The standardisation debate is settled; the deployment challenge is sector-specific. This article examines how post-quantum cryptography is being applied across IoT, blockchain, energy infrastructure, automotive systems, cloud platforms, and covert communications, revealing convergent integration patterns, performance bottlenecks, and the persistent gap between prototype and production.
From Theory to Sector-Specific Engineering
Standards are finalised. Algorithms are selected. Nobody is deployed.
That gap is what this article maps. The theoretical foundations and migration pathways are documented elsewhere in this series, but documentation is not deployment. An IoT sensor running on 64 KB of RAM, a cloud CSPM platform processing terabytes of security telemetry, an energy grid engineered to operate for 30 years, a vehicle OTA channel pushing firmware at motorway speeds: each of these operates under constraints so different from the others that “deploy PQC” is not one engineering problem. It is a family of problems sharing an algorithm portfolio.
What follows is a sector-by-sector examination of how those constraints shape integration decisions. One finding needs to be stated upfront, because it colours everything that follows: no reviewed paper reports a live production deployment. Every result is from a simulation, a prototype, or a conceptual framework. The publication volume is impressive. The operational footprint is zero.
Convergent Pattern: Kyber/Dilithium Dominance
One pattern is universal across every applied paper reviewed here: CRYSTALS-Kyber (ML-KEM) for key encapsulation, CRYSTALS-Dilithium (ML-DSA) for digital signatures. Full stop. No applied paper evaluates or deploys a non-lattice primary PQC algorithm. The uniformity makes sense (NIST standardisation, library availability, solid performance characteristics), but it also creates a concentration risk. None of the papers acknowledge this.
| Sector | Paper | KEM Choice | Signature Choice |
|---|---|---|---|
| IoT + Blockchain | Fahomida et al. | Kyber | Dilithium |
| Energy Grid | Krishnan et al. | Kyber-768 | Dilithium |
| Cloud CSPM | Joseph et al. | Kyber | N/A |
| Automotive OTA | Nakka et al. | Kyber | SPHINCS+ (backup) |
| DNA Storage | Raju et al. | Kyber-1024 | N/A |
| Covert Comms | Zhao et al. | Custom lattice KEM | N/A |
This convergence is pragmatic. Kyber and Dilithium offer the best performance-to-security ratio on commodity hardware, and NIST endorsement removes procurement and compliance friction. But there is a systemic risk that none of the reviewed papers acknowledge: the entire applied PQC deployment ecosystem sits on a single mathematical family. Lattice problems. If a lattice-breaking technique emerges, whether from quantum or classical cryptanalysis, the entire portfolio is compromised at once. Not just one sector. All of them.
Strategic implication: Crypto-agility at the deployment architecture level, not just the library level, is the mitigation. None of the reviewed implementations demonstrate it.
IoT and Blockchain: Quantum-Resistant Distributed Trust
IoT systems face a compound security problem. The devices are resource-constrained. The communication channels are wireless and often unauthenticated at the physical layer. The trust models tend toward centralisation, which creates single points of failure that a sufficiently motivated attacker can target. Several research groups have proposed blockchain as a decentralised trust anchor, with PQC protecting both on-chain and off-chain operations [1] [6] [2].
Fahomida et al.: CertiSense-PQ
CertiSense-PQ provides a quantum-resistant certificate management framework for IoT [1]. Certificates are issued and revoked on a distributed ledger (removing the CA single-point-of-failure), device certificates are signed with Dilithium, and session keys are exchanged via Kyber. The consensus mechanism is adapted for IoT networks where full Proof-of-Work would be computationally absurd. CertiSense-PQ provides a quantum-resistant certificate management framework for IoT [1]. Certificates are issued and revoked on a distributed ledger (removing the CA single-point-of-failure), device certificates are signed with Dilithium, and session keys are exchanged via Kyber. The consensus mechanism is adapted for IoT networks where full Proof-of-Work would be computationally absurd.
The performance cost is not negligible: certificate verification latency increased by roughly 40% compared to ECDSA-based certificates. For non-real-time IoT applications (environmental monitoring, asset tracking), that overhead sits within acceptable bounds. For anything with hard latency requirements, it might not. The performance cost is not negligible: certificate verification latency increased by roughly 40% compared to ECDSA-based certificates. For non-real-time IoT applications (environmental monitoring, asset tracking), that overhead sits within acceptable bounds. For anything with hard latency requirements, it might not.
Rajkumar et al.: Blockchain Authentication
Rajkumar et al.: Blockchain Authentication
Rajkumar et al. combine lattice-based PQC with blockchain for IoT device authentication and report 97.8% accuracy in device identity verification [6]. The paper focuses on the authentication protocol design; the underlying PQC performance characteristics are not benchmarked independently. Rajkumar et al. combine lattice-based PQC with blockchain for IoT device authentication and report 97.8% accuracy in device identity verification [6]. The paper focuses on the authentication protocol design; the underlying PQC performance characteristics are not benchmarked independently.
Huang et al.: Confidential Smart Contracts
Huang et al. address a more specific problem: executing smart contracts on quantum-vulnerable blockchains while maintaining input and output confidentiality [2]. Their framework uses lattice-based encryption for contract confidentiality, threshold PQC for multi-party execution, and PQC-compatible zero-knowledge arguments for on-chain verification.
The practical motivation is straightforward. If smart contracts manage property titles, derivatives, or insurance policies with lifetimes measured in decades, quantum resistance is not a future design consideration; it is a present one. Whether this particular framework survives contact with production smart contract platforms remains to be seen.
Energy Grid: The Most Urgent Case
Krishnan et al. make a case that the power grid is uniquely vulnerable to quantum attack, and it is a persuasive one [4]. Three factors converge. Grid infrastructure deployed today must remain secure for 30 years or more, which puts it well inside any plausible quantum timeline. SCADA and ICS protocols use authentication mechanisms designed in an era when computing threats to physical infrastructure seemed remote. And compromise in a power grid is not a data breach; it cascades into physical damage across interconnected networks.
The STRIDE-Guided Assessment
Krishnan et al. apply Microsoft’s STRIDE threat model (Spoofing, Tampering, Repudiation, Information disclosure, Denial of service, Elevation of privilege) to map quantum threats against power grid operations:
| STRIDE Category | Quantum Threat | PQC Mitigation |
|---|---|---|
| Spoofing | Shor breaks RSA authentication | ML-DSA device certificates |
| Tampering | Forged firmware updates | PQC-signed update chains |
| Information disclosure | HNDL on SCADA traffic | ML-KEM key encapsulation |
| Repudiation | Signature forgery | PQC audit trail signatures |
| Denial of service | Not quantum-specific | Rate limiting, redundancy |
| Elevation of privilege | Certificate forgery | PQC-based access control |
Smart Grid Architecture Recommendations
The paper proposes PQC integration at three grid layers: PQC-authenticated SCADA commands between control centres and generation units at the generation layer; PQC-encrypted inter-substation communication replacing IEC 62351 classical profiles at the transmission layer; and PQC certificate management for smart meters and distributed energy resources at the distribution layer. The paper proposes PQC integration at three grid layers: PQC-authenticated SCADA commands between control centres and generation units at the generation layer; PQC-encrypted inter-substation communication replacing IEC 62351 classical profiles at the transmission layer; and PQC certificate management for smart meters and distributed energy resources at the distribution layer.
Gap noted: Krishnan et al. provide no performance benchmarks for PQC on actual SCADA hardware. This is a significant omission. SCADA systems typically run on embedded processors with limited computational headroom, and the question of whether Kyber key encapsulation or Dilithium signature verification can complete within real-time control loop deadlines remains unanswered.
Automotive: Firmware Security Over Vehicle Lifetimes
Nakka et al. focus on a specific, high-consequence problem: securing over-the-air firmware updates for connected vehicles [5]. A compromised OTA channel is the highest-severity attack in automotive cybersecurity because it enables remote vehicle takeover at scale. Current OTA channels depend on RSA/ECDSA code signing and TLS key exchange. Both are quantum-vulnerable, and vehicles designed today will be on roads for 15 to 20 years.
Automotive-Specific Constraints
| Constraint | Requirement | PQC Impact |
|---|---|---|
| Signature verification time | < 2 seconds for firmware acceptance | Dilithium meets; SPHINCS+ marginal |
| Certificate storage | Limited ECU flash memory | Kyber public keys (1,184 B) fit; McEliece (1 MB) does not |
| Bandwidth | Cellular/satellite (intermittent) | Larger PQC signatures consume more OTA bandwidth |
| Vehicle lifetime | 15-20 years | Must resist quantum attacks through vehicle lifespan |
Key finding: Kyber + Dilithium fit within automotive ECU constraints. SPHINCS+ (larger signatures) is acceptable as a conservative backup for vehicles with longer planned lifespans, at the cost of increased OTA bandwidth consumption.
Cloud Security: Quantum-Resistant Posture Management
Joseph et al. take a different angle entirely [3]. Rather than replacing encryption in transit, they propose integrating PQC into cloud security posture management (CSPM) systems: Kyber-encrypted threat intelligence sharing between agents across multi-cloud environments, PQC-authenticated security events for quantum-resistant audit trails, and LWE-derived feature extraction for detecting cryptographic downgrade attacks.
Cloud environments face fewer resource constraints than IoT or automotive, so the mechanical difficulty of deploying PQC is lower. The challenge is operational. Coordinating PQC across multi-cloud CSPM agents means getting multiple cloud vendors to agree on implementation details, interoperability testing, and timeline. That kind of coordination does not exist at scale today.
Multi-Cloud Integration Architecture
| CSPM Function | Classical Approach | PQC Enhancement |
|---|---|---|
| Threat intel sharing | TLS 1.2/1.3 with ECDH | TLS 1.3 with ML-KEM |
| Audit trail integrity | HMAC-SHA256 | Dilithium-signed entries |
| Cross-cloud authentication | X.509 with RSA | PQC-hybrid certificates |
| Anomaly detection | ML on network features | LWE-derived feature extraction |
Unconventional Applications
Two papers push PQC into domains that rarely appear in migration discussions.
Raju et al. apply Kyber-1024 encryption to data encoded in synthetic DNA sequences [7]. The use case has its own logic. DNA storage offers extreme longevity (thousands of years) and extreme density (1 exabyte per cubic millimetre). If the storage medium will outlast the encryption, and it will, the data is eventually exposed unless the encryption is quantum-resistant from the start. Their approach encrypts data before DNA encoding and stores decryption keys in a separate PQC-protected key management system.
Zhao et al. apply lattice-based PQC to covert communications: legitimate-looking transmissions that conceal hidden messages [8]. They replace classical Diffie-Hellman key exchange with a lattice-based equivalent, preserving covertness properties while adding quantum resistance. The applications (censorship circumvention, diplomatic channels, intelligence) are obvious. Less obvious is that a quantum adversary breaking classical covert channels would expose not just the message content but the very existence of the hidden communication. That is a different threat profile from ordinary encryption failure.
Cross-Sector Analysis
What Works
Kyber and Dilithium as default selection is a pragmatic choice backed by NIST standardisation, library availability, and competitive performance characteristics. Hybrid migration strategies (dual classical + PQC during transition) maintain backward compatibility without forcing a cliff-edge cutover. Blockchain-anchored PKI removes certificate authority single points of failure in IoT architectures where centralised trust is a design liability.
What Is Missing
| Gap | Sectors Affected | Impact |
|---|---|---|
| No production deployments | All | Every reviewed paper is prototype or conceptual |
| No constrained-device benchmarks | IoT, automotive | PQC feasibility on 32-bit MCUs unvalidated |
| No cross-vendor interoperability testing | Cloud, energy | Multi-vendor PQC deployment untested |
| No formal hybrid security proofs | All using hybrid | Hybrid > single layer is assumed, not proven |
| No key lifecycle management | All | PQC key rotation, revocation, and escrow unaddressed |
| No latency impact on real-time systems | Energy, automotive | SCADA and ECU timing constraints unvalidated |
The Prototype-to-Production Gap
This is the single most important finding across the sector-specific literature, and it deserves direct language. Every paper reviewed here presents a conceptual framework, a simulation, or a small-scale prototype. None reports a production deployment. No real users, no real adversaries, no real operational constraints.
The gap is not unique to PQC; the field received its first formal standards only in 2024. But the implication for practitioners is that performance claims, security assurances, and integration architectures from these papers have not been stress-tested in environments where things actually break.
Takeaways
Kyber and Dilithium dominate every sector examined here. The reason is straightforward: NIST endorsement, library availability, and competitive performance on commodity hardware. But universal adoption of a single mathematical family creates a concentration risk that the applied literature has not confronted. If lattice assumptions weaken, every sector loses its PQC portfolio at once. Crypto-agility at the architecture level, not merely the library API level, is the only hedge, and none of the reviewed implementations provide it.
The prototype-to-production gap is the primary bottleneck of the field. IoT and blockchain generate the most proposals. Energy grids face the most acute urgency, with 30-year asset lifetimes that already exceed Mosca’s inequality for many data categories, yet they have the least validated benchmarks on actual SCADA hardware. Automotive OTA channels fit within ECU memory and latency constraints on paper, but vehicle lifespans of 15 to 20 years mean that PQC decisions made in the next few model years will determine whether those vehicles are quantum-vulnerable or quantum-resistant for their entire service life.
Algorithm selection is the solved problem. Integration architecture, constrained-device performance, and cross-vendor interoperability are not.
Applied Questions on PQC Deployment
Can IoT devices with limited memory run post-quantum cryptography?
Kyber-768 needs roughly 2.4 KB for public and private keys combined, which fits on most 32-bit microcontrollers. But “fits” is not the same as “works well.” No peer-reviewed benchmark validates PQC on production IoT hardware with real workloads. Devices below 32 KB of available RAM may need hardware-accelerated PQC, lighter constructions, or offloaded key operations.
Which sector faces the most urgent quantum threat?
Energy grid infrastructure. The combination of 30-year-plus operational lifetimes, cascading failure potential, and legacy SCADA authentication makes the case almost self-evident. Encrypted SCADA traffic captured today may well be decryptable within the operational lifespan of grid equipment being installed right now. Mosca’s inequality is already in the red for this sector.
Why does every applied PQC paper default to Kyber and Dilithium?
Incentive alignment. NIST standardisation brings library support, regulatory compliance, and interoperability expectations. Kyber and Dilithium also happen to perform well on commodity hardware. The downside is systemic: one mathematical family, one failure mode. If lattice assumptions weaken, every sector loses protection simultaneously.
Are there any production deployments of PQC?
Not among the papers reviewed here. Broader industry experiments exist (Google’s CECPQ2, Cloudflare’s post-quantum TLS rollout), but they sit outside the scope of this academic review. The applied research community is still at the conceptual and prototype stage. Production deployment with real adversaries and real operational constraints has not been reported in the peer-reviewed literature.
Technical Appendix
Source Credibility, Evidence Boundaries, and Technical Reference
Appendix Table of Contents
- Cited Work and Venue Context
- A. What the Evidence Does and Does Not Cover
- B. Domain Terminology
- C. Per-Paper Evaluation Notes
Cited Work and Venue Context
This article is authored by Zenith Law and synthesises findings on sector-specific PQC deployment from papers spanning IEEE Access, Springer, and ACM venues. Evidence quality varies: Fahomida et al. (2025) provide simulation benchmarks; Krishnan et al. (2025) offer a threat-modelling framework without performance data; Nakka et al. (2024) present an architectural proposal with constraint analysis but no prototype; Joseph et al. (2025) combine PQC with CSPM conceptually. Raju et al. (2025) and Zhao et al. (2025) address niche applications with experimental validation.
A. Evidence Boundary Notes
No production deployments are reported in any reviewed paper; all findings come from simulation, prototype, or conceptual analysis. IoT performance claims are based on simulation or desktop-class hardware rather than constrained devices, so real-world IoT PQC performance remains an open question. The energy grid analysis from Krishnan et al. provides threat modelling without PQC benchmarks on SCADA hardware. The automotive analysis of Nakka et al. derives constraint compatibility from algorithm specifications rather than empirical ECU testing. The cloud CSPM proposal of Joseph et al. is architectural only, with no implementation or evaluation. Blockchain consensus overhead from PQC is acknowledged in the reviewed papers but never quantified.
B. Domain Terminology
- CSPM (Cloud Security Posture Management)
- Automated tools that monitor cloud infrastructure configuration for security misconfigurations, compliance violations, and threat indicators across multi-cloud environments.
- SCADA (Supervisory Control and Data Acquisition)
- Industrial control systems used to monitor and control infrastructure processes (power grids, water treatment, manufacturing). SCADA protocols often lack modern cryptographic authentication.
- OTA (Over-the-Air)
- Remote firmware or software updates delivered to devices via wireless communication channels. In automotive contexts, OTA updates modify vehicle ECU software without physical access.
- ECU (Electronic Control Unit)
- Embedded computing modules in vehicles that control specific functions (engine, braking, infotainment). ECUs have constrained memory and processing capability compared to general-purpose computers.
- DER (Distributed Energy Resource)
- Small-scale electricity generation or storage units connected to the distribution grid (solar panels, batteries, wind turbines). Each DER requires authenticated communication with grid management systems.
C. Per-Paper Evaluation Notes
| Paper | Year | Type | Sector | Key Contribution | Confidence and Caveats |
|---|---|---|---|---|---|
| Fahomida et al. | 2025 | Framework | IoT | CertiSense-PQ certificate management | Simulated only; no constrained-device testing |
| Huang et al. | 2025 | Framework | Blockchain | Confidential smart contracts with PQC | Prototype exists; consensus overhead not quantified |
| Joseph et al. | 2025 | Architecture | Cloud | PQC-enhanced CSPM | Conceptual architecture; no implementation |
| Krishnan et al. | 2025 | Threat model | Energy | STRIDE-guided power grid PQC assessment | Threat mapping only; no SCADA benchmarks |
| Nakka et al. | 2024 | Architecture | Automotive | PQC-secured OTA firmware updates | Constraint analysis from specs; no prototype |
| Rajkumar et al. | 2024 | Framework | IoT | Blockchain + PQC device authentication | Experimental results reported |
| Raju et al. | 2025 | Experimental | Storage | DNA-based storage with Kyber-1024 | Lab-validated encoding/decoding pipeline |
| Zhao et al. | 2025 | Experimental | Communications | Lattice-based covert channel | Simulated covertness metrics |
D. SEO, GEO, and AEO Optimisation Notes
Primary search terms: PQC deployment IoT, post-quantum blockchain, quantum-resistant energy grid, automotive PQC, cloud CSPM post-quantum, sector-specific PQC.
Structured data: HowTo and FAQ schemas are implemented. Article schema includes author attribution and citation metadata.
Cross-references: Linked to companion PQC theoretical and migration articles.
References
- [1]M. Fahomida and F. A. Nafis, Post Quantum Cryptography Framework for Secure Data Transmission: Enhancing Confidentiality and Integrity with Kyber, Dilithium, and DNA-Keys, in 2025 28th International Conference on Computer and Information Technology (ICCIT), pp. 5287–5292, n.d. doi: 10.1109/ICCIT68739.2025.11491399. Accessed: 6 June 2026.
- [2]K. Huang and Y. Pan, Research on the Commercial Cryptography Protection Framework for the Power Sector: A Roadmap from Legacy Cryptography to Post-Quantum Migration, in 2025 5th International Conference on Computer Science, Electronic Information Engineering and Intelligent Control Technology (CEI), pp. 350–356, n.d. doi: 10.1109/CEI66465.2025.11398533. Accessed: 6 June 2026.
- [3]J. M. Joseph, C. S. Sreeja and S. Vinod, Integrating Post-Quantum Cryptography with DNA-Based Data Storage for Secure and Robust Data Preservation, in 2025 IEEE International Conference on Communication, Networks and Satellite (COMNETSAT), pp. 122–129, n.d. doi: 10.1109/COMNETSAT68601.2025.11324504. Accessed: 6 June 2026.
- [4]A. Krishnan and R. Arunachalam, Implementing Post-Quantum Cryptography in Blockchain for Securing IoT Data Transmission, in 2025 6th International Conference on Electronics and Sustainable Communication Systems (ICESC), pp. 685–690, n.d. doi: 10.1109/ICESC65114.2025.11212458. Accessed: 6 June 2026.
- [5]K. Nakka, S. Ahmad, T. Kim, L. Atkinson and H. M. Ammari, Post-Quantum Cryptography (PQC)-Grade IEEE 2030.5 for Quantum Secure Distributed Energy Resources Networks, in 2024 IEEE Power & Energy Society Innovative Smart Grid Technologies Conference (ISGT), pp. 1–5, n.d. doi: 10.1109/ISGT59692.2024.10454235. Accessed: 6 June 2026.
- [6]N. Rajkumar, K. K. Kumar, M. Gokul and S. Durai, Post-Quantum Cryptography Security with CSPM for Secure Data Transmission in Cloud Environments, in 2024 4th International Conference on Ubiquitous Computing and Intelligent Information Systems (ICUIS), pp. 1456–1462, n.d. doi: 10.1109/ICUIS64676.2024.10866709. Accessed: 6 June 2026.
- [7]K. K. Raju, R. H. Rao, B. N. Behara, G. S. S. Kumar, M. Harshitha and A. Varshney, Blockchain-Based Secure IoT Data Transmission Leveraging Post-Quantum Cryptography, in 2025 3rd International Conference on IoT, Communication and Automation Technology (ICICAT), pp. 1–6, n.d. doi: 10.1109/ICICAT68430.2025.11414715. Accessed: 6 June 2026.
- [8]W. Zhao, W. Zhang, L. Zhao and Z. Yu, Research on Security for Software Updates of Intelligent Connected Vehicles Based on Post-Quantum Cryptography, in 2025 International Conference on Electrical Engineering, Automation and Information Science (EEAIS), pp. 160–164, n.d. doi: 10.1109/EEAIS66172.2025.11171168. Accessed: 6 June 2026.
Continue Reading in This Series
These linked articles extend the same evidence trail and improve navigability for readers and search systems.
