PQC Migration Workbench
Start from what you run — get a sequenced, quantum-safe plan aligned to NIST IR 8547 (Initial Public Draft) & CNSA 2.0.
Start from what you run — get a sequenced, quantum-safe plan aligned to NIST IR 8547 (Initial Public Draft) & CNSA 2.0.
What this means for you
- Executive / Business Leader
- "Which of your suppliers have committed" counts the vendors with a published PQC roadmap we hold a copy of against those with nothing public; the "Vendor roadmaps" and "Vendor risk" tabs give the detail per supplier.
- GRC / Risk & Compliance
- Product rows on "Replace what you own" carry a PQC status (GA, Partial, Roadmap, No PQC), a FIPS 140-3 badge and a verification badge (Verified, Pending Verification); the "Vendor risk" tab scores a "Certification gap".
- Developer / Engineer
- Under "Replace what you own", the "Crypto libraries & frameworks" domain lists the libraries; use "Filter products…" to narrow, and a product's detail shows its CPE and PURL identifiers.
- Security Architect
- "Replace what you own" lists assets — TLS key exchange, IPsec / IKEv2 VPN, X.509 cert signatures, HSM-protected keys — each with a decision (Drop-in, Hybrid config, Re-key, Track roadmap, Mitigate); "Plan & sequence" orders by exposure.
- Researcher / Academic
- "This catalog as a corpus of claims" states how many products are backed by a dated document versus the vendor's word; every product row shows its verification status and evidence warnings.
- Certification & Validation Engineer
- Product rows carry a PQC status, a FIPS 140-3 badge and a verification badge; a product's detail names the stage and flags PQC that is CAVP-validated but outside the module certificate.
- IT Ops / DevOps
- The readiness panel shows the share of your assets with a GA path, the "HNDL-urgent" count, the "Nearest CNSA deadline" and your "Next move" with its wave; "Export plan + CBOM" on "Plan & sequence" downloads the plan.
- Curious Explorer
- "Who has already moved" says how many tracked products support post-quantum cryptography with a document proving it, and where it landed first; "Add what you run" starts a plan of your own.
A curated catalogue of 888 products — not an exhaustive list of the market. 628 products with PQC capability or a PQC plan (472 available · 94 partial · 63 planned or on a roadmap), and 252 migration-baseline products tracked because they matter to a PQC migration but have no confirmed PQC support yet. The two groups are counted separately.
Build your migration plan
Pick the cryptography you run — TLS, VPN, SSH, certs and more — to get a sequenced, quantum-safe plan aligned to NIST IR 8547 (Initial Public Draft) & CNSA 2.0.
What you run — pick to see replacements
Foundations & infrastructure
Viewing: TLS key exchange
TLS key exchange
Drop-inPublic web servers, load balancers, API gateways
Enable hybrid X25519+ML-KEM-768 key exchange on edge TLS terminators. Drop-in for modern stacks (OpenSSL 3.5+, BoringSSL, recent CDNs) — no application change required.
Products that replace this · 9 in catalog
300 additional catalog entries are currently hidden pending downloadable proof.
TLS/SSL Implementation Software
BoringSSL FIPS.md lists BoringCrypto FIPS 140 validation certificate lineage (#2964, #3318, #3678, #3753, #4156, #4407, #4735, #4953, #5104, #5244). These validated modules cover classical primitives only; PQC (ML-KEM/ML-DSA/SLH-DSA) is implemented in BoringSSL outside the FIPS-validated boundary. BoringSSL has shipped ML-KEM since 2024 (used by Chrome) and ML-DSA since early 2025; it is a rolling/continuous release with no fixed version, matching catalog. Published 4 months ago.
TLS/SSL Implementation Software
wolfSSL 5.9.0 release announcement: with the addition of SLH-DSA (FIPS 205), wolfSSL now supports the full NIST PQC signature portfolio — ML-DSA (FIPS 204), FALCON, and SLH-DSA — plus stateful-hash LMS/HSS and XMSS/XMSS^MT, and ML-KEM (FIPS 203) for key establishment. New wolfCrypt FIPS 140-3 cert incorporates ML-KEM, ML-DSA and SLH-DSA. Matches catalog's 5.9.0 / full FIPS 203/204/205 + LMS/XMSS + Falcon + hybrid TLS 1.3 description. Published 7 months ago.
TLS/SSL Implementation Software
GitHub aws/s2n-tls releases: latest is v1.7.3 — 'Add pure MLKEM1024 to AWS-CRT-SDK PQ policies', plus an ML-DSA key type validation fix. Prior milestones: v1.7.1 deleted all code that references Kyber; v1.6.4 (weekly release for Jan 5, 2026). PQC support includes hybrid X25519MLKEM768 and pure ML-KEM-1024. Published 5 months ago.
TLS/SSL Implementation Software
GnuTLS official news page: latest 3.8.x release is 3.8.13 (April 29, 2026), succeeding 3.8.12 (Feb 9, 2026). PQC lineage: ML-KEM hybrid key exchange (X25519MLKEM768, SecP256r1MLKEM768) added in 3.8.8 (Nov 2024); experimental ML-DSA (FIPS 204) signatures and leancrypto PQC backend added in 3.8.9 (Feb 2025). 3.8.13 also fixes multiple CVEs. Published 8 months ago.
TLS/SSL Implementation Software
Google Cloud blog (2025-10-30) states: 'We've migrated key exchanges for internal traffic to ML-KEM. All Google and select Google Cloud-native services are safeguarded by default using Google Cloud network encryption, using ML-KEM for cryptographic key exchange.' This supersedes the 2022 ALTS blog which described hybrid NTRU-HRSS + X25519. The catalog's pqc_support field already says ML-KEM, but the capability_description still cites NTRU-HRSS, and the catalog proof_url points to the outdated 2022 NTRU-HRSS post. Published 12 months ago.
TLS/SSL Implementation Software
Published 16 months ago.
TLS/SSL Implementation Software
LibreSSL official releases page: latest is 4.3.2 (May 25, 2026); branch history 4.3.1/4.3.0 (Apr 18, 2026), 4.2.1 (Oct 30, 2025), 4.2.0 (Oct 14, 2025). ChangeLog/coverage: 4.2.0 added public ML-KEM API and ML-KEM benchmarks; 4.3.x added MLKEM768_X25519 TLS key share support. Published 5 months ago.
TLS/SSL Implementation Software
Rustls 0.23.22+ PQ key exchange via ML-KEM hybrid X25519+Kyber. Published 2 years ago — old enough that the product may have moved on since. Worth re-checking against the vendor before you rely on it.
TLS/SSL Implementation Software
Mbed TLS roadmap (mbed-tls.readthedocs.io): 2025 CQ4 'ML-DSA Investigation'; 2026 CQ1 'Mbed TLS 4.1, TF-PSA-Crypto 1.1 LTS release' and 'ML-DSA Prototype'; 2026 CQ2 'ML-DSA - Initial support'; Future 'ML-KEM Support'. Completed: 'Mbed TLS 4.0, TF-PSA-Crypto 1.0 release'. We hold the document but not its publication date, so we cannot say how current it is.
Related content
Next step
Build the roadmapThe Roadmap Builder sequences the migration the catalogue rows describe.