PQC Migration Guide

Step 1: Assessment & Inventory

Est. duration: 4-8 weeks

Discover and catalog all cryptographic assets, algorithms, protocols, and dependencies across your organization. Build a Cryptographic Bill of Materials (CBOM) to understand your quantum-vulnerable attack surface.

Key Tasks

  • Build cryptographic inventory

    Catalog all cryptographic libraries, modules, and SDKs in use across applications and infrastructure.

  • Map certificate chains and PKI dependencies

    Document all X.509 certificate hierarchies, root CAs, intermediate CAs, and trust anchors.

  • Identify quantum-vulnerable algorithms

    Flag all RSA, ECDSA, ECDH, DH, and DSA usage. Assess key sizes and deprecation timelines per NIST IR 8547.

  • Assess data retention risk (HNDL)

    Identify data with long confidentiality requirements (10+ years) vulnerable to Harvest Now, Decrypt Later attacks.

  • Deploy cryptographic discovery tools

    Use automated scanning tools to detect cryptographic usage in CI/CD pipelines, network traffic, and stored data.

Framework Alignment

NIST IR 8547Inventory phase
CISAInventory & Risk Assessment
ETSI TR 103 619Asset Inventory
Try interactive CBOM Scanner →

Enterprise Infrastructure Stack

Select a layer to view post-quantum cryptographic software options.

Reference Catalog

Product
Layer
Category
PQC Support
License
FIPS
01 Quantum IronCAP
Current
Application Servers & SoftwareCryptographic LibrariesYes (NIST-aligned PQC)Commercial Partial
Adobe Acrobat Sign
Current
Application Servers & SoftwareDigital Signature SoftwareNoCommercial No
Adva Network Security FSP 3000 S-Flex
FSP 3000 S-Flex 400G
NetworkNetwork EncryptorsYes (Hybrid PQC + Classical)Commercial Partial
AMD SEV-SNP (Secure Encrypted Virtualization)
EPYC Genoa/Bergamo (4th Gen)
Hardware & Secure ElementsHardware Security Module (HSM) SoftwarePlannedCommercial (AMD) No
Android 16
16
Operating SystemOperating SystemsYes (Native API support)Apache-2.0 Partial
Apache HTTP Server
2.4.60+
Application Servers & SoftwareApplication ServersYes (via OpenSSL)Apache-2.0 No
Apple codesign
Xcode 16.x
Application Servers & SoftwareCode Signing and Software IntegrityNoCommercial No
Apple PQ3 / CoreCrypto
iOS 26.3
Application Servers & SoftwareSecure Messaging and CommunicationYes (ML-KEM ML-DSA Hybrid HPKE)Commercial Validated
Apple Safari
18.0+
Application Servers & SoftwareWeb BrowsersYes (ML-KEM)Freeware Partial
AppViewX CERT+
Current
Security StackCertificate Lifecycle ManagementPlannedCommercial No
ARM Confidential Compute Architecture (CCA)
ARMv9-A (Cortex-A Series)
Hardware & Secure ElementsHardware Security Module (HSM) SoftwarePlannedCommercial (ARM) No
ARM Trusted Firmware (TF-A)
2.14.0
Hardware & Secure ElementsSecure Boot and Firmware SecurityNoBSD-3-Clause No
Arqit Encryption Intelligence
Current
CloudCryptographic Agility FrameworksYes (Crypto Discovery and Migration)Commercial No
Atalla AT1000e
AT1000e
Application Servers & SoftwarePayment Cryptography SystemsNoCommercial Validated
Auth0 (Okta Customer Identity)
Current
Security StackCustomer Identity & Access Management (CIAM)PlannedCommercial (SaaS) No
AWS Application Load Balancer (ALB)
Current
CloudCloud Encryption GatewaysYes (Hybrid ML-KEM TLS)Commercial (AWS) Validated
AWS CloudHSM
Current
CloudCloud Hardware Security Module (HSM)PlannedCommercial (AWS) Validated
AWS KMS
Current
CloudCloud Key Management Service (KMS)Limited (Hybrid PQC TLS)Commercial (AWS) Validated
AWS KMS (Cloud Gateway)
Current
CloudCloud Encryption GatewaysLimited (Hybrid PQC TLS)Commercial (AWS) Validated
AWS s2n-tls
1.7.0
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (ML-KEM hybrid)Apache-2.0 No
AWS-LC
v1.68.0
Application Servers & Software, Security StackCryptographic LibrariesYes (ML-KEM ML-DSA)Apache-2.0/ISC Validated
Azure Dedicated HSM
Current
CloudCloud Hardware Security Module (HSM)PlannedCommercial (Microsoft) Validated
Azure Key Vault
Current
CloudCloud Key Management Service (KMS)PlannedCommercial (Microsoft) Validated
BitLocker (Windows)
Windows 11 24H2
Application Servers & SoftwareDisk and File Encryption SoftwareNoCommercial Validated
BoringSSL
Rolling
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (ML-KEM)OpenSSL/ISC Validated
Botan
3.10.0
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA SLH-DSA McEliece FrodoKEM)BSD-2 No
Bouncy Castle C# .NET
2.6.2
Application Servers & Software, Security StackCryptographic LibrariesYes (HQC ML-KEM)MIT/Bouncy Castle License Validated
Bouncy Castle Java
1.83
Application Servers & Software, Security StackCryptographic LibrariesYes (ML-KEM ML-DSA SLH-DSA HQC)MIT/Bouncy Castle License Validated
Bouncy Castle Java LTS
2.73.9
Application Servers & Software, Security StackCryptographic LibrariesYes (ML-DSA composite signatures)Bouncy Castle License Partial
BTQ Bitcoin Quantum
Testnet
Application Servers & SoftwareBlockchain and Cryptocurrency SoftwareYes (ML-DSA)Open Source No
Check Point Quantum
R82
NetworkNetwork Security SoftwareYes (ML-KEM Quantum-safe VPN)Commercial Partial
Ciena WaveLogic 6 Extreme
WaveLogic 6 Extreme (2026)
NetworkNetwork EncryptorsYes (PQC + QKD hybrid)Commercial No
Cisco IOS XE PQC
IOS XE 26
Operating SystemNetwork Security SoftwareYes (Full-Stack PQC NIST Algorithms)Commercial Validated
citadel_pqcrypto
Current
Application Servers & SoftwareCryptographic LibrariesYes (Kyber NTRU+)Apache-2.0/MIT No
Cloudflare CIRCL
1.6.3
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA hybrids)Apache-2.0 No
Cloudflare Edge Network
Current
CloudCloud Encryption GatewaysYes (X25519MLKEM768 enabled by default)Commercial Partial
CockroachDB Encryption
25.2
DatabaseDatabase Encryption SoftwareNoBSL/CockroachDB License No
coreboot
24.12
Hardware & Secure ElementsSecure Boot and Firmware SecurityNoGPLv2 No
Cosmian covercrypt
Current
Application Servers & SoftwareCryptographic LibrariesYes (KEMAC Hybrid)Apache-2.0 No
Crypto4A QxHSMNew
QxOS 5
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (ML-KEM FIPS 203 ML-DSA FIPS 204 SLH-DSA FIPS 205 LMS)Commercial Validated
Cryptomathic CKMS
Current
Application Servers & SoftwarePayment Cryptography SystemsPlannedCommercial No
Cryptosense Analyzer
Current
CloudCryptographic Agility FrameworksYes (PQC readiness)Commercial No
CRYSTALS Reference Implementations
FIPS 203/204 Final
Application Servers & SoftwarePost-Quantum Cryptography LibrariesYes (ML-KEM-512/768/1024 ML-DSA-44/65/87)Public Domain No
CyberArk Conjur
Current
Security StackSecrets ManagementPlannedCommercial Partial
DigiCert SigningHub
Current
Application Servers & SoftwareDigital Signature SoftwarePlannedCommercial Partial
DigiCert Software Trust Manager
Current
Application Servers & SoftwareCode Signing and Software IntegrityPlannedCommercial Partial
DigiCert Trust Lifecycle Manager
Current
Security StackCertificate Lifecycle ManagementYes (Hybrid PQC Certificates ML-DSA)Commercial Partial
DocuSign
Current
Application Servers & SoftwareDigital Signature SoftwareNoCommercial No
EJBCA
9.x
Security StackCertificate Lifecycle ManagementYes (via Bouncy Castle)LGPL/Enterprise Partial
Entrust KeyControl
10.4.3
Security StackKey Management Systems (KMS)Yes (ML-KEM ML-DSA SLH-DSA)Commercial Validated
Entrust nShield
13.x
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (Hybrid PQC)Commercial Validated
Entrust PKI
Current
Security StackPublic Key Infrastructure (PKI) SoftwareYes (Hybrid PQC via nShield)Commercial Validated
Entrust Signing Automation
Current
Application Servers & SoftwareDigital Signature SoftwarePlannedCommercial Partial
Envoy Proxy
1.37+
Application Servers & SoftwareApplication ServersYes (via BoringSSL)Apache-2.0 Partial
ExpressVPN Lightway
Current
NetworkVPN and IPsec SoftwareYes (ML-KEM Hybrid via wolfSSL)Proprietary Partial
F5 BIG-IP
17.5.x
NetworkNetwork Security SoftwareYes (ML-KEM TLS Hybrid)Commercial Validated
FileVault (macOS)
macOS 26.3
Operating SystemDisk and File Encryption SoftwareNoCommercial Partial
ForgeRock Identity Cloud
Current
Security StackCustomer Identity & Access Management (CIAM)PlannedCommercial Partial
Fortanix Data Security Manager
Current
CloudCloud Encryption GatewaysPlannedCommercial Validated
Fortinet FortiOS
7.6.5
Operating SystemNetwork Security SoftwareYes (ML-KEM BIKE HQC Frodo IPsec PQC)Commercial Partial
Forward Edge-AI Isidore Quantum
Current
NetworkNetwork Security SoftwareYes (ML-KEM AES-256 GCM)Commercial Validated
Futurex Cloud
Current
CloudCloud Encryption GatewaysYes (ML-KEM ML-DSA PCI Validated)Commercial Partial
Futurex CryptoHub
June 2025 FW
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (PCI HSM Validated PQC)Commercial Partial
Futurex Vectera Plus
Current
Application Servers & SoftwarePayment Cryptography SystemsPlannedCommercial Validated
GlobalSign Digital Signing Service
Current
Application Servers & SoftwareDigital Signature SoftwareNoCommercial No
GnuPG
2.5.x
Application Servers & SoftwareEmail Encryption SoftwareYes (ML-KEM-768+X25519 Composite KEM)GPLv3 No
GnuTLS
3.8.12
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (ML-KEM X25519MLKEM768 ML-DSA via leancrypto)LGPLv2.1+ No
Go stdlib crypto/mlkem
1.26
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM Hybrid PQC TLS)BSD-3-Clause Partial
go-jose v4
4.1.3
Application Servers & SoftwareAPI Security and JWT LibrariesNoApache-2.0 No
Google ALTS
Current
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (NTRU-HRSS+X25519)Apache-2.0 No
Google Chrome
131+
Application Servers & SoftwareWeb BrowsersYes (ML-KEM)Freeware No
Google Cloud HSM
Current
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (via Cloud KMS PQC key types)Commercial (Google) Validated
Google Cloud KMS
Current
CloudCloud Key Management Service (KMS)Yes (ML-KEM GA / ML-DSA Preview)Commercial (Google) Validated
Google Cloud KMS (Cloud Gateway)
Current
CloudCloud Encryption GatewaysYes (ML-KEM GA / ML-DSA Preview)Commercial (Google) Validated
Google Tink
1.20.0
Application Servers & Software, Security StackCryptographic LibrariesPlanned (ML-DSA SLH-DSA ML-KEM in progress)Apache-2.0 Partial
GPG Code Signing
2.5.x
Application Servers & SoftwareCode Signing and Software IntegrityYes (ML-KEM-768+X25519 Composite KEM)GPLv3 No
HAProxy
3.1.x
Application Servers & SoftwareApplication ServersYes (via OpenSSL/liboqs)GPLv2/Commercial No
HashiCorp Vault
1.21.2
Security StackKey Management Systems (KMS)Yes (ML-DSA SLH-DSA in Transit experimental)BUSL-1.1/Enterprise Partial
Hitachi DoMobile
Ver.5
Application Servers & SoftwareRemote Access and VDI SoftwareYes (ML-KEM FIPS 203)Commercial Validated
HQC Algorithm
N/A
Application Servers & SoftwareCryptographic LibrariesYes (HQC)Apache-2.0 (PQClean) No
IBM Guardium Key Lifecycle Manager
5.1
Security StackKey Management Systems (KMS)Planned (via Guardium Cryptography Manager)Commercial (IBM) Validated
IBM Guardium Quantum Safe
Current
Security StackCryptographic Discovery PlatformsYes (Quantum-Safe Posture Management)Commercial (IBM) No
IBM Quantum Safe Toolkit
Current
Application Servers & SoftwarePost-Quantum Cryptography LibrariesYes (ML-KEM ML-DSA SLH-DSA Hybrid)Commercial/Apache-2.0 Validated
IBM Security Guardium Data Protection
12.x
Security StackData Security & ProtectionPlannedCommercial Validated
ID Quantique Cerberis XGR QKD
Cerberis XGR
Hardware & Secure ElementsQuantum Key Distribution SoftwareYes (QKD + PQC hybrid)Commercial No
ID Quantique Quantis QRNG
Quantis 2.0 (PCIe/USB)
Hardware & Secure ElementsQuantum Random Number Generator (QRNG)Yes (Quantum entropy source for PQC)Commercial Validated
Imperva WAFNew
Current
NetworkNetwork Security SoftwarePlannedCommercial No
Intel TDX (Trust Domain Extensions)
Xeon 5th Gen (Emerald Rapids)
Hardware & Secure ElementsHardware Security Module (HSM) SoftwarePlannedCommercial (Intel) No
iOS 26 / macOS 26
iOS 26.3 macOS 26.3
Operating SystemOperating SystemsYes (PQ3 HPKE with ML-KEM ML-DSA)Commercial Partial
ISARA Radiate
Current
CloudCryptographic Agility FrameworksYes (Core focus)Commercial Partial
JFrog Artifactory
Current
Application Servers & SoftwareCI/CD & Artifact ManagementPlannedCommercial Partial
jose4j
0.9.6
Application Servers & SoftwareAPI Security and JWT LibrariesNoApache-2.0 No
jsonwebtoken (auth0)
9.0.2
Application Servers & SoftwareAPI Security and JWT LibrariesNoMIT No
Juniper Junos OS
25.4R1
Operating SystemNetwork Operating SystemsYes (RFC 8784 PQC PSK ML-DSA)Commercial Partial
Keycloak
26.x
Security StackIdentity & Access Management (IAM)PlannedApache-2.0 No
Keyfactor AgileSec Analytics
2025 Release
Cloud, Security StackCryptographic Discovery PlatformsYes (Crypto Discovery and Agility)Commercial Partial
Keyfactor Command
24.x
Security StackCertificate Lifecycle ManagementYes (Hybrid PQC certificates)Commercial Validated
Keyfactor EJBCA
Enterprise 9.x
Security StackPublic Key Infrastructure (PKI) SoftwareYesCommercial Validated
Kong API Gateway
3.9.x
Application Servers & SoftwareAPI Security and JWT LibrariesPlanned (Gateway API proposals)Apache-2.0/Commercial No
leancrypto
Current
Application Servers & SoftwareCryptographic LibrariesYes (SHA-3 SHAKE Ascon HQC)GPL-2.0+/BSD/Leancrypto Partial
liboqs
0.15.0
Application Servers & Software, Security StackPost-Quantum Cryptography LibrariesYes (ML-KEM ML-DSA SLH-DSA BIKE HQC FrodoKEM Classic McEliece NTRU)MIT (mixed) No
liboqs-rust (oqs crate)
0.11.0
Application Servers & SoftwareCryptographic LibrariesYes (All liboqs algorithms)Apache-2.0/MIT No
LibreSSL
4.2.1
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (ML-KEM 768/1024 imported from BoringSSL - not yet public API)OpenBSD/ISC No
Linux IMA/EVM
6.13
Hardware & Secure ElementsSecure Boot and Firmware SecurityNoGPLv2 No
LUKS/dm-crypt
2.7.5
Application Servers & SoftwareDisk and File Encryption SoftwareNoGPLv2+ No
Marvell LiquidSecurity 2
LiquidSecurity 2
Hardware & Secure ElementsHardware Security Module (HSM) SoftwarePlannedCommercial Validated
Microsoft AD CS
Windows Server 2025
Security StackPublic Key Infrastructure (PKI) SoftwarePlannedCommercial Partial
Microsoft Edge
131+
Application Servers & SoftwareWeb BrowsersYes (ML-KEM)Freeware No
Microsoft Outlook S/MIME
Microsoft 365
Application Servers & SoftwareEmail Encryption SoftwarePlannedCommercial Partial
Microsoft SignTool
Windows SDK
Application Servers & SoftwareCode Signing and Software IntegrityPlannedCommercial Partial
Microsoft SymCrypt
v103.9.1
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA XMSS LMS)Commercial Partial
mlkem-native
1.0.0
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM)Apache-2.0/MIT/ISC No
MongoDB Queryable Encryption
8.0
DatabaseDatabase Encryption SoftwareNoSSPL/Commercial No
Mozilla Firefox
132+
Application Servers & SoftwareWeb BrowsersYes (ML-KEM)MPLv2 No
Mullvad VPN App
2025.14
NetworkVPN and IPsec SoftwareYes (WireGuard PQC)GPLv3 Partial
MySQL Enterprise Encryption
9.2
DatabaseDatabase Encryption SoftwareNoCommercial/GPLv2 No
Nginx
1.28.x (stable) / 1.29.x (mainline)
Application Servers & SoftwareApplication ServersYes (via OpenSSL/BoringSSL)2-clause BSD No
Nimbus JOSE+JWT
10.x
Application Servers & SoftwareAPI Security and JWT LibrariesNoApache-2.0 No
Node.js
22.x LTS
Application Servers & SoftwareApplication ServersNo (Awaiting OpenSSL upgrade)MIT No
Notary Project
1.2.x
Application Servers & SoftwareCode Signing and Software IntegrityNoApache-2.0 No
Nvidia cuPQC
Current
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA Optimized)Nvidia License No
Okta Integration Network
Current
Application Servers & SoftwareAPI Security and JWT LibrariesPlannedCommercial (SaaS) Partial
Okta Workforce Identity
Current
Security StackIdentity & Access Management (IAM)PlannedCommercial (SaaS) Partial
OpenSSH
10.2p1
Application Servers & SoftwareSSH Implementation SoftwareYes (mlkem768x25519-sha256 default)BSD No
OpenSSL
3.6.1
Application Servers & Software, Security StackCryptographic LibrariesYes (ML-KEM ML-DSA SLH-DSA in v3.5+)Apache-2.0 Validated
oqs-provider
0.11.0
Application Servers & SoftwarePost-Quantum Cryptography LibrariesYes (All liboqs algorithms)MIT No
Oracle Key Vault
21.13
Security StackKey Management Systems (KMS)No (Planned via Oracle ecosystem)Commercial (Oracle) Partial
Oracle TDE
23ai
DatabaseDatabase Encryption SoftwareNoCommercial Validated
Palo Alto PAN-OS
12.1 Orion
NetworkNetwork Security SoftwareYes (ML-KEM ML-DSA Cipher Proxy)Commercial Partial
Ping Identity PingFederate
12.x
Security StackIdentity & Access Management (IAM)PlannedCommercial Validated
PostgreSQL pgcrypto
17.2
DatabaseDatabase Encryption SoftwareNoPostgreSQL License No
PQClean
Current
Application Servers & SoftwarePost-Quantum Cryptography LibrariesYes (ML-KEM ML-DSA SLH-DSA HQC Falcon)Public Domain/CC0 No
pqcrypto
0.18.1
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA SLH-DSA + Pre-Standard)Apache-2.0/MIT No
pqm4
Current
Application Servers & SoftwareCryptographic LibrariesYes (NIST PQC Suite)Apache-2.0/MIT/CC0 No
PQShield PQSDK
Current
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA Falcon)Commercial Validated
Project Eleven Solana PQC
Testnet
Application Servers & SoftwareBlockchain and Cryptocurrency SoftwareYes (ML-DSA)Open Source No
Proton Mail
4.x
Application Servers & SoftwareEmail Encryption SoftwareYes (Kyber/ML-KEM Hybrid)Open Source (Server proprietary) No
Quantinuum Quantum Origin
Current
Hardware & Secure ElementsQuantum Random Number Generator (QRNG)Yes (Quantum entropy for PQC keys)Commercial (SaaS) No
Quantum Bridge Subsea QKD
Current
Hardware & Secure ElementsQuantum Key Distribution SoftwareYes (QKD + PQC hybrid)Commercial No
QuintessenceLabs qStream
qStream 200
Hardware & Secure ElementsQuantum Random Number Generator (QRNG)Yes (Quantum entropy source)Commercial Partial
QuSecure QuProtect R3
R3
CloudCryptographic Agility FrameworksYes (Crypto-Agility Platform)Commercial No
RustCrypto ml-dsa
0.0.4
Application Servers & SoftwareCryptographic LibrariesYes (ML-DSA)Apache-2.0/MIT No
RustCrypto ml-kem
0.3.0
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM)Apache-2.0/MIT No
RustCrypto slh-dsa
0.1.0
Application Servers & SoftwareCryptographic LibrariesYes (SLH-DSA)Apache-2.0/MIT No
rustls
0.23.36
Application Servers & SoftwareTLS/SSL Implementation SoftwareYes (via aws-lc-rs)Apache-2.0/MIT No
SafeLogic CryptoComply
Go v4.0
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA SLH-DSA Hybrid)Commercial Validated
Samsung S3SSE2A eSE
S3SSE2A
Hardware & Secure ElementsHardware Security and SemiconductorsYes (ML-KEM Hardware Accelerated)Commercial No
SandboxAQ AQtive Guard
Current
Cloud, Security StackCryptographic Discovery PlatformsYes (Cryptographic Discovery and Migration)Commercial No
SandboxAQ Sandwich
0.3.0+
Application Servers & SoftwareCryptographic LibrariesYes (Agile API liboqs backend)AGPL-3.0 No
SAP Cryptographic Library
8.6
Application Servers & SoftwareCryptographic LibrariesYes (ML-KEM ML-DSA)Commercial Validated
SEALSQ Quantum Shield
QS7001
Hardware & Secure ElementsHardware Security and SemiconductorsYes (Post-Quantum Trust Anchors)Commercial No
Sectigo Certificate Manager
Current
Security StackCertificate Lifecycle ManagementPlannedCommercial Partial
Securosys CloudHSMNew
Current
CloudCloud Hardware Security Module (HSM)Yes (ML-KEM ML-DSA SLH-DSA HSS-LMS XMSS)Commercial Validated
Securosys Primus HSM
Current
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (ML-KEM ML-DSA SLH-DSA HSS-LMS XMSS)Commercial Validated
Senetas CN7000 Series
CN7000 Series (2025)
NetworkNetwork EncryptorsYes (All NIST PQC algorithms)Commercial Partial
Signal
v0.87.4
Application Servers & SoftwareSecure Messaging and CommunicationYes (PQXDH + PQ-enhanced Double Ratchet)GPLv3 No
SignServer
6.x
Application Servers & SoftwareDigital Signature SoftwareYes (via modules)LGPL/Commercial Partial
sigstore/cosign
2.4.x
Application Servers & SoftwareCode Signing and Software IntegrityPlannedApache-2.0 No
smallstep Certificate Authority
0.28.x
Security StackPublic Key Infrastructure (PKI) SoftwareLimitedApache-2.0 No
Sonatype Nexus
Current
Application Servers & SoftwareCI/CD & Artifact ManagementPlannedCommercial No
Spring Security OAuth2
6.4.4
Application Servers & SoftwareAPI Security and JWT LibrariesPlannedApache-2.0 No
SQL Server TDE/Always Encrypted
SQL Server 2022
DatabaseDatabase Encryption SoftwareNoCommercial Validated
SSLyze
6.x
NetworkCryptographic Protocol AnalyzersYes (detection)AGPLv3 No
strongSwan
6.0.0
NetworkVPN and IPsec SoftwareYes (ML-KEM experimental)GPLv2 Partial
testssl.sh
3.0.x
NetworkCryptographic Protocol AnalyzersYes (detection)GPLv2 No
Thales CipherTrust Data Security Platform
2.x
Security StackData Security & ProtectionYes (ML-KEM ML-DSA via Luna HSM)Commercial Validated
Thales CipherTrust Manager
7.x
CloudCloud Encryption GatewaysYes (ML-KEM ML-DSA via Luna HSM)Commercial Validated
Thales High Speed Encryptor (HSE)
HSE Firmware PQC Release (Mar 2025)
NetworkNetwork EncryptorsYes (ML-KEM ML-DSA SLH-DSA)Commercial Validated
Thales Luna Cloud HSM (DPoD)
7.x
CloudCloud Hardware Security Module (HSM)No (PQC roadmap pending)Commercial Validated
Thales Luna HSM
7.9.1
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (ML-KEM FIPS 203 ML-DSA FIPS 204)Commercial Validated
Thales payShield 10K
payShield 10K
Application Servers & SoftwarePayment Cryptography SystemsPlannedCommercial Validated
Thunderbird + OpenPGP
128.x
Application Servers & SoftwareEmail Encryption SoftwareNoMPL-2.0 No
Toshiba QKD System
Multiplexed QKD v2
Hardware & Secure ElementsQuantum Key Distribution SoftwareYes (QKD + PQC hybrid)Commercial No
Tuta Mail
Current
Application Servers & SoftwareSecure Messaging and CommunicationYes (TutaCrypt Hybrid ML-KEM)GPLv3 Partial
U-Boot
2026.01
Hardware & Secure ElementsSecure Boot and Firmware SecurityNoGPLv2+ No
UEFI Forum Secure Boot
UEFI 2.10
Hardware & Secure ElementsSecure Boot and Firmware SecurityPlannedIndustry Standard No
Utimaco Athos
5.x
Application Servers & SoftwarePayment Cryptography SystemsPlannedCommercial Validated
Utimaco ESKM
8.54
Security StackKey Management Systems (KMS)Yes (ML-KEM ML-DSA LMS XMSS)Commercial Validated
Utimaco SecurityServer
5.x
Hardware & Secure ElementsHardware Security Module (HSM) SoftwareYes (PQC roadmap)Commercial Validated
Venafi
24.1+
Security StackPublic Key Infrastructure (PKI) SoftwareYes (Experimental ML-DSA and SLH-DSA)Commercial No
Venafi TLS Protect
24.1+
Security StackCertificate Lifecycle ManagementYes (Experimental ML-DSA SLH-DSA)Commercial No
Venafi Trust Protection Platform
Current
Security StackPublic Key Infrastructure (PKI) SoftwareYes (Crypto agility)Commercial Partial
VeraCrypt
1.26.24
Application Servers & SoftwareDisk and File Encryption SoftwareNoApache-2.0 No
Virtru Data Protection
Current
Security StackData Security & ProtectionPlannedCommercial No
Windows Secure Boot
Windows 11 24H2
Hardware & Secure ElementsSecure Boot and Firmware SecurityPlannedCommercial Partial
Windows Server 2025
Nov 2025 Update
Operating SystemOperating SystemsYes (ML-KEM ML-DSA in CNG)Commercial Partial
wolfBoot
2.7.0
Hardware & Secure ElementsSecure Boot and Firmware SecurityYes (ML-DSA)GPLv3/Commercial Validated
wolfSSH
1.4.22
Application Servers & SoftwareSSH Implementation SoftwareYes (Kyber Ed25519)GPLv3/Commercial No
wolfSSL
5.8.4
Application Servers & Software, Security StackTLS/SSL Implementation SoftwareYes (ML-DSA ML-KEM Kyber)GPLv3/Commercial Validated