Post-quantum cryptography (PQC) uses quantum-resistant algorithms, standardized by NIST as ML-KEM, ML-DSA, and SLH-DSA, to help protect data and communications from future quantum-computer based attacks. Main challenges are implementation, certification, and integration.

Infineon implements these NIST-standardized algorithms in certified security hardware—from Trusted Platform Modules to security controllers and microcontrollers, helping customers build quantum-resistant, crypto-agile, field-updatable devices.

Public-key cryptography secures most digital communication using mathematical problems that classical computers cannot solve efficiently. A cryptographically relevant quantum computer (CRQC), using Shor’s algorithm, could break today’s widely used RSA and ECC encryption. Symmetric encryption like AES is less affected and can be strengthened with longer keys such as AES-256.


The risk already exists under “harvest now, decrypt later” attacks, where encrypted data captured today could be decrypted once appropriate quantum computers (“Cryptographically Relevant Quantum Computers (CRQC)” become available. According to Germany’s BSI, such systems could emerge as early as 2030–2035. 

Infineon post-quantum cryptography timeline showing Q-day readiness for long-lifecycle devices and quantum-safe security.
Infineon post-quantum cryptography timeline showing Q-day readiness for long-lifecycle devices and quantum-safe security.
Infineon post-quantum cryptography timeline showing Q-day readiness for long-lifecycle devices and quantum-safe security.

At a system level, post-quantum cryptography replaces vulnerable public-key building blocks — key exchange and digital signatures — while keeping symmetric encryption largely intact. Three algorithm families cover the functions a secured system typically needs:

Post-quantum algorithms are not drop-in replacements at the silicon level. Their keys and signatures are substantially larger than those used in RSA or ECC, and they require more compute. That creates concrete design implications — which is where certified security hardware proves its value:

The transition strategy most standards bodies recommend is crypto agility:

·        Deploy PQC-ready hardware now

·        Use hybrid cryptography during the migration period by combining classical and post-quantum algorithms

·        Enable field updates so algorithms can evolve alongside emerging standards

Post-quantum migration is most urgent for long-lifecycle devices — assets that will still be in the field on Q-day and are exposed to “harvest now, decrypt later” today. These are exactly the connected, secured edge applications Infineon's serves:

Infineon is an implementer and ecosystem enabler of post-quantum cryptography. While NIST standardizes algorithms, Infineon integrates independently certified implementations into its security hardware. Its credentials include early PQC research, algorithm development contributions, and Common Criteria certifications with Germany’s BSI.

Infineon post-quantum cryptography milestones in quantum-safe security, ML-KEM, ML-DSA and standards adoption.
Infineon post-quantum cryptography milestones in quantum-safe security, ML-KEM, ML-DSA and standards adoption.
Infineon post-quantum cryptography milestones in quantum-safe security, ML-KEM, ML-DSA and standards adoption.

Infineon implements post-quantum cryptography across three product lines, matched to different design points. This is a portfolio overview, not a parametric selection table.

Infineon post-quantum cryptography adoption path: assess migration, evaluate hardware and design quantum-safe security.
Infineon post-quantum cryptography adoption path: assess migration, evaluate hardware and design quantum-safe security.
Infineon post-quantum cryptography adoption path: assess migration, evaluate hardware and design quantum-safe security.

•     1. Assess & plan your migration. Inventory cryptographic assets, identify “harvest now, decrypt later” exposure and long-lifecycle devices, and define a crypto-agile transition plan. Read the Infineon PQC migration guidance  

•     2. Evaluate the hardware. Use evaluation kits and the OPTIGA™ TPM 2.0 Explorer / ModusToolbox™ tooling to prototype quantum-resistant firmware updates and secured boot. Browse PQC evaluation kits and tools

•     3. Design in & certify. Apply application notes and reference designs, select the certified controller for your target, and engage Infineon support for design-in.

Contact our PQC experts for guidance on architecture, product selection and design-in support. 

Have a specific PQC question? Contact us.

Post-quantum cryptography is not the same as the classical encryption in most phones and laptops today, though it protects the same kinds of data. Current devices rely mainly on RSA and elliptic-curve cryptography (ECC) for key exchange and signatures — the exact public-key algorithms a cryptographically relevant quantum computer could break using Shor's algorithm. Post-quantum cryptography replaces or augments those methods with quantum-resistant algorithms such as ML-KEM and ML-DSA, standardized by NIST in FIPS 203 and FIPS 204 on 13 August 2024. Symmetric algorithms like AES-256 stay in use, with larger keys to offset the weaker effect of Grover's algorithm.

Infineon's post-quantum cryptography implementations are included in Common Criteria certification for the appropriate products. Common Criteria (CC) is a well-known internationally recognized security evaluation and certification standard. In January 2025, Infineon received the first Common Criteria EAL6+ certificate for a security controller comprising a post-quantum cryptography algorithm (ML-KEM). Separately, Infineon's Common Criteria EAL6+ certified SLC27 security controller provides a cryptographic library covering both ML-KEM and ML-DSA, announced in 2025. The algorithms themselves are defined by NIST; Infineon is a member-implementer that builds certified hardware implementations of them.

Post-quantum cryptography can run on constrained IoT and embedded devices, but algorithm choice matters because PQC keys and signatures are larger and more processing-intensive than classical cryptography. For resource-limited Secure Elements, ML-KEM is the preferred key-encapsulation mechanism and ML-DSA the preferred signature scheme, while stateful hash-based signatures (LMS/XMSS) suit firmware-update verification. Infineon addresses this in hardware: the OPTIGA™ TPM SLB 9672 and SLB 9673 use XMSS for quantum-resistant firmware updates, and the PSOC™ Control C3 microcontroller family adds hardware acceleration for post-quantum secured boot. Dedicated accelerators and higher-bandwidth interfaces keep performance acceptable on small devices.

Post-quantum cryptography integrates with existing security standards rather than replacing them, and adoption is progressing across complementary ecosystems. The Trusted Computing Group added ML-KEM and ML-DSA to the TPM 2.0 library specification in 2025; the FIDO Alliance has been evaluating ML-DSA and ML-KEM for authenticators; and the Matter smart-home standard has post-quantum device attestation on its roadmap. Most bodies, including Germany's BSI, recommend hybrid cryptography — a classical algorithm combined with a post-quantum algorithm — during the transition, which supports crypto agility. Infineon implements these standardized algorithms in its security controllers and TPMs so devices can align with each ecosystem's timeline.