If you manage a website, you probably already know that SSL certificates are what help keep your site encrypted and show visitors they can trust your connection.
But the technology behind today’s SSL/TLS certificates is entering a new era. As quantum computing advances, the security industry is preparing for a future where some of today’s widely used encryption methods may no longer be strong enough.
That’s where post-quantum cryptography, or PQC, comes in.
While this change won’t happen overnight, website owners should understand what’s coming, why it matters, and how it could shape the future of website security.
Let’s start with the basics: what SSL certificates do today, and why the industry is preparing for what comes next.
What is an SSL certificate?
An SSL certificate helps protect the connection between a website and a visitor’s browser. It’s what enables HTTPS, the secure version of HTTP, and helps keep information like passwords, payment details, names, and addresses private as it moves between the browser and the website.
Today, when people say SSL certificate, they’re usually referring to a certificate used with TLS, the modern security protocol that replaced SSL. The certificate helps confirm that a website is connected to the domain it claims to represent, and it supports the encrypted connection visitors rely on when they see HTTPS in the address bar.
At a high level, an SSL/TLS certificate connects a website’s identity to a cryptographic key pair: a public key and a private key. The public key can be shared with browsers, while the private key stays protected on the server. Together, these keys help the browser and website establish an encrypted session.
That system has helped secure the web for years. But as quantum computing advances, the industry is preparing for a future where some of the cryptography used in today’s SSL/TLS ecosystem may need to change.
For a deeper look at how SSL certificates work, see our complete SSL guide.
What is quantum computing?
Quantum computing is an emerging type of computing that uses principles of quantum physics to process information differently from traditional computers. While classical computers use bits represented as 0s or 1s, quantum computers use quantum bits, or qubits, which can represent more complex states.
That doesn’t mean quantum computers will replace everyday computers or make every task faster. Instead, they may be especially powerful for certain types of problems, including simulating molecules, optimizing complex systems, and eventually breaking some of the public-key cryptography used to encrypt today’s internet.
That last point is why quantum computing matters for SSL/TLS certificates. Today’s SSL/TLS certificates rely on public-key cryptography, including methods known as RSA and elliptic-curve cryptography, to help browsers verify website identity and establish encrypted HTTPS connections. These methods are secure today because they rely on math problems that are extremely difficult for traditional computers to solve.
For example, RSA is built around the difficulty of factoring very large numbers into their prime factors, while elliptic-curve cryptography relies on the difficulty of working backward from points on a curve to find a hidden value.
However, a sufficiently powerful quantum computer could solve some of these problems much more efficiently than today’s computers, which is why the industry is preparing for post-quantum cryptography alternatives.
What is post-quantum cryptography (PQC)?
Post-quantum cryptography, or PQC, refers to new cryptographic methods designed to stay encrypted against both today’s computers and future quantum computers.
Today’s SSL/TLS ecosystem relies on public-key cryptography to help websites prove their identity and establish encrypted HTTPS connections. Those methods are still considered secure today, but a sufficiently powerful future quantum computer could eventually break some of the public-key algorithms that protect the web now. That’s why organizations like the National Institute of Standards and Technology (NIST) have been working with the global cryptography community to standardize quantum-resistant alternatives.
In August 2024, NIST finalized the first three post-quantum cryptography standards, including new methods for key exchange and digital signatures — two important building blocks of encrypted internet communications.
Key exchange helps a browser and website create a shared secret for that specific visit, which is then used to encrypt information moving between them. Digital signatures help prove that a website is really the site it claims to be, and that important information hasn’t been changed along the way.
What this means is, the security industry now has approved tools to begin preparing for a post-quantum future, including through PQC certificates.
What are PQC certificates?
Post-Quantum Cryptography (PQC) certificates are the next evolution of SSL/TLS certificates, designed to help protect website identity and encrypt connections against future quantum-computing threats.
Today, SSL/TLS certificates use public-key cryptography to help browsers verify that a website belongs to the legitimate domain owner and establish trusted HTTPS connections. But some of the public-key algorithms used today could eventually be broken by sufficiently powerful quantum computers.
That creates a long-term security risk for the web.
Quantum computers capable of breaking today's widely used public-key cryptography do not exist at the scale needed to threaten the internet today. But the transition to quantum-resistant cryptography is already underway. NIST finalized its first three PQC standards in August 2024 and is urging organizations to begin migrating now.
A fourth standard (FN-DSA/FIPS 206) remains in draft, with finalization expected in late 2026 or early 2027. Under NIST's transition roadmap, quantum-vulnerable algorithms are expected to begin being deprecated as early as 2030 for some and ultimately removed from NIST standards by 2035, with higher-risk systems encouraged to move much sooner.
The important message for website owners here is that you don't need to panic — but you shouldn't wait until quantum computing becomes a problem to start preparing.
Why should website owners care now?
The move to post-quantum security is not simply about what happens when a quantum computer arrives. Sensitive information transmitted or collected today could potentially be captured and stored by attackers and decrypted in the future — a threat often described as "harvest now, decrypt later."
For businesses that handle customer information, transactions, authentication, intellectual property, or other sensitive data, waiting until quantum computers become capable of breaking today's cryptography could leave too little time to migrate.
And certificates are about more than encryption. They are a fundamental part of how browsers establish trust in a website. If the cryptography used to authenticate that identity becomes vulnerable, the mechanisms that help visitors know they are connecting to the legitimate website will need to evolve as well.
That is why the industry is preparing now.
Post-quantum security may feel like a future problem, but cryptographic migrations take years. The organizations that prepare early will have more options, more time to test, and less risk of being caught unprepared when the standards and browsers move.— Shwetal Covert, Security Director, GoDaddy
Is PQC required today?
No. Most website owners do not need to replace their existing SSL/TLS certificate with a PQC certificate today.
However, that does not mean PQC is something to ignore.
The transition involves multiple parts of the internet ecosystem, including certificate authorities (CAs), browsers, TLS implementations, hosting platforms, and websites. Chromium's current post-quantum HTTPS roadmap describes a phased transition:
- What is expected today (Stage 1): Browsers begin adding support for post-quantum key agreement (Chrome has shipped ML-KEM-based hybrid key exchange by default since late 2024). Post-quantum authentication for certificates is still in early stages.
- Next (Stage 2): Individual websites can begin opting into stronger post-quantum protections.
- In the future (Stage 3): Browsers can move toward requiring a post-quantum public key infrastructure (PKI), meaning certificates from PQ-capable certificate authorities.
- Longer term (Stage 4): Websites eventually move to fully post-quantum TLS keys and authentication.
Chromium describes the final stage as a far-future transition because the entire web ecosystem needs to be ready first.
Is the CA/B Forum driving this change?
The CA/Browser Forum (CA/B Forum) is an important part of the ecosystem because it establishes requirements and standards used by publicly trusted certificate authorities and browsers. However, PQC certificates are not currently being mandated for ordinary website TLS certificates by the CA/B Forum. The industry is still working through how PQC should be incorporated into the public web PKI.
The CA/B Forum has already taken steps to enable experimentation with NIST-standardized PQC algorithms in certain certificate types. For example, Ballot SMC-013, adopted in August 2025, now permits ML-DSA and ML-KEM in S/MIME certificates. However, this should not be confused with a current requirement for website owners to deploy PQC TLS certificates. The transition will ultimately involve coordination among certificate authorities, browsers, standards organizations, hosting providers, and website owners.
What should website owners do now?
You don't need to replace your certificate simply because PQC is emerging. Instead, start preparing for the transition.
- Keep your SSL/TLS certificate current: HTTPS remains essential today. Make sure your certificate is valid, properly installed, and renewed on time.
- Understand your cryptographic exposure: Businesses with long-lived sensitive information, regulated data, financial transactions, or high-value intellectual property should begin understanding where their systems rely on quantum-vulnerable cryptography.
- Prepare for certificate changes: The future certificate transition could involve new algorithms, certificate types, key management, and server configurations. Automated certificate management can make these changes significantly easier as new standards become available.
- Don't wait for the quantum computer: The migration itself can take years. NIST is already recommending that organizations begin moving toward its finalized PQC standards rather than waiting for quantum computers to become capable of breaking today's cryptography.
- Watch for updates from GoDaddy: As PQC standards, browser support, and certificate requirements continue to evolve, GoDaddy will continue monitoring developments across NIST, the CA/Browser Forum, browser providers, and the broader security industry. As PQC-ready certificate technologies and products become available and appropriate for website owners, GoDaddy will provide guidance and announcements to help customers understand when and how to make the transition.
What happens next?
The move to post-quantum security will not happen overnight, but the transition has already started.
NIST's first three core PQC standards are finalized, and a fourth is in final development. Organizations are being encouraged to begin migration, and browser vendors are actively planning how post-quantum authentication will eventually work across the web.
For most GoDaddy customers, there is no need to replace your SSL/TLS certificate with a PQC certificate today.
But the right time to start paying attention is now.
Keep your SSL/TLS certificate current. Stay informed about changes to browser and certificate standards. And watch for GoDaddy announcements about PQC-ready products, certificates, and recommended next steps.







