Key Findings
DigiCert has published practical recommendations to guide organizations in planning their migration to post-quantum cryptography (PQC) within the Transport Layer Security (TLS) protocol. This guidance clearly distinguishes between the two primary aspects of TLS—key exchange and authentication—and presents optimal quantum-resistant solutions for each.
Technical Details & Recommendations
The first aspect of PQC migration in TLS is “key exchange,” the process for securely sharing session keys when establishing communication. DigiCert notes that the industry is currently converging on X25519MLKEM768, a hybrid scheme. This hybrid approach combines the current standard X25519 elliptic curve cryptography with ML-KEM-768, a quantum-resistant Key Encapsulation Mechanism (KEM) that NIST is standardizing. This ensures “quantum safety” by providing security even if one of the algorithms were to be broken, as the other would still protect the session. The second aspect is “authentication,” which verifies the identity of the communicating parties. DigiCert recommends using ML-DSA (the ML-DSA signature algorithm, standardized by NIST as FIPS 204) for authentication as the default. ML-DSA’s robustness has been validated through extensive cryptanalysis, positioning it as a reliable authentication method for the quantum era.
Background & Industry Context
The security of modern internet communication heavily relies on the TLS protocol and its underlying public-key cryptosystems. However, the advent of practical, large-scale quantum computers has been theoretically shown to possess the capability to efficiently break these conventional cryptographic algorithms (especially RSA and elliptic curve cryptography). This raises the “Harvest Now, Decrypt Later” risk, where current secure communications could be intercepted, stored, and decrypted by quantum computers in the future. Governments and enterprises worldwide recognize the transition to PQC as an urgent imperative to protect sensitive data from this threat. NIST’s standardization of PQC algorithms provides a crucial foundation for guiding this transition.
Strategic Significance & Outlook
DigiCert’s recommendations for PQC migration in TLS offer a practical roadmap for enterprises to prepare for quantum threats. Adopting hybrid key exchange and ML-DSA authentication represents a balanced approach that reconciles current security with future quantum resistance. Following this guidance will enable organizations to navigate the complex PQC migration process more efficiently, minimizing impacts on existing security infrastructure. Going forward, PQC will become an indispensable component for maintaining the trustworthiness and security of digital infrastructure, requiring enterprises to prioritize PQC in their cybersecurity strategies. While this migration will be a large-scale endeavor potentially spanning several years, it is crucial for long-term data protection.
Source: https://www.digicert.com/articles/pqc/recommendations-for-post-quantum-tls-migration
Get our weekly technology intelligence — free
Receive an infographic that lets you judge at a glance whether each field’s analysis report is worth reading.
Subscribe Free — Weekly Tech Intelligence
By subscribing, you’ll receive Troy-Technical’s weekly technology intelligence newsletter.
- Your email and selected fields are used only to deliver the newsletter.
- We never share your information with third parties.
- You can unsubscribe anytime via the link in each email.
See our Privacy Policy for details.
Takes about a minute · Unsubscribe anytime

Comments