Beyond the Algorithm: how PQ-REACT built Europe’s practical path to quantum-safe cryptography

Beyond the Algorithm: how PQ-REACT built Europe’s practical path to quantum-safe cryptography


Introduction: from an abstract warning to an engineering answer

After three years of work, the PQ-REACT project (Post-Quantum Cryptography Framework for an Energy-Aware Transition) is coming to a close — and with it, a body of evidence that turns an abstract warning into a concrete, engineering-ready answer.

The threat is well known: a sufficiently large quantum computer would break the public-key cryptography that protects almost every digital system today, from secure web traffic and firmware signing to the communications that keep critical infrastructure running. The danger is not only tomorrow’s machine but today’s behaviour — adversaries can already “harvest now and decrypt later”, capturing encrypted data now to unlock once the hardware matures. The question PQ-REACT set out to answer was deliberately practical:

What does a European organisation actually need in order to migrate to quantum-safe cryptography, and does it now exist?


A framework, not just an algorithm

Migrating to post-quantum cryptography (PQC) is rarely a matter of swapping one algorithm for another. New primitives can support longer keys, larger signatures and different performance profiles, and the standards landscape keeps moving. PQ-REACT therefore built an integrated, crypto-agile framework rather than a single tool. Its centrepiece is the Context Agility Manager (CAM), which discovers the cryptographic assets present in an environment, evaluates candidate configurations against real benchmarking evidence, and selects and configures the right algorithm for the operational context — monitoring and re-evaluating continuously as conditions change.

Around the CAM sit the project’s four Key Exploitable Results, which work as a chain: a Risk Assessment methodology decides where to migrate first; a Post-Quantum Validation Engine and Oracle measures what each candidate configuration costs in security and performance terms; an AI-assisted Recommendation Engine turns that evidence into an actionable choice; and the Context Agility Manager applies and maintains that choice in the running system. Crucially, the recommendations are grounded in a benchmarking ecosystem that measured primitives such as ML-KEM, ML-DSA, SPHINCS+ and HQC across classical high-performance computing, quantum back-ends and live TLS and IPsec tunnels — evidence, not estimation.


Proven on a live 5G testbed, across three pilots

The framework was not left on paper. It was demonstrated on a live 5G research testbed through three pilots, each chosen to expose a different constraint that makes migration hard in practice. In the smart-grid pilot, post-quantum digital signatures protected the smart-meter firmware-update process — a setting with severe processing and storage limits. In the quantum-secure 5G communications pilot, post-quantum and QKD-based approaches protected the IPsec tunnels of the network backhaul. In the network-slicing pilot, PQC was combined with a distributed ledger to anchor multi-domain trust across video, chat and IoT slice services.

The numbers matter because they replace open-ended risk with quantified cost. On the 5G slice channel, ML-KEM-768 added just 1.0 ms over the classical baseline — an increase of 2.1% — with cryptographic switching completing in around 49 ms. On the ledger, at a matched security level, ML-DSA verification was actually faster than the classical baseline; the real cost of migration showed up as a roughly 32- to 34-fold increase in signature size, not as added latency. The consolidated demonstration wove four interoperating repositories across nine hosts, a recommendation engine exposing 35 typed tools, and a cryptographic inventory of 38,162 assets — a scan that found a representative telecommunications environment to be 58% quantum-vulnerable, with RSA and ECDSA the leading exposed families. Of the eleven proposal KPIs measured live, nine were met.


The corrective lesson: size, not speed

Perhaps the single most useful outcome of PQ-REACT is a correction to a widespread assumption. In none of the three pilots was raw computational cost the obstacle to migration. In every case, the binding constraint was something else — the size of the new cryptographic material, or an assumption baked into an existing workflow or protocol. Both are design problems that can be solved with adequate evidence and an agile implementation, rather than physical limits that block the transition. That reframing, backed by live measurement, is what the consortium most hopes practitioners will take away.


Building an ecosystem, not just a project

Lasting impact depends on reaching beyond a single consortium. Through two competitive open calls with a combined cascade-funding budget of EUR 900,000, PQ-REACT engaged nine SMEs, start-ups and research organisations to extend and stress-test the framework in domains beyond the consortium’s own pilots — the strongest available evidence that the results transfer to organisations with no prior involvement. In parallel, the project co-founded the SPQR (Secure Post-Quantum eRa) cluster, which grew from a bilateral collaboration into a network of eight Horizon Europe projects, multiplying the reach of every event at negligible marginal cost.

The scientific and standardisation record is equally substantial: 25 peer-reviewed papers attracting more than 190 citations, and structured contributions to ETSI, IETF, 3GPP, GSMA and ITU — from testing and protection profiles for access and transport networks to guidelines for quantum risk management tailored to telecom operators. Open-source assets, including the CAM and contributions returned to Eclipse Qrisp and the QUJATA benchmarking project, were released so the tooling lives on beyond the grant.

And not only that! During the 36 months of the project, PQ-REACT built a community of over 1,500 followers across various social media platforms, achieving an impressive number of impressions (over 150K), indicating that the content appeared on over 150,000 screens. This ensured that the project’s activities were effectively promoted and reached the right communities, making PQ-REACT well known in the European post-quantum cryptography and cybersecurity fields.


An urgent, strategic transition

The move to post-quantum cryptography is not only a technical undertaking but a strategic priority for European digital sovereignty and resilience. PQ-REACT’s legal analysis confirms that European law already frames security around risk and accountability, which gives regulators a natural anchor for clear migration guidance and timelines for public-sector and critical-infrastructure systems. The project’s recommendations are consistent throughout: require a cryptographic inventory as the baseline for any migration plan, embed cryptographic agility into procurement and regulation, sustain cascade funding and clustering to widen participation, and keep the transition energy-aware — because at scale, across edge and IoT environments, the aggregate cost of a poorly chosen configuration is significant.

The project closed with the joint PQ-REACT and SPQR event “Beyond the Algorithm: the Road to a Quantum-Safe Future”, held in Bucharest in June 2026. But the work it leaves behind is meant to be used: a validated framework, reproducible benchmarks, open-source tools, published evidence and training material that give European organisations a directly usable foundation for their own journey to quantum-safe cryptography.

The quantum threat is still on the horizon — but thanks to three years of measurement rather than speculation, the path to meeting it is now a good deal clearer.


Farewell

This blog post closes the PQ-REACT’s public communication activity by consolidating, in a single accessible narrative, what the project set out to do and what it demonstrated: that a European organisation can plan and execute a migration to post-quantum cryptography today, using an inventory of its cryptographic assets, measured benchmarking evidence and a crypto-agile implementation. The evidence base behind the post — the framework and its four Key Exploitable Results, the three pilots on the live 5G testbed, the measured KPIs, the open-call results and the standardisation contributions — is documented in full in the corresponding technical and dissemination deliverables.

Next steps are exploitation-driven rather than project-driven. The post is published on the project website and amplified through the SPQR cluster and partner channels to maximise reach at the point of highest interest, at the end of the project. Beyond the grant, the open-source assets remain available, the SPQR cluster continues to operate, and partners carry the Key Exploitable Results forward through their own exploitation routes and standardisation work.

Author: Akis Kourtis

Editor: Marva Arampatzi