Docento.app
Glowing laptop screen at night
All Posts

Post-Quantum Cryptography and PDF Signatures: Should You Worry Yet?

By The Docento.app TeamPublished 3 min read
Sign or fill out your PDF now — Free, no sign-up, 100% private — files never leave your device.Open the editor

Digital signatures on PDFs rely on RSA or elliptic-curve cryptography. A large enough quantum computer could break both. No such machine exists yet, but in August 2024 the US National Institute of Standards and Technology (NIST) published its first post-quantum standards, including two signature schemes, and governments have set migration timelines running into the early 2030s. So: should you worry about the PDFs you sign today?

The short answer

For most signed business documents, not yet, and the fix will arrive through your tools. For documents that must be trusted for decades, it is time to understand the plan.

What the new standards are

NIST finalised three standards in 2024:

  • FIPS 203 (ML-KEM): key exchange, used for encryption.
  • FIPS 204 (ML-DSA): a general-purpose digital signature scheme.
  • FIPS 205 (SLH-DSA): a hash-based signature scheme, slower but built on very conservative assumptions.

A further signature standard based on the Falcon scheme is in progress. These are the algorithms PDF signatures will eventually use.

Signatures versus encryption: different risks

The well-known quantum threat, "harvest now, decrypt later", is about encryption. An attacker records encrypted data today and decrypts it once quantum computers exist. That matters for confidential PDFs you encrypt and send now. See PDF encryption explained.

Signatures are different. An attacker who can forge signatures in 2035 could create fake documents that appear signed by you, but properly archived documents have a defence: timestamps and validation data captured while the old algorithms were still secure.

Long-term validation is the existing safety net

PDF already has a mechanism for documents that must outlive their cryptography: long-term validation (LTV) and document timestamps. A signed PDF can carry the certificates and revocation data needed to verify it, plus a trusted timestamp. Before an algorithm weakens, an archive can add a fresh timestamp with a stronger algorithm, chaining the proof forward. See long-term validation and PDF timestamps.

What to do now

  1. Use LTV-enabled signatures for anything that must remain verifiable for more than ten years.
  2. Archive as PDF/A so the document itself remains renderable. See PDF/A explained.
  3. Ask your signing vendor about their post-quantum roadmap, especially if you are in government, finance or healthcare.
  4. Re-timestamp long-term archives periodically, which good archive systems do automatically.
  5. Do not panic-buy "quantum-safe" PDF products. PDF standards for post-quantum signatures are still maturing, and early proprietary approaches may not be widely verifiable.

What about simple electronic signatures?

A drawn or typed signature placed on a PDF, the kind you add in a browser editor like Docento.app, is not cryptographic at all. Its strength comes from context and audit trail, not mathematics, so quantum computing does not change it. See is it legal to sign documents electronically?.

Takeaway

Quantum computing is a real, slow-moving risk for long-lived signed documents. The defences already exist in PDF (LTV and timestamps), and the new algorithms are standardised. Use them for the documents that matter in 2040, and let your tools handle the migration for the rest. For background, see digital signature internals.

Sign or fill out your PDF now

Free, no sign-up, 100% private — files never leave your device.

Open the editor

Related Posts