PQC Migration Workbench

Start from what you run — get a sequenced, quantum-safe plan aligned to NIST IR 8547 (Initial Public Draft) & CNSA 2.0.

What this means for you

Executive / Business Leader
"Which of your suppliers have committed" counts the vendors with a published PQC roadmap we hold a copy of against those with nothing public; the "Vendor roadmaps" and "Vendor risk" tabs give the detail per supplier.
GRC / Risk & Compliance
Product rows on "Replace what you own" carry a PQC status (GA, Partial, Roadmap, No PQC), a FIPS 140-3 badge and a verification badge (Verified, Pending Verification); the "Vendor risk" tab scores a "Certification gap".
Developer / Engineer
Under "Replace what you own", the "Crypto libraries & frameworks" domain lists the libraries; use "Filter products…" to narrow, and a product's detail shows its CPE and PURL identifiers.
Security Architect
"Replace what you own" lists assets — TLS key exchange, IPsec / IKEv2 VPN, X.509 cert signatures, HSM-protected keys — each with a decision (Drop-in, Hybrid config, Re-key, Track roadmap, Mitigate); "Plan & sequence" orders by exposure.
Researcher / Academic
"This catalog as a corpus of claims" states how many products are backed by a dated document versus the vendor's word; every product row shows its verification status and evidence warnings.
Certification & Validation Engineer
Product rows carry a PQC status, a FIPS 140-3 badge and a verification badge; a product's detail names the stage and flags PQC that is CAVP-validated but outside the module certificate.
IT Ops / DevOps
The readiness panel shows the share of your assets with a GA path, the "HNDL-urgent" count, the "Nearest CNSA deadline" and your "Next move" with its wave; "Export plan + CBOM" on "Plan & sequence" downloads the plan.
Curious Explorer
"Who has already moved" says how many tracked products support post-quantum cryptography with a document proving it, and where it landed first; "Add what you run" starts a plan of your own.

A curated catalogue of 888 products — not an exhaustive list of the market. 628 products with PQC capability or a PQC plan (472 available · 94 partial · 63 planned or on a roadmap), and 252 migration-baseline products tracked because they matter to a PQC migration but have no confirmed PQC support yet. The two groups are counted separately.

Build your migration plan

Pick the cryptography you run — TLS, VPN, SSH, certs and more — to get a sequenced, quantum-safe plan aligned to NIST IR 8547 (Initial Public Draft) & CNSA 2.0.

Viewing: TLS key exchange

TLS key exchange

Drop-in

Public web servers, load balancers, API gateways

RSA-2048 / X25519ML-KEM-7682025 · External-facing — highest HNDL exposure

Enable hybrid X25519+ML-KEM-768 key exchange on edge TLS terminators. Drop-in for modern stacks (OpenSSL 3.5+, BoringSSL, recent CDNs) — no application change required.

Products that replace this · 9 in catalog

300 additional catalog entries are currently hidden pending downloadable proof.

Next step

Build the roadmap

The Roadmap Builder sequences the migration the catalogue rows describe.