HP Quantum-Resistant Cryptography
Learn how HP is building quantum‑resistant foundations into its devices to safeguard organizations against tomorrow’s cybersecurity threats.

A Strategic Defense for the Quantum Era
Quantum computing promises breakthroughs in many fields, but it also threatens the cryptographic foundations that secure modern digital systems. At HP, we are already acting to protect our customers and their data against this emerging threat. HP began executing its quantum-resistant migration strategy ahead of national authorities such as NIST or NSA issuing specific timelines for migration. Our proactive roadmap has helped ensure a resilient firmware foundation for HP’s PCs and printers long before large-scale quantum attacks become practical.
The Quantum Threat: Why Act Now?
Because of these risks, we must move to protect our systems and data before the quantum threat is realized. Migration must begin now — especially in sensitive environments such as government systems.
Asymmetric cryptography is at risk
The “harvest now, decrypt later” risk
Long-lived trusted keys are at risk, especially when rooted in hardware
Quantum computers running Shor’s algorithm can break widely used public-key schemes (e.g. RSA, ECC), rendering digital signatures and key exchange vulnerable.
Adversaries can intercept and store encrypted data today, waiting until quantum decryption is possible. This endangers long-lived sensitive data (e.g. national security, medical, financial) even before quantum computers fully mature.
Devices with fixed cryptographic keys or ROM-based signature verification cannot be retrofitted in the field. If quantum resistance is not built in at design time, devices may become insecure before retirement.
HP prioritized firmware integrity protection precisely because firmware is foundational to system security and hard to update across a device’s lifecycle. If firmware verification is compromised, an attacker can bypass all other protections.
HP Quantum-Resistant Cryptography
FPO
Objective Prioritize cryptography implementations to migrate.
Activity Identify cryptographic assets in products and solutions. Triage them for migration priority, with focus on identifying long-lived and hard-to- update components that must be addressed first, such as firmware.
Discover / Assess
Objective Design upgraded cryptography architecture, implementation, and testing plan, for prioritized products. Plan for transition in their roadmap. Activity Adopt migration goals into product roadmaps. Define how quantum- resistant algorithms will be integrated into product design, and identify dependencies. Establish product development plan and timeline.
Objective Implement, test, and deploy, to deliver upgraded quantum resistance for prioritized products.
Activity Implement quantum-resistant upgrades in hardware, firmware, and software. Test for security and resilience, taking especial care with introduction of new cryptographic algorithms. Roll-out for use by customers.
Plan / Design Develop / Deploy
To meet the quantum challenge, we have developed a multi-phase strategy to guide how we transition HP products and solutions to quantum-resistant cryptography.
The results of our assessment phase, which evaluates how the quantum computing threat may impact users of our products and solutions, identified that hardware foundations – particularly device trust anchors – are a high priority for quantum-resistant migration. By enabling a quantum-resistant foundation in hardware, we can protect firmware integrity and enable a quantum-resistant update capability for easier-to- update firmware or software elements in future. By doing this first, we are able to give our customers protection against the quantum threat in their devices and prepare their infrastructure for a simpler full-stack migration to quantum resistance over time.
Our detailed multi-phase strategy is designed to enable us to prioritize key products and use cases to migrate. It is broken down between a discovery and assessment phase, a planning and design phase, and a development and deployment phase, described below.
HP’s Approach to Quantum-Resistant Migration
HP’s Security Lab drives this Cryptography Migration Strategy for HP products and solutions, working closely with R&D, engineering, and enterprise security teams. HP also contributes to NIST’s National Cybersecurity Center of Excellence (NCCoE) Migration to Post-Quantum Cryptography (PQC) Project and presents strategic insights at international conferences such as the NIST PQC Standardization Conference, the European Telecommunications Standards Institute (ETSI) / Institute for Quantum Computer (IQC) Quantum Safe Cryptography Conference, and the International Cryptographic Module Conference.
Technical Foundation: Firmware Integrity as a Quantum-Resistant Root of Trust
Product Highlights & Innovations
HP has embedded quantum-resistant protections directly into roots of trust for our devices:
• The Endpoint Security Controller (ESC) Gen5, built into select HP Business PCs1, verifies firmware using both RSA select and the Leighton–Micali Signature (LMS), a NIST-standardized stateful hash-based signature scheme (SP 800-208).
• LMS was chosen for its security maturity, efficiency in verification use cases like firmware checks, and resilience as a conservative cryptographic choice.
• Using dual signatures (RSA and LMS) ensures resilience against both classical and quantum adversaries.
Because firmware verification happens at every boot and is rooted in hardware, this approach ensures that devices remain protected throughout their lifecycle — even as quantum computers advance.
Business PCs In March 2024, HP launched the world’s first business PCs (EliteBook) with quantum-resistant BIOS ...firmware integrity protection.² HP Launches World’s First Business PCs to Protect Firmware Against Quantum Computer Hacks | HP® Official Site. 2
Printers In March 2025, HP announced the world’s first printers (8000 Series including Color LaserJet Enterprise MFP 8801, Mono MFP 8601, LaserJet Pro 8501) with quantum-resistant firmware integrity checks.3 HP Launches World’s First Printers to Protect Against Quantum Computer Attacks | HP® Official Site.3
Coupled with HP’s strategy for quantum-resistant migration, these innovations position HP to support agency modernization efforts and compliance with emerging quantum-readiness mandates.
Tommy Charles HP Chief Cryptographer
“We identified that the quantum threat could pose unacceptable risk to our customers if they were not addressed immediately, so we worked to introduce protection starting from the hardware foundations. Dedication and teamwork spanning HP was key to enable us to start providing hardware with quantum- resistant firmware integrity protection for our customers as early as 2024”
Government & Enterprise Implications
Future Roadmap & Challenges
• Firmware integrity protections — identified as early migration priorities by national authorities such as NIST, NSA and CISA — are already quantum-resistant in designated HP Business PCs and Printers.
• HP’s quantum-resistant firmware integrity protections meets the requirements of CNSA 2.0, the Quantum Computing Cybersecurity Preparedness Act, and NIST PQC standards.
Track suite of NIST PQC standards (for general key exchange and digital signatures), and look to integrate and test them across our stack as appropriate (TLS, code signing, device authentication, secure channels).
Balancing performance, memory, and size trade-offs between quantum-resistant algorithms will require engineering innovation.
Supporting hybrid cryptographic modes (combining classical and quantum-resistant) will be critical for some customers in transition.
• By embedding PQC in hardware roots of trust, HP ensures long-lifecycle products remain upgradable and secure.
• For PCs, quantum-resistant firmware verification is always on and requires no configuration.
• For printers, quantum-resistant firmware verification is available via configuration, with customer support and documentation provided.
Compliance & standards alignment Risk management and modernization
FPO
HP’s Commitment to Security
Call to Action for GSA / Agencies
HP understands that the risk of quantum computers breaking RSA and ECC within the lifecycle of current products is too high to ignore. Our commitment is demonstrated by:
• Delivering the first quantum-resistant firmware integrity protection for select business PCs (2024)2 and select printers3 (2025).
• Having hardware-backed quantum-resistant device foundations.
• Driving standards and sharing best practices through NIST NCCoE projects, international conferences, and public blog articles.
HP’s proactive roadmap ensures that government agencies and enterprises can depend on our devices as secure, quantum-ready building blocks for modernization.
HP Services are governed by the applicable HP terms and conditions of service provided or indicated to Customer at the time of purchase. Customer may have additional statutory rights according to applicable local laws, and such rights are not in any way affected by the HP terms and conditions of service or the HP Limited Warranty provided with your HP Product.
1. Requires Windows 10 or higher. For supported HP PCs with the latest HP Endpoint Security Controller. See https://h20195.www2.hp.com/v2/GetDocument.aspx?docname=4AA8-3644ENW .
2. Based on HP’s internal analysis of business PCs with preinstalled encryption, authentication, malware protection, BIOS-level protection and passing MIL-STD testing, finding that no other in-class PC implements a quantum-resistant cryptographic scheme to protect the integrity of UEFI BIOS firmware as of March 2024. A quantum-re- sistant cryptographic scheme designed to protect UEFI BIOS firmware from potential quantum computer-based attacks, as of August 2024. Protection is enabled through HP Sure Start and HP Endpoint Security Controller, which utilizes a hybrid post-quantum cryptographic signature scheme (RSA + LMS/HSS). Requires Windows 10 or higher. For supported HP PCs with the latest HP Endpoint Security Controller. See https://h20195.www2.hp.com/v2/GetDocument.aspx?docname=4AA8-3644ENW.
3. Based on HP’s internal analysis of business Printers with preinstalled encryption, authentication, malware protection, post-quantum digital signature, and initial BIOS firmware integrity protection with automatic self-healing recovery finding that no other in-class Printers implement a quantum-resistant cryptographic scheme to protect the integrity of the BIOS and firmware as of March 2025.
© Copyright 2026 HP Development Company, L .P. The information contained herein is subject to change without notice. The only warranties for HP products and services are set forth in the express warranty statements accompanying such products and services. Nothing herein should be construed as constituting an additional warranty. HP shall not be liable for technical or editorial errors or omissions contained herein.
Pub ID 4AA8-5276ENUS
Engage early Begin quantum readiness assessments now, especially for long-lived systems or firmware- based trust anchors.
Require quantum-resistant roadmaps in procurement When specifying new hardware or firmware, insist on vendor support plans for quantum resistance.
Prioritize firmware integrity and authentication in early migration phases.
Leverage HP as a partner HP’s early deployment of quantum-resistant ESCs and future roadmap reduce your integration burden and risk.