Foundations
Post-Quantum Cryptography Foundations
Quantum computing does not threaten all cryptography equally. This course separates what actually breaks — the public-key cryptography behind TLS, VPNs, and code signing — from what does not, walks through the NIST standards that replace it, and ends with the practical shape of a migration: what to inventory, how to prioritize it, and how to build systems that can change their cryptography again when the next standard arrives.
Who this course is for: Engineers, security professionals, architects, technology leaders, and anyone new to post-quantum cryptography.
Your progress
Checking your progress in this browser…
The core question
"What is post-quantum cryptography, and why does it matter?"
Outcomes
What you can do when you finish.
- Explain which cryptographic algorithms a quantum computer breaks, and which it does not, without conflating Shor's algorithm and Grover's algorithm.
- Name the NIST post-quantum standards — ML-KEM, ML-DSA, SLH-DSA — what each replaces, and the status of HQC and FN-DSA.
- Explain what hybrid key exchange protects today, and why authentication is often still classical.
- Apply Mosca's inequality to explain why migration urgency does not depend on knowing when a capable quantum computer will exist.
- Describe the practical constraints — inventory, dependencies, protocol limits, third parties — that make a migration a multi-year program, and where to start one.
Topics
What the course covers.
Course outline
Modules and lessons.
Module 1
What quantum computing changes
Two quantum algorithms threaten two different kinds of cryptography, by very different amounts. This module separates the two before drawing any conclusions about what to do.
- The exposed half6 min
Modern cryptography is really two disciplines with two different failure modes. This lesson separates them before quantum computing enters the picture.
- Shor's algorithm6 min
The algorithm that gives public-key cryptography an expiration date, and the one qualifier that belongs next to every mention of it.
- Grover and symmetric crypto7 min
A quadratic speedup is real but far smaller than what Shor's algorithm does to public-key cryptography — why AES-256 and SHA-256 stay on NIST's list of acceptable algorithms.
Module 2
The post-quantum toolkit
What quantum-safe means, the NIST standards that define it, and the two-tier reality — hybrid key exchange in transport today, authentication still largely classical — that every migration has to reckon with.
- What quantum-safe means6 min
NIST's first three finalized post-quantum standards, what each replaces, and the two items still in progress.
- The math behind the standards6 min
A working vocabulary for lattice-based, hash-based, and code-based cryptography, and why NIST wanted more than one family.
- Hybrid exchange and signatures7 min
What a hybrid TLS handshake protects today, the gap between confidentiality and authentication, and why bigger keys and signatures are a real constraint.
Module 3
Preparing
Crypto agility, why a migration runs to years rather than months, and where a program actually starts.
Credential
PQC Foundations — Certificate of Completion
Awarded after the final assessment, which is graded server-side so the score cannot be a number the browser chose.
Every issued credential can be checked at RelixQ Academy credential verification.
Final assessment
16 questions · 80% to pass
Scenario-based, timed only by your own pace. Retake it as many times as you need.