⚛ Quantum Security Hub

NIST finalised PQC standards in August 2024. The migration window is open. These tools help you understand the threat, assess your exposure, and deploy post-quantum cryptography.

14
Tools
FIPS 203/204/205
Standards covered
2030–2035
Estimated CRQC window
Now
HNDL collection
⚠️

Harvest Now, Decrypt Later — The threat is present, not future. Nation-state adversaries are capturing encrypted network traffic today. If your data must stay secret for 10+ years (government records, medical data, financial archives, classified intelligence), it is at risk now — not when quantum computers arrive. Use Mosca's theorem: if your migration time + data secrecy period exceeds the estimated time to a CRQC, you need to act immediately.

🎯 Start Here — Threat & Urgency
Interactive⏱️

Quantum Threat Timeline

When will quantum break encryption? Expert timelines (NSA, NCSC, BSI), Mosca's theorem, data urgency by type, qubit progress tracker.

TimelineMoscaHNDL
Reference🔓

Vulnerable Algorithm Reference

Which algorithms are broken (RSA, ECC, DH), weakened (AES-128), or safe (AES-256, SHA-256). Mapped to TLS, SSH, VPN, JWT, code signing.

AlgorithmsShor'sGrover's
Interactive🏭

Sector Migration Urgency

Finance, healthcare, government — urgent now. SaaS, retail — more runway. Regulatory drivers and per-sector action priorities.

By sectorUrgencyCompliance
Reference🌐

Nation-State Programs

China, US, EU quantum investment and milestones. HNDL threat context. Intelligence assessment summaries for risk planning.

Threat intelChinaHNDL
🔐 Algorithm & Cryptography Reference
Reference📚

PQC Algorithm Reference

ML-KEM (FIPS 203), ML-DSA (FIPS 204), SLH-DSA (FIPS 205) — parameters, use cases, sizes, and performance.

FIPS 203FIPS 204FIPS 205
Reference🔑

Symmetric Crypto Safety

AES-256 is safe. AES-128 is weakened. SHA-256 is safe. 3DES is deprecated. Full table with Grover impact and migration actions.

AESSHAGrover's
Reference📦

PQC Open Source Libraries

liboqs, PQClean, Bouncy Castle, OQS-OpenSSL — algorithm support, audit status, and code examples in Python, Java, Rust, JS.

liboqsBouncy CastleCode
📋 Assessment & Planning
Interactive📊

PQC Readiness Assessment

Score your quantum cryptography exposure across 8 domains. Get a risk rating and prioritised remediation plan.

AssessmentScoringRisk
Reference📡

HNDL Threat Guide

How Harvest Now Decrypt Later attacks work, what data is at risk, what is protected by forward secrecy, and what needs action now.

HNDLForward secrecyRisk
Interactive🗂️

Crypto Inventory Builder

Build a risk-rated inventory of your RSA and ECC cryptographic assets. Identify migration priority and estimated effort.

InventoryRisk ratingMigration
Interactive🔧

Cryptographic Agility Assessment

Score each system as agile, semi-agile, or brittle. Estimate migration cost and complexity before the project begins.

AgilityAssessmentMigration cost
Reference🗺️

PQC Migration Roadmap

Three-phase plan: Discover (2024–2026), Hybrid Deploy (2025–2028), Full PQC (2027–2030). NIST and NSA CNSA 2.0 aligned.

RoadmapCNSA 2.03 phases
⚙️ Deployment & Implementation
Interactive🔒

PQC TLS & Protocol Config

Enable X25519Kyber768 hybrid in Nginx today. OpenSSH PQC setup. StrongSwan IKEv2 PQC VPN. Browser support status table.

NginxOpenSSHVPN
Reference📜

PKI & Certificate Migration

X.509 PQC support, hybrid certs, CA readiness status, ACME/Let's Encrypt path, step-by-step PKI migration guide.

X.509Hybrid certsCA migration
🔒

Tool