About PQC Today

What this means for you

Executive / Business Leader
The Trust Engine and Trust Score Methodology sections explain how much of the site's content is backed by a cached primary source — the figures to quote when you cite the site.
GRC / Risk & Compliance
The Transparency & Disclaimer and Independence sections state who runs the site, who funds it and how corrections are handled.
Developer / Engineer
The SBOM section lists every dependency by category; the Data Privacy section states that the site is static, with no backend and nothing leaving your browser.
Security Architect
The Platform Data section names each data file with its date — the provenance of every table you design from.
Researcher / Academic
The Trust Score Methodology and Trust Tiers are published in full; use them to judge any figure on the site.
Certification & Validation Engineer
The Trust Score Methodology and Trust Tiers say how each record and source is weighed; the Transparency & Disclaimer section says how corrections are handled.
IT Ops / DevOps
Your progress and settings live in your browser's localStorage; the Data Privacy section says exactly what is and is not collected.
Curious Explorer
The Transparency & Disclaimer section says who builds this site, why, and what is and is not tracked.

About PQC Today

v4.152.0

PQCToday — Public Vision

Preparing the world for the quantum cryptographic transition

The algorithms that protect your data today — RSA, ECC, the cryptography behind TLS, SSH, and every digital signature you have ever trusted — will be broken by quantum computers. The question is not whether. The question is when, and whether the world will be ready.

We are not ready. Most organisations do not know which systems are vulnerable. Most practitioners have never practiced post-quantum cryptography hands-on. The tools to learn, assess, and migrate exist — but they are scattered, vendor-biased, or inaccessible to the people who need them most.

PQCToday exists to close that gap.


What we are building

PQCToday is a neutral, community-governed platform providing independent education, hands-on simulation, and migration guidance for the global post-quantum cryptography transition.

We run real cryptographic reference implementations — including SoftHSMv3, an experimental open source PKCS#11 v3.2 HSM with NIST PQC algorithm support — directly in your browser. No installation. No cloud account. No data leaving your device.

We cover every domain the transition touches: TLS, SSH, email, PKI, HSM key management, 5G authentication, digital identity, blockchain, IoT, and the regulatory frameworks — NIST, ETSI, DORA, NIS2, NSM-10, ANSSI — that are setting the deadlines.

Our Command Center provides 37 interactive planning tools for executives and compliance teams — ROI calculators, RACI builders, vendor scorecards, policy generators, deployment playbooks, and audit checklists — all adapting to your industry, geography, and regulatory context.

73 learning modules37 business planning tools13-step risk assessment888 migration catalog products729 PQC patentsPKCS#11 v3.2 simulatorFIPS 203 / 204 / 205AI assistant — local or cloudNo accounts, anonymous usage analytics

Our founding principles

Worldwide

Not US-centric. NIST, ETSI, GSMA, ANSSI, ASD — all regulatory frameworks treated equally.

Transparent

Open source. GitHub-governed. Every correction, contribution, and decision is publicly auditable.

Neutral

No vendor relationships. No commercial bias. We do not take sides — we provide data so you can.

Private by design

No registration. Processing runs on your device. Google Analytics 4 counts anonymous usage on every visit; the Privacy section below says what it records and how to block it.

Free at the core

Access to knowledge must not be gated. The community edition is free. Always.

Community governed

PQC practitioners set the roadmap. The platform serves the community, not the other way around.


What we are not

Not a vendor

We have no commercial relationships with HSM, cloud, or security vendors. Our content is not for sale.

Not a standards body

We reference and empower NIST, ETSI, ANSSI, and GSMA. We do not replace them.

Not a surveillance platform

We have no accounts and ask for no personal details. Google Analytics 4 counts anonymous usage on every visit; the Privacy section says what it records and how to block it.

Not US-only

The quantum transition is a global challenge. Our platform is designed for every regulatory environment.


“We seek the endorsement and support of existing standards bodies and PQC experts. We aim to empower these bodies rather than replace them — and to enable them to simplify and improve the deployment of quantum-safe best practices worldwide.”


Who this is for

Every organisation that processes sensitive data has a quantum exposure problem — whether they know it yet or not. Governments. Banks. Hospitals. Telecoms. Manufacturers. The practitioner who needs to understand ML-KEM before their next architecture review. The CISO who needs to explain quantum risk to their board. The engineer who needs to practice PKCS#11 v3.2 operations before touching production.

PQCToday is built for all of them. The platform adapts to your role, your industry, your regulatory environment, and your proficiency level — and it does so without asking you to register, share data, or trust us with anything except your time.


The open source foundation

PQCToday is built on open source. Our platform code, our cryptographic simulators, and our community corpus are all publicly available. SoftHSMv3 — an experimental PKCS#11 v3.2 HSM implementation at the heart of our simulator — is a standalone open source project available on GitHub and npm, free for anyone to use in their own applications.

We believe the infrastructure for PQC migration training should be open, auditable, and independent of any single organisation's interests. That belief is not a marketing position. It is the architecture.


The timeline is not optional

NIST published its first post-quantum cryptographic standards in 2024. US federal agencies are under NSM-10 migration mandates. European financial institutions face DORA Article 9 cryptographic control requirements. The window for “we will think about it later” has closed.

The organisations that begin their cryptographic inventory, upskill their teams, and start their migration planning now will complete the transition on their terms. Those that wait will complete it under regulatory pressure, in crisis mode, with less time and more risk.

PQCToday exists to make sure the knowledge and tools needed for that transition are available to everyone — for free, without conditions, without a sales conversation, and without compromising the privacy of the people who need them.


Connect: Eric Amador on LinkedIn

How this hub adapts to you

Telling the hub your role changes four things: which pages lead your navigation, which sections your report opens on, where the reference pages land on first paint, and which progress ladder you climb. It never removes a page from the site — a route you are not offered is still reachable by URL, by deep link and from search — and wherever a route is deliberately not offered, the navigation says so and why, in place.

Your rail leads with Migrate, Compliance and Command Center · three other pages move behind More and search.

Leads your rail
Migrate · Compliance · Command Center · Assess · Report · Algorithms · Library · Community · Patents · Navigate · Simulation · Playground
Behind More
Explore · Business Tools · Revisions
Not offered
Nothing. Every route in the navigation is offered to this role.
Report opens on
Risk Score · Key Findings · Risk Breakdown · Executive Summary · Compliance Impact · Recommended Actions
Report omits
Algorithm Migration Priority — "Show full report" restores every one of them.
Algorithms lands on
the transition view, filtered to Certified
Compliance emphasises
CNSA-2, DORA, NIS2, SOX, GDPR, PCI-DSS — the rest of the landscape stays reachable, collapsed.
Timeline defaults to
americas — until you pick a region, which then wins on every visit.
Your ladder
Briefed → Aligned → Sponsoring → Board-Ready

How a claim earns its place here

Every record on this site carries a source, a trust tier scored from that source's credibility, its peer-review status, its vetting body and whether we hold a copy of the document itself. Conclusions are computed from the premises above them rather than typed beside them — the risk score, the Mosca window and the signature sizes are all derived, so they cannot quietly disagree with their own inputs. Where evidence is missing we mark the claim rather than dropping it, and where a source contradicts another we keep both.

Release Notes

What's new in v4.152.0 — features, fixes, and improvements

Deployed: Oct 8, 2026, 12:14 AM CDT

View

Transparency & Disclaimer

WIP

PQC Today is a community-driven educational platform built to help professionals understand and prepare for the post-quantum cryptography transition.

  • ●This website has not received endorsement from the organizations, standards bodies, or government agencies referenced in its content
  • ●All information is sourced from publicly available resources on the internet
  • ●Significant effort has gone into ensuring accuracy through thorough automated and manual verification processes, but the content may still contain inaccuracies
  • ●We are actively working to collaborate with authoritative organizations and domain experts to cross-validate and continuously improve the quality of this content
  • ●Industry leaders featured on this platform are included only with their written consent

If you represent a cited organization, are a domain expert, or simply want to help improve the accuracy of this platform, we welcome your involvement:

Google Drive Sync — Privacy Terms

The Sync to Google Drive feature is built into the app's code to back up and restore your progress across devices. It is not currently enabled in the interface — there is no sign-in control anywhere in the app today, so no one can turn cloud sync on or off right now. The points below document exactly what the code does, for transparency, even though the feature is currently dormant:

  • ●The sync feature collects no personal data. We do not request your name, email address, or profile picture. The consent screen only asks for access to your Google Drive app data folder.
  • ●Your data stays in your account. All progress data is saved to a hidden file in your own Google Drive — not on any server we own or control. Only you can access it.
  • ●No identity is transmitted. The Google access token (used to write to your Drive) is stored only in browser memory and is never sent to our servers. It disappears when you close the tab.
  • ●No API keys are synced. Your Gemini or other AI provider API keys are explicitly excluded from the sync payload and remain local to your device at all times.
  • ●No in-app control exists today. There is currently no sign-in or sign-out control anywhere in the app — cloud sync cannot be enabled or disabled from the home page or any other screen. Regardless, any data ever written to your Drive app-data folder can be permanently deleted at any time via Google Drive settings → Manage apps → PQC Today → Delete hidden app data — you do not need our app for that.
  • ●Nothing else is affected. The app works fully without any Google account. The current unavailability of this feature has no effect on any other functionality.

The scope requested is https://www.googleapis.com/auth/drive.appdata — the least-privileged Drive scope. It grants access only to a hidden app-specific folder and cannot read, modify, or delete any of your regular Drive files.

Platform Data

Curated datasets powering every page

184
Timeline Events
80+ orgs, 28 countries
1275
Library Resources
30+ standards bodies
125
Algorithm Reference
FIPS 203/204/205 (+206 draft)
191
Compliance Frameworks
NIST, CAVP, CC, ANSSI
888
Migrate Products
9 infrastructure layers
71
Threat Landscape
8+ industry sectors
364
Industry Leaders
Public, Private, Academic
1125
Quiz Questions
All PQC topic areas
737
Authoritative Sources
Gov, Academic, Industry
73
Learning Modules
3,800+ min of content
729
PQC Patents
USPTO, EPO, WIPO
5,762+total curated records
Compliance data last updated September 27, 2026

Security Audit

Last audited: March 22, 2026

0 vulnerabilities (production and dev)

All dependencies — runtime and development — have zero known CVEs. Verified via npm audit in CI on every push.

OWASP Top 10 compliant

  • No dangerouslySetInnerHTML, eval(), or innerHTML in production code
  • Every external link protected against tabnabbing (rel="noopener noreferrer")
  • No hardcoded secrets — all credentials via environment variables
  • Content Security Policy configured with scoped connect-src whitelist
  • ESLint security plugin active in CI

Open Source License

PQC Today is open source software released under the GNU General Public License v3.0 (GPLv3).

You are free to copy, distribute, and modify this software, provided that any modifications are also released under the same license terms. This ensures that the project remains free and accessible to the PQC community.

Cryptography Buff

Curated websites and essential reading

AI Technology Acknowledgment

This site is developed, documented, validated and deployed using advanced AI technologies including Google Antigravity, ChatGPT, Claude AI, Perplexity, and Gemini Pro. While the presented information has been manually curated, it may still contain inaccuracies.

Appearance

Choose your preferred color scheme.

Pick a starting point

Tell us a bit about your role and we will route you to the page that fits you best — takes about 30 seconds.

Find my starting point

Next step

How the content stays independent

The policy behind the assessments and vendor rows on this site.