SoK: Post-Quantum Cryptography (PQC) Implementation in Software Systems
Pith reviewed 2026-06-28 06:01 UTC · model grok-4.3
The pith
PQC implementation in software requires coordinated human, organizational, and technological approaches rather than algorithm swaps alone.
A machine-rendered reading of the paper's core claim, the machinery that carries it, and where it could break.
Core claim
The paper establishes that PQC implementation extends beyond cryptographic replacement and represents a broader socio-technological transformation requiring coordinated approaches across all HOT dimensions. Challenges emerge as interconnected constraints that span human, organizational, and technological contexts and collectively shape outcomes. The PQC-HOT model is proposed to synthesize identified interventions and challenges into an integrated structure supporting systematic decision-making, planning, and organizational transition strategies.
What carries the argument
The PQC-HOT model, a conceptual framework that organizes implementation interventions and challenges across the Human, Organisation, and Technology dimensions to explain their interactions and guide coordinated planning.
If this is right
- Implementation challenges are interconnected across human, organizational, and technological dimensions rather than isolated.
- Current research shows a clear imbalance with technological solutions dominating the literature.
- Successful outcomes require coordinated strategies that address all three dimensions together.
- The PQC-HOT model can serve as a basis for organizational planning and transition roadmaps.
Where Pith is reading between the lines
- Teams adopting the model might discover specific training gaps or governance changes needed before technical work begins.
- The same structure could be tested on other security transitions such as large-scale key rotation or zero-trust rollouts.
- Empirical checks could measure whether projects using the model achieve faster or more complete migrations than those that do not.
Load-bearing premise
The reviewed literature, when grouped into human, organizational, and technological categories, supplies a sufficiently complete picture of actual implementation challenges.
What would settle it
A detailed case study or survey of organizations that have attempted PQC migration and uncovers major barriers that cannot be placed in the HOT categories or that show no cross-dimension interactions.
Figures
read the original abstract
The transition to Post-Quantum Cryptography (PQC) is essential to protect software systems from emerging quantum-enabled threats. Although standardised PQC algorithms are now available, developers and organisations continue to face significant challenges in integrating them into real-world software systems. While existing studies primarily focus on cryptographic performance and algorithmic security, it provides limited understanding of the broader socio-technological factors that influence successful PQC implementation. This SoK investigates PQC implementation approaches and challenges through the Human, Organisation, and Technology (HOT) dimensions. By systematically synthesising existing approaches across these dimensions, we reveal a notable imbalance in the current body of knowledge, where technological solutions dominate, while human and organisational considerations remain underexplored. Our analysis further shows that PQC implementation challenges are not isolated to individual dimensions; rather, they emerge as interconnected socio-technological constraints that span HOT contexts, collectively shaping implementation outcomes. These findings indicate that PQC implementation extends beyond cryptographic replacement and represents a broader socio-technological transformation requiring coordinated approaches across all HOT dimensions. To address this gap, we propose the PQC-HOT model, a conceptual framework that explains how interactions among HOT dimensions collectively influence PQC implementation in software. The model synthesises the implementation interventions and challenges identified in the SoK into an integrated structure that supports systematic decision-making, planning, and organisational transition strategies. Based on these insights, we outline future research directions and design implications for scalable and sustainable PQC implementation in software systems.
Editorial analysis
A structured set of objections, weighed in public.
Referee Report
Summary. The paper is an SoK on PQC implementation in software systems. It synthesizes literature through the Human-Organisation-Technology (HOT) lens, reports a strong imbalance (technology dominates while human and organisational factors are underexplored), argues that challenges are socio-technological and interconnected, and proposes the PQC-HOT model as an integrated conceptual framework to guide decision-making and transition strategies. It concludes with future research directions.
Significance. If the literature map is shown to be complete and the HOT categorisation reproducible, the work would usefully shift attention from isolated algorithmic performance to coordinated socio-technical planning for PQC deployment. The proposed PQC-HOT model could provide a practical organising structure for practitioners and a research agenda for the field.
major comments (2)
- [Methods / systematic review protocol] Methods / systematic review protocol (exact section number not visible in supplied text): the abstract and body claim a 'systematic synthesis' that reveals a 'notable imbalance' across HOT dimensions and underpins the PQC-HOT model, yet no search protocol, databases, keywords, date ranges, inclusion/exclusion criteria, total papers screened, papers per dimension, or inter-rater process for HOT assignment are provided. Without these details the reported imbalance cannot be verified and may be an artifact of selection or categorisation bias.
- [§4 / PQC-HOT model definition] §4 / PQC-HOT model definition: the model is presented as synthesising 'implementation interventions and challenges' into an integrated structure, but the paper does not specify how the three dimensions and their interactions were operationalised from the reviewed papers or how the model was validated against the source literature.
minor comments (2)
- [Abstract / Introduction] Abstract and introduction: the claim that 'PQC implementation extends beyond cryptographic replacement' is repeated but would benefit from a short concrete example of a non-cryptographic constraint drawn from the reviewed literature.
- [Terminology / early sections] Terminology: 'HOT dimensions' and 'PQC-HOT model' are introduced without an early, compact definition or diagram that readers can refer to when the later analysis is presented.
Simulated Author's Rebuttal
We thank the referee for the constructive comments, which highlight important opportunities to improve methodological transparency and the description of our conceptual model. We address each point below and will revise the manuscript accordingly.
read point-by-point responses
-
Referee: [Methods / systematic review protocol] Methods / systematic review protocol (exact section number not visible in supplied text): the abstract and body claim a 'systematic synthesis' that reveals a 'notable imbalance' across HOT dimensions and underpins the PQC-HOT model, yet no search protocol, databases, keywords, date ranges, inclusion/exclusion criteria, total papers screened, papers per dimension, or inter-rater process for HOT assignment are provided. Without these details the reported imbalance cannot be verified and may be an artifact of selection or categorisation bias.
Authors: We agree that the current manuscript lacks sufficient detail on the review process to allow independent verification of the reported imbalance. Although the work is framed as an SoK rather than a full PRISMA-style systematic review, the claim of 'systematic synthesis' requires supporting documentation. In the revised version we will insert a dedicated Methods section that specifies: the databases searched (IEEE Xplore, ACM DL, arXiv, Google Scholar), the keyword strings and date range used, inclusion/exclusion criteria, the total number of papers screened and retained, the distribution of papers across the three HOT dimensions, and the procedure (including any dual-coding or discussion steps) used to assign papers to dimensions. This addition will make the imbalance claim reproducible and address the concern about potential selection or categorisation bias. revision: yes
-
Referee: [§4 / PQC-HOT model definition] §4 / PQC-HOT model definition: the model is presented as synthesising 'implementation interventions and challenges' into an integrated structure, but the paper does not specify how the three dimensions and their interactions were operationalised from the reviewed papers or how the model was validated against the source literature.
Authors: We accept that the manuscript does not explicitly describe the operationalisation steps or provide a traceable mapping from source papers to model elements. In revision we will expand §4 to include: (1) explicit definitions of each HOT dimension as derived from the literature, (2) a table or set of examples showing how specific interventions and challenges identified in the reviewed papers were grouped into the three dimensions and their interactions, and (3) a clear statement that the model was constructed inductively from the synthesised findings rather than through separate empirical validation (e.g., expert review or case studies). We will also note the absence of formal validation as a limitation and suggest it as a direction for future work. revision: yes
Circularity Check
No circularity: synthesis derives from external literature
full rationale
The paper is an SoK that synthesizes external literature on PQC implementation challenges grouped by HOT dimensions and proposes the PQC-HOT model from that synthesis. No self-definitional equations, fitted inputs renamed as predictions, or load-bearing self-citations appear in the provided text. The derivation chain consists of literature review steps whose outputs are not forced by the paper's own inputs or prior author work; the central claims remain independent of any internal reduction.
Axiom & Free-Parameter Ledger
axioms (1)
- domain assumption Existing PQC literature can be exhaustively and non-overlappingly classified into Human, Organisation, and Technology dimensions.
invented entities (1)
-
PQC-HOT model
no independent evidence
Reference graph
Works this paper leans on
-
[1]
D. J. Bernstein, T. Lange, Post-quantum cryptography, Nature 549 (2017) 188–194
2017
-
[2]
S.S.Gill,R.Buyya, Transformingresearchwithquantumcomputing, Journal of Economy and Technology 4 (2026) 1–8
2026
-
[3]
D.-T.Dam,T.-H.Tran,V.-P.Hoang,C.-K.Pham,T.-T.Hoang, Asur- veyofpost-quantumcryptography:Startofanewrace, Cryptography 7 (2023) 40
2023
-
[4]
D. Lazar, H. Chen, X. Wang, N. Zeldovich, Why does cryptographic softwarefail?acasestudyandopenproblems, in:Proceedingsof5th Asia-PacificWorkshoponSystems,APSys’14,AssociationforCom- puting Machinery, New York, NY, USA, 2014, pp. 1–7. URL:https: //doi.org/10.1145/2637166.2637237. doi:10.1145/2637166.2637237
-
[5]
Bagirovs, G
E. Bagirovs, G. Provodin, T. Sipola, J. Hautamäki, Applications of post-quantum cryptography, Proceedings of the 23rd European Conference on Cyber Warfare and Security (2024) 23 (2024) 49–57
2024
-
[6]
M.Toruan,R.D.N.Shakya,S.Tseitkin,R.K.Zhao,N.Arachchilage, When security meets usability: An empirical investigation of post- quantum cryptography apis, in: Proceedings of the 2026 Symposium on Usable Security and Privacy (USEC), NDSS Symposium 2026, San Diego, CA, USA, 2026, pp. 1–16. doi:10.14722/usec.2026.23076
-
[7]
Zhang, A
L. Zhang, A. Miranskyy, W. Rjaibi, G. Stager, M. Gray, J. Peck, Making existing software quantum safe: A case study on IBM Db2, Information and Software Technology 161 (2023) 107249
2023
-
[8]
J.Hekkala,M.Muurman,K.Halunen,V.A.Vallivaara,Implementing post-quantum cryptography for developers, SN Computer Science 4 (2023) 365
2023
-
[9]
E. O. Sodiya, U. J. Umoga, O. O. Amoo, A. Atadoga, Quantum computing and its potential impact on U.S. cybersecurity: A review, Global Journal of Engineering and Technology Advances 18 (2024) 49–64
2024
-
[10]
A. Aydeger, E. Zeydan, A. K. Yadav, K. T. Hemachandra, M. Liyan- age,Towardsaquantum-resilientfuture:Strategiesfortransitioningto post-quantum cryptography, in: 2024 15th International Conference on Network of the Future (NoF), IEEE, 2024, pp. 195–203. doi:10. 1109/NoF62948.2024.10741441
arXiv 2024
-
[11]
A. A. Giron, Migrating applications to post-quantum cryptography: Beyond algorithm replacement, in: Proceedings of the 20th Interna- tional Conference on Security and Cryptography (SECRYPT), 2023, pp. 857–862. doi:10.5220/0012138800003555
-
[12]
M. J. Kannwischer, P. Schwabe, D. Stebila, T. Wiggers, Improv- ing software quality in cryptography standardization projects, in: Proceedings of the 7th IEEE European Symposium on Security and Privacy Workshops (EuroS&PW), IEEE, 2022, pp. 19–30. doi:10. 1109/EUROSPW55150.2022.00010
arXiv 2022
-
[13]
Berglund, A
M. Berglund, A. Karltun, J. Eklund, J. Karltun, HTO – A Concept of Humans, Technology and Organisation in Interaction, Technical Re- port HELIX Working Papers 20:002, Linköping University, HELIX Competence Centre, Linköping, Sweden, 2020
2020
-
[14]
Baseri, V
Y. Baseri, V. Chouhan, A. Ghorbani, Cybersecurity in the quantum era: Assessing the impact of quantum computing on infrastructure, Computers & Security 167 (2026) 104917
2026
-
[15]
Näther, D
C. Näther, D. Herzinger, S.-L. Gazdag, J.-P. Steghöfer, S. Daum, D. Loebenberger, Migrating software systems toward post-quantum cryptography-a systematic literature review, IEEE Access 12 (2024) 132107–132126
2024
-
[16]
Predict and conquer: Navigating algorithm trade-offs with quantum design automation,
N. Ahmed, L. Zhang, A. Gangopadhyay, A survey of post-quantum cryptography support in cryptographic libraries, in: 2025 IEEE International Conference on Quantum Computing and Engineering (QCE), volume 01, 2025, pp. 906–917. doi:10.1109/QCE65121.2025. 00102
-
[17]
A. Mishra, Applied cryptography in security-critical domains: A systematic review of design and deployment practices, International Journal of Communication Networks and Information Security (IJC- NIS) 14 (2022) 189–194
2022
-
[18]
Kitchenham, Procedures for Performing Systematic Reviews, Technical Report TR/SE-0401, Keele University, 2004
B. Kitchenham, Procedures for Performing Systematic Reviews, Technical Report TR/SE-0401, Keele University, 2004
2004
-
[19]
Booth, A
A. Booth, A. Sutton, D. Papaioannou, Systematic Approaches to a Successful Literature Review, 2nd edition ed., SAGE Publications Ltd, 2016
2016
-
[20]
M.J.Page,J.E.McKenzie,P.M.Bossuyt,I.Boutron,T.C.Hoffmann, C. D. Mulrow, L. Shamseer, J. M. Tetzlaff, E. A. Akl, S. E. Brennan, R. Chou, J. Glanville, J. M. Grimshaw, A. Hróbjartsson, M. M. Lalu, T.Li,E.W.Loder,E.Mayo-Wilson,S.McDonald,L.A.McGuinness, L. A. Stewart, J. Thomas, A. C. Tricco, V. A. Welch, P. Whiting, D. Moher, The PRISMA 2020 statement: an u...
2020
-
[21]
V.Braun,V.Clarke, Usingthematicanalysisinpsychology, Qualita- tive Research in Psychology 3 (2006) 77–101
2006
-
[22]
Ramachandran, Guidelines based software engineering for de- veloping software components, Journal of Software Engineering and Applications 05 (2012) 1–6
M. Ramachandran, Guidelines based software engineering for de- veloping software components, Journal of Software Engineering and Applications 05 (2012) 1–6
2012
-
[23]
J. Howe, T. Prest, D. Apon, SoK: How (not) to design and imple- ment post-quantum cryptography, in: Topics in Cryptology - CT- RSA2021,volume12704,Springer,2021,pp.444–477.doi:10.1007/ 978-3-030-75539-3\_19
2021
-
[24]
Topics, Cryptographic frameworks, Meegle Topics, 2026
M. Topics, Cryptographic frameworks, Meegle Topics, 2026. URL:https://www.meegle.com/en_us/topics/cryptography/ cryptographic-frameworks, published: February 5, 2026; Accessed: May 25, 2026
2026
-
[25]
S. R. Gulomov, T. R. Khudayberganov, M. X. Ravshanova, T. T. Turdiev, S. S. Atabayev, Exploring post-quantum cryptographic algorithms for secure data transmission, in: 2024 IEEE 3rd In- ternational Conference on Problems of Informatics, Electronics and Radio Engineering (PIERE), IEEE, 2024, pp. 1480–1483. doi:10. 1109/PIERE62470.2024.10805050
arXiv 2024
-
[26]
P. Chandre, H. Hingoliwala, A. Uttarkar, B. D. Shendkar, D. Lokare, P. Sontakke, Post-quantum cryptography: Securing critical infras- tructure against emerging quantum threats, in: 2024 IEEE 4th In- ternational Conference on ICT in Business Industry and Government (ICTBIG), 2024, pp. 1–7. doi:10.1109/ICTBIG64922.2024.10911612
-
[27]
V. P. Ojha, S. Chauhan, S. Yarahmadhian, D. Carvalho, Adoption of post-quantum cryptography in communication technologies, Au- tomation, Robotics and Communications for Industry 4.0/5.0 (2025) 21
2025
-
[28]
A. Tsili, K. Kordolaimis, K. Krilakis, D. Syvridis, A scalable frame- work for post-quantum authentication in public key infrastructures, in: 2025 International Conference on Quantum Communications, Networking, and Computing (QCNC), 2025, pp. 279–286. doi:10. 1109/QCNC64685.2025.00052
arXiv 2025
-
[29]
Zhang, J
M. Zhang, J. Wang, J. Lai, M. Dong, Z. Zhu, R. Ma, J. Yang, Re- search on development progress and test evaluation of post-quantum cryptography, Entropy 27 (2025) 212
2025
-
[30]
C. Turino, W. J. Buchanan, O. Lo, C. Thümmler, Pqc-leo: An evaluation framework for post-quantum cryptographic algorithms, in: 2025 IEEE 7th International Conference on Trust, Privacy and Security in Intelligent Systems, and Applications (TPS-ISA), 2025, pp. 237–247. doi:10.1109/TPS-ISA67132.2025.00033
-
[31]
R. J. Anthony, Chapter 5 - the architecture view, in: Systems Programming, Morgan Kaufmann, Boston, 2016, pp. 277–382. URL:https://www.sciencedirect.com/science/ article/pii/B9780128007297000054. doi:https://doi.org/10.1016/ R.D.N. Shakya et al.:Preprint submitted to ElsevierPage 21 of 22 SoK: PQC implementation in Software Systems B978-0-12-800729-7.00005-4
2016
-
[32]
S. P. Reiss, Software tools and environments, ACM Computing Surveys 28 (1996) 281–284
1996
-
[33]
A.Esser,J.Verbel,F.Zweydinger,E.Bellini, SoK:CryptographicEs- timators – a software library for cryptographic hardness estimation, in: Proceedings of the 19th ACM Asia Conference on Computer and Communications Security (ASIA CCS ’24), ACM, 2024, pp. 560–
2024
-
[34]
doi:10.1145/3634737.3645007
-
[35]
Stability and Decay properties of Solitary wave solutions for the generalized BO-ZK equation
O. Saucedo-Estrada, M. C. Hernandez, G. Gallegos-Garcia, M. Salinas-Rosales, Post-quantum cryptographic schemes library for android operating system, in: 2020 IEEE International Autumn Meeting on Power, Electronics and Computing (ROPEC), IEEE, 2020, pp. 1–6. doi:10.1109/ROPEC50909.2020.9258758
work page internal anchor Pith review Pith/arXiv arXiv doi:10.1109/ropec50909.2020.9258758 2020
-
[36]
Lyubashevsky, G
V. Lyubashevsky, G. Seiler, P. Steuer, The LaZer library: Lattice- based zero knowledge and succinct proofs for quantum-safe privacy, in: Proceedings of the 2024 ACM SIGSAC Conference on Computer and Communications Security (CCS ’24), ACM, 2024, pp. 3125–
2024
-
[37]
doi:10.1145/3658644.3690330
-
[38]
D. J. Bernstein, T. Lange, J. Levin, B.-Y. Yang, PQConnect: Au- tomated post-quantum end-to-end tunnels, 2025. doi:10.14722/ndss. 2025.241879
-
[39]
A.Hülsing,K.-C.Ning,P.Schwabe,F.J.Weber,P.R.Zimmermann, Post-quantumWireGuard,in:2021IEEESymposiumonSecurityand Privacy (SP), IEEE, 2021, pp. 304–321. doi:10.1109/SP40001.2021. 00030
-
[40]
A. C. Aguilera, C. R. Garcia, R. Frantz, I. T. Monroy, J. L. Imaña, J. J. V. Olmos, Integrating post-quantum cryptography plugins for IPsec offloads to data processing units in the cloud-edge contin- uum, in: 32nd IEEE International Conference on Network Protocols (ICNP), IEEE, 2024, pp. 1–6. doi:10.1109/ICNP61940.2024.10858568
-
[41]
N.Rattanavipanon,J.Suaboot,W.Werapun, Atoolchainforassisting migration of software executables towards post-quantum cryptogra- phy, IEEE Access 13 (2025) 4368–4380
2025
-
[42]
Anderson, What is educational interventions?,https: //focuskeeper.co/glossary/what-is-educational-interventions,
C. Anderson, What is educational interventions?,https: //focuskeeper.co/glossary/what-is-educational-interventions,
-
[43]
Accessed: 2026-06-03
2026
-
[44]
T. J. Borrelli, S. Mishra, M. Polak, S. P. Radziszowski, Towards a quantum-resistantfuture:Experiencesinpost-quantumcryptography education, in: Proceedings of the 56th ACM Technical Symposium onComputerScienceEducation(SIGCSETS2025),ACM,2025,pp. 1393–1394. doi:10.1145/3641555.3705271
-
[45]
T. J. Borrelli, M. Polak, S. P. Radziszowski, Designing and deliv- ering a post-quantum cryptography course, in: Proceedings of the 55th ACM Technical Symposium on Computer Science Education (SIGCSE 2024), ACM, 2024, pp. 137–143. doi:10.1145/3626252. 3630823
-
[46]
Available: https://doi.org/10.1109/QCE60285.2024.10291
A. Parakh, M. Subramaniam, QUINTET: An experiential learning platformforquantumeducation, in:2024IEEEInternationalConfer- ence on Quantum Computing and Engineering (QCE), IEEE, 2024, pp. 128–137. doi:10.1109/QCE60285.2024.20468
-
[47]
S. E. Abdelhamid, S. Patterson, B. Patterson, G. Woodward, R. Sarkari, H. Rose, WIP: CryptoQuest - interactive animation series for teaching cryptography, post-quantum cryptography, and cybersecurity using extended reality (XR), in: IEEE Frontiers in EducationConference(FIE2024),IEEE,2024,pp.1–5.doi:10.1109/ FIE61694.2024.10893119
arXiv 2024
-
[48]
A. Parakh, M. Subramaniam, E. Ostler, QuaSim: A virtual quantum cryptography educator, in: 2017 IEEE International Conference on Electro Information Technology (EIT), IEEE, 2017, pp. 600–605. doi:10.1109/EIT.2017.8053434
-
[49]
D. Abeyrathna, S. Vadla, V. Bommanapally, M. Subramaniam, P.Chundi,A.Parakh,Analyzingandpredictingplayerperformancein a Quantum cryptography serious game, in: Games and Learning Al- liance,volume11385ofLecture Notes in Computer Science,Springer, 2019, pp. 267–276. doi:10.1007/978-3-030-11548-7_25
-
[50]
R. Bavdekar, E. J. Chopde, A. Agrawal, A. Bhatia, K. Tiwari, Post quantum cryptography: A review of techniques, challenges and stan- dardizations,in:InternationalConferenceonInformationNetworking (ICOIN), IEEE, 2023, pp. 146–151. doi:10.1109/ICOIN56518.2023. 10048976
-
[51]
J.Hughes,B.Nahill,E.Simpson,J.Lim,R.Burrow,J.Dean,B.Lee, M. Vai, R. Khazan, S. O’Melia, A. Ho, M. Parrish, J. Womack, S. Trotter, M. Lodico, High assurance multi-function crypto de- velopment, in: MILCOM 2024 - 2024 IEEE Military Commu- nications Conference (MILCOM), 2024, pp. 969–974. doi:10.1109/ MILCOM61039.2024.10773892
arXiv 2024
-
[52]
A. Aydeger, M. Carvalho, Real-time cryptographic agility for autonomous uav swarms: A performance-driven approach to post- quantum migration, in: 2026 IEEE 23rd Consumer Communications & Networking Conference (CCNC), 2026, pp. 1–6. doi:10.1109/ CCNC65079.2026.11366545
arXiv 2026
-
[53]
Anomah, B
S. Anomah, B. Ayeboafo, Beyond compliance: Institutional and cybersecurity pathways to blockchain audit readiness in emerging financial systems, The Electronic Journal of Information Systems in Developing Countries 92 (2026)
2026
-
[54]
M. Tahaei, K. Vaniea, A survey on developer-centred security, in: 2019IEEEEuropeanSymposiumonSecurityandPrivacyWorkshops (EuroS&PW), 2019, pp. 129–138. doi:10.1109/EuroSPW.2019.00021
-
[55]
CMMI Institute, CMMI institute - what is CMMI?,https:// cmmiinstitute.com/cmmi/intro, 2020
2020
-
[56]
EC-Council, Certified ethical hacker | CEH certification | EC-Council,https://www.eccouncil.org/train-certify/ certified-ethical-hacker-ceh/, 2025. R.D.N. Shakyais a PhD researcher in Computer Science at the University of Moratuwa, Sri Lanka, and RMIT University, Australia. Her research interests include Post-Quantum Cryptography, usable security, and sec...
2025
discussion (0)
Sign in with ORCID, Apple, or X to comment. Anyone can read and Pith papers without signing in.