SoK: Post-Quantum Cryptography Implementation in Software: Approaches, Challenges and the PQC-HOT Framework
cs.CR, cs.SE
Submitted: 2026-06-03
Updated: 2026-09-22
License: http://creativecommons.org/licenses/by/4.0/
The gist: Secure implementation of post-quantum cryptography (PQC) requires attention to cryptographic mechanisms, software integration, developer capability, and organisational support.
Terminology
Abstract
Secure implementation of post-quantum cryptography (PQC) requires attention to cryptographic mechanisms, software integration, developer capability, and organisational support. Understanding how available approaches address these requirements is important for preparing software systems for quantum threats. This Systematisation of Knowledge (SoK) synthesises 33 publications and analyses PQC implementation approaches and challenges using a Human, Organisational, and Technological (HOT) perspective. We identify four approach categories: guidelines, frameworks, tools and libraries, and educational interventions. Technological support receives greater representation in the extracted mapping, while no approach is classified primarily as organisational, despite secondary organisational contributions in some approaches. The challenge synthesis identifies five layers covering implementation security, system integration and lifecycle, tooling, organisational governance, and human factors. Together, these findings highlight a difference between the primary support functions of the mapped approaches and the breadth of the reported implementation challenges. We propose PQC-HOT, an evidence-informed analytical framework connecting implementation tasks with technical resources, practitioner capabilities, and organisational arrangements. We derive research priorities and engineering implications to guide framework evaluation and support secure, maintainable PQC-enabled software.
Related papers
- SoK: AI-Augmented Binary Reversing
- Relaxed Sender Anonymity for CBDC Interbank Settlement: A Zero-Knowledge Approach on Permissioned EVM
- Calibration-Family Overfit: Why Trusted Sabotage Monitors Don't Transfer Across Lineages
- Efficient Fuzzy PSI under One-Sided Assumptions
- Sealing the Audit-Runtime Gap for LLM Skills
- Token Composition: A Graph Based on EVM Logs