Skip to content AI
  • Overview

    • AI news
    • Technical blog
    • Live AI events
    • Inference explained
    • See our approach
  • Products

    • Red Hat AI Enterprise
    • Red Hat AI Inference
    • Red Hat Enterprise Linux AI
    • Red Hat OpenShift AI
    • Explore Red Hat AI
  • Engage & learn

    • Learning hub
    • AI topics
    • AI partners
    • Services for AI
Hybrid cloud
  • Platform solutions

    • Artificial intelligence

      Build, deploy, and monitor AI models and apps.

    • Linux standardization

      Get consistency across operating environments.

    • Application development

      Simplify the way you build, deploy, and manage apps.

    • Automation

      Scale automation and unite tech, teams, and environments.

  • Use cases

    • Virtualization

      Modernize operations for virtualized and containerized workloads.

    • Digital sovereignty

      Control and protect critical infrastructure.

    • Security

      Code, build, deploy, and monitor security-focused software.

    • Edge computing

      Deploy workloads closer to the source with edge technology.

  • Explore solutions
  • Solutions by industry

    • Automotive
    • Financial services
    • Healthcare
    • Industrial sector
    • Media and entertainment
    • Public sector (Global)
    • Public sector (U.S.)
    • Telecommunications

Discover cloud technologies

Learn how to use our cloud products and solutions at your own pace in the Red Hat® Hybrid Cloud Console.

Products
  • Platforms

    • Red Hat AI iconartificial intelligence, Red Hat Enterprise Linux AI, Red Hat OpenShift AI, RHEL AI, machine learning38382025-03-12T19:43:40.963Zimage/svg+xmlRed Hat AI iconartificial intelligence, Red Hat Enterprise Linux AI, Red Hat OpenShift AI, RHEL AI, machine learningIconno2025-03-12T19:39:59.817ZTechnology iconStandardRed Hat AI

      Develop and deploy AI solutions across the hybrid cloud.

    • Red Hat Enterprise Linux iconRHEL, Linux platforms, CentOS2024-03-01T15:26:42.958ZpendingTRA3b65dd25-844d-49bb-93c1-30f5b34684f1Icon2024-03-01T15:26:42.958Ztruepending2024-03-21T00:40:29.326Zrhcc-audience:internalnoTechnology iconDER3b65dd25-844d-49bb-93c1-30f5b34684f1Standardyesrhcc-product:red-hat-enterprise-linuxTechnology iconimage/svg+xml2024-05-10T14:11:29.114ZRed Hat Enterprise Linux iconRHEL, Linux platforms, CentOSActivateActivate2024-05-10T14:11:29.836Zworkflow-process-serviceActivateworkflow-process-servicefalse2024-05-10T14:11:29.836Zworkflow-process-service2024-05-10T14:11:29.836ZUse technology icons to represent Red Hat products and components. Do not remove the icon from the bounding shape.Red Hat Enterprise Linux

      Support hybrid cloud innovation on a flexible operating system.

    • Red Hat OpenShift iconCloud, Containers, Kubernetes2024-03-01T15:26:53.684ZpendingTRA9ec76aa9-ef09-4c49-8816-01dd13970ca7Icon2024-03-01T15:26:53.684Ztruepending2024-03-21T00:39:44.126Zrhcc-audience:internalnoTechnology iconDER9ec76aa9-ef09-4c49-8816-01dd13970ca7Standardyesrhcc-product:red-hat-openshiftrhcc-product:red-hat-openshift-on-ibm-cloudrhcc-product:microsoft-azure-red-hat-openshiftrhcc-product:red-hat-openshift-service-on-awsrhcc-product:red-hat-openshift-container-platformrhcc-product:red-hat-openshift-platform-plusTechnology iconimage/svg+xml2024-05-10T14:18:23.703ZRed Hat OpenShift iconCloud, Containers, KubernetesActivateActivate2024-05-10T14:18:25.221Zworkflow-process-serviceActivateworkflow-process-servicefalse2024-05-10T14:18:25.221Zworkflow-process-service2024-05-10T14:18:25.221ZUse technology icons to represent Red Hat products and components. Do not remove the icon from the bounding shape.Red Hat OpenShift

      Build, modernize, and deploy apps at scale.

    • Red Hat Ansible Automation Platform iconManagement, edge2024-03-01T15:26:35.068ZpendingTRA759b57c4-760b-45a0-a939-821f47181964Icon2024-03-01T15:26:35.068Ztruepending2024-03-21T00:39:55.923Zrhcc-audience:internalnoTechnology iconDER759b57c4-760b-45a0-a939-821f47181964Standardyesrhcc-product:red-hat-ansible-automation-platformTechnology iconimage/svg+xml2024-05-10T14:04:00.014ZRed Hat Ansible Automation Platform iconManagement, edgeActivateActivate2024-05-10T14:04:01.784Zworkflow-process-serviceActivateworkflow-process-servicefalse2024-05-10T14:04:01.784Zworkflow-process-service2024-05-10T14:04:01.784ZUse technology icons to represent Red Hat products and components. Do not remove the icon from the bounding shape.Red Hat Ansible Automation Platform

      Implement enterprise-wide automation.

      New version
  • Featured

    • Lightwell
    • Red Hat AI Enterprise
    • Red Hat OpenShift Virtualization Engine
    • Red Hat Desktop
    • See all products
  • Try & buy

    • Start a trial
    • Buy online
    • Integrate with major cloud providers
  • Services & support

    • Consulting
    • Product support
    • Services for AI
    • Technical Account Management
    • Explore services
Training
  • Training & certification

    • Courses and exams
    • Certifications
    • Skills assessments
    • Red Hat Academy
    • Learning subscription
    • Explore training
  • Featured

    • Red Hat Certified System Administrator exam
    • Red Hat System Administration I
    • Red Hat Learning Subscription trial (No cost)
    • Red Hat Certified Engineer exam
    • Red Hat Certified OpenShift Administrator exam
  • Services

    • Consulting
    • Partner training
    • Product support
    • Services for AI
    • Technical Account Management
Learn
  • Build your skills

    • Documentation
    • Hands-on labs
    • Hybrid cloud learning hub
    • Interactive demos
    • Training and certification
  • More ways to learn

    • Blog
    • Events and webinars
    • Podcasts and video series
    • Red Hat TV
    • Resource library

For developers

Discover resources and tools to help you build, deliver, and manage cloud-native applications and services.

Partners
  • For customers

    • Our partners
    • Red Hat Ecosystem Catalog
    • Find a partner
  • For partners

    • Partner Connect
    • Become a partner
    • Training
    • Support
    • Access the partner portal

Build solutions powered by trusted partners

Find solutions from our collaborative community of experts and technologies in the Red Hat® Ecosystem Catalog.

ConsoleDocsSupport Search

I'd like to:

  • Start a trial
  • Buy a learning subscription
  • Manage subscriptions
  • Contact sales
  • Contact customer service
  • See Red Hat jobs

Help me find:

  • Documentation
  • Developer resources
  • Tech topics
  • Architecture center
  • Security updates
  • Customer support

I want to learn more about:

  • AI
  • Application modernization
  • Automation
  • Cloud-native applications
  • Linux
  • Virtualization
New For you

Recommended

We'll recommend resources you may like as you browse. Try these suggestions for now.

  • Product trial center
  • Courses and exams
  • All products
  • Tech topics
  • Resource library
Log in

Get more with a Red Hat account

  • Console access
  • Event registration
  • Training & trials
  • World-class support

A subscription may be required for some services.

Log in or register
Contact us
Red Hat logo
  • Home
  • Resources
  • Red Hat’s strategy for post-quantum cryptography

Red Hat’s strategy for post-quantum cryptography

July 23, 2026•
Resource type: Detail
Print to PDF

A trusted foundation for cryptographic transformation in a modern, agile, managed enterprise

Traditional encryption faces a hard deadline. Cryptographically relevant quantum computers (CRQCs) are moving from theory to reality. When they arrive, they will break the public-key cryptography that protects nearly every modern digital asset, process, hardware or software system, and network identity. 

Security relies on 3 core pillars: confidentiality, integrity, and availability. A quantum computer powerful enough to run advanced decryption algorithms puts all 3 at risk. For IT leaders, this means the daunting task of identifying and replacing outdated encryption across systems must start today. 

“Q-Day” is the day when a CRQC becomes available. While estimates for Q-Day vary, it is becoming clearer that it is arriving sooner than expected. Quantum information science and technology (QIST) continues to mature with newer, larger quantum computers, advancements beyond Shor's algorithm, and more reliable error correction in ever-larger ensembles of Qubits. 

Cryptography is woven into many modern systems, but Red Hat has spent years planning for Q-Day. Post-quantum cryptography (PQC) relies on complex mathematical algorithms that run on classical hardware but can successfully resist both classical and quantum attacks. Transitioning to quantum-resistant security is a long-term strategy, not a quick patch. Red Hat can help you build an operational roadmap.

Understanding the full risk landscape

Early industry conversations focused almost entirely on harvest now, decrypt later (HNDL) attacks. In an HNDL scenario, an adversary intercepts and archives encrypted enterprise traffic today, waiting to decrypt it once they gain access to a quantum computer. 

HNDL remains a serious threat, but it is not the only one. As Q-Day approaches, you must account for a much wider circle of vulnerabilities. 

Figure 1. Potential vulnerabilities associated with Q-Day.

Threat vector

Capability (example)

Risk (example)

Break confidentiality

Decrypt lost or harvested confidential data by stealing encryption keys.

Ransom, extortion, or IP theft that directly uses or threatens to disclose harvested data

Fracture integrity

Manipulate firmware updates and transactions through fraudulent authentication.

Impersonation with fake identities of systems, software, or people with authority to act within your security boundaries

Damage availability

Forge session termination tokens, inject rogue routing protocols, or bypass authentication to hijack administrative control planes.

Malicious Denial-of-Service (DoS) attack that disrupts running services and forces systemic data quarantines or shutdowns because unverified telemetry, logs, and command streams induce a total operational deadlock

IBM is developing some of the largest and most capable quantum computers. Today, this includes:

  • 127-qubit Eagle.
  • 133-qubit Heron r1.
  • 156-qubit Heron r2 and r3 processors. 

Nighthawk has a scale-out architecture roadmap over 1,000 logical qubits by 2027.

The Red Hat blueprint for quantum safety

Red Hat uses a 3-step strategy to help enterprises establish operational resilience before classical encryption fails.

Step  1: PQC modernization

We are building standard, quantum-resistant algorithms (QRAs) directly into the core of our platform ecosystem. Red Hat® Enterprise Linux® 10 includes default hybrid-PQC capabilities for secure sockets layers (SSL), alongside National Institute of Standards and Technology’s (NIST) standardized algorithms: 

  • FIPS 203: (ML-KEM, formerly Crystals-Kyber) for secure key encapsulation.  
  • FIPS 204: (ML-DSA, formerly Crystals-Dilithium) for digital signatures.  
  • FIPS 205: (SLH-DSA, formerly SPHINCS+) for stateless hash-based signatures.

Deploying these algorithms is difficult due to complex open source dependencies. Red Hat is using its leadership in upstream communities to help prepare core standards like SSL and X.509 for the quantum era. To accommodate what is expected to be a complex transition period, hybrid protocols and mixed-mode operations are provided whenever they support such modes.

Quantum safety is not merely about having algorithms present; it's about effectively using them to protect your assets. Red Hat is driving PQC adoption across its layered portfolio to provide libraries, applications, and tools that are quantum-resistant.

  • Red Hat Enterprise Linux 10 has already been released with NIST-standard QRAs, default hybrid-PQC for SSL, and other core capabilities.
  • Red Hat OpenShift® serves as a self-contained, hybrid cloud foundation that lets you consistently run and protect your most critical workloads.
  • Red Hat is supporting PQC in key application libraries and runtimes, including Python, Go, and Java.
  • Red Hat Advanced Developer Suite is preparing to deliver PQC for key components of the software supply chain, including trusted artifacts, signing, and verification.
  • Red Hat is investing and accelerating PQC for Red Hat identity platforms—including Identity Management in Red Hat Enterprise Linux, Red Hat Certificate System, and Red Hat Directory Server—to build a quantum-ready trust basis.

As Red Hat makes quantum resistance available, it will inform customers through product tagging, individual component tagging, and cryptographic bills of materials (CBOMs). A CBOM is an inventory of all cryptographic assets and dependencies within an application, helping security teams track what needs to be modernized.

Figure 2. Q-Day preparation roadmap.

YesterdayTodayTomorrowFuture
Traditional cryptography; no quantum-resistant algorithms available.Includes available QRAs and PQC functions. Not available for all applications. Classical by default with configurable use of available QRAs.QRAs and PQC functions by default where available, configurable classical where needed.Classical algorithms and functions will be marked as deprecated with eventual removal. Capabilities and mechanisms to be resistant to downgrade attacks.
government building icon

Classical

red hat icon

PQ-capable

heart rate icon

PQ-ready

red target icon

Deprecation and removal

Step 2: Cryptographic agility

PQC migration is qualitatively different from either past cryptographic updates or IT modernizations: It’s a must-succeed, novel synthesis of both. Achieving the necessary agility requires organizations to map how platforms exchange cryptographic keys. 

This process begins with a clear inventory of your software assets. It starts with the basics: inventory and risk management. Once inventory information is complete and checked for accuracy, optimization and management work can begin.

Red Hat tools can help automate this process: Red Hat Lightspeed telemetry platforms are integrating cryptographic discovery and Red Hat Ansible® Automation Platform can apply general-purpose system automation to the discovery process. This facilitates modernization and builds the foundation for future enterprise agility.

Adopting PQC may motivate organizations to focus on fundamental enterprise agility, but there are many other reasons to do so:

  • Artificial intelligence and agentic systems will rely on nonhuman identity and specialized authentication and authorization systems.
  • Software-defined IT systems with a higher dynamic nature require frequent use of independent cryptographic trust and trust anchor systems.
  • Cybersecurity risks, particularly in supply chains, are rapidly increasing and the industry is responding with wider use of cryptographically secured or organized digital assets.

Step 3: Cryptographic posture management

Enterprise governance is at the heart of cryptographic posture, assessing the state and actively managing the use of cryptography within an organization. Assessment and management needs to outlast PQC migration and remain relevant even after migration to QRAs is complete. CBOMs will provide an invaluable tool for exchanging posture information across applications, teams, and vendor ecosystems—and to your Chief Information Security Officer (CISO) for effective policy definition and management.

Figure 3: Example cryptographic discovery scan results from Red Hat Ansible Automation Platform over a set of hosts.

Example cryptographic discovery scan results from Red Hat Ansible Automation Platform over a set of hosts.

It’s a governance challenge, and well-defined policies are critical to success. Red Hat has provided specialized cryptographic policies in Red Hat Enterprise Linux since version 8, and is providing policies to support the transition process and prepare for a future, policy-managed state. Equally critical to managing your own assets is applying the same CPM rigor to all dependencies in your enterprise: external managed services, supply chain and vendors, and hardware and network providers.

Lay your quantum foundation

Because the risk landscape extends beyond simple data harvesting, your immediate steps should focus on establishing a strong foundation.

Early analysis suggests some basic steps to prioritize for Linux users, in the near term.

Figure 4. Prioritized steps for Linux users.

Immediate

Root of trust (integrity)

Operational horizon (availability)

Protect long shelf life.

Defeat quantum forgery.

Provide real-time authentication and agility through zero trust.

  • Update LUKS (Linux Unified Key Setup) and key escrow to PQC-ready standards.
  • Secure long-lived transport layer security (TLS) tunnels and backend database connections.
  • Prioritize PQC-capable hardware security modules (HSMs) for root-key storage.
  • Verify what is real.
  • Transition to ML-DSA signatures on artifacts. 
  • Enable PQ secure boot as soon as it is available.
  • Transition multi-factor authentication (MFA) and passwordless access to hardware tokens and drivers to prepare for PQC.
  • Adopt PQC mutual transport layer security (mTLS) for inter-service traffic protection.
  • Crypto-agility for simple config (not code) changes.

As Q-Day gets closer and eventually arrives, the range of risks will increase and threats and threat actors will materialize.

Prepare your organization

The transition to post-quantum cryptography has been compared to Y2K—but this comparison downplays the organizational changes that will be required to meet this challenge.

Figure 5. Change management and alignment to goals.

collaboration icon

Cultural change

government building icon

Policy development

red collaboration icon

Collaboration

red maze icon

Roadmap

PQC forces us to move past the "padlock fallacy"—the habit of setting up encryption once and never checking it again. 

Instead of treating security as a static compliance checklist, teams must view cryptography as a dynamic system requiring continuous, active management.

Align cryptographic strategies with international best practices.

Implement policies that track the threat clock across your global presence, so you can take calculated steps to resilience and sovereignty.

Work within the global community to ensure open, neutral standards.

Red Hat works to maintain interoperability with global upstream communities, like those around Linux, OpenSSL, and Sigstore.

Plan to implement a transition while maintaining operations and resiliency of high-value assets and impacted  business workflows.

Prioritize the most sensitive global assets while automating to systematically reduce migration time. 


While your organization matures, Red Hat can help with early, high-value activities, such as:

  • PQC assessment: Create a maturity roadmap to guide your journey. Red Hat Consulting can help you deploy cryptographic scanning tools and methods, and put you on a path to understanding your current usage and encoding CBOMs.
  • Crypto agility foundation: Start implementing supply chain oversight, crafting policies, and deploying continuous cryptographic monitoring.
  • Compliance maintenance: Integrate your cryptographic posture data into your enterprise compliance to ensure you meet your jurisdiction's requirements and address emerging threats and risks.
  • Zero trust architectures: During the PQC transition period, many existing and low-priority enterprise resources will lag in quantum readiness. Red Hat can help by using best practices to mitigate risk with layered defenses.
  • Build standard operating environments (SOE): Use Red Hat Enterprise Linux, Red Hat Satellite, Red Hat OpenShift, Red Hat Ansible Automation Platform, and others to build environments with well-known post-quantum readiness and roadmaps for the future.

Accelerate your transition to PQC

Build a foundation for modern, policy-managed crypto functions

Use Red Hat Enterprise Linux 10.1 (or later) and Red Hat OpenShift to bring quantum-safe TLS to the connections carrying critical data today, with emerging PQC certificate and signature support to harden identity and access systems.

Take an automated approach to PQC modernization

Discover how Red Hat Ansible Automation Platform helps provide enterprise coverage and repeatable processes for cryptographic discovery and remediation.

Engage with Red Hat Consulting for practiced expertise

Work with Red Hat specialists to audit your systems, develop a migration roadmap, and implement quantum-resistant security measures step by step.

Tags:Automation and management, Security

Red Hat logo

About Red Hat

Red Hat is the open hybrid cloud technology leader, delivering a trusted, consistent and comprehensive foundation for transformative IT innovation and AI applications. Its portfolio of cloud, developer, AI, Linux, automation and application platform technologies enables any application, anywhere—from the datacenter to the edge. As the world's leading provider of enterprise open source software solutions, Red Hat invests in open ecosystems and communities to solve tomorrow's IT challenges. Collaborating with partners and customers, Red Hat helps them build, connect, automate, secure, and manage their IT environments, supported by consulting services and award-winning training and certification offerings.

  • North America
  • Asia Pacific
  • Latin America
  • Europe, Middle East, and Africa
  • 888-REDHAT1
  • +6564904200
  • +5443297300
  • +0080073342835
  • www.redhat.com
  • apace@redhat.com
  • info-latam@redhat.com
  • europe@redhat.com
  • @red-hat
  • @redhat
  • @redhat
  • @red_hat

Copyright © 2026 Red Hat. Red Hat, the Red Hat logo, Ansible, and OpenShift are trademarks or registered trademarks of Red Hat, LLC or its subsidiaries in the United States and other countries. Linux® is the registered trademark of Linus Torvalds in the U.S. and other countries. The OPENSTACK logo and word mark are trademarks or registered trademarks of OpenInfra Foundation, used under license. All other trademarks are the property of their respective owners.

Red Hat logoLinkedInYouTubeFacebookXInstagram

Platforms

  • Red Hat AI
  • Red Hat Enterprise Linux
  • Red Hat OpenShift
  • Red Hat Ansible Automation Platform
  • See all products

Tools

  • Training and certification
  • My account
  • Customer support
  • Developer resources
  • Find a partner
  • Red Hat Ecosystem Catalog
  • Documentation

Try, buy, & sell

  • Product trial center
  • Red Hat Store
  • Buy online (Japan)
  • Console

Communicate

  • Contact sales
  • Contact customer service
  • Contact training
  • Social

About Red Hat

Red Hat is an open hybrid cloud technology leader, delivering a consistent, comprehensive foundation for transformative IT and artificial intelligence (AI) applications in the enterprise. As a trusted adviser to the Fortune 500, Red Hat offers cloud, developer, Linux, automation, and application platform technologies, as well as award-winning services.

  • Our company
  • How we work
  • Customer success stories
  • Analyst relations
  • Newsroom
  • Open source commitments
  • Our social impact
  • Jobs

Change page language

Red Hat legal and privacy links

  • About Red Hat
  • Jobs
  • Events
  • Locations
  • Contact Red Hat
  • Red Hat Blog
  • Inclusion at Red Hat
  • Cool Stuff Store
  • Red Hat Summit
© 2026 Red Hat

Red Hat legal and privacy links

  • Privacy statement
  • Terms of use
  • All policies and guidelines
  • Digital accessibility