Quantum computers are machines that exploit quantum mechanical phenomena to solve mathematical problems that are difficult or intractable for conventional computers. If large-scale machines are built, they will be able to break many of the cryptosystems currently in use. Recent progress suggests that it might happen very soon as most of the open problems are of engineering rather than conceptual type. Fortunately, there exist protocols for which no efficient quantum attacks are known. Future cryptography must be based on them but since a worldwide migration to new systems is a huge undertaking, the time to start it is now.We start our presentation by a simple description of quantum computers’ operation. We pinpoint the source of its power and discuss the limitations. Next, we explain Shor’s algorithm which is the main threat posed by quantum information to modern cryptography. Its form allows us to find the requirements for quantum computers to break some commonly used cryptosystems. Then, by shortly discussing the most recent advancements in experimental quantum computation, we estimate when these systems become insecure. Next, we move to the second part of our presentation in which we discuss the challenge facing modern cryptography in the post-quantum world. When the cornerstone problems such as computing discrete logarithms and integer factorization are no longer intractable, we need to look for alternatives. United States’ National Institute of Standards and Technology (NIST) recognized this need and last year initiated a process to gather and evaluate new public key algorithms that are secure even after the advent of quantum computers. This initiative attracted a lot of attention from the cryptographic community and is currently one of the very active areas of research.Using NIST post-quantum cryptography call submissions as a reference, we discuss main classes of underlying mathematical problems that can be used to construct quantum-secure public key cryptosystems. We show examples of concrete constructions and highlight relevant attacks. We also comment on implementation aspects of more interesting candidates.