Post-Quantum Cryptography · Assessment
Adversaries are archiving your TLS sessions today. When a cryptographically relevant quantum computer (CRQC) arrives — Mosca's theorem puts the window at 2028–2035 — those ciphertexts decrypt. Q finds, scores, and migrates your cryptographic estate before that window closes.
// Mosca's inequality: if t_migrate + t_threat ≥ t_secure — migrate now.
48 / 58
Tracked algorithms are quantum-vulnerable
RSA, ECDH, ECDSA, DSA — all broken by Shor's algorithm at scale
2028–2035
CRQC arrival window
NIST IR 8547 and NSA CNSA 2.0 migration deadline guidance
≥ 2^152
Classical security of ML-KEM-768
NIST FIPS 203 Category 3 — equivalent to AES-192 classical security
Platform
Cryptographic Bill of Materials
Active TLS inspection + certificate analysis across your IP ranges and domains. Produces a full CBOM in CycloneDX 1.6 format — every algorithm, key length, curve, and protocol version. Ingests Shodan, passive DNS, and agent-based inventory.
Output: CycloneDX 1.6 CBOM · Formats: JSON, XML, CSV
HNDL Risk Quantification
Harvest Now, Decrypt Later risk scored 0–100 across seven weighted factors: algorithm weakness, key longevity, data sensitivity, adversary capability index, migration lead time, regulatory exposure, and detected HNDL campaign indicators.
Output: board-ready HNDL score + 90th-pct financial exposure
Adversarial Quantum Testing
Simulated quantum decryption attacks modeled against real hardware capability trajectories (IBM Heron r2, Google Willow roadmap). Generates a probability-weighted Board Number — dollar exposure at each CRQC milestone year.
Output: probability-weighted financial exposure matrix
NIST FIPS 203 / 204 / 205 · Algorithm Reference
Measured on an AMD EPYC 9654 (Genoa), single core, liboqs 0.10.1. ECDH-P256 included as classical baseline.
† Classical security level only — broken by Shor's algorithm at scale. Sec. Level: NIST categories 1–5 (AES-128 through AES-256 equivalent). Op = Encaps/Decaps for KEM, Sign for signature.
Threat Model
2016–present
Nation-state adversaries (APT41, Cozy Bear, Unit 61398) archive encrypted TLS sessions, VPN captures, and key exchanges at petabyte scale. GCHQ / NSA intercept documentation confirms bulk capture programmes.
2024
ML-KEM, ML-DSA, SLH-DSA finalized. NSA CNSA 2.0 mandates migration timelines. OMB M-23-02 requires agencies to begin cryptographic inventory. The standard is live — the migration clock is running.
2025–2027
Large systems (PKI roots, HSMs, TLS termination, code-signing pipelines) require 18–36 months for safe migration. Organizations that have not begun CBOM generation by end-2025 risk missing the safe window entirely.
2028–2035
IBM, Google, IonQ, and PsiQuantum roadmaps converge on cryptographically relevant qubit counts in this window. At ~4,000 noisy-or-corrected logical qubits, RSA-2048 falls to Shor in hours. Mosca's theorem: if you haven't migrated, it's already too late.
Migration Roadmap
A phased approach to post-quantum cryptographic readiness, calibrated to OMB M-23-02 and NSA CNSA 2.0 timelines. Begin Phase 01 before end-2025 to remain inside the safe migration window.
Months 1 — 3
Inventory and risk assessment. CBOM generation across IP ranges, domains, and code repositories. Baseline HNDL exposure scored.
Months 4 — 9
Prioritization and roadmap. ML-KEM / ML-DSA selection per system tier. PKI hierarchy mapping. Vendor-side migration timelines collected.
Months 10 — 36
Algorithm migration and testing. Hybrid-mode rollout (X25519 + ML-KEM-768). HSM firmware upgrades. Code-signing pipeline transition.
Ongoing
Continuous monitoring and updates. New-algorithm watch (FIPS 206, BIKE, HQC). Crypto-agility validation against future standards.
Competitive Landscape
Traditional vulnerability scanners were designed for CVE triage, not cryptographic agility assessment. The capabilities they lack are precisely the ones Mosca's theorem demands.
| Capability | Q | Tenable | Qualys |
|---|---|---|---|
| HNDL risk scoring (0–100) | |||
| CBOM generation (CycloneDX 1.6) | |||
| PQC algorithm detection | |||
| Adversarial quantum simulation | |||
| Board-ready financial exposure | |||
| Mosca timeline calculator | |||
| Crypto-agility migration roadmap | |||
| OMB M-23-02 / NSA CNSA 2.0 mapping |
Standards Alignment
Get started
No agent installation required. Q runs an edge HTTPS reachability probe, builds a partial CBOM from the in-app algorithm database, and returns an HNDL risk score from a domain list and data-sensitivity profile. Full on-the-wire cipher enumeration (deep TLS inspection) is in beta. Q is in private beta — request early access and we'll set up your account.