Imo NIST encryption is OK until the first ‘Entangled’ Quantum Computer Cluster Shows up, then with PQC Binary Math it becomes a race to the bottom, crack n change, crack an change ;ad infinitum; with huge losses piling up along the way. Some but not all Quantum computer clusters will get re-organized to get very good at guessing using approximation math…making several guesses in parallel in real time, because the payoffs are HUGE and cost of these ‘gas pipes’ is only US $1.5M to US $2.5 M today.
The question is how quickly ‘they’ show up, as the AI driven design continues to accelerate the creation of everything, especially Quantum Computer Capabilities, Decryption being the obvious big reward motivation, aside from total nation state control of their populace.
The expected Q-Day arrival date Range is 4 to 10 years for Q-Day to show up, estimated by the ‘smart’ researchers and analysts in the binary math space.
That said only a Few of these ‘smart’ math heads have have ever heard of :
Discrete Deterministic Chaos Theory which can be incorporated to inject multiple passes of entropy to eliminate patternicity making it virtually impossible to crack by creating True Random Numbers for keys..
In fact if one tries to explain the above to a math head, one is more likely to get in a shouting match with them if one brings up the topic as the topic is not in their ‘wheel house’ … 
also there is a thing called a Mathematical Barren Plateau that when applied to the generation of pure Random Numbers (used to create keys) together with the above, it creates an unsolvable problem in math which is the only thing Quantum computers are good at, doing it REALLY FAST.
My bet is on the latter two techniques, and definitely not NIST.
The PQC Vendors doing the ‘Binary Math encryption sell’ to the customers that they are protected for 100 years is a ‘big stretch’,
however Quantum Qubit power is doubling every 6 months accelerated by AI,
in four years that is a 256X increase by 2029,
then the clever opportunists gang them into clusters and aim they at high value Targets. Like BTC dormant Wallets, or Banks, or if they are into take-overs, Nation States.
Back of the envelop math says AES 256 will be broken in under < 1 year by a quadratic Cluster of Quantum Computers using the highest speed we today have as the starting point for Qubit power before doubling every 6 months. That means companies that are high value targets, BIG ones
have til 2030 to get ready. One thing I do know is while the awareness might be there of Q-Day in the FT 100, it will take those companies four years to get anything done.
Whoops. It’s Y2K all over again and this time Binary Math is not going to help, in fact it will be slowing us all down with giant keys in the ‘guessing game’, latency will really start to suck.
Any way, the homework I have done points me away, far far away from PQC Binary Math based solutions, especially NIST. So that is the path I am taking and also recommending others to take.
As always do your own research though. 
Quantum Computer bonus joke. Just heard it today…
“A Quantum Computer shows up at two bars”