Pós-Quântico
Certificados Digitais
LGPD
Governança
Segurança da Informação

Post-Quantum Certificates and PKI: What Public Managers Should Plan Now

Post-quantum PKI is a long-term problem that requires short-term decisions, especially for those who store citizen data with long validity.

Post-Quantum Certificates and PKI: What Public Managers Should Plan Now

Of the entire cryptographic infrastructure of an organization, the one that is most resistant to change is certificates. PKI is the silent backbone of digital trust: it says that a website is who it claims to be, that an update came from the right source, that a document was signed by whoever it should have been.

This infrastructure has a characteristic that makes it especially sensitive to quantum risk: long validity and slow change. Root certificates live for decades. Changing the basis of a chain of trust involves manufacturers, browsers, operating systems and devices that may no longer receive updates. It's the kind of thing you plan years in advance or suffer in a rush.

For the public sector, which signs and stores citizen data with validity measured in decades, the equation is even more serious. This article closes the series by discussing what leaders, and especially public managers, need to start planning now.

Why PKI is the hardest case

Most post-quantum migration is laborious but contained: you update libraries, tweak configurations, swap algorithms behind well-defined boundaries. PKI deviates from this standard for three reasons.

First, longevity. A root certificate can be valid for twenty years or more. It is distributed and trusted by a multitude of systems. Replacing it is not a local operation, it is a coordinated orchestration of systems.

Second, the chain of dependencies. Trust in PKI is hierarchical: roots sign intermediaries, which sign end certificates. Migrating the hierarchy requires coordination between those who issue, those who distribute trust and those who consume it, and not everyone moves at the same pace.

Third, the legacy that does not update. Embedded devices, industrial systems, long-life equipment in the field carry fixed trust anchors, often with no practical update mechanism. For these, "migrating the PKI" can mean changing the hardware, and this has a cost and deadline that cannot be fit into a sprint.

The specific risk of signature versus secrecy

It is worth separating two types of risk that PKI carries, because they have different urgency and confusing them leads to wrong priorities.

The risk of secrecy is that of "harvest now, decrypt later", the capture of encrypted data today to decipher with quantum computing in the future. This risk is already taking place: what is intercepted now can be read later. It's what makes key exchange protection an immediate priority.

The signature risk is different. Forging a digital signature requires the quantum computer existing at the time of the fraud, not before. No one today forges a signature to use ten years from now in the same way as capturing encrypted data. This seems like a break, and in part it is.

Slack, however, is misleading for PKI because of longevity. A root certificate or a firmware signature that needs to be trusted for fifteen years crosses, within its validity, the likely horizon of arrival of quantum computing. Once the machine exists, it will be able to forge signatures that its systems still consider valid. That's why the signing of long-lived things, roots, firmware, documents of lasting value, needs to be included in the planning even without the immediate urgency of secrecy.

What changes in post-quantum certificates

The transition from PKI to algorithms such as ML-DSA, NIST's digital signature standard, brings concrete technical challenges that managers need to be aware of to plan deadlines and costs.

Post-quantum signatures and keys are larger than classical ones. This inflates the size of certificates, trust chains, and handshake messages. Systems, protocols and devices that have assumed small sizes may need adjustment, and some old equipment may simply not support the new sizes.

Compatibility is the second challenge. For years, systems that understand post-quantum certificates and systems that only understand classical ones will coexist. The industry is moving toward hybrid certificates and transition chains that carry both, maintaining the trust of legacy systems while adding new protection. This requires coexistence planning, not a dry cut.

And there is operational maturity. PKI has consolidated issuance, renewal, revocation and audit processes, built over decades on classical algorithms. Reconstructing these processes for post-quantum algorithms, with their own characteristics, is part of the work that tends to be underestimated.

The extra weight of the public sector

Those who store citizen data bear a responsibility that the private sector, in general, does not have on the same scale.

The validity of public data is long in nature. A citizen's identity, biometrics, tax, judicial, social security and health records are sensitive throughout their life, and sometimes beyond. This data is right in the critical "harvest now, decrypt later" zone: if it is captured today under vulnerable protection, it will be readable within a period where it still causes harm.

There is also the institutional weight of the signature. Official acts, documents with public trust, citizens' digital identities, and the public key infrastructure that supports government services need to remain trustworthy for a long time. A government signature that becomes forgeable compromises not just a piece of data, but trust in an entire public service.

And the public sector moves with its own cadences: bidding cycles, multi-year contracts, legacy systems that are difficult to replace. These cadences are slow, which is why anticipation matters even more. Anyone who only starts thinking about this when deadlines get tight will discover that they purchased systems, signed contracts and implemented infrastructure without foreseeing the transition, and that correcting them later costs much more.

What to plan now

Post-quantum PKI is a long-term problem that requires short-term decision-making. Some fronts cannot wait.

Include post-quantum requirements in purchases. Systems, certificates, devices and services contracted now will last for years. Asking for crypto-agility and post-quantum transition plan in procurement requirements avoids buying a problem today that you will have to solve expensively later. For the public sector, this means updating notices and terms of reference.

Map your PKI and trust anchors. You need to know which root and intermediate certificates underpin your services, which have long validity, and which devices and systems carry trust that is difficult to update. This is the cryptographic inventory applied to PKI, and it is what reveals where the transition will hurt.

Track and cover your suppliers and certificate providers. PKI migration is coordinated in nature. Knowing which certification authorities, manufacturers and providers have a post-quantum roadmap, and demanding deadlines from them, is part of your planning. Ecosystem timeframe benchmarks, such as the NSA's 2030 target for national security systems and NIST's anticipated deprecation of vulnerable algorithms by 2035, help calibrate what to demand and when.

Put the post-quantum transition on the acquisition and PKI agenda during this planning cycle. For long-term infrastructure, the decision that matters most is the one you make early, before signing the next multi-year contract or deploying the next decade-long system.

Also read