Test your understanding of post-quantum cryptography across 79 topic areas.
Data Source: pqcquiz_10042026.csv • Updated: 10/4/2026
We'll pick the right number of questions
20 questions from 928 pool
AI model protection, true data provenance, scale encryption, and securing agentic workflows.
15 questions
Quantum threats, HNDL attacks, and the basics of post-quantum cryptography.
23 questions
Lattice-based, code-based, and hash-based PQC algorithms — names, properties, and trade-offs.
30 questions
FIPS standards, security levels, and the NIST PQC standardization process.
25 questions
Migration frameworks, crypto agility, CBOM, and hybrid deployment strategies.
20 questions
CNSA 2.0, ANSSI, eIDAS 2.0, and global PQC compliance deadlines.
PQC in TLS, IPsec, CMS/S/MIME, OpenPGP, 5G, and SSH protocols.
28 questions
Sector-specific quantum risks across finance, healthcare, telecom, and more.
KEMs vs signatures, key sizes, encapsulation, performance, and practical trade-offs.
Blockchain cryptography, elliptic curves, HD wallets, and post-quantum threats to digital assets.
TLS 1.3 handshake, cipher suites, key exchange, certificates, and PQC integration.
21 questions
X.509 certificates, certificate authorities, digital signatures, and PQC migration for PKI.
eIDAS 2.0, EUDI Wallets, credential formats, trust frameworks, and post-quantum readiness for digital identity.
SUCI subscriber privacy, 5G-AKA authentication, MILENAGE, SIM provisioning, and post-quantum upgrades for 5G networks.
Shor's and Grover's algorithms, CRQC timelines, HNDL attack mechanics, and security level degradation.
Hybrid KEMs, composite signatures, X25519MLKEM768, dual-OID certificates, and transition standards.
Abstraction layers, CBOM scanning, provider model, CycloneDX, and the 7-phase migration framework.
13 questions
IKEv2 with ML-KEM, SSH hybrid key exchange, WireGuard Rosenpass, and protocol size comparisons.
10 questions
ML-DSA-44 for DNSSEC (IANA algorithm 18), Cloudflare’s 1.1.1.1 pilot, and the signature-size problem.
6 questions
LMS/HSS, XMSS/XMSS^MT, Merkle tree signatures, one-time signature state, and NIST SP 800-208.
16 questions
S/MIME, CMS SignedData/EnvelopedData, RFC 9629 KEMRecipientInfo, and PQC migration for email.
Key lifecycle (NIST SP 800-57), envelope encryption with ML-KEM, hybrid key wrapping, multi-provider rotation planning.
SIMD, crypto instructions, GPU, FPGA, ASIC and NPU acceleration of ML-DSA and SLH-DSA, with measured Arm and FPGA results.
8 questions
PKCS#11 v3.2, HSM vendor comparison, firmware migration, and FIPS 140-3 validation.
What each certification scheme proves, scope before level, and what adding PQC changes in a certified product.
5 questions
FIPS 140-3 and the CMVP, security levels, the validation queue, and algorithm validation vs module certificates.
PCI PTS HSM device approval, what v5.0 changed, and the payment operating stack (PIN, P2PE, KMO).
3 questions
CNSA 2.0 and what it replaces, the CNSSP 15 dates, NSS vs federal civilian mandates, and NSA’s position on hybrids.
EST and CMP enrollment, proof-of-possession for KEM keys (RFC 9810 encrCert), and the ML-DSA / ML-KEM X.509 identifiers.
Which dates are real and whose they are, what a certificate proves, and which claims to avoid.
7 questions
CAVP vs CMVP, the ACVP vector-set lifecycle, what a PKCS#11 adapter can and cannot test, and evidence levels.
Common Criteria EALs and augmentations, CC:2022, EUCC, eIDAS qualified devices and their Protection Profiles.
SP 800-90 A/B/C, DRBGs, entropy sources, TRNG vs QRNG, and min-entropy estimation.
MTC batch signing, inclusion proofs, MTCA architecture, domain-separated hashing, and IETF PLANTS WG standardization.
BB84 protocol, QBER eavesdropper detection, sifted keys, privacy amplification, satellite QKD, and QKD + PQC hybrid integration.
Code signing certificate chains, ML-DSA package signing, Sigstore keyless signing, and supply chain integrity.
JWT/JWS/JWE with PQC algorithms, JOSE header changes, ML-DSA token signing, ML-KEM key agreement, and OAuth 2.0 migration.
PQC for constrained devices: algorithm fit by device class, firmware signing (SUIT/COSE), DTLS 1.3 and EDHOC, certificate size, device identity, fleet keys, and IoT regulation.
22 questions
Risk quantification, CRQC timeline planning, risk registers, and quantum threat-based risk assessment.
ROI modeling, breach cost analysis, budget frameworks, and executive communication for PQC investment.
11 questions
RACI matrices, PQC policies, governance models, board reporting, and organizational accountability.
Multi-jurisdiction mapping, audit readiness, regulatory horizon scanning, and compliance planning.
Roadmap construction, phase-gating, resource planning, stakeholder communications, and KPI tracking.
Vendor PQC scorecards, contract requirements, SBOM/CBOM evaluation, and third-party risk assessment.
Classifying data assets, mapping compliance obligations, NIST RMF/ISO 27005/FAIR methodologies, and PQC migration priority.
NIST, ISO/IEC, ETSI, IETF, CMVP, ENISA, ANSSI, BSI — who creates standards, who certifies, and who mandates.
PQC deployment at web gateways, CDNs, load balancers, and WAFs: TLS termination, certificate lifecycle, and vendor migration.
IEC 62443 zones and conduits, OT protocol security (IEC 61850/62351, DNP3, OPC UA, CIP Security, PROFINET, BACnet/SC), safety timing, PLC signing, NERC CIP and NIS2.
EMV chip card authentication, payment network PQC migration, tokenization, POS terminal crypto, and PCI DSS compliance.
HIPAA/HITECH compliance, HL7 FHIR security, medical device cryptography, and healthcare data protection.
Avionics protocol constraints, satellite link budgets, DO-178C certification, export controls, and multi-decade fleet crypto interoperability.
Vehicle E/E architecture, sensor data integrity, ISO 26262 safety-crypto, automotive HSM lifecycle, digital car keys, OTA orchestration, and V2X PKI migration.
JCA/JCE, OpenSSL EVP, PKCS#11, Windows CNG, Bouncy Castle, and Rust/Go/Python/Java crypto ecosystems with PQC library selection, provider patterns, and migration guidance.
TEE architectures (SGX, TDX, CCA, SEV-SNP, Nitro), remote attestation, memory encryption, TEE-HSM integration, and quantum threat analysis for confidential computing.
Fully homomorphic encryption (FHE): the ISO/IEC 28033 draft schemes, FHE keys and who runs each operation, FHE against the quantum threat, and how an HSM holds the FHE secret key without becoming a decryption oracle.
14 questions
CI/CD pipeline crypto inventory, container signing migration, IaC quantum-vulnerable defaults, policy enforcement, posture monitoring, and platform migration runway.
Migrate secrets managers (Vault, AWS Secrets Manager, Azure Key Vault) to quantum-safe encryption, automated rotation, and PQC key wrapping.
NGFWs, IDS/IPS, TLS inspection, and zero trust network architecture migration to post-quantum cryptography.
TDE, column-level encryption, queryable encryption, and BYOK/HYOK migration for databases with external PQC KMS.
JWT/SAML/OIDC token signing with ML-DSA, Active Directory quantum risks, and PQC zero trust identity architecture.
Migrate UEFI Secure Boot, firmware signing, and TPM attestation to post-quantum cryptography with ML-DSA-65.
System-wide TLS policies, SSH host key migration, package signing, and FIPS mode compatibility for OS-level PQC.
Fiduciary risk, regulatory deadlines, board-level PQC action planning, and quantum exposure self-assessment.
Library transitions, key/signature size impacts, TLS/JWT migration, and developer PQC readiness.
PKI hierarchy migration, hybrid certificate design, HSM root of trust, and crypto-agile architecture.
Certificate operations, VPN/SSH fleet migration, monitoring recalibration, and deployment pipeline PQC.
Research data HNDL exposure, institutional infrastructure, PQC algorithm research opportunities.
Passive discovery, active scanning, performance benchmarking, interoperability testing, TVLA, and test strategy design.
Crypto inventory, agility, lifecycle management, and modernization programs for post-quantum readiness.
Stateless hash-based digital signatures (FIPS 205) — SPHINCS+ standardised for post-quantum signing.
Messaging Layer Security (RFC 9420) — PQC-hybrid group key establishment for secure group communication.
NIST Round 4 and on-ramp candidates — Falcon, HQC, FrodoKEM, Classic McEliece, and other post-quantum contenders.
SPDX vs CycloneDX, NTIA minimum elements, VEX vulnerability triage, and the EO 14028 / EU CRA regulatory drivers.
17 questions
Cryptographic asset inventory, ghost crypto, layered discovery, key identity & provenance, and machine-verifiable CBOMs.
The canonical algorithm and elliptic-curve naming catalog that resolves the same mechanism across HSMs, certificates, protocols, and libraries.
Retiring classical cryptography on a defensible schedule, proving migration from observed behaviour, and closing the program to business-as-usual.
The KRI cascade, risk-appetite statement, regulatory horizon reporting, and GRC-SOC handoff that make a PQC migration governable and auditable.
12 questions
Staffing a PQC migration program — core roles, team-sizing heuristics, build/borrow/buy decisions, and the federated Crypto Champion network.
Detection use cases, quantum threat intelligence, incident-response playbooks, and tabletop exercises for operationalizing PQC defense in the SOC.