Security teams are currently executing the largest cryptographic migration in history, swapping RSA and elliptic-curve for lattice-based and other post-quantum schemes. The NSA and NIST have directed this move, and most practitioners are following the playbook without questioning the long-term horizon. Renato Renner, a leading quantum information theorist at ETH Zurich, agrees with the short-term strategy but delivers a sobering reality check on its shelf life. In this conversation with Quantum CEO Ivan Miskovic, recorded at QIP 2026, Renner dissects the foundational difference between post-quantum cryptography and quantum cryptography. The former rests on the assumed hardness of relatively new math problems—problems that have been stress-tested by orders of magnitude fewer mathematicians than factoring and could fall to classical attacks alone. The latter rests on the laws of physics. Renner makes the case that a hybrid approach (elliptic-curve plus lattice-based, layered) is the only responsible path today, but that device-independent quantum cryptography is the only way to permanently end the attacker-defender cycle. For practitioners making stack decisions with a 10-plus-year security horizon, this is essential context.

Key Takeaways

  • Post-quantum cryptography relies on mathematical problems like lattices that have been explored by far fewer researchers than RSA factoring, meaning our confidence in their hardness is significantly lower and classical breaks remain a real possibility.
  • A hybrid encryption model—layering elliptic-curve cryptography with lattice-based and hash-based schemes—is not just prudent but almost necessary for any system requiring security beyond the next five years.
  • Quantum cryptography derives its security guarantees from physical laws rather than computational assumptions, which Renner argues permanently ends the cat-and-mouse game between cryptographers and attackers.
  • Device-independent quantum security protocols can provide guarantees even when the underlying hardware is untrusted or partially compromised, a critical property for real-world deployment.
  • The NSA's recommendation to migrate to post-quantum schemes is correct for the short term, but organizations with long-term confidentiality requirements must begin planning for quantum cryptographic infrastructure now.

Who should watch: Security architects and cryptography engineers at financial institutions, defense contractors, and blockchain protocols who are currently implementing NIST PQC standards and need to understand the residual risk and the 10-plus-year roadmap.

Why This Matters

The post-quantum migration is being treated as a finish line when it is actually a stopgap. Renner's distinction between math-based and physics-based security forces a conversation most enterprise security teams are not yet having: what comes after NIST compliance.

Watch the full video →