Keeper Deploys Quantum-Resistant Encryption in All

Get the Finance newsletter
Daily finance — markets, central banks, M&A, the prints that move money. Free.
- Keeper Security rolled out quantum-resistant cryptography across all client applications in November 2025 using Kyber Hybrid Key Encapsulation Mechanisms (KEM) to shield vaults from Harvest Now, Decrypt Later attacks.
- NSA's CNSA Suite 2.0 requires new national security systems to begin supporting quantum-resistant algorithms on January 1, 2027, with full quantum resistance mandated across all national security systems by 2035.
- NIST's draft IR 8547 deprecates RSA-2048 and ECC P-256 after 2030 and disallows them entirely after 2035, while a full enterprise migration typically runs 5 to 15 years — with the discovery phase alone consuming 1 to 2 years in large enterprises.
- The Global Risk Institute's 2025 Quantum Threat Timeline report found that 51–70% of surveyed security specialists believe a cryptographically relevant quantum computer will be available within 15 years.
- Non-Human Identities (NHIs) such as service accounts and API keys are flagged as the highest-risk credentials because they are long-lived, rarely rotated, and often untracked for cryptographic exposure.
- The source notes that Peter Shor's 1994 algorithm breaks public-key cryptography like RSA and ECC but poses no meaningful threat to symmetric encryption such as AES-256 — a distinction most public coverage collapses.
Why it matters: The NSA's January 2027 deadline collides with 5–15 year enterprise migrations and 1–2 year discovery phases, leaving organizations little runway. Non-Human Identities — service accounts and API keys that nobody rotates — are the most exposed because their confidentiality lifetime outlasts any encryption upgrade cycle, making Keeper's November 2025 vault rollout a tangible signal that vendors are moving before mandates bite.
Ask SkimNews




