Quantum Computing for Software Engineers: What You Actually Need to Know in 2026

Table of Contents
Quantum computing gets covered like science fiction. Most articles focus on qubits, superposition, and entanglement in abstract terms, leaving software engineers with no actionable direction.
This article is different. It focuses on what's actually happening in 2026 — specifically the cryptography implications — and what you need to do about it.
The Part That Actually Matters: Cryptography
Most quantum computing coverage obsesses over theoretical applications (drug discovery, climate modeling). The near-term impact that's already forcing action is cryptography.
The threat model is simple: a sufficiently powerful quantum computer running Shor's algorithm can factor large integers and solve discrete logarithm problems in polynomial time. This breaks:
- RSA (relies on integer factorization)
- ECDSA / ECDH (relies on discrete log problem on elliptic curves)
- Diffie-Hellman key exchange
Everything that secures HTTPS, SSH, code signing, and JWT signing today is vulnerable — eventually.
Symmetric encryption is mostly safe. AES-256 is considered quantum-resistant. Grover's algorithm halves the effective key length, so AES-128 → effectively AES-64 (broken), but AES-256 → effectively AES-128 (still fine).
NIST PQC: The Standards That Already Exist
In August 2024, NIST finalized its first post-quantum cryptography (PQC) standards:
| Algorithm | NIST Standard | Use Case | Based On |
|---|---|---|---|
| CRYSTALS-Kyber | FIPS 203 (ML-KEM) | Key encapsulation (TLS key exchange) | Module lattice problem |
| CRYSTALS-Dilithium | FIPS 204 (ML-DSA) | Digital signatures | Module lattice problem |
| SPHINCS+ | FIPS 205 (SLH-DSA) | Digital signatures (conservative) | Hash functions |
A fourth standard (FALCON / FN-DSA, FIPS 206) is expected soon for smaller signature sizes.
Why lattice-based? Lattice problems (shortest vector problem, learning with errors) have no known efficient quantum algorithm. They've been studied for 30+ years. Kyber and Dilithium are fast, have reasonable key/ciphertext sizes, and are already implemented in major crypto libraries.
The Timeline: "Store Now, Decrypt Later"
The threat isn't immediate. A cryptographically relevant quantum computer (CRQC) — one with thousands of fault-tolerant logical qubits — doesn't exist yet. Current NISQ devices have 1,000–1,400 noisy physical qubits, which is orders of magnitude short.
Estimates vary:
- IBM's roadmap: 100,000 physical qubits by 2033, targeting error-corrected logical qubits
- NIST's timeline: Recommends migrating away from RSA/ECDSA by 2030, mandatory by 2035
- NSA: Has already directed federal agencies to begin PQC migration
The real risk today is "harvest now, decrypt later" attacks: adversaries are storing encrypted traffic today to decrypt once quantum computers arrive. If you're transmitting data that must remain secret for 10+ years (medical records, defense data, long-lived credentials), the threat is now.
What This Means for Your Code
TLS/HTTPS
Chrome 131 (November 2024) enabled ML-KEM (Kyber) by default for TLS 1.3 hybrid key exchange. This is X25519MLKEM768 — a hybrid of classical ECDH and Kyber. You get quantum resistance without losing classical security.
If you control your server: OpenSSL 3.x supports Kyber in hybrid mode. Most managed TLS (Cloudflare, AWS, GCP) already handles this.
If you're pinning TLS certificates or doing custom TLS: Review your pinning logic to ensure it tolerates hybrid key exchange.
JWT Signing
JWTs signed with RS256 (RSA) or ES256 (ECDSA) are vulnerable long-term. The python-jwt and PyJWT libraries don't yet support PQC signature algorithms natively, but liboqs-python wraps Open Quantum Safe and supports Dilithium:
# Experimental: PQC JWT signing with liboqs
# Install: pip install pyoqs
import oqs
import json
import base64
def sign_payload_dilithium(payload: dict) -> tuple[str, bytes]:
"""Sign a JSON payload using CRYSTALS-Dilithium (ML-DSA)."""
signer = oqs.Signature("Dilithium3")
public_key = signer.generate_keypair()
payload_bytes = json.dumps(payload).encode()
signature = signer.sign(payload_bytes)
return base64.b64encode(payload_bytes).decode(), signature
def verify_dilithium(payload_b64: str, signature: bytes, public_key: bytes) -> bool:
"""Verify a Dilithium signature."""
verifier = oqs.Signature("Dilithium3")
payload_bytes = base64.b64decode(payload_b64)
return verifier.verify(payload_bytes, signature, public_key)
For production JWT signing, watch the IETF drafts for ML-DSA-65 in JOSE (JSON Object Signing and Encryption).
SSH Keys
OpenSSH 9.0+ supports CRYSTALS-Kyber hybrid key exchange. If your servers allow SSH access, auditing key types matters:
# Check what key exchange algorithms your SSH server supports
ssh -Q kex | grep -i ky
# sntrup761x25519-sha512@openssh.com (post-quantum hybrid)
# Generate an SSH key using the PQC hybrid algorithm
ssh-keygen -t ed25519 # Still fine — signatures aren't broken yet
# For key exchange, configure in /etc/ssh/sshd_config:
# KexAlgorithms sntrup761x25519-sha512@openssh.com,curve25519-sha256
Code Signing
GPG keys used for code signing (PyPI, npm, container images) use RSA or ECDSA. Migration paths:
- Container images: Sigstore/Cosign is working on PQC support
- PyPI: No timeline yet, but PEP process is underway
- Git commit signing: Same issue —
gpg --gen-keydefaults to RSA
For internal systems, Dilithium-signed artifacts are achievable today via liboqs.
Practical Crypto Inventory: What to Audit
Run this script to find RSA and ECDSA usage in a Python project:
#!/usr/bin/env python3
"""Audit a codebase for quantum-vulnerable cryptographic usage."""
import subprocess
import sys
from pathlib import Path
VULNERABLE_PATTERNS = [
# RSA
("rsa.generate_private_key", "RSA key generation"),
("RSA.generate", "RSA key generation (PyCryptodome)"),
("rsa.verify", "RSA signature verification"),
# ECDSA / ECDH
("ec.generate_private_key", "ECDSA/ECDH key generation"),
("SECP256R1", "NIST P-256 curve (ECDH/ECDSA)"),
("SECP384R1", "NIST P-384 curve"),
# JWT
('algorithm="RS256"', "RSA-signed JWT"),
('algorithm="ES256"', "ECDSA-signed JWT"),
('algorithms=["RS256"', "RSA JWT verification"),
# TLS
('ssl.PROTOCOL_TLS', "TLS connection (verify key exchange)"),
("paramiko", "SSH library (review key exchange config)"),
]
def audit_directory(path: str) -> None:
root = Path(path)
findings = []
for py_file in root.rglob("*.py"):
content = py_file.read_text(errors="ignore")
for pattern, description in VULNERABLE_PATTERNS:
if pattern in content:
# Find line numbers
for i, line in enumerate(content.splitlines(), 1):
if pattern in line:
findings.append({
"file": str(py_file.relative_to(root)),
"line": i,
"pattern": pattern,
"description": description,
"code": line.strip(),
})
if findings:
print(f"Found {len(findings)} potentially quantum-vulnerable cryptography usages:\n")
for f in findings:
print(f" {f['file']}:{f['line']}")
print(f" → {f['description']}")
print(f" → {f['code']}\n")
else:
print("No quantum-vulnerable patterns found.")
if __name__ == "__main__":
audit_directory(sys.argv[1] if len(sys.argv) > 1 else ".")
The Qubits Part (Briefly)
Since it's everywhere: qubits are quantum bits that exploit superposition (existing in 0 and 1 simultaneously) and entanglement (correlated states across qubits). This lets quantum algorithms evaluate exponentially many possibilities at once — but only for specific mathematical problems that map to quantum circuits.
Not everything benefits. Problems like database searches (Grover's: square root speedup) and factoring (Shor's: polynomial time) are amenable to quantum speedup. Most everyday computational tasks (sorting, rendering, HTTP) see no quantum advantage.
Current NISQ (Noisy Intermediate-Scale Quantum) devices at IBM, Google, and IonQ have 400–1,400 physical qubits but high error rates. Getting to the thousands of logical (error-corrected) qubits needed for Shor's algorithm requires millions of physical qubits. We're not there yet — but governments and large enterprises are planning for 2030–2035.
Migration Checklist
| Priority | Item | Action |
|---|---|---|
| 🔴 Critical | TLS stack | Ensure your CDN/proxy supports hybrid Kyber (Cloudflare, AWS do by default) |
| 🔴 Critical | Long-lived secrets | Audit anything encrypted that must stay secret for 10+ years |
| 🟡 High | SSH key exchange | Add sntrup761x25519-sha512 to KexAlgorithms |
| 🟡 High | JWT signing algorithm | Plan migration from RS256/ES256 to future ML-DSA standard |
| 🟢 Medium | Code signing | Monitor Sigstore PQC roadmap |
| 🟢 Medium | Internal PKI | Plan CA migration to hybrid certs |
| ⚪ Low | Symmetric encryption | AES-256 is fine; don't change |
Further Reading
- NIST PQC Final Standards (FIPS 203/204/205)
- Open Quantum Safe (liboqs) — open-source PQC implementations
- IETF Post-Quantum Use in Protocols
- Cloudflare PQC Blog
You Might Also Like
Free In-Browser Developer Tools
Clean AI CLI logs, build cron expressions, decode JWTs, and calculate chmod permissions offline.
Related Articles

Post-Quantum Cryptography (PQC) Migration Guide for Backend Developers
Comprehensive guide to migrating backend infrastructure to NIST Post-Quantum Cryptography standards: ML-KEM, ML-DSA, hybrid TLS 1.3, and packet fragmentation.
Read more
Serverless Analytics Warehouse with BigQuery & Cloud Run: From GA4 Streams to Automated SEO Alerts
How to build an automated serverless analytics warehouse with BigQuery, Google Analytics 4, and Cloud Run: schema modeling, scheduled SQL transformations, zero-idle cost, and automated SEO query alerts.
Read more
BigQuery + Cloud Run: Building a Production Serverless Data Ingestion Pipeline
A production-grade guide to serverless data ingestion on Google Cloud: the BigQuery Storage Write API, partitioning and clustering strategy, a FastAPI async receiver on Cloud Run, complete Terraform, a real cost breakdown, and the failure modes that page you at 3am.
Read more