NIST finalized PQC standards in 2024
ML-KEM, ML-DSA, and SLH-DSA are now published federal standards.
PQC Radar scans your TLS, certificates, SSH, APIs, vendors, and long-lived data systems to show where RSA/ECC exposure exists and what to fix first.
Console preview: sample data, not a live customer scan
Quantum risk is not only about future computers. It is about data lifetime, and the clock starts the moment data is captured.
An attacker records encrypted traffic or steals an archive.
It sits untouched, still protected by RSA/ECC.
A future quantum computer breaks the public-key layer.
Yesterday's confidential data becomes readable.
“If your data must stay confidential for the next decade, your quantum risk window may already be open.”
Law firm: Confidential acquisition documents archived for years: captured today, readable later.
Fintech: Customer KYC documents and identity records with long regulatory retention windows.
Healthtech: Medical records that must stay private for the lifetime of the patient.
B2B SaaS: Enterprise customer contracts and tenant data under multi-year confidentiality terms.
IoT vendor: Devices shipped to the field expected to stay deployed for 10-20 years.
Any org: VPN, TLS, SSH and certificates in use without a record of which algorithms back them.
Cryptography hides in more places than any inventory expects. Here is where we look, and what we check.
Checks: Negotiated key-exchange groups, cipher suites, certificate algorithms, and hybrid support.
Checks: VPN endpoints, IKE proposals, certificate chains, and PSK vs public-key usage.
Checks: Host key types, key-exchange algorithms, and key inventory across fleets.
Checks: Signing key algorithms, certificate lifetimes, and CI/CD signing flows.
Checks: Full certificate inventory, key algorithms, expiry, and issuing CA dependencies.
Checks: JWT/JWS algorithms, mTLS configs, and OAuth/OIDC signing keys.
Checks: Key-wrapping algorithms, KMS configuration, and backup retention windows.
Checks: Retention periods vs. crypto lifetime, envelope encryption, and access exposure.
Checks: Secure-boot/update signature schemes and crypto-agility of the update channel.
Checks: Vendor PQC roadmaps, supported algorithms, and contractual/procurement exposure.
Standards are final and major platforms have shipped. Every claim links to a primary source.
ML-KEM, ML-DSA, and SLH-DSA are now published federal standards.
Official guidance: inventory your cryptography and begin migration planning.
Apple, Signal, Google, and Cloudflare have deployed post-quantum or hybrid key exchange in production.
Larger keys and added latency make PQC an engineering project. It needs planning, not a flag flip.
Migration is an engineering process, not a one-click certificate update.
See the full timelineFour steps: from scattered cryptography to a prioritized migration plan.
Scan endpoints, certificates, repositories, and cloud assets plus any infrastructure data you provide.
Map every place RSA, ECC, DH/ECDH, TLS, SSH, and signing dependencies actually live.
Rank by data lifetime, exposure, algorithm, and migration difficulty so you fix the right things first.
Deliver a 30/60/90-day plan: quick wins, hybrid PQC candidates, and the right questions for your vendors.
The questions security leads, founders, and engineers actually ask.
No, not for normal systems at meaningful scale. The near-term risk is harvest-now-decrypt-later, and being ready to migrate before it is urgent.
RSA, elliptic-curve cryptography, Diffie-Hellman, ECDH, and ECDSA are the primary concern. Symmetric encryption like AES is affected differently and is usually handled with larger keys.
Crypto hides across TLS, certificates, APIs, SSH, VPNs, cloud, code dependencies, vendors, backups, and firmware. You cannot migrate what you cannot find.
It identifies your exposure and builds a migration roadmap. Actual migration depends on your systems, vendors, and protocols. We do not claim instant quantum-proofing.
A readable report with a crypto inventory, evidence-backed findings, prioritized risks, vendor questions where relevant, and a practical 30/60/90-day migration plan.
PQC standards are newer, vendor support is uneven, and PKI, signing, legacy systems, and larger keys need careful sequencing. Inventory first, then migrate the highest-risk paths.
Anyone with long-lived or regulated data, enterprise or government customers, or products with long deployment lifetimes.
Attackers can capture encrypted data now and decrypt it later. Large crypto migrations also take years to plan and execute.
Get a clear view of your RSA/ECC exposure and a practical 30/60/90-day roadmap.
A few details on your systems. We reply to scope a short call and confirm written authorization before anything is scanned.