Video companion
After Veritasium: from Shor's threat to NIST PQC standards
Veritasium's explainer lands the full arc: Shor breaks RSA, adversaries store ciphertext today, and NIST spent eight years standardizing quantum-resistant replacements.

What the video gets right
The video connects three ideas that belong in every board briefing:
- Shor's algorithm breaks the math behind RSA and ECC — not by brute force, but by exploiting quantum parallelism.
- Harvest now, decrypt later (HNDL) means adversaries copy encrypted traffic today and decrypt it after a CRQC exists. Storage is cheap; breaking crypto today is not required.
- NIST's PQC project selected algorithms now standardized as FIPS 203 (ML-KEM), FIPS 204 (ML-DSA), and FIPS 205 (SLH-DSA).
Industry timelines accelerated: Google's 2029 readiness target signals that migration planning cannot wait for headlines.
What it does not cover
Federal policy adds teeth: NSM-10 requires US agencies to migrate away from quantum-vulnerable algorithms. Private-sector contractors inherit similar expectations through supply-chain clauses.
Qtangl maps findings to NSM-10 and NIST IR 8547 deadline tiers with signed scan artifacts.
This quarter
- Map your longest-lived data classes (health, finance, IP) against migration runway using the Mosca calculator.
- Inventory external TLS for RSA and ECDSA — not a one-time spreadsheet.
- Read NIST IR 8547 deprecation tiers and assign owners per tier.
Continue on the Q-Day hub: PQC deadlines guide
References & further reading
Authoritative primary sources cited in this article. Summaries are our own — follow links for full context.
Last verified 2026-06-21
- What Makes Quantum Computers SO Powerful?Veritasium (YouTube) · 2023Covers Shor's threat, harvest-now-decrypt-later, NIST PQC competition, and migration urgency.
- What Is Post-Quantum Cryptography?NIST · 2024Official overview of NIST's PQC project, finalized standards, and the harvest-now-decrypt-later threat model.
- National Security Memorandum on Post-Quantum Cryptography (NSM-10)White House · 2022-05Federal mandate requiring migration away from quantum-vulnerable algorithms by 2035.
- Google bumps up Q Day deadline to 2029Ars Technica · 2026-03Coverage of Google's accelerated 2029 post-quantum readiness target and industry timeline shift.
See your exposure with evidence
Run a live PQC inventory scan, export a CBOM, and verify signed reports independently.