Is UIID ready for a post-quantum world? What our architecture already gets right

A fair question, worth answering honestly.

Where things stand industry-wide. In August 2024, NIST finalized the first three official post-quantum cryptography standards after an eight-year evaluation. NIST's transition plan calls for today's quantum-vulnerable algorithms to be phased out of federal standards by 2035 — a scheduled migration the entire tech industry is working through, not just us.

Where UIID's architecture already has an advantage. Because UIID credentials are device-based rather than sitting in one central database, there is no single honeypot of encrypted records for a future quantum-capable attacker to harvest today and decrypt years later — a pattern known as "harvest now, decrypt later," and one of the more realistic long-term risks in this space. That architectural choice lines up well with where post-quantum defense is heading, even without being built specifically for a future quantum computer.

Questions about our security roadmap: [email protected].