • IBM Quantum Safe Explorer, Remediator and Guardium Quantum Safe
  • Hybrid cryptography at the application and infrastructure levels
Miloš Soukup speaking at Alanata TALKS
Miloš Soukup presenting IBM’s approach to quantum-safe cryptography. Source image.

Soukup also discussed cryptographic agility, which allows organizations to change cryptographic methods without redesigning every affected system. Hybrid approaches can use established and post-quantum algorithms during the same transition period.

Cryptography inventories and CBOMs

Both migration planning and cryptographic agility depend on knowing which algorithms, certificates, keys and libraries an organization currently uses. The session covered cryptography inventories and the cryptographic bill of materials (CBOM) as ways to record those dependencies.

IBM Quantum Safe Explorer was presented as one tool for discovering cryptographic assets and producing the information needed to prioritize future changes.

The full session is available in the Alanata TALKS recording.