Quantum computers could eventually crack the RSA and ECC encryption that most VPNs still rely on. This is why major providers are moving to a quantum-safe VPN model built on new encryption standards from NIST. Below, we cover what the new NIST post-quantum standards actually do and how to choose one that will keep your data safe well past 2030.
Quick facts about quantum-safe VPNs
- Experts expect quantum computers could threaten RSA and ECC encryption sometime around 2030
- Attackers are already collecting encrypted traffic today to decrypt later, a tactic called harvest now, decrypt later
- NIST finalized its first three post-quantum cryptography standards in August 2024
- Switching to post-quantum encryption has shown little to no effect on connection speed
Why quantum computers are the next level of VPN encryption
Most VPNs today use RSA and Elliptic Curve Cryptography (ECC) to exchange keys and confirm identity. Both rely on math problems, like factoring huge numbers, that are extremely hard for ordinary computers to solve. That difficulty is what keeps your connection private.
Quantum computers work differently. Instead of processing one calculation at a time, they use qubits that can hold multiple states at once, letting them run certain calculations in parallel. That’s where the real risk comes in.
How Shor’s algorithm breaks encryption
In 1994, mathematician Peter Shor showed that a powerful enough quantum computer could factor large numbers and solve the math behind RSA and ECC far faster than any ordinary computer.
A sufficiently advanced quantum machine could theoretically break 2048-bit RSA encryption in hours instead of millions of years. That directly undermines the key exchange and authentication VPNs depend on.
How Grover’s algorithm affects AES
Grover’s algorithm only cuts its effective strength in half, so AES-256 would behave more like AES-128 against a quantum attacker. The fix is simple: use longer keys. AES-256 stays reasonably secure even in a post-quantum world, unlike RSA and ECC, which face a much bigger problem.
What is harvest now, decrypt later
Some attackers are already collecting encrypted VPN traffic now, planning to decrypt it once quantum computers are ready. This tactic, known as harvest now, decrypt later, puts any long-lived sensitive data at risk right now, not years from now.
Some research suggests the number of qubits needed to break RSA-2048 may be lower than once assumed, with estimates dropping from around 20 million to closer to 1 million. IBM’s public roadmap also points to fault-tolerant quantum computers by 2029.
Taken together, many experts now place “Q-Day,” the point where quantum computers can break today’s encryption, at around 2030. If your data needs to stay private for more than three to five years, this isn’t a future problem. It’s a current one.
NIST post-quantum standards explained
In August 2024, NIST finalized its first three post-quantum cryptography standards after eight years of testing by cryptographers worldwide. These now form the foundation of quantum-resistant VPN encryption.
How ML-KEM replaces old key exchanges
ML-KEM encryption (Module-Lattice-Based Key-Encapsulation Mechanism) replaces the RSA and Diffie-Hellman key exchanges used in older VPNs. Known before standardization as CRYSTALS-Kyber, it’s built on lattice math problems that stay hard to solve for both classical and quantum computers.
NIST’s FIPS 203 standard defines three versions: ML-KEM-512, ML-KEM-768, and ML-KEM-1024. ML-KEM-768 is the common choice for most VPN services, while ML-KEM-1024 is reserved for the highest security needs.
How ML-DSA verifies your VPN server
ML-DSA (based on CRYSTALS-Dilithium and standardized as FIPS 204) confirms that you’re connecting to your VPN’s real server, not an impersonator.
Its main drawback is size. A single ML-DSA signature can be larger than an entire HTTPS handshake, so providers need to optimize carefully.
SLH-DSA and HQC as backup options
SLH-DSA (FIPS 205) offers an alternative signature method built on different math, useful as a backup if issues arise in ML-DSA.
In March 2025, NIST also selected HQC as a backup for ML-KEM, using code-based math instead of lattices, as extra insurance against a future weakness in lattice-based systems.
A fourth standard, FIPS 206, based on the FALCON algorithm, is still in draft as of 2026, with a final version expected in late 2026 or early 2027.
Which VPN providers already offer quantum-safe encryption
NordVPN was among the first to complete a full rollout. It began adding post-quantum protection to its Linux app in September 2024 and extended it to Windows, macOS, iOS, Android, Android TV, and tvOS by early 2025. The company built ML-KEM into its WireGuard-based NordLynx protocol without any noticeable drop in speed.
ExpressVPN replaced its earlier, experimental Kyber implementation with the finalized ML-KEM standard inside its Lightway protocol, using NIST’s highest security level for both TCP and UDP connections. ExpressVPN has also published technical documentation explaining its approach, a good sign of transparency.
Other providers moving in this direction include Mullvad, Windscribe, and PureVPN, along with enterprise vendors like Palo Alto Networks, which supports quantum-resistant connections through RFC 9242.
If a provider doesn’t mention post-quantum encryption, ML-KEM, or NIST standards anywhere in its documentation, it likely hasn’t made the switch yet.
What is hybrid encryption and why it matters
Most quantum-resistant VPN setups don’t rely on post-quantum algorithms alone. They use hybrid encryption, combining a classical method like RSA or ECC with a post-quantum method like ML-KEM at the same time. This matters for a few reasons.
- It stays secure as long as at least one of the two algorithms holds up, even if the other is broken later
- It lets providers roll out quantum protection without breaking compatibility with older devices
- It keeps performance close to what you’re used to today
This dual-layer setup is likely to remain standard practice for a few more years, even after most providers fully adopt the new algorithms.
How to choose the best quantum-safe VPN
Not every provider labeled “quantum-safe” has done the same amount of work. Check these before you commit to a plan.
- Step 1: Look for specific mentions of ML-KEM or NIST FIPS 203, not vague marketing language about “quantum protection.”
- Step 2: Some providers support post-quantum encryption only on certain apps, so ask whether it’s active on every device you use.
- Step 3: A well-optimized provider shouldn’t cause a noticeable slowdown.
- Step 4: Providers that publish technical papers about their post-quantum setup usually take security more seriously.
- Step 5: If you handle sensitive business data or anything that needs to stay private for years, prioritize quantum protection now.
If you’re comparing options for the best quantum-safe VPN, run a few providers through this checklist instead of relying on marketing pages alone. Two providers can both claim quantum protection while offering very different levels of coverage.
Common myths about quantum-safe VPNs
“Quantum computers don’t exist yet, so why worry?”
Large-scale quantum computers capable of breaking RSA don’t exist today. But harvest-now, decrypt-later attacks mean your data can already be at risk before that day arrives.
“Is AES-256 already broken?”
No. AES-256 remains reasonably secure against quantum attacks. The real weak point is in key exchange and authentication, not symmetric encryption itself.
“Does post-quantum encryption slow down my connection?”
Not in a properly built implementation. NordVPN and ExpressVPN have both shown that quantum protection doesn’t have to come at the cost of speed.
“Is this only a concern for governments?”
No. Any data that needs to stay private for three to five years or more, including business communications, financial records, health information, and personal messages, can be exposed by future decryption. This applies to individuals and small businesses too.
How to make the switch to a quantum-safe VPN
- Check your current provider’s documentation for ML-KEM or post-quantum support
- Turn on quantum-safe settings if they exist but aren’t active by default
- Update your VPN app, since older versions may not include post-quantum features
- Test your connection speed after switching to confirm there’s no meaningful slowdown
- If your provider hasn’t made the switch, compare a few quantum-ready alternatives before renewing your plan
For businesses, review which systems handle long-term sensitive data first, since those are the highest priority for an early upgrade.
Final thoughts
The shift to post-quantum cryptography isn’t a distant concern. Waiting for quantum computers to arrive means accepting that some of your data may already be exposed through harvest-now, decrypt-later attacks. Moving to a quantum-resistant VPN now is a straightforward way to close that gap before it grows.
Frequently asked questions
They mean the same thing. Both describe VPNs using post-quantum cryptography, like ML-KEM, to protect against classical and quantum attacks.
Check your provider’s website or app settings for mentions of ML-KEM, post-quantum cryptography, or NIST FIPS 203.
Not with a well-built implementation. NordVPN and ExpressVPN both report no meaningful speed loss after adding post-quantum encryption.
As soon as possible if your data needs to stay private for more than three to five years, including business records, financial details, and personal communications.
Rarely. Post-quantum encryption takes real engineering investment, and most free services haven’t added it yet.
Yes. NordVPN and ExpressVPN both support post-quantum encryption on iOS and Android, as well as desktop platforms.