Quantum Computers and the Internet: What Should We Prepare For?

Aug 11, 2026 | Jindřich Zechmeister

Terms like “post-quantum cryptography” or “the quantum threat to the internet” may sound like science fiction. But the threat is real and already underway, affecting how securely we shop, bank, and communicate online. Here’s what you need to know—without the technical jargon.

What is it actually about?

All current internet security – encryption, digital certificates, logging in via HTTPS – is based on mathematical problems that are extremely difficult for classical computers to solve. However, quantum computers (if and when they become powerful enough) would be able to solve these problems relatively easily. Experts refer to such a hypothetical machine as a CRQC (Cryptographically Relevant Quantum Computer).

The good news is that no such computer exists yet. The bad news is that we need to prepare for its arrival now – for one simple reason.

“Harvest now, decrypt later”

There is a real threat called harvest now, decrypt later. An attacker can already intercept and store encrypted communication that they currently cannot decipher. However, once a quantum computer is created, they can return to the stored data and decrypt it retroactively. For sensitive information that needs to remain confidential for a long time (such as medical records, trade secrets, government communications), this is a real risk even now – not just ten years from now.

This is why the cryptography community is not waiting for quantum computers to actually arrive and is addressing the threat today.

Where we stand today?

In 2024, the American NIST agency (the equivalent of a standardization institute) officially approved new cryptographic algorithms resistant to quantum computers after years of preparation. The two most important are:

ML-KEM – used for secure key exchange
ML-DSA – used for digital signatures and identity verification

Encryption of communication (i.e., protection against eavesdropping) is advancing relatively quickly as a result. Browsers and major internet infrastructure providers have already started implementing so-called hybrid solutions, combining proven elliptic cryptography with the new ML-KEM. As a result, a significant portion of web traffic is already partially protected against future quantum threats.

Interestingly, Google has chosen a somewhat independent path. It does not like that the ML-DSA signatures are quite large (which slows down communication), so it is developing an alternative called Merkle Tree Certificates (MTC) – a new type of certificate that is expected to be faster and more efficient. However, the result is that the certificate ecosystem is beginning to split into two branches: the traditional (X.509 with ML-DSA) and the new (MTC). New MTC certificates are expected around 2027.

Where the hardest work lies ahead

While encryption of communication is progressing at a good pace, identity verification (i.e., digital certificates on which trust in HTTPS sites is based) is at the very beginning of its transformation.

Why is it so complicated?

1. More certificates will be needed. Today, servers typically use one or two certificates. In the future, they will likely need four to five because new types of certificates (fast and slow) will operate alongside the existing ones.

2. A new infrastructure must be created. New certification authorities will need to be built, the automatic certificate issuance system (ACME) will need to be adjusted, and the way servers manage and renew certificates will need to be redesigned.

3. Downgrade attacks. This is probably the most pressing issue. Even if a website has a new, quantum-resistant certificate, an attacker with a quantum computer could theoretically forge the old type of certificate and "convince" the browser to use outdated, vulnerable encryption instead of the new one. To prevent this, support for old cryptography must eventually be completely turned off – a process that will require years of coordination among browsers, servers, and certification authorities.

What is the timeline?

Originally, the entire transition was expected to take roughly until 2035. However, due to concerns about the faster development of quantum computers, several big technology companies have set a new, more ambitious goal: by 2029.

What to take away from this

Protection against eavesdropping (encryption) is preparing quite well and quickly for the quantum era.
Identity verification and the trustworthiness of certificates is a much more complex puzzle that still needs to be solved.
As a regular internet user, you will not notice anything significant yet – the entire process runs in the background and is managed by browsers, operating systems, and certification authorities.
However, for companies and website operators, it is crucial to follow this development because the way certificates are issued and managed will change significantly in the coming years.

Source: Feisty Duck's Cryptography & Security Newsletter


Ing. Jindřich Zechmeister
TLS certificate specialist
Certificated Sales Expert Plus
e-mail: jindrich.zechmeister(at)zoner.com