Post Quantum Cryptography has been in the infosec news of lately for the threat actors collecting encrypted data now so they can decrypt it later when Quantum Computing takes off. I’ve been watching this world for several years now as I asked the question of companies at Edge Field Day 3 back in 2024.
When tech giants like Cisco, especially from the likes of Stephen Orr, begin to talk about a subject, I highly recommend we start listening.
At Mobility Field Day 14, Cisco took the stage to talk about how Post Quantum Cryptography (PQC) is going to affect the Wi-Fi industry just as much as other industries. What is Cisco doing to push the industry along? That’s what we are going to dig into. I’m sure this is going to be a big discussion this week at Cisco Live.
Collect Now, Decrypt Later, The Why of Post Quantum Computing
Why should a regular small business, enterprise, or Wi-Fi Engineer worry about Post Quantum Computing? Are not the current Wi-Fi security protocol secure?

Securing a network is a constant game of wack-a-mole. The miscreants continue to develop new techniques to break security and the industry continues to patch against those vulnerabilities. We all know the issues with WEP and WPA, but for over 20 years, we’ve relied on WPA2 to secure our Wi-Fi networks. It was good enough for the time, until October 16, 2017. KRACK (Key Reinstallation Attack) showed that the industry needed to keep evolving instead of sitting on their morals.
Still to this day, most networks are operating WPA2 or even WPA. The Wi-Fi Alliance could see this being an issue so they developed WPA3 as a replacement back in 2018. Very few were adopting it though, so they pushed the industry along with WPA3 being required in 6GHz when Wi-Fi 6e was release and now in Wi-Fi 7 being required across all the bands. That is a good step forward in the right direction. But now we are being faced with a new threat. Threat actors are collecting encrypted data now and planning to decrypt it later when our computing capabilities can handle the massive sizes of the prime numbers.
Building Post Quantum Computing Resilient Networks
At MFD14, Cisco dug into how we can build networks that are capable to withstand this next wave of threats. If someone can just go sniff the packets in the air, financial institutions, governments, health care, and just about everyone is vulnerable.

Several years ago, NIST put out a request to the mathematicians and industry to find algorithms that could survive and remain secure on Quantum Computing networks. The algorithms were compiled into the CNSA 2.0 framework. The NSA of the United States has required that all government transmitions be secured from Quantum Computing by 2035, but has an even quicker timeframe of January 1, 2027, this coming year for new acquisitions to CNSA 2.0 compliant.
Algorithms such as ML-KEM, ML-DSA, and SLH-DSA are going to be required of all communications in the distant future and RSA, Elliptic Curve Cryptography (ECC) and Diffie Hellman (DH), will all become things of the past.
So how do we build PQC compliant networks by these time frames? The industry is already working on it.
Wi-Fi 802.11bt and PQC
Cisco says that the Wi-Fi industry’s approach to securing Wi-Fi networks from Post Quantum Cryptography is new standards that are being developed. Wi-Fi 802.11bt or TG11bt is being developed to include new Authentication and Key Management (AKM) protocols that are resistant to these types of attacks.

To ensure these algorithms and protocols are protected, we will be using much larger key sizes. To handle the larger key sizes, we are going to have to fragment and reassemble authentication frames. This is go to be interesting to see in packet captures.
ML-DSA will have the highest growth in key size with a potential 30.5 times increase in the size of the public key required. TLS handshakes will have MTU fragmentation risks because of the increases in size.

What Do I Need to Do?
For now, as Wi-Fi engineers we need to start planning for how to accommodate the increases in key sizes for Post Quantum Cryptography. The industry is largely doing this for us, but to ensure you are ready when 802.11bt arrives, it’s wise to start looking at this sooner than later.
I highly recommend you watch the video from the event:

